From a.peacock at chime.ucl.ac.uk Tue May 1 08:11:34 2007 From: a.peacock at chime.ucl.ac.uk (Anthony Peacock) Date: Tue May 1 08:12:12 2007 Subject: A lot of spam getting through In-Reply-To: <04D932B0071FE34FA63EBB1977B48D1502816DB1@woodenex.woodmaclaw.local> References: <04D932B0071FE34FA63EBB1977B48D1502816DB1@woodenex.woodmaclaw.local> Message-ID: <4636E826.1070104@chime.ucl.ac.uk> Billy A. Pumphrey wrote: > Hello everyone. I am having quite a few spam get through. I thought > that I had quite a few things installed and configured correctly. > Actually they used to work really well then when I had to rebuild bayes > as there were too many FP and turn off RBL's, then a lot of spam are > getting through. Somewhere around 50-100 per user are seemingly getting > through on a weekend. I have put down as much information as I thought > about for my configuration. I am looking for recommendations to > recrease my block rate. Please let me know if I left any information > out. jThank you. > > After looking at a few emails I can see that pyzor and DCC and bayes are > scoring: > Score Matching Rule Description > cached not > score=24.094 > 6 required > autolearn=spam > 2.17 DCC_CHECK Listed in DCC (http://rhyolite.com/anti-spam/dcc/) > 0.33 FH_DATE_ISNT_2006 > 0.77 FH_DATE_ISNT_200X > 0.40 FH_LEADINGPREP > 0.71 FS_START_BUY > 3.70 PYZOR_CHECK Listed in Pyzor (http://pyzor.sf.net/) > 0.61 SARE_SXLIFE Talks about your sex life > 3.81 URIBL_AB_SURBL Contains an URL listed in the AB SURBL blocklist > 4.09 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist > 3.01 URIBL_OB_SURBL Contains an URL listed in the OB SURBL blocklist > 4.50 URIBL_SC_SURBL Contains an URL listed in the SC SURBL blocklist Are these the scores that your system gives to one of the emails that are gettig through? If so that scored 24 points. So this email should have been filtered. This suggests to me that the problem isn't with SA but with something in your MailScanner settings. If these aren't the scores from one of the emails that are getting through can you save an email to a text file and send the output of the following command: spamassassin --test-mode < email.txt -- Anthony Peacock CHIME, Royal Free & University College Medical School WWW: http://www.chime.ucl.ac.uk/~rmhiajp/ "If you have an apple and I have an apple and we exchange apples then you and I will still each have one apple. But if you have an idea and I have an idea and we exchange these ideas, then each of us will have two ideas." -- George Bernard Shaw From glenn.steen at gmail.com Tue May 1 10:12:19 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue May 1 10:12:23 2007 Subject: Postfix milter with MailScanner , extra 0 problem In-Reply-To: <20070430193605.B02521224A1@mx-b.vdnet.lt> References: <1177340488.25796.153.camel@localhost.localdomain> <223f97700704230818t3ffae2e3u1f28b09aad5d454@mail.gmail.com> <1177343963.25796.159.camel@localhost.localdomain> <223f97700704240216u4cbd4cbey1df9503fa3a2c7f6@mail.gmail.com> <20070430193605.B02521224A1@mx-b.vdnet.lt> Message-ID: <223f97700705010212t3356ff62s4d7c93c10f2344f4@mail.gmail.com> On 30/04/07, Nerijus Baliunas wrote: > On Tue, 24 Apr 2007 11:16:23 +0200 Glenn Steen wrote: > > > These patches are for use with Postfix 2.3... Although PFDiskStore.pm > > will handle the body edits we need do some check to see that all the > > body is there by spinning through the p records in ReadQf (in > > Postfix.pm)... Or something smarter (I'm open to sugegstions:-). > > If you need that (and run PF 2.4) I can probably find my patch for > > that too ... somewhere...:-) > > BTW, can I use these patches with PF 2.4 if my milter modifies headers > only (not body)? Or should I need your patch for 2.4? > > Regards, > Nerijus They should work OK for milters only modifying headers using PF 2.4 ... There isn't much difference between the patches, just the verification part in ReadQf (IIRC:-)... So go ahead... Please report any problems directly to me and I'll try see if there's anything I can do;-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Tue May 1 10:16:02 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue May 1 10:16:05 2007 Subject: New Stable Release, Clamd and Postfix? In-Reply-To: References: <4635F88E.4040509@slackadelic.com> Message-ID: <223f97700705010216s6071bf87hd8a1a514ed72a4d1@mail.gmail.com> On 30/04/07, Scott Silva wrote: > Matt Hayes spake the following on 4/30/2007 7:09 AM: > > Paul Hutchings wrote: > >> My MailScanner box runs quite nicely running the previous stable version > >> 4.58.9. > >> > >> I'm suffering from the slow clamscan performance issue, and noticed the > >> new stable release supports clamd (which I'm running). > >> > >> Having looked at the manual it appears it should simply be a case of run > >> the installer script, then use upgrade_MailScanner_conf to update > >> MailScanner.conf with the new settings. > >> > >> Not having ever upgraded MailScanner before, I'd sooner ask the question > >> than get caught out - is this all there is to it (barring something > >> totally unforeseen happening)? > >> > >> Also as I run Postfix I have my MailScanner set to run as user "postfix" > >> as per the docs. Will this cause me a problem (or can someone point me > >> where to go to RTFM?) > >> > >> Cheers, > >> Paul > >> > > > > Paul, > > > > That is basically all there is to it. However, if you are like me, > > anything custom that you've added like %rules-dir% files will more than > > likely have to be re-entered in. If you use Mailwatch, some things with > > quarantine configuration to allow for released messages to bypass spam > > checks may have to be reconfigured. > > > > The great thing about the upgrade of mailscanner.. it leaves your old > > installation in place :) > > > > -Matt > > > > > The last statement isn't totally true. The rpm version will replace the > running files. I have a backup script I run that copies the running system > into a new directory and then I can upgrade or go back. > And this is actually well documented (sort of:) in the MAQ and wiki ... Go have a look, it's rather prominetly visible;-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From grpprod at gmail.com Tue May 1 10:58:19 2007 From: grpprod at gmail.com (G P) Date: Tue May 1 10:58:20 2007 Subject: Latest MS keeps restarting Message-ID: <773fecad0705010258k6a71712fmf85ec9638b766bb4@mail.gmail.com> Hi all, I just installed latest version, and it keeps restarting its children every 1 minute. This wasn't happening with the previous version. I have just switched back to 4.58.9, keeping the same configuration, and problem seems solved now. Any comments would be appreciated. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070501/443b739c/attachment.html From raymond at prolocation.net Tue May 1 11:00:59 2007 From: raymond at prolocation.net (Raymond Dijkxhoorn) Date: Tue May 1 11:00:58 2007 Subject: Latest MS keeps restarting In-Reply-To: <773fecad0705010258k6a71712fmf85ec9638b766bb4@mail.gmail.com> References: <773fecad0705010258k6a71712fmf85ec9638b766bb4@mail.gmail.com> Message-ID: Hi! > I just installed latest version, and it keeps restarting its children every > 1 minute. This wasn't happening with the previous version. I have just > switched back to 4.58.9, keeping the same configuration, and problem seems > solved now. Run in debug mode pls, you most likely have a issue with the new one thats making it restart... Bye, Raymond. From martinh at solidstatelogic.com Tue May 1 11:06:23 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Tue May 1 11:06:39 2007 Subject: Latest MS keeps restarting In-Reply-To: <773fecad0705010258k6a71712fmf85ec9638b766bb4@mail.gmail.com> Message-ID: Hi What O/S and what virus scanners are being used...... -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of G P > Sent: 01 May 2007 10:58 > To: mailscanner@lists.mailscanner.info > Subject: Latest MS keeps restarting > > Hi all, > I just installed latest version, and it keeps restarting its children > every 1 minute. This wasn't happening with the previous version. I have > just switched back to 4.58.9, keeping the same configuration, and problem > seems solved now. > > Any comments would be appreciated. ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From grpprod at gmail.com Tue May 1 11:32:59 2007 From: grpprod at gmail.com (G P) Date: Tue May 1 11:33:02 2007 Subject: Latest MS keeps restarting In-Reply-To: References: <773fecad0705010258k6a71712fmf85ec9638b766bb4@mail.gmail.com> Message-ID: <773fecad0705010332l15f21b31sf632839259b7bb9d@mail.gmail.com> > > What O/S and what virus scanners are being used...... > > It runs under CentOS 3.8, and clamavmodule is used. Haven't run it in debug mode yet, I will do and let the list of the results. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070501/101605c2/attachment.html From dave.list at pixelhammer.com Tue May 1 13:32:18 2007 From: dave.list at pixelhammer.com (DAve) Date: Tue May 1 13:33:40 2007 Subject: Slightly OT: How do you deal with domains you forward to who consider you a spammer based in user reports? In-Reply-To: <57573D714A832C43B9D80EAFBDA48D03057BDAC1@inex3.herffjones.hj-int> References: <57573D714A832C43B9D80EAFBDA48D03057BDAB2@inex3.herffjones.hj-int> <46365924.7000202@pixelhammer.com> <57573D714A832C43B9D80EAFBDA48D03057BDAC1@inex3.herffjones.hj-int> Message-ID: <46373352.3030904@pixelhammer.com> Furnish, Trever G wrote: >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of DAve >> Sent: Monday, April 30, 2007 5:01 PM >> To: MailScanner discussion >> Subject: Re: Slightly OT: How do you deal with domains you >> forward to who consider you a spammer based in user reports? > >> An exasperating situation. We have been dealing with the same >> issue for quite a awhile. Our current solution is to use >> verp, if AOL returns the message in a scomp report we remove >> the users email address and add it to a subscriber black >> list. That email address is never allowed to subscribe to >> another mail list we host. So far, no client has complained, >> AOL is happy, our scomp reports have plummeted. > > Are you using verp only in conjunction with mailing lists? > Unfortunately my forwards aren't going through any kind of mailing list > manager -- they're just coming in and getting forwarded immediately back > out, since each address goes to an individual. The forwards were set up > so that outside sales reps who don't pick up mail from out systems could > still have a "company" email address -- a practice I'm hoping to end, > but which I expect to continue. Yes, verp just for the mail lists for now. We haven't had to go chase down a forwarding solution, yet. I am hoping we don't have to, but that will be my solution if needed. > >> You might see if there is a way to inject something into the >> headers that AOL will no redact. Then, if the user reports >> their forwarded mail as spam, simply stop forwarding. > > That might actually make a big difference. Any ideas on how to > implement it, short of placing a footer in the body of the message? Not really ;^), but if it comes down to it I will have to find something. Likely I will look at removing the forward and letting the message deliver locally, then have a cron job read the mailbox, add the header, resend the mail. Ideally, we provide webmail over ssh, imap, pop, and smtp-auth. So if it comes up again I will suggest that forwarding is not needed and the possibility that business correspondence is subject to family review and accidental use. Social solutions are almost always the better choice, training the user is harder than programming, but infinitely better in the long run. >I've noted that aol "redacts" anything that looks like an email address > in the headers, but not the body, but if I could insert a header that > says, for example, "X-HJ-MailScanner-To: foo at foo dot com", they > probably wouldn't redact that. I suppose I could modify that bit of > code in mailscanner that adds that header...hmmm... Painful for > upgrades, but better than nothing... scomp reports are kinda funny, some are redacted some are not. We have even gotten scomp reports from a netblock we don't own. > >> Not the >> best solution business wise, but the safe option for certain. >> If the user wants the authority to declare spam/not spam, >> they should be responsible for the actions they set into motion. >> >> In the end we all want to make the client happy, but >> protecting your network must come first. You can't make a >> client happy if no one will accept your server's mail. > > Good points and it's nice to know I'm not the only one who feels that > way. > DAve -- Three years now I've asked Google why they don't have a logo change for Memorial Day. Why do they choose to do logos for other non-international holidays, but nothing for Veterans? Maybe they forgot who made that choice possible. From bpumphrey at woodmclaw.com Tue May 1 14:36:52 2007 From: bpumphrey at woodmclaw.com (Billy A. Pumphrey) Date: Tue May 1 14:36:56 2007 Subject: A lot of spam getting through In-Reply-To: Message-ID: <04D932B0071FE34FA63EBB1977B48D1502816F72@woodenex.woodmaclaw.local> > > > 2) Install Fuzzyocr which works well at detecting the image spams > > > (http://www.gbnetwork.co.uk/mailscanner/ for the URL's) > > > > I got this installed and a lint shows OK. > > Have a look at http://www.freespamfilter.org/forum/viewforum.php?f=25 > That forum although quiet has some good tips for additional fuzzyocr > configuration such as additional words and scansets. Did you install gocr > and ocrad OCR plugins? I followed the instructions and then when I was double checking that I had what you mentioned, I realized that I downloaded and installed the 2.3b version. I will now have to go back and install the 3.5.1 version. I hope that this is as simple as running the install of the new version. I really don't know how to Uninstall the old version. From alex at nkpanama.com Tue May 1 14:46:18 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Tue May 1 14:47:03 2007 Subject: A lot of spam getting through In-Reply-To: <04D932B0071FE34FA63EBB1977B48D1502816E99@woodenex.woodmaclaw.local> References: <04D932B0071FE34FA63EBB1977B48D1502816E99@woodenex.woodmaclaw.local> Message-ID: <463744AA.40504@nkpanama.com> Billy A. Pumphrey wrote: > > Ok, I had edited this file but it points to my local domain windows dns > server. Does that mean that I should change it to something else? > Definitely. Feel free to install a more respectable operating system on it at any time. ;-) In regards to your actual problem, you may want to install a caching nameserver on your MailScanner box and point resolv.conf to 127.0.0.1 (and maybe something else, like your ISP's DNS servers as secondary, just in case). Unless your setup *requires* it, you shouldn't have to ask for DNS information from the *ugh* Windows machine ;-) From campbell at cnpapers.com Tue May 1 15:07:13 2007 From: campbell at cnpapers.com (Steve Campbell) Date: Tue May 1 15:07:29 2007 Subject: A lot of spam getting through References: <04D932B0071FE34FA63EBB1977B48D1502816E99@woodenex.woodmaclaw.local> <463744AA.40504@nkpanama.com> Message-ID: <002901c78bfa$045b5dd0$0705000a@ddf5dw71> ----- Original Message ----- From: "Alex Neuman van der Hans" To: "MailScanner discussion" Sent: Tuesday, May 01, 2007 9:46 AM Subject: Re: A lot of spam getting through > Billy A. Pumphrey wrote: >> >> Ok, I had edited this file but it points to my local domain windows dns >> server. Does that mean that I should change it to something else? >> > > Definitely. Feel free to install a more respectable operating system on it > at any time. ;-) > Just curious now. What OS are you running on this machine currently? What does your Windows DNS server manage? Steve From bpumphrey at woodmclaw.com Tue May 1 15:11:09 2007 From: bpumphrey at woodmclaw.com (Billy A. Pumphrey) Date: Tue May 1 15:11:12 2007 Subject: A lot of spam getting through In-Reply-To: Message-ID: <04D932B0071FE34FA63EBB1977B48D1502816FAA@woodenex.woodmaclaw.local> > Have a look at http://www.freespamfilter.org/forum/viewforum.php?f=25 > That forum although quiet has some good tips for additional fuzzyocr > configuration such as additional words and scansets. Did you install gocr > and ocrad OCR plugins? > Ok, after I downloaded it, I remembered and seen that they are just files to be put in the directories. As far as the installs, I installed: I had some of the things installed before I upgraded fuzzy, then I installed more. I went through the instructions seemingly thoroughly for the install of the 3.5.1 version. I installed a ton of stuff, well seems like it. The only thing that I did not install was the DBD::mysql module part. I install the optional MLDBM and other. I am now getting some errors in the lint test. I have not enabled the hashing yet. [8894] warn: FuzzyOcr: Cannot find executable for giftopnm 0.00013 [8894] warn: FuzzyOcr: Cannot find executable for jpegtopnm 0.00012 [8894] warn: FuzzyOcr: Cannot find executable for pngtopnm 0.00012 [8894] warn: FuzzyOcr: Cannot find executable for bmptopnm 0.00012 [8894] warn: FuzzyOcr: Cannot find executable for tifftopnm 0.00012 [8894] warn: FuzzyOcr: Cannot find executable for ppmhist 0.00012 [8894] warn: FuzzyOcr: Cannot find executable for pamfile 0.00012 [8894] info: FuzzyOcr: Using ocrad => /usr/local/bin/ocrad 0.00017 [8894] info: FuzzyOcr: Using gocr => /usr/local/bin/gocr 0.00012 [8894] warn: FuzzyOcr: Cannot find executable for pnmnorm 0.0001 [8894] warn: FuzzyOcr: Cannot find executable for pnminvert 0.0001 [8894] warn: FuzzyOcr: Cannot find executable for pamthreshold 0.00011 [8894] warn: FuzzyOcr: Cannot find executable for ppmtopgm 0.00012 [8894] warn: FuzzyOcr: Cannot find executable for pamtopnm 0.00012 [8894] warn: FuzzyOcr: Cannot find executable for tesseract Man, there are a lot of entries for the fuzzy in the lint. Do you have a quick answer on how to fix the above? From bpumphrey at woodmclaw.com Tue May 1 15:12:17 2007 From: bpumphrey at woodmclaw.com (Billy A. Pumphrey) Date: Tue May 1 15:12:20 2007 Subject: A lot of spam getting through In-Reply-To: <463744AA.40504@nkpanama.com> Message-ID: <04D932B0071FE34FA63EBB1977B48D1502816FAC@woodenex.woodmaclaw.local> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Alex Neuman van der Hans > Sent: Tuesday, May 01, 2007 9:46 AM > To: MailScanner discussion > Subject: Re: A lot of spam getting through > > Billy A. Pumphrey wrote: > > > > Ok, I had edited this file but it points to my local domain windows dns > > server. Does that mean that I should change it to something else? > > > > Definitely. Feel free to install a more respectable operating system on > it at any time. ;-) > And what would that be? :) From bpumphrey at woodmclaw.com Tue May 1 15:13:11 2007 From: bpumphrey at woodmclaw.com (Billy A. Pumphrey) Date: Tue May 1 15:13:14 2007 Subject: A lot of spam getting through In-Reply-To: <002901c78bfa$045b5dd0$0705000a@ddf5dw71> Message-ID: <04D932B0071FE34FA63EBB1977B48D1502816FAD@woodenex.woodmaclaw.local> > > What OS are you running on this machine currently? What does your Windows > DNS server manage? > > Steve > > > -- CentOS 4.4 From mogens at fumlersoft.dk Tue May 1 15:13:08 2007 From: mogens at fumlersoft.dk (Mogens Melander) Date: Tue May 1 15:14:01 2007 Subject: A lot of spam getting through In-Reply-To: <463744AA.40504@nkpanama.com> References: <04D932B0071FE34FA63EBB1977B48D1502816E99@woodenex.woodmaclaw.local> <463744AA.40504@nkpanama.com> Message-ID: <2465.90.184.17.152.1178028788.squirrel@mail.fumlersoft.dk> On Tue, May 1, 2007 15:46, Alex Neuman van der Hans wrote: > Billy A. Pumphrey wrote: >> >> Ok, I had edited this file but it points to my local domain windows dns >> server. Does that mean that I should change it to something else? >> > > Definitely. Feel free to install a more respectable operating system on > it at any time. ;-) > > In regards to your actual problem, you may want to install a caching > nameserver on your MailScanner box and point resolv.conf to 127.0.0.1 > (and maybe something else, like your ISP's DNS servers as secondary, > just in case). Unless your setup *requires* it, you shouldn't have to > ask for DNS information from the *ugh* Windows machine ;-) I think something like dnsmasq could be used for this. -- Later Mogens Melander +45 40 85 71 38 +66 870 133 224 -- This message has been scanned for viruses and dangerous content by OpenProtect(http://www.openprotect.com), and is believed to be clean. From bpumphrey at woodmclaw.com Tue May 1 15:17:58 2007 From: bpumphrey at woodmclaw.com (Billy A. Pumphrey) Date: Tue May 1 15:18:00 2007 Subject: A lot of spam getting through In-Reply-To: Message-ID: <04D932B0071FE34FA63EBB1977B48D1502816FBD@woodenex.woodmaclaw.local> > 4) Add this following custom rule to match those spams which just link to > a > picture. > uri GRB_Imagehost > /\.(?:|imageshack|2and2|afreeimagehost|imagehosting)\.(?:com|net|us)/i > score GRB_Imagehost 1.0 > describe GRB_Imagehost Linking to free image hosting service > Well I thought there were no error. Please excuse me for being dense. I am getting the below. Maybe I am seeing word wrap on your rule and it is messing me up. I put the rule in as I see it above. Each line starting with: Uri /\. Score Describe Is that correct? [8894] warn: config: SpamAssassin failed to parse line, no value provided for "uri", skipping: uri GRB_Imagehost 0.05375 [8894] warn: config: failed to parse line, skipping: /\.(?:|imageshack|2and2|afreeimagehost|imagehosting)\.(?:com|net|us)/i 0.00016 [8894] warn: config: warning: description exists for non-existent rule GRB_Imagehost 0.39171 [8894] warn: config: warning: score set for non-existent rule GRB_Imagehost From list-mailscanner at linguaphone.com Tue May 1 15:18:35 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue May 1 15:18:53 2007 Subject: A lot of spam getting through In-Reply-To: <04D932B0071FE34FA63EBB1977B48D1502816FAA@woodenex.woodmaclaw.local> References: <04D932B0071FE34FA63EBB1977B48D1502816FAA@woodenex.woodmaclaw.local> Message-ID: <1178029114.14746.28.camel@gblades-suse.linguaphone-intranet.co.uk> On Tue, 2007-05-01 at 15:11, Billy A. Pumphrey wrote: > > Have a look at http://www.freespamfilter.org/forum/viewforum.php?f=25 > > That forum although quiet has some good tips for additional fuzzyocr > > configuration such as additional words and scansets. Did you install > gocr > > and ocrad OCR plugins? > > > > Ok, after I downloaded it, I remembered and seen that they are just > files to be put in the directories. As far as the installs, I > installed: > > I had some of the things installed before I upgraded fuzzy, then I > installed more. I went through the instructions seemingly thoroughly > for the install of the 3.5.1 version. I installed a ton of stuff, well > seems like it. The only thing that I did not install was the DBD::mysql > module part. I install the optional MLDBM and other. I am now getting > some errors in the lint test. > > I have not enabled the hashing yet. > > [8894] warn: FuzzyOcr: Cannot find executable for giftopnm 0.00013 > [8894] warn: FuzzyOcr: Cannot find executable for jpegtopnm 0.00012 > [8894] warn: FuzzyOcr: Cannot find executable for pngtopnm 0.00012 > [8894] warn: FuzzyOcr: Cannot find executable for bmptopnm 0.00012 > [8894] warn: FuzzyOcr: Cannot find executable for tifftopnm 0.00012 > [8894] warn: FuzzyOcr: Cannot find executable for ppmhist 0.00012 > [8894] warn: FuzzyOcr: Cannot find executable for pamfile 0.00012 > [8894] info: FuzzyOcr: Using ocrad => /usr/local/bin/ocrad 0.00017 > [8894] info: FuzzyOcr: Using gocr => /usr/local/bin/gocr 0.00012 > [8894] warn: FuzzyOcr: Cannot find executable for pnmnorm 0.0001 > [8894] warn: FuzzyOcr: Cannot find executable for pnminvert 0.0001 > [8894] warn: FuzzyOcr: Cannot find executable for pamthreshold 0.00011 > [8894] warn: FuzzyOcr: Cannot find executable for ppmtopgm 0.00012 > [8894] warn: FuzzyOcr: Cannot find executable for pamtopnm 0.00012 > [8894] warn: FuzzyOcr: Cannot find executable for tesseract > > Man, there are a lot of entries for the fuzzy in the lint. Do you have > a quick answer on how to fix the above? It looks as though you dont have the netpbm package installed. You may have the netpbm rpm installed but that is only the libraries. Redhat for example also has netpbm-progs which you also need to install. From list-mailscanner at linguaphone.com Tue May 1 15:21:33 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue May 1 15:21:40 2007 Subject: A lot of spam getting through In-Reply-To: <04D932B0071FE34FA63EBB1977B48D1502816FBD@woodenex.woodmaclaw.local> References: <04D932B0071FE34FA63EBB1977B48D1502816FBD@woodenex.woodmaclaw.local> Message-ID: <1178029293.14744.31.camel@gblades-suse.linguaphone-intranet.co.uk> On Tue, 2007-05-01 at 15:17, Billy A. Pumphrey wrote: > > 4) Add this following custom rule to match those spams which just link > to > > a > > picture. > > uri GRB_Imagehost > > /\.(?:|imageshack|2and2|afreeimagehost|imagehosting)\.(?:com|net|us)/i > > score GRB_Imagehost 1.0 > > describe GRB_Imagehost Linking to free image hosting service > > > > Well I thought there were no error. Please excuse me for being dense. > I am getting the below. Maybe I am seeing word wrap on your rule and it > is messing me up. I put the rule in as I see it above. Each line > starting with: > Uri > /\. > Score > Describe > > Is that correct? > > [8894] warn: config: SpamAssassin failed to parse line, no value > provided for "uri", skipping: uri GRB_Imagehost 0.05375 > [8894] warn: config: failed to parse line, skipping: > /\.(?:|imageshack|2and2|afreeimagehost|imagehosting)\.(?:com|net|us)/i > 0.00016 > [8894] warn: config: warning: description exists for non-existent rule > GRB_Imagehost 0.39171 > [8894] warn: config: warning: score set for non-existent rule > GRB_Imagehost The line which appears to start with /\. is a continuation of the first line. Just join the lines and it should be ok. From bpumphrey at woodmclaw.com Tue May 1 15:30:49 2007 From: bpumphrey at woodmclaw.com (Billy A. Pumphrey) Date: Tue May 1 15:30:53 2007 Subject: A lot of spam getting through In-Reply-To: <002901c78bfa$045b5dd0$0705000a@ddf5dw71> Message-ID: <04D932B0071FE34FA63EBB1977B48D1502816FDA@woodenex.woodmaclaw.local> > > Billy A. Pumphrey wrote: > >> > >> Ok, I had edited this file but it points to my local domain windows dns > >> server. Does that mean that I should change it to something else? > >> > > > > Definitely. Feel free to install a more respectable operating system on > it > > at any time. ;-) > > > Just curious now. > > What OS are you running on this machine currently? CentOS 4.4 > What does your Windows DNS server manage? It is a domain controller, WINS, DNS, Active Directory, DHCP > Steve > > > -- From bpumphrey at woodmclaw.com Tue May 1 15:34:05 2007 From: bpumphrey at woodmclaw.com (Billy A. Pumphrey) Date: Tue May 1 15:34:07 2007 Subject: A lot of spam getting through In-Reply-To: <001701c78b6a$ddc5caf0$0705000a@ddf5dw71> Message-ID: <04D932B0071FE34FA63EBB1977B48D1502816FDC@woodenex.woodmaclaw.local> Results of the DNS server commands. I am pretty sure that I don't have a DNS server on this machine. > > -- > If you're running RH flavor OS, do one of the following as root: > > ps -ax | grep named 11957 pts/0 S+ 0:00 grep named > > chkconfig --list named error reading information on service named: No such file or directory > > ls /etc/rc.d/init.d/named ls: /etc/rc.d/init.d/named: No such file or directory > > netstat -an | grep 53 tcp 0 0 127.0.0.1:11553 0.0.0.0:* LISTEN tcp 0 0 127.0.0.1:11553 127.0.0.1:51545 CLOSE_WAIT tcp 0 116 10.1.1.24:25 81.217.42.147:35365 FIN_WAIT1 tcp 0 0 127.0.0.1:51525 127.0.0.1:11553 TIME_WAIT tcp 0 0 127.0.0.1:51527 127.0.0.1:11553 TIME_WAIT tcp 0 0 127.0.0.1:51523 127.0.0.1:11553 TIME_WAIT tcp 0 0 127.0.0.1:51532 127.0.0.1:11553 TIME_WAIT tcp 0 0 127.0.0.1:51535 127.0.0.1:11553 TIME_WAIT tcp 0 0 127.0.0.1:51534 127.0.0.1:11553 TIME_WAIT tcp 0 0 127.0.0.1:51528 127.0.0.1:11553 TIME_WAIT tcp 0 0 127.0.0.1:51531 127.0.0.1:11553 TIME_WAIT tcp 0 0 127.0.0.1:51530 127.0.0.1:11553 TIME_WAIT tcp 0 0 127.0.0.1:51540 127.0.0.1:11553 TIME_WAIT tcp 0 0 127.0.0.1:51542 127.0.0.1:11553 TIME_WAIT tcp 0 0 127.0.0.1:51536 127.0.0.1:11553 TIME_WAIT tcp 0 0 127.0.0.1:51538 127.0.0.1:11553 TIME_WAIT tcp 0 0 127.0.0.1:51545 127.0.0.1:11553 FIN_WAIT2 tcp 0 0 127.0.0.1:51544 127.0.0.1:11553 TIME_WAIT tcp 0 0 ::ffff:10.1.1.24:51537 ::ffff:10.1.1.22:25 TIME_WAIT tcp 0 0 ::ffff:10.1.1.24:51533 ::ffff:10.1.1.22:25 TIME_WAIT unix 2 [ ACC ] STREAM LISTENING 12953341 /var/lib/mysql/mysql.sock unix 2 [ ACC ] STREAM LISTENING 25378793 /var/run/dcc/dccm unix 3 [ ] STREAM CONNECTED 25538221 /var/lib/mysql/mysql.sock unix 3 [ ] STREAM CONNECTED 25538220 unix 2 [ ] DGRAM 25538209 unix 2 [ ] DGRAM 25537800 unix 2 [ ] DGRAM 25537373 unix 2 [ ] DGRAM 25536669 unix 2 [ ] DGRAM 25536086 unix 2 [ ] DGRAM 25378792 [root@WoodenMS2 spamassassin]# > One of these should maybe give you an idea about a DNS server. If you're > running some other OS, I can't really help. > > Steve > > From campbell at cnpapers.com Tue May 1 15:53:03 2007 From: campbell at cnpapers.com (Steve Campbell) Date: Tue May 1 15:54:10 2007 Subject: A lot of spam getting through References: <04D932B0071FE34FA63EBB1977B48D1502816FDC@woodenex.woodmaclaw.local> Message-ID: <002a01c78c00$6bd68ce0$0705000a@ddf5dw71> ----- Original Message ----- From: "Billy A. Pumphrey" To: "MailScanner discussion" Sent: Tuesday, May 01, 2007 10:34 AM Subject: RE: A lot of spam getting through > Results of the DNS server commands. I am pretty sure that I don't have > a DNS server on this machine. > >> > -- >> If you're running RH flavor OS, do one of the following as root: >> >> ps -ax | grep named > > 11957 pts/0 S+ 0:00 grep named > >> >> chkconfig --list named > > error reading information on service named: No such file or directory > >> >> ls /etc/rc.d/init.d/named > > ls: /etc/rc.d/init.d/named: No such file or directory > >> >> netstat -an | grep 53 > > tcp 0 0 127.0.0.1:11553 0.0.0.0:* > LISTEN > tcp 0 0 127.0.0.1:11553 127.0.0.1:51545 > CLOSE_WAIT > tcp 0 116 10.1.1.24:25 81.217.42.147:35365 > FIN_WAIT1 > tcp 0 0 127.0.0.1:51525 127.0.0.1:11553 > TIME_WAIT > tcp 0 0 127.0.0.1:51527 127.0.0.1:11553 > TIME_WAIT > tcp 0 0 127.0.0.1:51523 127.0.0.1:11553 > TIME_WAIT > tcp 0 0 127.0.0.1:51532 127.0.0.1:11553 > TIME_WAIT > tcp 0 0 127.0.0.1:51535 127.0.0.1:11553 > TIME_WAIT > tcp 0 0 127.0.0.1:51534 127.0.0.1:11553 > TIME_WAIT > tcp 0 0 127.0.0.1:51528 127.0.0.1:11553 > TIME_WAIT > tcp 0 0 127.0.0.1:51531 127.0.0.1:11553 > TIME_WAIT > tcp 0 0 127.0.0.1:51530 127.0.0.1:11553 > TIME_WAIT > tcp 0 0 127.0.0.1:51540 127.0.0.1:11553 > TIME_WAIT > tcp 0 0 127.0.0.1:51542 127.0.0.1:11553 > TIME_WAIT > tcp 0 0 127.0.0.1:51536 127.0.0.1:11553 > TIME_WAIT > tcp 0 0 127.0.0.1:51538 127.0.0.1:11553 > TIME_WAIT > tcp 0 0 127.0.0.1:51545 127.0.0.1:11553 > FIN_WAIT2 > tcp 0 0 127.0.0.1:51544 127.0.0.1:11553 > TIME_WAIT > tcp 0 0 ::ffff:10.1.1.24:51537 ::ffff:10.1.1.22:25 > TIME_WAIT > tcp 0 0 ::ffff:10.1.1.24:51533 ::ffff:10.1.1.22:25 > TIME_WAIT > unix 2 [ ACC ] STREAM LISTENING 12953341 > /var/lib/mysql/mysql.sock > unix 2 [ ACC ] STREAM LISTENING 25378793 > /var/run/dcc/dccm > unix 3 [ ] STREAM CONNECTED 25538221 > /var/lib/mysql/mysql.sock > unix 3 [ ] STREAM CONNECTED 25538220 > unix 2 [ ] DGRAM 25538209 > unix 2 [ ] DGRAM 25537800 > unix 2 [ ] DGRAM 25537373 > unix 2 [ ] DGRAM 25536669 > unix 2 [ ] DGRAM 25536086 > unix 2 [ ] DGRAM 25378792 > [root@WoodenMS2 spamassassin]# > >> One of these should maybe give you an idea about a DNS server. If > you're >> running some other OS, I can't really help. >> >> Steve >> >> > -- OK, it looks pretty certain that you aren't running a DNS server on the box. Don't change your resolv.conf, then, until you install Bind or, as Mogens Melander suggested, one of the other DNS servers. But that's a project for another day, it sounds like. Steve From gmane at tippingmar.com Tue May 1 17:46:58 2007 From: gmane at tippingmar.com (Mark Nienberg) Date: Tue May 1 17:47:24 2007 Subject: how to block mail where From and To are the same? In-Reply-To: <1E293D3FF63A3740B10AD5AAD88535D204CD3925@UBIMAIL1.ubisoft.org> References: <1E293D3FF63A3740B10AD5AAD88535D204CD3925@UBIMAIL1.ubisoft.org> Message-ID: Daniel Maher wrote: > net result is that many of my users appear to be receiving spam /from > themselves/, which is causing some distress amongst the user base. If you can publish a SPF record for your domain, then the SPF checking in SA would catch this. Personally, I increase the score for SPF Fail, but see recent discussion about this for other points of view. Mark Nienberg From alex at nkpanama.com Tue May 1 17:54:54 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Tue May 1 17:55:38 2007 Subject: A lot of spam getting through In-Reply-To: <04D932B0071FE34FA63EBB1977B48D1502816FAC@woodenex.woodmaclaw.local> References: <04D932B0071FE34FA63EBB1977B48D1502816FAC@woodenex.woodmaclaw.local> Message-ID: <463770DE.40307@nkpanama.com> Billy A. Pumphrey wrote: > And what would that be? :) > Anything after CP/M, I'd think, but I would look to the download page for a list of highly respectable operating systems: * Version 4.59.4-2 for RedHat, Fedora and Mandrake Linux (and other RPM-based Linux distributions) (PGP signature) * Version 4.59.4-2 for SuSE (PGP signature) * Version 4.59.4-2 for Solaris / BSD / Other Linux / Other Unix (PGP signature) So your safest bet would be, RedHat (or CentOS), Fedora, Mandrake, SuSE, Solaris, BSD, Other Linux, or Other Unix, probably in that order... Anything else and MailScanner could cause swapping! ;-) From e.bloodaxe at gold.ac.uk Tue May 1 18:58:37 2007 From: e.bloodaxe at gold.ac.uk (e.bloodaxe@gold.ac.uk) Date: Tue May 1 18:58:50 2007 Subject: SophosAVI Message-ID: <46377FCD.2080608@gold.ac.uk> Can someone point me to or tell me why I might want to use SophosAVI over plain Sophos. although there is documenatation about how to install SophosAVI there is nothing telling me why I would want to do this. Eric From bpumphrey at woodmclaw.com Tue May 1 20:18:51 2007 From: bpumphrey at woodmclaw.com (Billy A. Pumphrey) Date: Tue May 1 20:18:55 2007 Subject: A lot of spam getting through In-Reply-To: <4636E826.1070104@chime.ucl.ac.uk> Message-ID: <04D932B0071FE34FA63EBB1977B48D15028171C9@woodenex.woodmaclaw.local> > > After looking at a few emails I can see that pyzor and DCC and bayes are > > scoring: > > Score Matching Rule Description > > cached not > > score=24.094 > > 6 required > > autolearn=spam > > 2.17 DCC_CHECK Listed in DCC (http://rhyolite.com/anti-spam/dcc/) > > 0.33 FH_DATE_ISNT_2006 > > 0.77 FH_DATE_ISNT_200X > > 0.40 FH_LEADINGPREP > > 0.71 FS_START_BUY > > 3.70 PYZOR_CHECK Listed in Pyzor (http://pyzor.sf.net/) > > 0.61 SARE_SXLIFE Talks about your sex life > > 3.81 URIBL_AB_SURBL Contains an URL listed in the AB SURBL blocklist > > 4.09 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist > > 3.01 URIBL_OB_SURBL Contains an URL listed in the OB SURBL blocklist > > 4.50 URIBL_SC_SURBL Contains an URL listed in the SC SURBL blocklist > > Are these the scores that your system gives to one of the emails that > are gettig through? If so that scored 24 points. So this email should > have been filtered. This suggests to me that the problem isn't with SA > but with something in your MailScanner settings. > This email was tagged as spam so good to go there. > If these aren't the scores from one of the emails that are getting > through can you save an email to a text file and send the output of the > following command: > > spamassassin --test-mode < email.txt > > > > -- > Anthony Peacock > CHIME, Royal Free & University College Medical School > WWW: http://www.chime.ucl.ac.uk/~rmhiajp/ > "If you have an apple and I have an apple and we exchange apples > then you and I will still each have one apple. But if you have an > idea and I have an idea and we exchange these ideas, then each of us > will have two ideas." -- George Bernard Shaw > -- From drew at technologytiger.net Tue May 1 21:56:54 2007 From: drew at technologytiger.net (Drew Marshall) Date: Tue May 1 21:57:13 2007 Subject: ClamAV Module Core Dump Message-ID: <8264588D-CE5E-443D-AC9A-20BCB16F3C24@technologytiger.net> Hi all Ok another challenge that I hope you can help with. I am running a FreeBSD 6 box that I have just upgraded to ClamAV 0.90.2 which was upgraded from the ports tree. Knowing there can be issues, I also forced an update (Which in effect recompiles) of the Clam perl module. Restarted MailScanner and ever since MS core dumps. I can run MS using ClamAV only but it makes quite a performance hit so I want to get t reinstalled ASAP. Running in debug mode, I helpfully get: root@mx1 /usr/local/etc/MailScanner # mailscanner --debug In Debugging mode, not forking... Segmentation fault /var/log/messages gets: May 1 20:34:14 mx1 kernel: pid 43095 (perl5.8.8), uid 0: exited on signal 11 (core dumped) Again no clues that I can see. Can any one give me some ideas where to start with this? For the record: This is MailScanner version 4.58.9 Module versions are: 1.00 AnyDBM_File 1.18 Archive::Zip 1.04 Carp 1.119 Convert::BinHex 1.00 DirHandle 1.05 Fcntl 2.74 File::Basename 2.09 File::Copy 2.01 FileHandle 1.08 File::Path 0.18 File::Temp 0.92 Filesys::Df 1.35 HTML::Entities 3.56 HTML::Parser 2.37 HTML::TokeParser 1.22 IO 1.13 IO::File 1.13 IO::Pipe 1.74 Mail::Header 3.07 MIME::Base64 5.420 MIME::Decoder 5.420 MIME::Decoder::UU 5.420 MIME::Head 5.420 MIME::Parser 3.07 MIME::QuotedPrint 5.420 MIME::Tools 0.11 Net::CIDR 1.09 POSIX 1.78 Socket 1.4 Sys::Hostname::Long 0.13 Sys::Syslog 1.9707 Time::HiRes 1.02 Time::localtime Optional module versions are: 0.17 Convert::TNEF 1.814 DB_File 1.13 DBD::SQLite 1.54 DBI 1.15 Digest 1.01 Digest::HMAC 2.36 Digest::MD5 2.11 Digest::SHA1 0.44 Inline Segmentation fault (core dumped) #(It really doesn't like the ClamAV module, which I have uninstalled and reinstalled to no effect.) TIA Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by the Technology Tiger MailScanner. Further information can be found at www.technologytiger.net/policy Technology Tiger Limited is registered in Scotland with registration number: 310997 Registered Office 55-57 West High Street Inverurie AB51 3QQ From r.berber at computer.org Tue May 1 22:23:47 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Tue May 1 22:24:09 2007 Subject: ClamAV Module Core Dump In-Reply-To: <8264588D-CE5E-443D-AC9A-20BCB16F3C24@technologytiger.net> References: <8264588D-CE5E-443D-AC9A-20BCB16F3C24@technologytiger.net> Message-ID: Drew Marshall wrote: > Ok another challenge that I hope you can help with. I am running a > FreeBSD 6 box that I have just upgraded to ClamAV 0.90.2 which was > upgraded from the ports tree. Knowing there can be issues, I also forced > an update (Which in effect recompiles) of the Clam perl module. Which version of Mail::ClamAV? your long list below doesn't include it, version 0.20 is required. Did you also run ldconfig? (required when installing clamav-0.90.2) > Restarted MailScanner and ever since MS core dumps. I can run MS using > ClamAV only but it makes quite a performance hit so I want to get t > reinstalled ASAP. You can also use clamd/clamdscan with the new beta version of MS or with a few changes to the version you have. > Running in debug mode, I helpfully get: > > root@mx1 /usr/local/etc/MailScanner # mailscanner --debug > In Debugging mode, not forking... > Segmentation fault Do you have a core file? can you run the debugger on it? > /var/log/messages gets: > > May 1 20:34:14 mx1 kernel: pid 43095 (perl5.8.8), uid 0: exited on > signal 11 (core dumped) > > Again no clues that I can see. Can any one give me some ideas where to > start with this? > > For the record: > > This is MailScanner version 4.58.9 ... -- Ren? Berber From drew at technologytiger.net Tue May 1 22:35:07 2007 From: drew at technologytiger.net (Drew Marshall) Date: Tue May 1 22:35:25 2007 Subject: ClamAV Module Core Dump In-Reply-To: References: <8264588D-CE5E-443D-AC9A-20BCB16F3C24@technologytiger.net> Message-ID: <089CB271-EBCE-4738-9AF2-7F7867567CB3@technologytiger.net> On 1 May 2007, at 22:23, Ren? Berber wrote: > Drew Marshall wrote: > >> Ok another challenge that I hope you can help with. I am running a >> FreeBSD 6 box that I have just upgraded to ClamAV 0.90.2 which was >> upgraded from the ports tree. Knowing there can be issues, I also >> forced an update (Which in effect recompiles) of the Clam perl >> module. > > Which version of Mail::ClamAV? your long list below doesn't > include it, version 0.20 is required. It is version 0.20, I forgot that it core dumped while trying to even list it. > > Did you also run ldconfig? (required when installing clamav-0.90.2) As part of the ports build process, I believe so. I normally just portupgrade and sit back and wait. > >> Restarted MailScanner and ever since MS core dumps. I can run MS >> using ClamAV only but it makes quite a performance hit so I want >> to get t reinstalled ASAP. > > You can also use clamd/clamdscan with the new beta version of MS or > with a few changes to the version you have. True. > >> Running in debug mode, I helpfully get: >> root@mx1 /usr/local/etc/MailScanner # mailscanner --debug >> In Debugging mode, not forking... >> Segmentation fault > > Do you have a core file? can you run the debugger on it? No, I can't find the damn thing. I would have expected it to drop into the directory that either I was in or MS was running in and neither (Unless MS is cleaning it up when starting/ failing). Thanks for your help. Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by the Technology Tiger MailScanner. Further information can be found at www.technologytiger.net/policy Technology Tiger Limited is registered in Scotland with registration number: 310997 Registered Office 55-57 West High Street Inverurie AB51 3QQ From ssilva at sgvwater.com Tue May 1 22:41:20 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 1 22:41:35 2007 Subject: ClamAV Module Core Dump In-Reply-To: <8264588D-CE5E-443D-AC9A-20BCB16F3C24@technologytiger.net> References: <8264588D-CE5E-443D-AC9A-20BCB16F3C24@technologytiger.net> Message-ID: Drew Marshall spake the following on 5/1/2007 1:56 PM: > Hi all > > Ok another challenge that I hope you can help with. I am running a > FreeBSD 6 box that I have just upgraded to ClamAV 0.90.2 which was > upgraded from the ports tree. Knowing there can be issues, I also forced > an update (Which in effect recompiles) of the Clam perl module. > Restarted MailScanner and ever since MS core dumps. I can run MS using > ClamAV only but it makes quite a performance hit so I want to get t > reinstalled ASAP. > > Running in debug mode, I helpfully get: > > root@mx1 /usr/local/etc/MailScanner # mailscanner --debug > In Debugging mode, not forking... > Segmentation fault > > /var/log/messages gets: > > May 1 20:34:14 mx1 kernel: pid 43095 (perl5.8.8), uid 0: exited on > signal 11 (core dumped) > > Again no clues that I can see. Can any one give me some ideas where to > start with this? I have a similar issue in Centos 4. While I am not getting cores, MailScanner will not run with the 0.20 module and 0.90.2 on one of my servers. It runs fine with the commandline scanner, and I haven't had the time to upgrade to the new version of MailScanner to test the clamd functionality. I get nothing in debug, either. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From z at ziff.net Tue May 1 23:01:42 2007 From: z at ziff.net (Zivago Lee) Date: Tue May 1 23:01:50 2007 Subject: ClamAV Module Core Dump In-Reply-To: References: <8264588D-CE5E-443D-AC9A-20BCB16F3C24@technologytiger.net> Message-ID: <63170.209.104.55.7.1178056902.squirrel@mail.ziff.net> > Drew Marshall spake the following on 5/1/2007 1:56 PM: >> Hi all >> >> Ok another challenge that I hope you can help with. I am running a >> FreeBSD 6 box that I have just upgraded to ClamAV 0.90.2 which was >> upgraded from the ports tree. Knowing there can be issues, I also forced >> an update (Which in effect recompiles) of the Clam perl module. >> Restarted MailScanner and ever since MS core dumps. I can run MS using >> ClamAV only but it makes quite a performance hit so I want to get t >> reinstalled ASAP. >> >> Running in debug mode, I helpfully get: >> >> root@mx1 /usr/local/etc/MailScanner # mailscanner --debug >> In Debugging mode, not forking... >> Segmentation fault >> >> /var/log/messages gets: >> >> May 1 20:34:14 mx1 kernel: pid 43095 (perl5.8.8), uid 0: exited on >> signal 11 (core dumped) >> >> Again no clues that I can see. Can any one give me some ideas where to >> start with this? > I have a similar issue in Centos 4. While I am not getting cores, > MailScanner > will not run with the 0.20 module and 0.90.2 on one of my servers. It runs > fine with the commandline scanner, and I haven't had the time to upgrade > to > the new version of MailScanner to test the clamd functionality. I get > nothing > in debug, either. Wow.. I thought it was just my server and/or config on why the clamavmodule was not working. It would just keep restarting the MailScanner processes and -debug would not display any issues. clamd works just fine, however, and works really well! -- Zivago Lee z@ziff.net From ssilva at sgvwater.com Tue May 1 23:15:03 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 1 23:15:16 2007 Subject: ClamAV Module Core Dump In-Reply-To: <63170.209.104.55.7.1178056902.squirrel@mail.ziff.net> References: <8264588D-CE5E-443D-AC9A-20BCB16F3C24@technologytiger.net> <63170.209.104.55.7.1178056902.squirrel@mail.ziff.net> Message-ID: Zivago Lee spake the following on 5/1/2007 3:01 PM: >> Drew Marshall spake the following on 5/1/2007 1:56 PM: >>> Hi all >>> >>> Ok another challenge that I hope you can help with. I am running a >>> FreeBSD 6 box that I have just upgraded to ClamAV 0.90.2 which was >>> upgraded from the ports tree. Knowing there can be issues, I also forced >>> an update (Which in effect recompiles) of the Clam perl module. >>> Restarted MailScanner and ever since MS core dumps. I can run MS using >>> ClamAV only but it makes quite a performance hit so I want to get t >>> reinstalled ASAP. >>> >>> Running in debug mode, I helpfully get: >>> >>> root@mx1 /usr/local/etc/MailScanner # mailscanner --debug >>> In Debugging mode, not forking... >>> Segmentation fault >>> >>> /var/log/messages gets: >>> >>> May 1 20:34:14 mx1 kernel: pid 43095 (perl5.8.8), uid 0: exited on >>> signal 11 (core dumped) >>> >>> Again no clues that I can see. Can any one give me some ideas where to >>> start with this? >> I have a similar issue in Centos 4. While I am not getting cores, >> MailScanner >> will not run with the 0.20 module and 0.90.2 on one of my servers. It runs >> fine with the commandline scanner, and I haven't had the time to upgrade >> to >> the new version of MailScanner to test the clamd functionality. I get >> nothing >> in debug, either. > > Wow.. I thought it was just my server and/or config on why the > clamavmodule was not working. It would just keep restarting the > MailScanner processes and -debug would not display any issues. clamd > works just fine, however, and works really well! > I have tried installing more than once, and I am near to wiping out the clam library and installing again. I might try clamd first, as anything has to be better than the commandline scanner. I am already running a few scanners, and every bit of load adds up. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From mbneto at gmail.com Wed May 2 00:20:15 2007 From: mbneto at gmail.com (mbneto) Date: Wed May 2 00:20:16 2007 Subject: Switching to clamd in new MailScanner Message-ID: <5cf776b80705011620h7eeba9a9k170132219527bff3@mail.gmail.com> Hi, I am currently using clamav (rpm) with my MailScanner setup. I've noticed that it calls a clamav-wrapper so I am assuming that every email that the server receives invokes this wrapper. Some posts in this list mentioned that using clamd would give faster results so how can I make MailScanner use clamav such way? thanks. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070501/0366eb41/attachment.html From z at ziff.net Wed May 2 00:26:26 2007 From: z at ziff.net (Zivago Lee) Date: Wed May 2 00:26:30 2007 Subject: Switching to clamd in new MailScanner In-Reply-To: <5cf776b80705011620h7eeba9a9k170132219527bff3@mail.gmail.com> References: <5cf776b80705011620h7eeba9a9k170132219527bff3@mail.gmail.com> Message-ID: <55632.209.104.55.7.1178061986.squirrel@mail.ziff.net> > I am currently using clamav (rpm) with my MailScanner setup. I've > noticed > that it calls a clamav-wrapper so I am assuming that every email that > the > server receives invokes this wrapper. > > Some posts in this list mentioned that using clamd would give faster > results > so how can I make MailScanner use clamav such way? Upgrade to the latest version of MS and the use the clamd virus scanner instead of clamav. -- Zivago Lee z@ziff.net From simon.walter at hp-factory.de Wed May 2 00:42:42 2007 From: simon.walter at hp-factory.de (Simon Walter) Date: Wed May 2 00:42:47 2007 Subject: ANNOUNCE: MailScanner stable 4.59 In-Reply-To: <4635D8B9.1010202@ecs.soton.ac.uk> (Julian Field's message of "Mon, 30 Apr 2007 12:53:29 +0100") References: <804d04538f794f46b267ddf96294c135@solidstatelogic.com> <4635D8B9.1010202@ecs.soton.ac.uk> Message-ID: <87ejm0t8jx.fsf@hp-factory.de> Hello Julian Field writes: > Please can you try 4.49.4-2 and see if this still works for you. It > still includes the patch but is wrapped up so the truncation only > happens if his regexp matches. Duh! I found this problem shortly after I send you the patch and fixed it in the debian package. If anyone would have asked me I would have sworn I informed you about the buggy patch, but I can't find any mail. So I probably thought about sending you a mail but never did it. Sorry for that. -- Regards Simon From markee at bandwidthco.com Wed May 2 03:34:03 2007 From: markee at bandwidthco.com (markee) Date: Wed May 2 03:36:57 2007 Subject: ClamAV Module Core Dump In-Reply-To: Message-ID: <004601c78c62$5973bf70$0300a8c0@bandwidthco.com> I have tried installing more than once, and I am near to wiping out the clam library and installing again. I might try clamd first, as anything has to be better than the commandline scanner. I am already running a few scanners, and every bit of load adds up. -- I'm thinking perhaps we need some of Julian's expert help here. The clamavmodule does not seem to be working period for me on my two gateway boxes. It did start once I upgraded to 0.90.2. ######################################################## This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. postmaster@bandwidthco.com MailScanner at Bandwidthco Computer Security is for your absolute protection. ######################################################## ######################################################## This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. postmaster@bandwidthco.com MailScanner at Bandwidthco Computer Security is for your absolute protection. ######################################################## From goetz.reinicke at filmakademie.de Wed May 2 07:04:30 2007 From: goetz.reinicke at filmakademie.de (=?ISO-8859-15?Q?G=F6tz_Reinicke?=) Date: Wed May 2 07:04:38 2007 Subject: log message MailScanner: waiting for children to die Message-ID: <463829EE.7080009@filmakademie.de> Hi, we recently upgraded our mailserver from Red Hat Enterprise Linux 4 to RHEL 5. We use the latest release of mailscanner and sendmail-8.13.8. Everything is up and running very good, beside I do get the following message lots of time: MailScanner: waiting for children to die: Process did not exit cleanly, returned 255 with signal 0 I'm using our "old" configuration from RHEL4 which worked without the message for a couple off years. Any ideas or tips? Best regards G?tz Reinicke -- G?tz Reinicke IT Koordinator Tel. +49 7141 969 420 Fax +49 7141 969 55 420 E-Mail goetz.reinicke@filmakademie.de Filmakademie Baden-W?rttemberg GmbH Mathildenstr. 20 71638 Ludwigsburg www.filmakademie.de Eintragung Amtsgericht Stuttgart HRB 205016 Vorsitzender des Aufsichtsrats: Dr. Christoph Palmer, MdL, Minister a.D. Gesch?ftsf?hrer: Prof. Thomas Schadt From stork at openenterprise.ca Wed May 2 07:50:57 2007 From: stork at openenterprise.ca (Johnny Stork) Date: Wed May 2 07:51:04 2007 Subject: Mailscanner 4.59.4 and Mailwatch with clamd? Message-ID: <463834D1.8050602@openenterprise.ca> Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: stork.vcf Type: text/x-vcard Size: 330 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070501/e04cf7fd/stork-0001.vcf From stork at openenterprise.ca Wed May 2 07:52:32 2007 From: stork at openenterprise.ca (Johnny Stork) Date: Wed May 2 07:52:39 2007 Subject: Mailscanner 4.59.4 and Mailwatch with clamd? In-Reply-To: <463834D1.8050602@openenterprise.ca> References: <463834D1.8050602@openenterprise.ca> Message-ID: <46383530.5000008@openenterprise.ca> Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: stork.vcf Type: text/x-vcard Size: 330 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070501/16bd86b1/stork.vcf From benedict at kmun.gov.kw Wed May 2 07:31:23 2007 From: benedict at kmun.gov.kw (benedict@kmun.gov.kw) Date: Wed May 2 08:31:04 2007 Subject: query regading quarintine items Message-ID: <2487.62.150.152.42.1178087483.squirrel@webmail.baladia.gov.kw> dear All I have been recently using mailSacnner and its workin beautifully but i do have a query suppose i get an zip attachment which contains an exe file the mailscanner put the attachment in my quarantine directory which is perfect now the user says he recived it from trusted source and want the attachement how could i get the attachement back in his inbox so he could download it to his computer thnks and regards simon From bilias at edu.physics.uoc.gr Wed May 2 08:52:33 2007 From: bilias at edu.physics.uoc.gr (Kapetanakis Giannis) Date: Wed May 2 08:52:46 2007 Subject: Mailscanner 4.59.4 and Mailwatch with clamd? In-Reply-To: <463834D1.8050602@openenterprise.ca> References: <463834D1.8050602@openenterprise.ca> Message-ID: On Tue, 1 May 2007, Johnny Stork wrote: > Just upgraded to MS 4.59.4 and switched to clamd, but when I try to > get to the mailwatch interface I get > > *Error:* > Unable to select a regular expression for your primary virus scanner > (clamd) - please see the examples in functions.php to create one. > > but there does not appear to be any settings for using clamd? > > Any suggestions? That is not MailScanner's problem. It is mailwatch. anyway... edit functions.php and and add the above under the clamav definition case 'clamd': define(VIRUS_REGEX, '/(.+) contains (\S+)/'); break; Giannis From list-mailscanner at linguaphone.com Wed May 2 08:55:28 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed May 2 08:55:43 2007 Subject: query regading quarintine items In-Reply-To: <2487.62.150.152.42.1178087483.squirrel@webmail.baladia.gov.kw> References: <2487.62.150.152.42.1178087483.squirrel@webmail.baladia.gov.kw> Message-ID: <1178092528.17439.5.camel@gblades-suse.linguaphone-intranet.co.uk> On Wed, 2007-05-02 at 07:31, benedict@kmun.gov.kw wrote: > dear All > > > I have been recently using mailSacnner and its workin beautifully > > but i do have a query > > suppose i get an zip attachment which contains an exe file the mailscanner > put the attachment in my quarantine directory which is perfect > > now the user says he recived it from trusted source and want the attachement > > how could i get the attachement back in his inbox so he could download it > to his computer I would install Mailwatch and then you can release it from the quaranteen. You could even give the user an account and they can release their own messages if you wish. Note that mailwatch wont allow you to release a message if it contains a virus. From martinh at solidstatelogic.com Wed May 2 09:23:16 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 2 09:23:50 2007 Subject: SophosAVI In-Reply-To: <46377FCD.2080608@gold.ac.uk> Message-ID: <9edf4c5b34771e4b9445252efd4055fe@solidstatelogic.com> Eric 1) its cheaper - about 33% discount for the server last time I renewed (but that was about 3 years ago so I'm just about to find out by how much this time!) 2) It's faster - you don't have to start a new process to scan the email. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of e.bloodaxe@gold.ac.uk > Sent: 01 May 2007 18:59 > To: MailScanner discussion > Subject: SophosAVI > > Can someone point me to or tell me why I might want to use SophosAVI > over plain Sophos. although there is documenatation about how to > install SophosAVI > there is nothing telling me why I would want to do this. > > Eric > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From martinh at solidstatelogic.com Wed May 2 09:26:06 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 2 09:26:10 2007 Subject: ClamAV Module Core Dump In-Reply-To: <089CB271-EBCE-4738-9AF2-7F7867567CB3@technologytiger.net> Message-ID: <774368311c56f847880c7861fc0135b6@solidstatelogic.com> Drew I've never managed to get clammodule working with FreeBSD (well the 4.x version of FreeBSD). Just switched to the clamd version and it's working fine. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Drew Marshall > Sent: 01 May 2007 22:35 > To: MailScanner discussion > Subject: Re: ClamAV Module Core Dump > > On 1 May 2007, at 22:23, Ren? Berber wrote: > > > Drew Marshall wrote: > > > >> Ok another challenge that I hope you can help with. I am running a > >> FreeBSD 6 box that I have just upgraded to ClamAV 0.90.2 which was > >> upgraded from the ports tree. Knowing there can be issues, I also > >> forced an update (Which in effect recompiles) of the Clam perl > >> module. > > > > Which version of Mail::ClamAV? your long list below doesn't > > include it, version 0.20 is required. > > It is version 0.20, I forgot that it core dumped while trying to even > list it. > > > > > Did you also run ldconfig? (required when installing clamav-0.90.2) > > As part of the ports build process, I believe so. I normally just > portupgrade and sit back and wait. > > > > >> Restarted MailScanner and ever since MS core dumps. I can run MS > >> using ClamAV only but it makes quite a performance hit so I want > >> to get t reinstalled ASAP. > > > > You can also use clamd/clamdscan with the new beta version of MS or > > with a few changes to the version you have. > > True. > > > > >> Running in debug mode, I helpfully get: > >> root@mx1 /usr/local/etc/MailScanner # mailscanner --debug > >> In Debugging mode, not forking... > >> Segmentation fault > > > > Do you have a core file? can you run the debugger on it? > > No, I can't find the damn thing. I would have expected it to drop > into the directory that either I was in or MS was running in and > neither (Unless MS is cleaning it up when starting/ failing). > > Thanks for your help. > > Drew > -- > In line with our policy, this message has been scanned > for viruses and dangerous content by the Technology Tiger MailScanner. > Further information can be found at www.technologytiger.net/policy > > Technology Tiger Limited is registered in Scotland with registration > number: 310997 > Registered Office 55-57 West High Street Inverurie AB51 3QQ > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From martinh at solidstatelogic.com Wed May 2 09:27:38 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 2 09:27:43 2007 Subject: log message MailScanner: waiting for children to die In-Reply-To: <463829EE.7080009@filmakademie.de> Message-ID: <7749f34107be65419d7a566a3b67215f@solidstatelogic.com> Hi You say - 'old' configuration. Did you run the upgrade scripts to make sure new settings get inserted etc or just copy MailScanner.conf across? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of G?tz Reinicke > Sent: 02 May 2007 07:05 > To: mailscanner@lists.mailscanner.info > Subject: log message MailScanner: waiting for children to die > > Hi, > > we recently upgraded our mailserver from Red Hat Enterprise Linux 4 to > RHEL 5. We use the latest release of mailscanner and sendmail-8.13.8. > > Everything is up and running very good, beside I do get the following > message lots of time: > > MailScanner: waiting for children to die: Process did not exit cleanly, > returned 255 with signal 0 > > I'm using our "old" configuration from RHEL4 which worked without the > message for a couple off years. > > Any ideas or tips? > > > Best regards > > G?tz Reinicke > -- > G?tz Reinicke > IT Koordinator > > Tel. +49 7141 969 420 > Fax +49 7141 969 55 420 > E-Mail goetz.reinicke@filmakademie.de > > Filmakademie Baden-W?rttemberg GmbH > Mathildenstr. 20 > 71638 Ludwigsburg > www.filmakademie.de > > Eintragung Amtsgericht Stuttgart HRB 205016 > Vorsitzender des Aufsichtsrats: > Dr. Christoph Palmer, MdL, Minister a.D. > > Gesch?ftsf?hrer: > Prof. Thomas Schadt > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From a.peacock at chime.ucl.ac.uk Wed May 2 09:53:20 2007 From: a.peacock at chime.ucl.ac.uk (Anthony Peacock) Date: Wed May 2 09:53:44 2007 Subject: A lot of spam getting through In-Reply-To: <04D932B0071FE34FA63EBB1977B48D15028171C9@woodenex.woodmaclaw.local> References: <04D932B0071FE34FA63EBB1977B48D15028171C9@woodenex.woodmaclaw.local> Message-ID: <46385180.5090601@chime.ucl.ac.uk> Hi, Billy A. Pumphrey wrote: >>> After looking at a few emails I can see that pyzor and DCC and bayes > are >>> scoring: >>> Score Matching Rule Description >>> cached not >>> score=24.094 >>> 6 required >>> autolearn=spam >>> 2.17 DCC_CHECK Listed in DCC (http://rhyolite.com/anti-spam/dcc/) >>> 0.33 FH_DATE_ISNT_2006 >>> 0.77 FH_DATE_ISNT_200X >>> 0.40 FH_LEADINGPREP >>> 0.71 FS_START_BUY >>> 3.70 PYZOR_CHECK Listed in Pyzor (http://pyzor.sf.net/) >>> 0.61 SARE_SXLIFE Talks about your sex life >>> 3.81 URIBL_AB_SURBL Contains an URL listed in the AB SURBL blocklist >>> 4.09 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist >>> 3.01 URIBL_OB_SURBL Contains an URL listed in the OB SURBL blocklist >>> 4.50 URIBL_SC_SURBL Contains an URL listed in the SC SURBL blocklist >> Are these the scores that your system gives to one of the emails that >> are gettig through? If so that scored 24 points. So this email > should >> have been filtered. This suggests to me that the problem isn't with > SA >> but with something in your MailScanner settings. >> > > This email was tagged as spam so good to go there. So, help us out and show us the scores and headers from one that does get through. We might be able to see where they are failing then. Even better... Save one of the misdiagnosed emails as a text file, post it to a web address and let us know. We can then run that email through our systems and tell you what scores we get and what rules helped. > >> If these aren't the scores from one of the emails that are getting >> through can you save an email to a text file and send the output of > the >> following command: >> >> spamassassin --test-mode < email.txt >> >> >> >> -- >> Anthony Peacock >> CHIME, Royal Free & University College Medical School >> WWW: http://www.chime.ucl.ac.uk/~rmhiajp/ >> "If you have an apple and I have an apple and we exchange apples >> then you and I will still each have one apple. But if you have an >> idea and I have an idea and we exchange these ideas, then each of us >> will have two ideas." -- George Bernard Shaw >> -- > > -- Anthony Peacock CHIME, Royal Free & University College Medical School WWW: http://www.chime.ucl.ac.uk/~rmhiajp/ "If you have an apple and I have an apple and we exchange apples then you and I will still each have one apple. But if you have an idea and I have an idea and we exchange these ideas, then each of us will have two ideas." -- George Bernard Shaw From goetz.reinicke at filmakademie.de Wed May 2 09:55:50 2007 From: goetz.reinicke at filmakademie.de (=?ISO-8859-1?Q?G=F6tz_Reinicke?=) Date: Wed May 2 09:56:03 2007 Subject: log message MailScanner: waiting for children to die In-Reply-To: <7749f34107be65419d7a566a3b67215f@solidstatelogic.com> References: <7749f34107be65419d7a566a3b67215f@solidstatelogic.com> Message-ID: <46385216.1070501@filmakademie.de> Hallo, yes, I run the upgrade scripts. Regards G?tz Martin.Hepworth schrieb: > Hi > > You say - 'old' configuration. Did you run the upgrade scripts to make > sure new settings get inserted etc or just copy MailScanner.conf across? > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of G?tz Reinicke >> Sent: 02 May 2007 07:05 >> To: mailscanner@lists.mailscanner.info >> Subject: log message MailScanner: waiting for children to die >> >> Hi, >> >> we recently upgraded our mailserver from Red Hat Enterprise Linux 4 to >> RHEL 5. We use the latest release of mailscanner and sendmail-8.13.8. >> >> Everything is up and running very good, beside I do get the following >> message lots of time: >> >> MailScanner: waiting for children to die: Process did not exit > cleanly, >> returned 255 with signal 0 >> >> I'm using our "old" configuration from RHEL4 which worked without the >> message for a couple off years. -- G?tz Reinicke IT Koordinator Tel. +49 7141 969 420 Fax +49 7141 969 55 420 E-Mail goetz.reinicke@filmakademie.de Filmakademie Baden-W?rttemberg GmbH Mathildenstr. 20 71638 Ludwigsburg www.filmakademie.de Eintragung Amtsgericht Stuttgart HRB 205016 Vorsitzender des Aufsichtsrats: Dr. Christoph Palmer, MdL, Minister a.D. Gesch?ftsf?hrer: Prof. Thomas Schadt From martinh at solidstatelogic.com Wed May 2 10:11:28 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 2 10:11:36 2007 Subject: log message MailScanner: waiting for children to die In-Reply-To: <46385216.1070501@filmakademie.de> Message-ID: OK, Can you do a MailScanner -v and post the output. I wonder if the upgrade to RHES5 broke something. Other thing to do is stop mailscanner then run, "MailScanner -debug" which will hopefully show you where things are breaking. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of G?tz Reinicke > Sent: 02 May 2007 09:56 > To: MailScanner discussion > Subject: Re: log message MailScanner: waiting for children to die > > Hallo, > > yes, I run the upgrade scripts. > > Regards > > G?tz > > Martin.Hepworth schrieb: > > Hi > > > > You say - 'old' configuration. Did you run the upgrade scripts to make > > sure new settings get inserted etc or just copy MailScanner.conf across? > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > >> -----Original Message----- > >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > >> bounces@lists.mailscanner.info] On Behalf Of G?tz Reinicke > >> Sent: 02 May 2007 07:05 > >> To: mailscanner@lists.mailscanner.info > >> Subject: log message MailScanner: waiting for children to die > >> > >> Hi, > >> > >> we recently upgraded our mailserver from Red Hat Enterprise Linux 4 to > >> RHEL 5. We use the latest release of mailscanner and sendmail-8.13.8. > >> > >> Everything is up and running very good, beside I do get the following > >> message lots of time: > >> > >> MailScanner: waiting for children to die: Process did not exit > > cleanly, > >> returned 255 with signal 0 > >> > >> I'm using our "old" configuration from RHEL4 which worked without the > >> message for a couple off years. > > > -- > G?tz Reinicke > IT Koordinator > > Tel. +49 7141 969 420 > Fax +49 7141 969 55 420 > E-Mail goetz.reinicke@filmakademie.de > > Filmakademie Baden-W?rttemberg GmbH > Mathildenstr. 20 > 71638 Ludwigsburg > www.filmakademie.de > > Eintragung Amtsgericht Stuttgart HRB 205016 > Vorsitzender des Aufsichtsrats: > Dr. Christoph Palmer, MdL, Minister a.D. > > Gesch?ftsf?hrer: > Prof. Thomas Schadt > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From fssilva at gmail.com Wed May 2 12:15:17 2007 From: fssilva at gmail.com (Fabio Silva) Date: Wed May 2 12:15:53 2007 Subject: Fwd: [shell-script] Oportunidade - TALENT FOUR/ Administrador de Redes e Sistemas - LINUX In-Reply-To: <6C590FEEFDEC05478512F3771363C6DB489830@tfcmail02.tfc.com.br> References: <6C590FEEFDEC05478512F3771363C6DB489830@tfcmail02.tfc.com.br> Message-ID: ---------- Forwarded message ---------- From: Renata Dardis de Souza Date: Apr 30, 2007 4:30 PM Subject: [shell-script] Oportunidade - TALENT FOUR/ Administrador de Redes e Sistemas - LINUX To: shell-script@yahoogrupos.com.br Ol? Grupo, Boa tarde!!!! A Talent Four Consulting ? uma empresa de consultoria em projetos de Tecnologia da Informa??o, especializada em servi?os e terceiriza??o de Profissionais. Atuamos em servi?os de Body Shop, Desenvolvimento de Sistemas, F?brica de Software e Documenta??o de Sistemas Legados, Help Desk e Recrutamento e Sele??o (exclusivamente para profissionais de T.I). Nosso quadro de consultores contempla mais de 300 Profissionais ativos com capilaridade nacional de atendimento. Acesse nosso site: www.talentfour.com.br e verifique todas as nossas oportunidades e servi?os. Favor encaminhar curr?culos para renata.souza@talentfour.com.br ADMINISTRADOR DE REDES E SISTEMAS Experi?ncia: Sistemas Operacionais: Linux (Dom?nio) Linguagens de programa??o, Shell Script, Perl Servi?os/Aplicativos de redes de computadores: SNMP, SMTP, POP, IMAP, Samba, HTTP, VPN Hardware: Conhecimentos Avan?ados Switches e Roteadores: Exigido Conhecimento em ITIL: Exigido P?s-graduado em Administra??o de Redes, Gest?o de TI e/ou Gerenciamento de Projetos em ?nfase em Ti Certifica??es (Exigido): CCNA, LPI, MCSE Gest?o de redes, sistemas operacionais e hardwares Gest?o de monitoramento do ambiente computacional Gera??o de relat?rios relacionados ao ambiente gerenciado Idiomas: Ingl?s - Fluente Espanhol - Intermedi?rio Contrata??o: CLT - diretamente pelo cliente. Hor?rio de Expediente: 08h00 as 17h00 - flexibilidade para trabalhos espor?dicos fora do hor?rio de expediente Local de trabalho: Vl Ol?mpia - S?o Paulo - SP Disponibilidade: Imediata. Caso houver indica??es de profissionais dentro deste perfil, ficarei aguardando. OS: C.Vs fora do perfil ser?o desconsiderados automaticamente. Att, Renata Dardis de Souza Talent Four - Analista de RH Avenida Dr. Cardoso de Melo, 1608 4o. Vila Ol?mpia 04548-005 S?o Paulo-SP Fone: 55 11 3848-4445 Celular: 55 11 9283-9093 E-mail: renata.souza@talentfour.com.br www.talentfour.com.br [As partes desta mensagem que n?o continham texto foram removidas] __._,_.___ Mensagens neste t?pico ( 1) Responder (atrav?s da web) | Adicionar um novo t?pico Mensagens| Arquivos| Fotos| Links --------------------------------------------------------------------- Esta lista n?o admite a abordagem de outras liguagens de programa??o, como perl, C etc. Quem insistir em n?o seguir esta regra ser? moderado sem pr?vio aviso. --------------------------------------------------------------------- Sair da lista: shell-script-unsubscribe@yahoogrupos.com.br --------------------------------------------------------------------- Esta lista ? moderada de acordo com o previsto em http://www.listas-discussao.cjb.net --------------------------------------------------------------------- Servidor Newsgroup da lista: news.gmane.org Grupo: gmane.org.user-groups.programming.shell.brazil [image: Yahoo! Grupos] Alterar configura??es via web(Requer Yahoo! ID) Alterar configura??es via e-mail: Alterar recebimento para lista di?ria de mensagens| Alterar formato para o tradicional Visite seu Grupo | Termos de uso do Yahoo! Grupos | Sair do grupo Atividade nos ?ltimos dias - 21 Novos usu?rios Visite seu Grupo Yahoo! Mail Conecte-se ao mundo Prote??o anti-spam Muito mais espa?o Yahoo! Barra Instale gr?tis Buscar sites na web Checar seus e-mails . Yahoo! Grupos Crie seu pr?prio grupo A melhor forma de comunica??o . __,_._,___ -- Fabio S. Silva -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070502/f8be7ff7/attachment.html From rcooper at dwford.com Wed May 2 12:43:55 2007 From: rcooper at dwford.com (Rick Cooper) Date: Wed May 2 12:44:01 2007 Subject: Mailscanner 4.59.4 and Mailwatch with clamd? In-Reply-To: <46383530.5000008@openenterprise.ca> References: <463834D1.8050602@openenterprise.ca> <46383530.5000008@openenterprise.ca> Message-ID: <032101c78caf$2a805f50$0301a8c0@SAHOMELT> ________________________________ From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Johnny Stork Sent: Wednesday, May 02, 2007 2:53 AM To: MailScanner discussion Subject: Re: Mailscanner 4.59.4 and Mailwatch with clamd? oops...meant to send this to the mailwatch list....sorry....but feel free to answer if someone has a solution. Johnny Stork wrote: Just upgraded to MS 4.59.4 and switched to clamd, but when I try to get to the mailwatch interface I get Error: Unable to select a regular expression for your primary virus scanner (clamd) - please see the examples in functions.php to create one. but there does not appear to be any settings for using clamd? Any suggestions? [..] Find functions.php in your MailWatch web directory (ie /var/www/html/mailscanner). Open functions.php in an editor and look for (about line 71) : case 'clamav': define(VIRUS_REGEX, '/(.+) contains (\S+)/'); break; Insert below the "break;" line: case 'clamd': define(VIRUS_REGEX, '/(.+) contains (\S+)/'); break; I don't remember if you need to restart MS, I would think not. Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From goetz.reinicke at filmakademie.de Wed May 2 13:24:16 2007 From: goetz.reinicke at filmakademie.de (=?ISO-8859-1?Q?G=F6tz_Reinicke?=) Date: Wed May 2 13:24:23 2007 Subject: log message MailScanner: waiting for children to die In-Reply-To: References: Message-ID: <463882F0.3060207@filmakademie.de> Martin.Hepworth schrieb: > OK, > > Can you do a MailScanner -v and post the output. I wonder if the upgrade > to RHES5 broke something. [root@mail en]# MailScanner -v Running on Linux mail.filmakademie.de 2.6.18-8.1.1.el5 #1 SMP Mon Feb 26 20:38:02 EST 2007 i686 i686 i386 GNU/Linux This is Red Hat Enterprise Linux Server release 5 (Tikanga) This is Perl version 5.008008 (5.8.8) This is MailScanner version 4.59.4 Module versions are: 1.00 AnyDBM_File 1.16 Archive::Zip 1.04 Carp 1.119 Convert::BinHex 1.00 DirHandle 1.05 Fcntl 2.74 File::Basename 2.09 File::Copy 2.01 FileHandle 1.08 File::Path 0.16 File::Temp 0.90 Filesys::Df 1.35 HTML::Entities 3.55 HTML::Parser 2.37 HTML::TokeParser 1.22 IO 1.13 IO::File 1.13 IO::Pipe 1.76 Mail::Header 3.05 MIME::Base64 5.420 MIME::Decoder 5.420 MIME::Decoder::UU 5.420 MIME::Head 5.420 MIME::Parser 3.03 MIME::QuotedPrint 5.420 MIME::Tools 0.11 Net::CIDR 1.09 POSIX 1.78 Socket 1.4 Sys::Hostname::Long 0.18 Sys::Syslog 1.86 Time::HiRes 1.02 Time::localtime Optional module versions are: 0.17 Convert::TNEF 1.814 DB_File 1.13 DBD::SQLite 1.52 DBI 1.14 Digest 1.01 Digest::HMAC 2.36 Digest::MD5 2.11 Digest::SHA1 0.44 Inline missing Mail::ClamAV 3.001008 Mail::SpamAssassin 1.999001 Mail::SPF::Query 0.20 Net::CIDR::Lite 1.25 Net::IP 0.59 Net::DNS 0.32 Net::LDAP missing Parse::RecDescent missing SAVI 2.56 Test::Harness 0.62 Test::Simple 1.95 Text::Balanced 1.35 URI > > Other thing to do is stop mailscanner then run, "MailScanner -debug" > which will hopefully show you where things are breaking. This didn't show anything yet ... Thanks and regards G?tz -- G?tz Reinicke IT Koordinator Tel. +49 7141 969 420 Fax +49 7141 969 55 420 E-Mail goetz.reinicke@filmakademie.de Filmakademie Baden-W?rttemberg GmbH Mathildenstr. 20 71638 Ludwigsburg www.filmakademie.de Eintragung Amtsgericht Stuttgart HRB 205016 Vorsitzender des Aufsichtsrats: Dr. Christoph Palmer, MdL, Minister a.D. Gesch?ftsf?hrer: Prof. Thomas Schadt From list-mailscanner at linguaphone.com Wed May 2 13:25:48 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed May 2 13:26:08 2007 Subject: Spam detection rates Message-ID: <1178108748.17627.17.camel@gblades-suse.linguaphone-intranet.co.uk> I was wondering what sort of detection rates people are getting when using Mailscanner. Our old spamassassin 2.64 based system was only getting about 80% but with Mailscanner and the latest software we seem to be getting over 99.5% which is extremely good. False positives are very low aswell. We do tend to be very strict about pictures attached to emails as I think we have a few rules which do the same sort of checks. Some external people using the incredimail 'piece of cr**p' mail client get a continuous score about 4.3 which leaves the AWL little room to bring the occasional higher scoring mail back below the 5.0 threshold. It hasn't caused any people to complain though. From martinh at solidstatelogic.com Wed May 2 13:42:56 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 2 13:43:07 2007 Subject: Spam detection rates In-Reply-To: <1178108748.17627.17.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <4ba8efec2dc55e4fb46d4580263ece61@solidstatelogic.com> About the same - I've got lots of extra rules and also use dcc/pyzor etc so it's difficult to say there's been an improvement as I updated from 2.64 when 3.01 came along a few years ago. BTW - any just noticed 3.2.0 has been released ! -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Gareth > Sent: 02 May 2007 13:26 > To: mailscanner@lists.mailscanner.info > Subject: Spam detection rates > > I was wondering what sort of detection rates people are getting when > using Mailscanner. > Our old spamassassin 2.64 based system was only getting about 80% but > with Mailscanner and the latest software we seem to be getting over > 99.5% which is extremely good. False positives are very low aswell. > > We do tend to be very strict about pictures attached to emails as I > think we have a few rules which do the same sort of checks. Some > external people using the incredimail 'piece of cr**p' mail client get a > continuous score about 4.3 which leaves the AWL little room to bring the > occasional higher scoring mail back below the 5.0 threshold. It hasn't > caused any people to complain though. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From dominian at slackadelic.com Wed May 2 13:43:09 2007 From: dominian at slackadelic.com (Matt Hayes) Date: Wed May 2 13:43:21 2007 Subject: Mailscanner 4.59.4 and Mailwatch with clamd? In-Reply-To: <46383530.5000008@openenterprise.ca> References: <463834D1.8050602@openenterprise.ca> <46383530.5000008@openenterprise.ca> Message-ID: <4638875D.5090800@slackadelic.com> Johnny Stork wrote: > oops...meant to send this to the mailwatch list....sorry....but feel > free to answer if someone has a solution. > > Johnny Stork wrote: >> Just upgraded to MS 4.59.4 and switched to clamd, but when I try to >> get to the mailwatch interface I get >> >> *Error:* >> Unable to select a regular expression for your primary virus scanner >> (clamd) - please see the examples in functions.php to create one. >> >> but there does not appear to be any settings for using clamd? >> >> Any suggestions? >> What you need to do is add in another antivirus for mailwatch to use. In your mailwatch directory in the functions.php just under the clamavmodule definition I added: case 'clamd': define(VIRUS_REGEX, '/(.+) contains (\S+)/'); break; Then mailwatch works fine :) -Matt From prandal at herefordshire.gov.uk Wed May 2 13:42:57 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Wed May 2 13:43:22 2007 Subject: Spam detection rates In-Reply-To: <1178108748.17627.17.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1178108748.17627.17.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA9222C4@HC-MBX02.herefordshire.gov.uk> We consistently get over 99.5% of spam too. Last month we blocked around 260,000 at the sendmail level (cbl.abuseat.org RBL and GreetPause), and 400,000 in MailScanner. Spam seems to be around 75% of total emails here. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Gareth > Sent: 02 May 2007 13:26 > To: mailscanner@lists.mailscanner.info > Subject: Spam detection rates > > I was wondering what sort of detection rates people are getting when > using Mailscanner. > Our old spamassassin 2.64 based system was only getting about 80% but > with Mailscanner and the latest software we seem to be getting over > 99.5% which is extremely good. False positives are very low aswell. > > We do tend to be very strict about pictures attached to emails as I > think we have a few rules which do the same sort of checks. Some > external people using the incredimail 'piece of cr**p' mail > client get a > continuous score about 4.3 which leaves the AWL little room > to bring the > occasional higher scoring mail back below the 5.0 threshold. It hasn't > caused any people to complain though. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From jonbjorn at mbl.is Wed May 2 14:39:33 2007 From: jonbjorn at mbl.is (Jon Bjorn Njalsson) Date: Wed May 2 14:39:50 2007 Subject: No Programs allowed Message-ID: <1178113173.14147.16.camel@viper.mbl.is> Why does MS think msg-26670-41.txt is a program ? MailScanner: No programs allowed (msg-26670-41.txt) regards Jon Bjorn From martinh at solidstatelogic.com Wed May 2 14:44:21 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 2 14:44:21 2007 Subject: No Programs allowed In-Reply-To: <1178113173.14147.16.camel@viper.mbl.is> Message-ID: Jon The file command is showing it as a program. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Jon Bjorn Njalsson > Sent: 02 May 2007 14:40 > To: MailScanner discussion > Subject: No Programs allowed > > Why does MS think msg-26670-41.txt is a program ? > > MailScanner: No programs allowed (msg-26670-41.txt) > > regards > Jon Bjorn > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From jonbjorn at mbl.is Wed May 2 14:48:46 2007 From: jonbjorn at mbl.is (Jon Bjorn Njalsson) Date: Wed May 2 14:48:58 2007 Subject: No Programs allowed In-Reply-To: References: Message-ID: <1178113726.14147.20.camel@viper.mbl.is> so is it safe to disable File Command = /usr/bin/file ? On mi?, 2007-05-02 at 14:44 +0100, Martin.Hepworth wrote: > Jon > > The file command is showing it as a program. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Jon Bjorn Njalsson > > Sent: 02 May 2007 14:40 > > To: MailScanner discussion > > Subject: No Programs allowed > > > > Why does MS think msg-26670-41.txt is a program ? > > > > MailScanner: No programs allowed (msg-26670-41.txt) > > > > regards > > Jon Bjorn > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > From list-mailscanner at linguaphone.com Wed May 2 14:51:01 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed May 2 14:51:17 2007 Subject: No Programs allowed In-Reply-To: <1178113173.14147.16.camel@viper.mbl.is> References: <1178113173.14147.16.camel@viper.mbl.is> Message-ID: <1178113860.17628.21.camel@gblades-suse.linguaphone-intranet.co.uk> On Wed, 2007-05-02 at 14:39, Jon Bjorn Njalsson wrote: > Why does MS think msg-26670-41.txt is a program ? > > MailScanner: No programs allowed (msg-26670-41.txt) > > regards > Jon Bjorn One of the checks Mailscanner does is use the 'file' command to check the actual type of the file. I have seen it get confused sometimes when a TNEF is decoded and the body message in the form you describe. I assume the message is in a foreign character set or may even be corrupt. From martinh at solidstatelogic.com Wed May 2 14:52:02 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 2 14:52:14 2007 Subject: No Programs allowed In-Reply-To: <1178113726.14147.20.camel@viper.mbl.is> Message-ID: <7c1f6fd152c6644ba6e543b0384f6f4a@solidstatelogic.com> I wouldn't advise it - why is that file showing as a program when file runs against it.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Jon Bjorn Njalsson > Sent: 02 May 2007 14:49 > To: MailScanner discussion > Subject: RE: No Programs allowed > > so is it safe to disable File Command = /usr/bin/file ? > > On mi?, 2007-05-02 at 14:44 +0100, Martin.Hepworth wrote: > > Jon > > > > The file command is showing it as a program. > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > > bounces@lists.mailscanner.info] On Behalf Of Jon Bjorn Njalsson > > > Sent: 02 May 2007 14:40 > > > To: MailScanner discussion > > > Subject: No Programs allowed > > > > > > Why does MS think msg-26670-41.txt is a program ? > > > > > > MailScanner: No programs allowed (msg-26670-41.txt) > > > > > > regards > > > Jon Bjorn > > > > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are intended for the > > addressee only and may be confidential. If they come to you in error > > you must take no action based on them, nor must you copy or show them > > to anyone. Please advise the sender by replying to this e-mail > > immediately and then delete the original from your computer. > > > > Opinion : Any opinions expressed in this e-mail are entirely those of > > the author and unless specifically stated to the contrary, are not > > necessarily those of the author's employer. > > > > Security Warning : Internet e-mail is not necessarily a secure > > communications medium and can be subject to data corruption. We advise > > that you consider this fact when e-mailing us. > > > > Viruses : We have taken steps to ensure that this e-mail and any > > attachments are free from known viruses but in keeping with good > > computing practice, you should ensure that they are virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic > > Registered as a limited company in England and Wales > > (Company No:5362730) > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > United Kingdom > > ********************************************************************** > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From pete at enitech.com.au Wed May 2 15:00:20 2007 From: pete at enitech.com.au (Pete Russell) Date: Wed May 2 15:00:32 2007 Subject: Spam detection rates In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA9222C4@HC-MBX02.herefordshire.gov.uk> References: <1178108748.17627.17.camel@gblades-suse.linguaphone-intranet.co.uk> <7EF0EE5CB3B263488C8C18823239BEBA9222C4@HC-MBX02.herefordshire.gov.uk> Message-ID: <46389974.9060000@enitech.com.au> I dont see how its possible to measure. Unless users report (and you count) every single spam they receive that they shouldnt have. I can tell you that my systems cathc more FPs and less spam than they did 6 months ago. Maybe its a sing i need fuzzy ocr and greylisting? Hope the new MS and SA this month will cure some of it. Randal, Phil wrote: > We consistently get over 99.5% of spam too. > > Last month we blocked around 260,000 at the sendmail level > (cbl.abuseat.org RBL and GreetPause), and 400,000 in MailScanner. > > Spam seems to be around 75% of total emails here. > > Cheers, > > Phil > -- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf >> Of Gareth >> Sent: 02 May 2007 13:26 >> To: mailscanner@lists.mailscanner.info >> Subject: Spam detection rates >> >> I was wondering what sort of detection rates people are getting when >> using Mailscanner. >> Our old spamassassin 2.64 based system was only getting about 80% but >> with Mailscanner and the latest software we seem to be getting over >> 99.5% which is extremely good. False positives are very low aswell. >> >> We do tend to be very strict about pictures attached to emails as I >> think we have a few rules which do the same sort of checks. Some >> external people using the incredimail 'piece of cr**p' mail >> client get a >> continuous score about 4.3 which leaves the AWL little room >> to bring the >> occasional higher scoring mail back below the 5.0 threshold. It hasn't >> caused any people to complain though. >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> From jon at radel.com Wed May 2 15:07:45 2007 From: jon at radel.com (Jon Radel) Date: Wed May 2 15:07:59 2007 Subject: No Programs allowed In-Reply-To: <1178113726.14147.20.camel@viper.mbl.is> References: <1178113726.14147.20.camel@viper.mbl.is> Message-ID: <46389B31.4040809@radel.com> Jon Bjorn Njalsson wrote: > so is it safe to disable File Command = /usr/bin/file ? That would be between you, your management (if any), and your security policy (should you have one). What I would consider not safe at all is expecting us to know the local factors that govern the trade offs between: * The low probability, but potentially extremely expensive, scenario where file turns out to have been capable of catching that brand new nasty that just reduced your LAN to a smoldering ruin, and * The much higher probability, but much lower cost, cases of false positives. --Jon Radel -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 2890 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070502/9928ebbc/smime.bin From jonbjorn at mbl.is Wed May 2 15:14:47 2007 From: jonbjorn at mbl.is (Jon Bjorn Njalsson) Date: Wed May 2 15:15:04 2007 Subject: No Programs allowed In-Reply-To: <7c1f6fd152c6644ba6e543b0384f6f4a@solidstatelogic.com> References: <7c1f6fd152c6644ba6e543b0384f6f4a@solidstatelogic.com> Message-ID: <1178115287.14147.24.camel@viper.mbl.is> I have no idea, looking at the message in mailwatch I see at the bottom of the page File msg-26492-33.txt Type text/plain; charset=iso-8859-1 and the file command run against message body says ASCII HTML document text. On mi?, 2007-05-02 at 14:52 +0100, Martin.Hepworth wrote: > I wouldn't advise it - why is that file showing as a program when file > runs against it.. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Jon Bjorn Njalsson > > Sent: 02 May 2007 14:49 > > To: MailScanner discussion > > Subject: RE: No Programs allowed > > > > so is it safe to disable File Command = /usr/bin/file ? > > > > On mi?, 2007-05-02 at 14:44 +0100, Martin.Hepworth wrote: > > > Jon > > > > > > The file command is showing it as a program. > > > > > > -- > > > Martin Hepworth > > > Snr Systems Administrator > > > Solid State Logic > > > Tel: +44 (0)1865 842300 > > > > > > > -----Original Message----- > > > > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- > > > > bounces@lists.mailscanner.info] On Behalf Of Jon Bjorn Njalsson > > > > Sent: 02 May 2007 14:40 > > > > To: MailScanner discussion > > > > Subject: No Programs allowed > > > > > > > > Why does MS think msg-26670-41.txt is a program ? > > > > > > > > MailScanner: No programs allowed (msg-26670-41.txt) > > > > > > > > regards > > > > Jon Bjorn > > > > > > > > -- > > > > MailScanner mailing list > > > > mailscanner@lists.mailscanner.info > > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > > > > > > > ********************************************************************** > > > Confidentiality : This e-mail and any attachments are intended for > the > > > addressee only and may be confidential. If they come to you in error > > > you must take no action based on them, nor must you copy or show > them > > > to anyone. Please advise the sender by replying to this e-mail > > > immediately and then delete the original from your computer. > > > > > > Opinion : Any opinions expressed in this e-mail are entirely those > of > > > the author and unless specifically stated to the contrary, are not > > > necessarily those of the author's employer. > > > > > > Security Warning : Internet e-mail is not necessarily a secure > > > communications medium and can be subject to data corruption. We > advise > > > that you consider this fact when e-mailing us. > > > > > > Viruses : We have taken steps to ensure that this e-mail and any > > > attachments are free from known viruses but in keeping with good > > > computing practice, you should ensure that they are virus free. > > > > > > Red Lion 49 Ltd T/A Solid State Logic > > > Registered as a limited company in England and Wales > > > (Company No:5362730) > > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > > United Kingdom > > > > ********************************************************************** > > > > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > From martinh at solidstatelogic.com Wed May 2 15:21:37 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 2 15:21:33 2007 Subject: No Programs allowed In-Reply-To: <1178115287.14147.24.camel@viper.mbl.is> Message-ID: <9fdae64d9cb45742839ee4b8c753c7c3@solidstatelogic.com> Jon Any attachments in the email? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Jon Bjorn Njalsson > Sent: 02 May 2007 15:15 > To: MailScanner discussion > Subject: RE: No Programs allowed > > I have no idea, looking at the message in mailwatch I see at the bottom > of the page File msg-26492-33.txt Type text/plain; charset=iso-8859-1 > and the file command run against message body says ASCII HTML document > text. > > On mi?, 2007-05-02 at 14:52 +0100, Martin.Hepworth wrote: > > I wouldn't advise it - why is that file showing as a program when file > > runs against it.. > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > > bounces@lists.mailscanner.info] On Behalf Of Jon Bjorn Njalsson > > > Sent: 02 May 2007 14:49 > > > To: MailScanner discussion > > > Subject: RE: No Programs allowed > > > > > > so is it safe to disable File Command = /usr/bin/file ? > > > > > > On mi?, 2007-05-02 at 14:44 +0100, Martin.Hepworth wrote: > > > > Jon > > > > > > > > The file command is showing it as a program. > > > > > > > > -- > > > > Martin Hepworth > > > > Snr Systems Administrator > > > > Solid State Logic > > > > Tel: +44 (0)1865 842300 > > > > > > > > > -----Original Message----- > > > > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner- > > > > > bounces@lists.mailscanner.info] On Behalf Of Jon Bjorn Njalsson > > > > > Sent: 02 May 2007 14:40 > > > > > To: MailScanner discussion > > > > > Subject: No Programs allowed > > > > > > > > > > Why does MS think msg-26670-41.txt is a program ? > > > > > > > > > > MailScanner: No programs allowed (msg-26670-41.txt) > > > > > > > > > > regards > > > > > Jon Bjorn > > > > > > > > > > -- > > > > > MailScanner mailing list > > > > > mailscanner@lists.mailscanner.info > > > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > > > > > > > > > > > > > ********************************************************************** > > > > Confidentiality : This e-mail and any attachments are intended for > > the > > > > addressee only and may be confidential. If they come to you in error > > > > you must take no action based on them, nor must you copy or show > > them > > > > to anyone. Please advise the sender by replying to this e-mail > > > > immediately and then delete the original from your computer. > > > > > > > > Opinion : Any opinions expressed in this e-mail are entirely those > > of > > > > the author and unless specifically stated to the contrary, are not > > > > necessarily those of the author's employer. > > > > > > > > Security Warning : Internet e-mail is not necessarily a secure > > > > communications medium and can be subject to data corruption. We > > advise > > > > that you consider this fact when e-mailing us. > > > > > > > > Viruses : We have taken steps to ensure that this e-mail and any > > > > attachments are free from known viruses but in keeping with good > > > > computing practice, you should ensure that they are virus free. > > > > > > > > Red Lion 49 Ltd T/A Solid State Logic > > > > Registered as a limited company in England and Wales > > > > (Company No:5362730) > > > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > > > United Kingdom > > > > > > ********************************************************************** > > > > > > > > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are intended for the > > addressee only and may be confidential. If they come to you in error > > you must take no action based on them, nor must you copy or show them > > to anyone. Please advise the sender by replying to this e-mail > > immediately and then delete the original from your computer. > > > > Opinion : Any opinions expressed in this e-mail are entirely those of > > the author and unless specifically stated to the contrary, are not > > necessarily those of the author's employer. > > > > Security Warning : Internet e-mail is not necessarily a secure > > communications medium and can be subject to data corruption. We advise > > that you consider this fact when e-mailing us. > > > > Viruses : We have taken steps to ensure that this e-mail and any > > attachments are free from known viruses but in keeping with good > > computing practice, you should ensure that they are virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic > > Registered as a limited company in England and Wales > > (Company No:5362730) > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > United Kingdom > > ********************************************************************** > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From glenn.steen at gmail.com Wed May 2 15:27:08 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed May 2 15:27:11 2007 Subject: No Programs allowed In-Reply-To: <1178115287.14147.24.camel@viper.mbl.is> References: <7c1f6fd152c6644ba6e543b0384f6f4a@solidstatelogic.com> <1178115287.14147.24.camel@viper.mbl.is> Message-ID: <223f97700705020727i503181cdp1598aebd456a1c64@mail.gmail.com> On 02/05/07, Jon Bjorn Njalsson wrote: > I have no idea, looking at the message in mailwatch I see at the bottom > of the page File msg-26492-33.txt Type text/plain; charset=iso-8859-1 > and the file command run against message body says ASCII HTML document > text. So it is already decoded to its own file in the quarantine... If you run file on that file, what does it (literally) say? -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From ajs at vifilfell.is Wed May 2 15:30:40 2007 From: ajs at vifilfell.is (ajs@vifilfell.is) Date: Wed May 2 15:33:04 2007 Subject: No Programs allowed In-Reply-To: <223f97700705020727i503181cdp1598aebd456a1c64@mail.gmail.com> Message-ID: This is related to the letter '?'. If a mail or an attachment starts with this character (hex 0xC9), file flags the mail as a DOS executable. Regards, Asgeir. "Glenn Steen" Sent by: mailscanner-bounces@lists.mailscanner.info 02.05.2007 14:27 Please respond to MailScanner discussion To "MailScanner discussion" cc Subject Re: No Programs allowed On 02/05/07, Jon Bjorn Njalsson wrote: > I have no idea, looking at the message in mailwatch I see at the bottom > of the page File msg-26492-33.txt Type text/plain; charset=iso-8859-1 > and the file command run against message body says ASCII HTML document > text. So it is already decoded to its own file in the quarantine... If you run file on that file, what does it (literally) say? -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070502/bf3a9b69/attachment-0001.html From ajs at vifilfell.is Wed May 2 15:34:41 2007 From: ajs at vifilfell.is (ajs@vifilfell.is) Date: Wed May 2 15:37:04 2007 Subject: No Programs allowed In-Reply-To: <223f97700705020727i503181cdp1598aebd456a1c64@mail.gmail.com> Message-ID: forgot to add, that it is possible to edit the file 'magic' so that emails starting with this letter will no longer get flagged as a DOS executable Asgeir. "Glenn Steen" Sent by: mailscanner-bounces@lists.mailscanner.info 02.05.2007 14:27 Please respond to MailScanner discussion To "MailScanner discussion" cc Subject Re: No Programs allowed On 02/05/07, Jon Bjorn Njalsson wrote: > I have no idea, looking at the message in mailwatch I see at the bottom > of the page File msg-26492-33.txt Type text/plain; charset=iso-8859-1 > and the file command run against message body says ASCII HTML document > text. So it is already decoded to its own file in the quarantine... If you run file on that file, what does it (literally) say? -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070502/d81c2c16/attachment.html From glenn.steen at gmail.com Wed May 2 15:46:33 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed May 2 15:46:37 2007 Subject: No Programs allowed In-Reply-To: References: <223f97700705020727i503181cdp1598aebd456a1c64@mail.gmail.com> Message-ID: <223f97700705020746u3015ab59r3cdbe3c0dac2f7c5@mail.gmail.com> On 02/05/07, ajs@vifilfell.is wrote: > > forgot to add, that it is possible to edit the file 'magic' so that emails starting with this letter will no longer get flagged as a DOS executable > > Asgeir. > Yes Asgeir, this may very well be the case this time too... We're slowly moving in this direction:-). Personally I tend to want the complete picture, or do some "nudging" (by way of some well phrased (hopefully:) questions) before stating my pet guess as fact though...;) As I'm sure you've noted (while checking over your own magic file) there are a few other "possible misdetections" in there;-). BTW, could you refrain from HTML mails to the list? Please... Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From ajs at vifilfell.is Wed May 2 16:00:43 2007 From: ajs at vifilfell.is (ajs@vifilfell.is) Date: Wed May 2 16:03:06 2007 Subject: No Programs allowed In-Reply-To: <223f97700705020746u3015ab59r3cdbe3c0dac2f7c5@mail.gmail.com> Message-ID: this is the case, Jon has tried the solution I pm-ed him and it works. I use Lotus for email and sometimes forget to switch to plain text when sending email to mailing list, will try to remember it next time. cheers, asgeir, "Glenn Steen" Sent by: mailscanner-bounces@lists.mailscanner.info 02.05.2007 14:46 Please respond to MailScanner discussion To "MailScanner discussion" cc Subject Re: No Programs allowed On 02/05/07, ajs@vifilfell.is wrote: > > forgot to add, that it is possible to edit the file 'magic' so that emails starting with this letter will no longer get flagged as a DOS executable > > Asgeir. > Yes Asgeir, this may very well be the case this time too... We're slowly moving in this direction:-). Personally I tend to want the complete picture, or do some "nudging" (by way of some well phrased (hopefully:) questions) before stating my pet guess as fact though...;) As I'm sure you've noted (while checking over your own magic file) there are a few other "possible misdetections" in there;-). BTW, could you refrain from HTML mails to the list? Please... Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From paul.hutchings at mira.co.uk Wed May 2 16:25:49 2007 From: paul.hutchings at mira.co.uk (Paul Hutchings) Date: Wed May 2 16:26:58 2007 Subject: 32 bit distro or 64? Message-ID: Again probably not a MailScanner specific query but as this box is specifically to run MailScanner I'll ask here. I have a new DL360 G5 and I'm planning on installing OpenSuse 10.2. Should I be using the 32 bit or 64 bit with regards to MailScanner, basically are there any reasons to choose one over the other? The box has 2gb of RAM so there's no "large memory" type issues involved it's purely why I might choose one over the other for this application. Cheers, Paul Paul Hutchings Network Administrator, MIRA Ltd. Tel: 44 (0)24 7635 5378 Fax: 44 (0)24 7635 8378 mailto:paul.hutchings@mira.co.uk -- MIRA Ltd. Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. Registered in England No. 402570 VAT Registration GB 114 5409 96 The contents of this e-mail are confidential and are solely for the use of the intended recipient. If you receive this e-mail in error, please delete it and notify us either by e-mail, telephone or fax. You should not copy, forward or otherwise disclose the content of the e-mail as this is prohibited. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070502/1d128d31/attachment.html From amaclach at yahoo.co.uk Wed May 2 16:33:55 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Wed May 2 16:33:56 2007 Subject: Spam detection rates Message-ID: <20070502153355.21002.qmail@web26306.mail.ukl.yahoo.com> SQLgrey is very effective at the postfix level - and cheap in terms of system resources. You just need a mysql database you can attach to. I have used postgrey in the past but it's not nice to manage. Regards, Andrew MacLachlan ----- Original Message ---- From: Pete Russell To: MailScanner discussion Sent: Wednesday, 2 May, 2007 3:00:20 PM Subject: Re: Spam detection rates I dont see how its possible to measure. Unless users report (and you count) every single spam they receive that they shouldnt have. I can tell you that my systems cathc more FPs and less spam than they did 6 months ago. Maybe its a sing i need fuzzy ocr and greylisting? Hope the new MS and SA this month will cure some of it. Randal, Phil wrote: > We consistently get over 99.5% of spam too. > > Last month we blocked around 260,000 at the sendmail level > (cbl.abuseat.org RBL and GreetPause), and 400,000 in MailScanner. > > Spam seems to be around 75% of total emails here. > > Cheers, > > Phil > -- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf >> Of Gareth >> Sent: 02 May 2007 13:26 >> To: mailscanner@lists.mailscanner.info >> Subject: Spam detection rates >> >> I was wondering what sort of detection rates people are getting when >> using Mailscanner. >> Our old spamassassin 2.64 based system was only getting about 80% but >> with Mailscanner and the latest software we seem to be getting over >> 99.5% which is extremely good. False positives are very low aswell. >> >> We do tend to be very strict about pictures attached to emails as I >> think we have a few rules which do the same sort of checks. Some >> external people using the incredimail 'piece of cr**p' mail >> client get a >> continuous score about 4.3 which leaves the AWL little room >> to bring the >> occasional higher scoring mail back below the 5.0 threshold. It hasn't >> caused any people to complain though. >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From cleveland at winnefox.org Wed May 2 16:46:59 2007 From: cleveland at winnefox.org (Jody Cleveland) Date: Wed May 2 16:47:03 2007 Subject: Can't locate Convert/BinHex.pm in @INC Message-ID: Hello, I just tried to install the latest version of MailScanner on my RedHat 5 server, and I get this error when trying to start mailscanner: Starting MailScanner daemons: incoming postfix: [ OK ] outgoing postfix: [ OK ] MailScanner: Can't locate Convert/BinHex.pm in @INC (@INC contains: /usr/lib/MailScanner /usr/lib/perl5/site_perl/5.8.8/i386-linux-thread-multi /usr/lib/perl5/site_perl/5.8.7/i386-linux-thread-multi /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi /usr/lib/perl5/site_perl/5.8.8 /usr/lib/perl5/site_perl/5.8.7 /usr/lib/perl5/site_perl/5.8.6 /usr/lib/perl5/site_perl/5.8.5 /usr/lib/perl5/site_perl /usr/lib/perl5/vendor_perl/5.8.8/i386-linux-thread-multi /usr/lib/perl5/vendor_perl/5.8.7/i386-linux-thread-multi /usr/lib/perl5/vendor_perl/5.8.6/i386-linux-thread-multi /usr/lib/perl5/vendor_perl/5.8.5/i386-linux-thread-multi /usr/lib/perl5/vendor_perl/5.8.8 /usr/lib/perl5/vendor_perl/5.8.7 /usr/lib/perl5/vendor_perl/5.8.6 /usr/lib/perl5/vendor_perl/5.8.5 /usr/lib/perl5/vendor_perl /usr/lib/perl5/5.8.8/i386-linux-thread-multi /usr/lib/perl5/5.8.8 . /usr/lib/MailScanner) at /usr/lib/perl5/site_perl/5.8.8/MIME/Decoder/BinHex.pm line 44. BEGIN failed--compilation aborted at /usr/lib/perl5/site_perl/5.8.8/MIME/Decoder/BinHex.pm line 44. Compilation failed in require at /usr/lib/MailScanner/MailScanner/Message.pm line 43. BEGIN failed--compilation aborted at /usr/lib/MailScanner/MailScanner/Message.pm line 43. Compilation failed in require at /usr/sbin/MailScanner line 79. BEGIN failed--compilation aborted at /usr/sbin/MailScanner line 79. I checked, and Convert::BinHex is installed. Any ideas what may be wrong? - jody From prandal at herefordshire.gov.uk Wed May 2 15:56:19 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Wed May 2 17:19:39 2007 Subject: Spam detection rates In-Reply-To: <46389974.9060000@enitech.com.au> References: <1178108748.17627.17.camel@gblades-suse.linguaphone-intranet.co.uk><7EF0EE5CB3B263488C8C18823239BEBA9222C4@HC-MBX02.herefordshire.gov.uk> <46389974.9060000@enitech.com.au> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA92230B@HC-MBX02.herefordshire.gov.uk> We have a zealous bunch of users who love reporting spam which gets through to their inboxes to me. And I do spot checks of our Mailwatch logs from time to time. About 3000 emails get flagged as low-scoring (possible) spam here, and delivered. Of those around 80% are spam, the rest are what I call "subscriber spam" - special offers mailing lists, etc. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Pete Russell > Sent: 02 May 2007 15:00 > To: MailScanner discussion > Subject: Re: Spam detection rates > > I dont see how its possible to measure. Unless users report (and you > count) every single spam they receive that they shouldnt have. > > I can tell you that my systems cathc more FPs and less spam than they > did 6 months ago. Maybe its a sing i need fuzzy ocr and greylisting? > > Hope the new MS and SA this month will cure some of it. > > > Randal, Phil wrote: > > We consistently get over 99.5% of spam too. > > > > Last month we blocked around 260,000 at the sendmail level > > (cbl.abuseat.org RBL and GreetPause), and 400,000 in MailScanner. > > > > Spam seems to be around 75% of total emails here. > > > > Cheers, > > > > Phil > > -- > > Phil Randal > > Network Engineer > > Herefordshire Council > > Hereford, UK > > > >> -----Original Message----- > >> From: mailscanner-bounces@lists.mailscanner.info > >> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > >> Of Gareth > >> Sent: 02 May 2007 13:26 > >> To: mailscanner@lists.mailscanner.info > >> Subject: Spam detection rates > >> > >> I was wondering what sort of detection rates people are > getting when > >> using Mailscanner. > >> Our old spamassassin 2.64 based system was only getting > about 80% but > >> with Mailscanner and the latest software we seem to be getting over > >> 99.5% which is extremely good. False positives are very low aswell. > >> > >> We do tend to be very strict about pictures attached to emails as I > >> think we have a few rules which do the same sort of checks. Some > >> external people using the incredimail 'piece of cr**p' mail > >> client get a > >> continuous score about 4.3 which leaves the AWL little room > >> to bring the > >> occasional higher scoring mail back below the 5.0 > threshold. It hasn't > >> caused any people to complain though. > >> > >> -- > >> MailScanner mailing list > >> mailscanner@lists.mailscanner.info > >> http://lists.mailscanner.info/mailman/listinfo/mailscanner > >> > >> Before posting, read http://wiki.mailscanner.info/posting > >> > >> Support MailScanner development - buy the book off the website! > >> > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From bpumphrey at woodmclaw.com Wed May 2 17:24:07 2007 From: bpumphrey at woodmclaw.com (Billy A. Pumphrey) Date: Wed May 2 17:24:09 2007 Subject: A lot of spam getting through In-Reply-To: <46385180.5090601@chime.ucl.ac.uk> Message-ID: <04D932B0071FE34FA63EBB1977B48D150281747A@woodenex.woodmaclaw.local> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Anthony Peacock > Sent: Wednesday, May 02, 2007 4:53 AM > To: MailScanner discussion > Subject: Re: A lot of spam getting through > So, help us out and show us the scores and headers from one that does > get through. We might be able to see where they are failing then. > > Even better... Save one of the misdiagnosed emails as a text file, post > it to a web address and let us know. We can then run that email through > our systems and tell you what scores we get and what rules helped. > I am having trouble getting the testing to work, or knowing how to test it. I have saved some messages from Oulook with the extension of .msg. When I run a spamassassin -t message.msg it returns a bunch of junk and then the score: Content analysis details: (51.5 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.0 NO_RELAYS Informational: message was not relayed via SMTP 2.5 MISSING_HB_SEP Missing blank line between message header and body 2.3 MANGLED_DOSE BODY: mangled dose 2.3 MANGLED_OFF BODY: mangled off 2.3 MANGLED_YOUR BODY: mangled your 2.3 MANGLED_FORM BODY: mangled form 2.3 MANGLED_HERE BODY: mangled here 2.3 MANGLED_HALF BODY: mangled half 2.3 MANGLED_TIME BODY: mangled time 2.3 MANGLED_MEDS BODY: mangled med(s) 2.3 MANGLED_GIRL BODY: mangled girl(s) 2.3 MANGLED_FROM BODY: mangled from 2.3 MANGLED_LOVE BODY: mangled love 2.3 MANGLED_TEXT BODY: mangled text 2.3 MANGLED_LOOK BODY: mangled look(s) 2.3 MANGLED_SPAM BODY: mangled spam 2.3 MANGLED_PRIOR BODY: mangled prior 2.3 MANGLED_PLEASE BODY: mangled please 2.3 MANGLED_TRNFER BODY: mangled TRANSFER 2.3 MANGLED_TOOL BODY: mangled tool 3.5 BAYES_99 BODY: Bayesian spam probability is 99 to 100% [score: 1.0000] 2.2 NULL_IN_BODY FULL: Message has NUL (ASCII 0) byte in message 1.8 MISSING_SUBJECT Missing Subject: header 0.0 UPPERCASE_25_50 message body is 25-50% uppercase 0.1 TO_CC_NONE No To: or Cc: header -0.0 NO_RECEIVED Informational: message has no Received headers (then some more junk) [root@WoodenMS2 spamemail]# PuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPu TTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTT YPuTTYPuTTYPuTTYPuTTYPuTTYTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPu Does the testing support .msg files? Also what is the best way to convert the email to text and have it correct? From cleveland at winnefox.org Wed May 2 17:25:51 2007 From: cleveland at winnefox.org (Jody Cleveland) Date: Wed May 2 17:25:56 2007 Subject: Can't locate Convert/BinHex.pm in @INC In-Reply-To: Message-ID: Hello again, On 5/2/07 10:46 AM, "Jody Cleveland" wrote: > Hello, > > I just tried to install the latest version of MailScanner on my RedHat 5 > server, and I get this error when trying to start mailscanner: > > Starting MailScanner daemons: > incoming postfix: [ OK ] > outgoing postfix: [ OK ] > MailScanner: Can't locate Convert/BinHex.pm in @INC (@INC Ok, I did a force install, and that reinstalled the pm, and I was able to start MailScanner. BUT, now MailScanner isn't checking incoming mail. I can send a message from gmail, and the message never goes through. I looked in my maillog, and this is what shows up when I start mailscanner: May 2 11:22:44 destiny postfix/postfix-script: starting the Postfix mail system May 2 11:22:44 destiny postfix/master[5581]: daemon started -- version 2.3.3, configuration /etc/postfix May 2 11:22:44 destiny postfix/qmgr[5591]: warning: bounce_queue_lifetime is larger than maximal_queue_lifetime - adjusting bounce_queue_lifetime May 2 11:22:44 destiny postfix/qmgr[5591]: 19B3C3E4029: from=<>, size=4046, nrcpt=1 (queue active) May 2 11:22:44 destiny postfix/qmgr[5591]: 7B5D73E402A: from=<>, size=4102, nrcpt=1 (queue active) May 2 11:22:44 destiny postfix/qmgr[5591]: CEB1A3E402D: from=<>, size=4394, nrcpt=1 (queue active) May 2 11:22:44 destiny postfix/qmgr[5591]: 101313E4027: from=<>, size=4020, nrcpt=1 (queue active) May 2 11:22:44 destiny postfix/local[5598]: fatal: open database /etc/postfix/aliases.db: No such file or directory May 2 11:22:45 destiny postfix/master[5581]: warning: process /usr/libexec/postfix/local pid 5598 exit status 1 May 2 11:22:45 destiny postfix/master[5581]: warning: /usr/libexec/postfix/local: bad command startup -- throttling May 2 11:22:46 destiny MailScanner[5604]: MailScanner E-Mail Virus Scanner version 4.59.4 starting... May 2 11:22:46 destiny MailScanner[5604]: Skipping Custom Function file SQLBlackWhiteList.old as its name does not end in .pm or .pl May 2 11:22:46 destiny MailScanner[5604]: Skipping Custom Function file SQLBlackWhiteList.pm~ as its name does not end in .pm or .pl May 2 11:22:46 destiny MailScanner[5604]: Read 778 hostnames from the phishing whitelist May 2 11:22:46 destiny MailScanner[5604]: Config: calling custom init function SQLBlacklist May 2 11:22:46 destiny MailScanner[5604]: Starting up SQL Blacklist May 2 11:22:46 destiny MailScanner[5604]: Read 29 blacklist entries May 2 11:22:46 destiny MailScanner[5604]: Config: calling custom init function MailWatchLogging May 2 11:22:46 destiny MailScanner[5604]: Started SQL Logging child May 2 11:22:46 destiny MailScanner[5604]: Config: calling custom init function SQLWhitelist May 2 11:22:46 destiny MailScanner[5604]: Starting up SQL Whitelist May 2 11:22:46 destiny MailScanner[5604]: Read 59 whitelist entries May 2 11:22:46 destiny MailScanner[5604]: User's home directory /var/spool/postfix is not writable May 2 11:22:46 destiny MailScanner[5604]: You need to set the "SpamAssassin User State Dir" to a directory that the "Run As User" can write to May 2 11:22:46 destiny MailScanner[5604]: Using SpamAssassin results cache May 2 11:22:46 destiny MailScanner[5604]: Connected to SpamAssassin cache database May 2 11:22:49 destiny MailScanner[5604]: Expired 654 records from the SpamAssassin cache May 2 11:22:49 destiny MailScanner[5604]: Enabling SpamAssassin auto-whitelist functionality... May 2 11:22:49 destiny postfix/smtpd[5613]: fatal: open database /etc/postfix/aliases.db: No such file or directory May 2 11:22:50 destiny postfix/master[5581]: warning: process /usr/libexec/postfix/smtpd pid 5613 exit status 1 May 2 11:22:50 destiny postfix/master[5581]: warning: /usr/libexec/postfix/smtpd: bad command startup -- throttling May 2 11:22:51 destiny MailScanner[5615]: MailScanner E-Mail Virus Scanner version 4.59.4 starting... May 2 11:22:51 destiny MailScanner[5615]: Skipping Custom Function file SQLBlackWhiteList.old as its name does not end in .pm or .pl May 2 11:22:51 destiny MailScanner[5615]: Skipping Custom Function file SQLBlackWhiteList.pm~ as its name does not end in .pm or .pl May 2 11:22:51 destiny MailScanner[5615]: Read 778 hostnames from the phishing whitelist May 2 11:22:51 destiny MailScanner[5615]: Config: calling custom init function SQLBlacklist May 2 11:22:51 destiny MailScanner[5615]: Starting up SQL Blacklist May 2 11:22:51 destiny MailScanner[5615]: Read 29 blacklist entries May 2 11:22:51 destiny MailScanner[5615]: Config: calling custom init function MailWatchLogging May 2 11:22:51 destiny MailScanner[5615]: Started SQL Logging child May 2 11:22:51 destiny MailScanner[5615]: Config: calling custom init function SQLWhitelist May 2 11:22:51 destiny MailScanner[5615]: Starting up SQL Whitelist May 2 11:22:51 destiny MailScanner[5615]: Read 59 whitelist entries May 2 11:22:51 destiny MailScanner[5615]: User's home directory /var/spool/postfix is not writable May 2 11:22:51 destiny MailScanner[5615]: You need to set the "SpamAssassin User State Dir" to a directory that the "Run As User" can write to May 2 11:22:52 destiny MailScanner[5615]: Using SpamAssassin results cache May 2 11:22:52 destiny MailScanner[5615]: Connected to SpamAssassin cache database May 2 11:22:52 destiny MailScanner[5615]: Enabling SpamAssassin auto-whitelist functionality... May 2 11:22:56 destiny MailScanner[5624]: MailScanner E-Mail Virus Scanner version 4.59.4 starting... May 2 11:22:56 destiny MailScanner[5624]: Skipping Custom Function file SQLBlackWhiteList.old as its name does not end in .pm or .pl May 2 11:22:56 destiny MailScanner[5624]: Skipping Custom Function file SQLBlackWhiteList.pm~ as its name does not end in .pm or .pl Is there anything in there that is a problem? If not, any ideas where I can look to find the problem? - jody From mikea at mikea.ath.cx Wed May 2 17:28:45 2007 From: mikea at mikea.ath.cx (mikea) Date: Wed May 2 17:28:54 2007 Subject: Can't locate Convert/BinHex.pm in @INC In-Reply-To: References: Message-ID: <20070502162845.GM20170@mikea.ath.cx> On Wed, May 02, 2007 at 10:46:59AM -0500, Jody Cleveland wrote: > Hello, > > I just tried to install the latest version of MailScanner on my RedHat 5 > server, and I get this error when trying to start mailscanner: > > Starting MailScanner daemons: > incoming postfix: [ OK ] > outgoing postfix: [ OK ] > MailScanner: Can't locate Convert/BinHex.pm in @INC (@INC > contains: /usr/lib/MailScanner > /usr/lib/perl5/site_perl/5.8.8/i386-linux-thread-multi > /usr/lib/perl5/site_perl/5.8.7/i386-linux-thread-multi > /usr/lib/perl5/site_perl/5.8.6/i386-linux-thread-multi > /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi > /usr/lib/perl5/site_perl/5.8.8 /usr/lib/perl5/site_perl/5.8.7 > /usr/lib/perl5/site_perl/5.8.6 /usr/lib/perl5/site_perl/5.8.5 > /usr/lib/perl5/site_perl > /usr/lib/perl5/vendor_perl/5.8.8/i386-linux-thread-multi > /usr/lib/perl5/vendor_perl/5.8.7/i386-linux-thread-multi > /usr/lib/perl5/vendor_perl/5.8.6/i386-linux-thread-multi > /usr/lib/perl5/vendor_perl/5.8.5/i386-linux-thread-multi > /usr/lib/perl5/vendor_perl/5.8.8 /usr/lib/perl5/vendor_perl/5.8.7 > /usr/lib/perl5/vendor_perl/5.8.6 /usr/lib/perl5/vendor_perl/5.8.5 > /usr/lib/perl5/vendor_perl /usr/lib/perl5/5.8.8/i386-linux-thread-multi > /usr/lib/perl5/5.8.8 . /usr/lib/MailScanner) at > /usr/lib/perl5/site_perl/5.8.8/MIME/Decoder/BinHex.pm line 44. > BEGIN failed--compilation aborted at > /usr/lib/perl5/site_perl/5.8.8/MIME/Decoder/BinHex.pm line 44. > Compilation failed in require at /usr/lib/MailScanner/MailScanner/Message.pm > line 43. > BEGIN failed--compilation aborted at > /usr/lib/MailScanner/MailScanner/Message.pm line 43. > Compilation failed in require at /usr/sbin/MailScanner line 79. > BEGIN failed--compilation aborted at /usr/sbin/MailScanner line 79. > > I checked, and Convert::BinHex is installed. Any ideas what may be wrong? Exactly where is Convert::BinHex installed? Is that directory in @INC? -- Mike Andrews, W5EGO mikea@mikea.ath.cx Tired old sysadmin From grpprod at gmail.com Wed May 2 17:58:25 2007 From: grpprod at gmail.com (G P) Date: Wed May 2 17:58:28 2007 Subject: Latest MS keeps restarting In-Reply-To: References: <773fecad0705010258k6a71712fmf85ec9638b766bb4@mail.gmail.com> Message-ID: <773fecad0705020958h7ac092fcpaeced7e08a5375a7@mail.gmail.com> > > Run in debug mode pls, you most likely have a issue with the new one thats > making it restart... > > OK, here are the results of debug mode: In Debugging mode, not forking... > Ignore errors about failing to find EOCD signature > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > DisarmPhishingFound = 0 on message l42GsXJX012133 > DisarmPhishingFound = 0 on message l42GsUaU012126 > DisarmPhishingFound = 0 on message l42Gt6ML012174 > DisarmPhishingFound = 0 on message l42GskTX012165 > DisarmPhishingFound = 0 on message l42Gt6L6012193 > DisarmPhishingFound = 0 on message l42GsRkR012119 > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070502/a1b0a106/attachment.html From list-mailscanner at linguaphone.com Wed May 2 18:02:08 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed May 2 18:02:13 2007 Subject: Can't locate Convert/BinHex.pm in @INC In-Reply-To: Message-ID: > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Jody > Cleveland > Sent: 02 May 2007 17:26 > To: MailScanner discussion > Subject: Re: Can't locate Convert/BinHex.pm in @INC > > > May 2 11:22:49 destiny postfix/smtpd[5613]: fatal: open database > /etc/postfix/aliases.db: No such file or directory > May 2 11:22:50 destiny postfix/master[5581]: warning: process > /usr/libexec/postfix/smtpd pid 5613 exit status 1 > May 2 11:22:50 destiny postfix/master[5581]: warning: > /usr/libexec/postfix/smtpd: bad command startup -- throttling Looks like a permissions issue where postfix cant open its alias database. From list-mailscanner at linguaphone.com Wed May 2 18:03:47 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed May 2 18:03:50 2007 Subject: A lot of spam getting through In-Reply-To: <04D932B0071FE34FA63EBB1977B48D150281747A@woodenex.woodmaclaw.local> Message-ID: > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Billy A. > Pumphrey > Sent: 02 May 2007 17:24 > To: MailScanner discussion > Subject: RE: A lot of spam getting through > > > I am having trouble getting the testing to work, or knowing how to test > it. I have saved some messages from Oulook with the extension of .msg. > When I run a spamassassin -t message.msg it returns a bunch of junk and > then the score: > > Content analysis details: (51.5 points, 5.0 required) snip > > Does the testing support .msg files? Also what is the best way to > convert the email to text and have it correct? I think msg files are encrypted in some way. I use IMAP as the mail store so I just query the message that is stored on the mail servers file system directly. From list-mailscanner at linguaphone.com Wed May 2 18:05:40 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed May 2 18:05:42 2007 Subject: Spam detection rates In-Reply-To: <46389974.9060000@enitech.com.au> Message-ID: > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Pete > Russell > Sent: 02 May 2007 15:00 > To: MailScanner discussion > Subject: Re: Spam detection rates > > > I dont see how its possible to measure. Unless users report (and you > count) every single spam they receive that they shouldnt have. > > I can tell you that my systems cathc more FPs and less spam than they > did 6 months ago. Maybe its a sing i need fuzzy ocr and greylisting? > > Hope the new MS and SA this month will cure some of it. I have some addresses that have been receiving over 100 spams a day for a long time. They are no longer in use so I redirect them to a test account and have all identified spams deleted automatically. Thats makes it easy to see what gets through and if required write a custom rule to detect them. From ssilva at sgvwater.com Wed May 2 18:24:53 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed May 2 18:25:30 2007 Subject: ClamAV Module Core Dump In-Reply-To: <004601c78c62$5973bf70$0300a8c0@bandwidthco.com> References: <004601c78c62$5973bf70$0300a8c0@bandwidthco.com> Message-ID: markee spake the following on 5/1/2007 7:34 PM: > I have tried installing more than once, and I am near to wiping out the clam > library and installing again. I might try clamd first, as anything has to be > better than the commandline scanner. I am already running a few scanners, > and every bit of load adds up. > I have 2 as near identical as possible boxes running CentOS 4. One works with the module, and one doesn't. I am currently looking for an init script for clamd since I installed from Julian's tarball. I am just going to download the rpm and extract the init script and check it. I wish he had a version of his spamassassin-clamav tarball that did rpm like the mailscanner install can. Maybe I will give it a shot and see what I can do next week. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From mikes at hartwellcorp.com Wed May 2 18:45:46 2007 From: mikes at hartwellcorp.com (Michael St. Laurent) Date: Wed May 2 18:46:11 2007 Subject: Spam detection rates Message-ID: <3BF93070B3D1B047BA7ABF612958950D018FB9D5@hcex.hartwellcorp.com> How long is your greet pause? > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Randal, Phil > Sent: Wednesday, May 02, 2007 5:43 AM > To: MailScanner discussion > Subject: RE: Spam detection rates > > We consistently get over 99.5% of spam too. > > Last month we blocked around 260,000 at the sendmail level > (cbl.abuseat.org RBL and GreetPause), and 400,000 in MailScanner. > > Spam seems to be around 75% of total emails here. > > Cheers, > > Phil > -- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > > Of Gareth > > Sent: 02 May 2007 13:26 > > To: mailscanner@lists.mailscanner.info > > Subject: Spam detection rates > > > > I was wondering what sort of detection rates people are getting when > > using Mailscanner. > > Our old spamassassin 2.64 based system was only getting > about 80% but > > with Mailscanner and the latest software we seem to be getting over > > 99.5% which is extremely good. False positives are very low aswell. > > > > We do tend to be very strict about pictures attached to emails as I > > think we have a few rules which do the same sort of checks. Some > > external people using the incredimail 'piece of cr**p' mail > > client get a > > continuous score about 4.3 which leaves the AWL little room > > to bring the > > occasional higher scoring mail back below the 5.0 > threshold. It hasn't > > caused any people to complain though. > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From ssilva at sgvwater.com Wed May 2 19:05:51 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed May 2 19:06:27 2007 Subject: No Programs allowed In-Reply-To: References: <223f97700705020727i503181cdp1598aebd456a1c64@mail.gmail.com> Message-ID: ajs@vifilfell.is spake the following on 5/2/2007 7:34 AM: > > forgot to add, that it is possible to edit the file 'magic' so that > emails starting with this letter will no longer get flagged as a DOS > executable > > Asgeir. I had to do this for one of the quicktime entries. Every time someone started a message with "I'm free ... " which seems to happen often here, it would get detected as a quicktime movie. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Wed May 2 19:08:41 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed May 2 19:10:11 2007 Subject: No Programs allowed In-Reply-To: References: <223f97700705020746u3015ab59r3cdbe3c0dac2f7c5@mail.gmail.com> Message-ID: ajs@vifilfell.is spake the following on 5/2/2007 8:00 AM: > this is the case, Jon has tried the solution I pm-ed him and it works. > > I use Lotus for email and sometimes forget to switch to plain text when > sending email to mailing list, will try to remember it next time. > > cheers, asgeir, The last time I used Notes, you could set certain addresses to only get text mail. But that was a long time ago. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Wed May 2 19:06:53 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed May 2 19:15:14 2007 Subject: Fwd: [shell-script] Oportunidade - TALENT FOUR/ Administrador de Redes e Sistemas - LINUX In-Reply-To: References: <6C590FEEFDEC05478512F3771363C6DB489830@tfcmail02.tfc.com.br> Message-ID: Fabio Silva spake the following on 5/2/2007 4:15 AM: > > > ---------- Forwarded message ---------- > From: *Renata Dardis de Souza* > > Date: Apr 30, 2007 4:30 PM > Subject: [shell-script] Oportunidade - TALENT FOUR/ Administrador de > Redes e Sistemas - LINUX > To: shell-script@yahoogrupos.com.br > > > Ol? Grupo, > > Boa tarde!!!! > > A Talent Four Consulting ? uma empresa de consultoria em projetos de > Tecnologia da Informa??o, especializada em servi?os e terceiriza??o de > Profissionais. Can't be too professional when you spam a spam-fighting mail list. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From mikes at hartwellcorp.com Wed May 2 20:13:01 2007 From: mikes at hartwellcorp.com (Michael St. Laurent) Date: Wed May 2 20:13:33 2007 Subject: RPM for milter-null? Message-ID: <3BF93070B3D1B047BA7ABF612958950D018FB9D6@hcex.hartwellcorp.com> Does anyone know of an RPM or SRPM for the milter-null package? From jstevens at athensdistributing.com Wed May 2 20:18:01 2007 From: jstevens at athensdistributing.com (James R. Stevens) Date: Wed May 2 20:18:10 2007 Subject: RPM for milter-null? References: <3BF93070B3D1B047BA7ABF612958950D018FB9D6@hcex.hartwellcorp.com> Message-ID: <1A65E6BAEADF9B4F865314484A13ECF1608865@atlas.athensdistributing.com> I wish.. Been trying to get libsnert to compile on RH 9 with the sole purpose to install milter-null... no luck -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Michael St. Laurent Sent: Wednesday, May 02, 2007 2:13 PM To: MailScanner discussion Subject: RPM for milter-null? Does anyone know of an RPM or SRPM for the milter-null package? -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by Athens Hyperion Scanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by Athens Hyperion Scanner, and is believed to be clean. From ka at pacific.net Wed May 2 20:21:21 2007 From: ka at pacific.net (Ken A) Date: Wed May 2 20:21:18 2007 Subject: RPM for milter-null? In-Reply-To: <3BF93070B3D1B047BA7ABF612958950D018FB9D6@hcex.hartwellcorp.com> References: <3BF93070B3D1B047BA7ABF612958950D018FB9D6@hcex.hartwellcorp.com> Message-ID: <4638E4B1.30809@pacific.net> Michael St. Laurent wrote: > Does anyone know of an RPM or SRPM for the milter-null package? It gets compiled against libsnert (on which you only do 'make', not 'make install') in com/snert/lib source tree, so there's no rpm. Just use the source for both from snertsoft.com. Both are free. -- Ken Anderson Pacific.Net From jstevens at athensdistributing.com Wed May 2 20:32:48 2007 From: jstevens at athensdistributing.com (James R. Stevens) Date: Wed May 2 20:32:58 2007 Subject: RPM for milter-null? References: <3BF93070B3D1B047BA7ABF612958950D018FB9D6@hcex.hartwellcorp.com> <4638E4B1.30809@pacific.net> Message-ID: <1A65E6BAEADF9B4F865314484A13ECF1608866@atlas.athensdistributing.com> Since this is already out there... Does this make sense to anyone? Trying to make libsnert bombs with error 2 I pass /configure with no arguments and all seems fine LibSnert/1.63.892 Copyright 1996, 2007 by Anthony Howe. All rights reserved. Platform............: Linux gcc Berkeley DB.........: 4.0 -ldb-4.0 POSIX Threads.......: yes yes SQLite3.............: yes Sendmail libmilter..: yes Semaphore API.......: SYSTEMV_API Shared Memory API...: SYSTEMV_API Time API............: BSD_API CFLAGS..............: -I/usr/include/db4 -I/usr/local/org/sqlite/include -D_REENTRANT -O2 -Wall -I${top_srcdir}/../../include LDFLAGS.............: -L/usr/local/org/sqlite/lib -L${top_srcdir}/../../lib LIBS................: -lpthread -ldl BUT after passing 'make clean build' it bombs.. *************************************************************** ==> /usr/local/com/snert/src/lib/../tools *************************************************************** gcc -I/usr/include/db4 -I/usr/local/org/sqlite/include -D_REENTRANT -O2 -Wall -I./../../include -L/usr/local/org/sqlite/lib -L./../../lib -o ansi ansi.c gcc -I/usr/include/db4 -I/usr/local/org/sqlite/include -D_REENTRANT -O2 -Wall -I./../../include -L/usr/local/org/sqlite/lib -L./../../lib -o flip flip.c -lsnert gcc -I/usr/include/db4 -I/usr/local/org/sqlite/include -D_REENTRANT -O2 -Wall -I./../../include -L/usr/local/org/sqlite/lib -L./../../lib -o smtpout smtpout.c -lsnert -lpthread -ldl ./../../lib/libsnert.a(socket2.o)(.text+0x3ee): In function `socketAddressCreate': : undefined reference to `VectorGet' [SNIP-IT] ./../../lib/libsnert.a(TextSplit.o)(.text+0x4e): In function `TextSplit': : undefined reference to `VectorAdd' collect2: ld returned 1 exit status make[1]: *** [smtpout] Error 1 make[1]: Leaving directory `/usr/local/com/snert/src/tools' make: *** [build] Error 2 -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Ken A Sent: Wednesday, May 02, 2007 2:21 PM To: MailScanner discussion Subject: Re: RPM for milter-null? Michael St. Laurent wrote: > Does anyone know of an RPM or SRPM for the milter-null package? It gets compiled against libsnert (on which you only do 'make', not 'make install') in com/snert/lib source tree, so there's no rpm. Just use the source for both from snertsoft.com. Both are free. -- Ken Anderson Pacific.Net -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by Athens Hyperion Scanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by Athens Hyperion Scanner, and is believed to be clean. From Denis.Beauchemin at USherbrooke.ca Wed May 2 20:43:06 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Wed May 2 20:43:31 2007 Subject: RPM for milter-null? In-Reply-To: <1A65E6BAEADF9B4F865314484A13ECF1608866@atlas.athensdistributing.com> References: <3BF93070B3D1B047BA7ABF612958950D018FB9D6@hcex.hartwellcorp.com> <4638E4B1.30809@pacific.net> <1A65E6BAEADF9B4F865314484A13ECF1608866@atlas.athensdistributing.com> Message-ID: <4638E9CA.1010908@USherbrooke.ca> James R. Stevens a ?crit : > Since this is already out there... Does this make sense to anyone? > > Trying to make libsnert bombs with error 2 > I think you need to install sendmail-devel under RH/CentOS for it to compile... Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3595 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070502/d9dd3123/smime-0001.bin From MailScanner at ecs.soton.ac.uk Wed May 2 20:40:16 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 2 20:43:36 2007 Subject: 32 bit distro or 64? In-Reply-To: References: Message-ID: <4638E920.6000706@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I've never had the time recently to do 32-bit versus 64-bit speed tests on the same hardware, I tend to install 64-bit on 64-bit machines by default, though. One thing I can say: if you use Sophos, I believe they still don't have a 64-bit version of the SAVI library available. This will affect you if you are using the "sophossavi" Virus Scanners setting. Jules. Paul Hutchings wrote: > > Again probably not a MailScanner specific query but as this box is > specifically to run MailScanner I?ll ask here. > > I have a new DL360 G5 and I?m planning on installing OpenSuse 10.2. > Should I be using the 32 bit or 64 bit with regards to MailScanner, > basically are there any reasons to choose one over the other? > > The box has 2gb of RAM so there?s no ?large memory? type issues > involved it?s purely why I might choose one over the other for this > application. > > Cheers, > > Paul > > Paul Hutchings > > Network Administrator, MIRA Ltd. > > Tel: 44 (0)24 7635 5378 > > Fax: 44 (0)24 7635 8378 > > mailto:paul.hutchings@mira.co.uk > > > > ------------------------------------------------------------------------ > *MIRA Ltd.* > Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. > Registered in England No. 402570 > VAT Registration GB 114 5409 96 > > The contents of this e-mail are confidential and are solely for the > use of the intended recipient. > If you receive this e-mail in error, please delete it and notify us > either by e-mail, telephone or fax. > You should not copy, forward or otherwise disclose the content of the > e-mail as this is prohibited. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: windows-1252 wj8DBQFGOOnJEfZZRxQVtlQRAuYwAJ9vQgHcjG/HdrrLm4QKtrutBdWK5QCfXD+o EJPoQyOLMSzfsspnbiUcMeg= =f3SB -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Wed May 2 20:45:16 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 2 20:48:14 2007 Subject: Latest MS keeps restarting In-Reply-To: <773fecad0705020958h7ac092fcpaeced7e08a5375a7@mail.gmail.com> References: <773fecad0705010258k6a71712fmf85ec9638b766bb4@mail.gmail.com> <773fecad0705020958h7ac092fcpaeced7e08a5375a7@mail.gmail.com> Message-ID: <4638EA4C.7080307@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 The EOCD messages can be safe ignored, just as it says. So that's not it. Was that the complete output of debug mode? It doesn't show any signs of errors, except I'm worried you haven't posted what would normally be the last line of output: Stopping now as you are debugging me. Jules. G P wrote: > > Run in debug mode pls, you most likely have a issue with the new > one thats > making it restart... > > OK, here are the results of debug mode: > > In Debugging mode, not forking... > Ignore errors about failing to find EOCD signature > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > format error: can't find EOCD signature > at /opt/MailScanner/bin/MailScanner line 832 > DisarmPhishingFound = 0 on message l42GsXJX012133 > DisarmPhishingFound = 0 on message l42GsUaU012126 > DisarmPhishingFound = 0 on message l42Gt6ML012174 > DisarmPhishingFound = 0 on message l42GskTX012165 > DisarmPhishingFound = 0 on message l42Gt6L6012193 > DisarmPhishingFound = 0 on message l42GsRkR012119 > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGOOrcEfZZRxQVtlQRAlE8AKDc1Hl8AYq5F2jHxsev+gy5bA3g0gCdET2S foMf9JQ6i6MjmovQ7L9K4b4= =9hQN -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From grpprod at gmail.com Wed May 2 21:12:39 2007 From: grpprod at gmail.com (G P) Date: Wed May 2 21:12:41 2007 Subject: Latest MS keeps restarting In-Reply-To: <4638EA4C.7080307@ecs.soton.ac.uk> References: <773fecad0705010258k6a71712fmf85ec9638b766bb4@mail.gmail.com> <773fecad0705020958h7ac092fcpaeced7e08a5375a7@mail.gmail.com> <4638EA4C.7080307@ecs.soton.ac.uk> Message-ID: <773fecad0705021312q4fad6f8fnc2976122321ed055@mail.gmail.com> > > The EOCD messages can be safe ignored, just as it says. So that's not it. > Was that the complete output of debug mode? > It doesn't show any signs of errors, except I'm worried you haven't > posted what would normally be the last line of output: > Stopping now as you are debugging me. You're right, yet I deliberately omitted the last line. I just double-checked, and I can confirm this is the total output. I will make one more attempt to switch to the latest version and post here the results. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070502/38518b0a/attachment.html From mkettler at evi-inc.com Wed May 2 21:51:34 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Wed May 2 21:51:45 2007 Subject: 32 bit distro or 64? In-Reply-To: References: Message-ID: <4638F9D6.1070003@evi-inc.com> Paul Hutchings wrote: > Again probably not a MailScanner specific query but as this box is > specifically to run MailScanner I?ll ask here. > > > > I have a new DL360 G5 and I?m planning on installing OpenSuse 10.2. > Should I be using the 32 bit or 64 bit with regards to MailScanner, > basically are there any reasons to choose one over the other? > I've not benchmarked it, but theoretically the difference should be insignificant. On the up-side the 64bit version will use native 64bit math instructions for 64-bit arithmetic (ie: file offsets), making common additions take 1 instruction cycle instead of 2. However, this isn't so common, particularly in a MailScanner/SA/AV setup, that it would make a big difference. The downside 64bit version will also use 64-bit pointers and code segments, increasing memory usage slightly. However, this isn't big enough to make a significant difference either. You've almost certainly increased memory usage by less than 5%, and probably less than 1%. However, if you ever expect to "scale up" the memory beyond 4gb, the 64-bit version would be helpful. Otherwise, it's a wash. You gain a small amount of performance for a small increase in memory use. From res at ausics.net Wed May 2 22:04:19 2007 From: res at ausics.net (Res) Date: Wed May 2 22:04:30 2007 Subject: RPM for milter-null? In-Reply-To: <4638E9CA.1010908@USherbrooke.ca> References: <3BF93070B3D1B047BA7ABF612958950D018FB9D6@hcex.hartwellcorp.com> <4638E4B1.30809@pacific.net> <1A65E6BAEADF9B4F865314484A13ECF1608866@atlas.athensdistributing.com> <4638E9CA.1010908@USherbrooke.ca> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Wed, 2 May 2007, Denis Beauchemin wrote: > James R. Stevens a écrit : >> Since this is already out there... Does this make sense to anyone? >> >> Trying to make libsnert bombs with error 2 >> > > I think you need to install sendmail-devel under RH/CentOS for it to > compile... > Since there has been no rpm update of RH9 sendmail (even from the now defunct legacy network) for several years I would HOPE he is not running any rpm version of sendmail and has the actual tarballs of at least more current stuff. - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGOPzWsWhAmSIQh7MRAoh/AJ9PB/oIUGUM68mTYfcb1fKRgAcarwCeKQfA OFo6kvpserOfyDM0Go+CX/g= =1Xug -----END PGP SIGNATURE----- From mailscanner at yeticomputers.com Wed May 2 22:21:58 2007 From: mailscanner at yeticomputers.com (Rick Chadderdon) Date: Wed May 2 22:15:32 2007 Subject: 32 bit distro or 64? In-Reply-To: References: Message-ID: <463900F6.1070103@yeticomputers.com> Paul Hutchings wrote: > > I have a new DL360 G5 and I?m planning on installing OpenSuse 10.2. > Should I be using the 32 bit or 64 bit with regards to MailScanner, > basically are there any reasons to choose one over the other? > It's probably worth some consideration that there is less software available in 64-bit versions. Julian touched on this with the Sophos information he offered, and my personal experience leads me to believe that Sophos is not likely to be the only vendor with this issue. Hence, a 64-bit distro likely limits your choices if you should need to look for a variety of antivirus vendors (or if the future need should arise to change vendors from ones you have already determined to be 64-bit ready), and it will do so while offering a very minimal increase in performance, if any. Be aware that I have no knowledge of any specific virus scanner that does/does not work in a 64-bit environment - I'm just cautious because this issue has bitten me before, and have come to think of 64-bit as "option limiting". I only use 64-bit OSes when I have absolute certainty that I will not need to rely on any closed-source vendor to provide 64-bit support. Rick From MailScanner at ecs.soton.ac.uk Wed May 2 22:20:49 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 2 22:23:42 2007 Subject: SpamAssassin 3.2.0 Message-ID: <463900B1.8080301@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Well, as someone else has already said, it's been released. Its list of requirements has grown quite a lot. In addition to whatever else you already have from an existing SA install, you need to install this load of Perl modules, in this order: YAML -- requires y\n in perl Makefile.PL ExtUtils::CBuilder ExtUtils::ParseXS Module::Build version Net::DNS::Resolver::Programmable Error NetAddr::IP Net::DNS >=0.58 Data::Dump Encode::Detect Mail::SPF Mail::SpamAssassin -- requires \n in perl Makefile.PL It puts in a v320.pre into /etc/mail/spamassassin and comes with a load of new plugins. Some of them are loaded by the default supplied v320.pre file, but here are the ones that aren't: Hashcash.pm Rule2XSBody.pm ASN.pm SpamCop.pm AutoLearnThreshold.pm SPF.pm AWL.pm Test.pm TextCat.pm MIMEHeader.pm BodyRuleBaseExtractor.pm OneLineBodyRuleType.pm URIDNSBL.pm Pyzor.pm DCC.pm Razor2.pm RelayCountry.pm WhiteListSubject.pm ReplaceTags.pm My next step is to read the man pages for all of these, and work out which ones you probably want to load and which ones you don't, so that my install script can set you up with a sensible system. One thing I'm not installing is support for DKIM which, although available, requires so many pre-requisites that it's not feasible for me to do here. You have to start at the OpenSSL libraries and work your way up :-( Once I've got something working here, I'll write up an install script for it all and wrap it into a package for you. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGOQEwEfZZRxQVtlQRArCWAJ95n3Z0uHjg/25LaIHPFUauWsZ+vACfYdtP qjZF/RoldGlTZywtz3b9U/8= =yA8+ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Wed May 2 22:33:58 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed May 2 22:35:12 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: <463900B1.8080301@ecs.soton.ac.uk> References: <463900B1.8080301@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 5/2/2007 2:20 PM: > Well, as someone else has already said, it's been released. > > Its list of requirements has grown quite a lot. In addition to whatever > else you already have from an existing SA install, you need to install > this load of Perl modules, in this order: > > YAML -- requires y\n in perl Makefile.PL > ExtUtils::CBuilder > ExtUtils::ParseXS > Module::Build > version > Net::DNS::Resolver::Programmable > Error > NetAddr::IP > Net::DNS >=0.58 > Data::Dump > Encode::Detect > Mail::SPF > Mail::SpamAssassin -- requires \n in perl Makefile.PL > > It puts in a v320.pre into /etc/mail/spamassassin and comes with a load > of new plugins. Some of them are loaded by the default supplied v320.pre > file, but here are the ones that aren't: > > Hashcash.pm Rule2XSBody.pm > ASN.pm SpamCop.pm > AutoLearnThreshold.pm SPF.pm > AWL.pm Test.pm > TextCat.pm > MIMEHeader.pm > BodyRuleBaseExtractor.pm OneLineBodyRuleType.pm URIDNSBL.pm > Pyzor.pm > DCC.pm Razor2.pm > RelayCountry.pm WhiteListSubject.pm > ReplaceTags.pm > > My next step is to read the man pages for all of these, and work out > which ones you probably want to load and which ones you don't, so that > my install script can set you up with a sensible system. One thing I'm > not installing is support for DKIM which, although available, requires > so many pre-requisites that it's not feasible for me to do here. You > have to start at the OpenSSL libraries and work your way up :-( > > Once I've got something working here, I'll write up an install script > for it all and wrap it into a package for you. > > Jules > Looking at your daily increased activity on the list, I am assuming (hopefully) that you are feeling somewhat better. Keep up the good healing, and rest as much as you can without driving yourself crazy. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From Richard.Frovarp at sendit.nodak.edu Wed May 2 22:38:02 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Wed May 2 22:38:07 2007 Subject: 32 bit distro or 64? In-Reply-To: <463900F6.1070103@yeticomputers.com> References: <463900F6.1070103@yeticomputers.com> Message-ID: <463904BA.4040402@sendit.nodak.edu> Rick Chadderdon wrote: > Paul Hutchings wrote: > >> I have a new DL360 G5 and I?m planning on installing OpenSuse 10.2. >> Should I be using the 32 bit or 64 bit with regards to MailScanner, >> basically are there any reasons to choose one over the other? >> >> > > It's probably worth some consideration that there is less software > available in 64-bit versions. Julian touched on this with the Sophos > information he offered, and my personal experience leads me to believe > that Sophos is not likely to be the only vendor with this issue. Hence, > a 64-bit distro likely limits your choices if you should need to look > for a variety of antivirus vendors (or if the future need should arise > to change vendors from ones you have already determined to be 64-bit > ready), and it will do so while offering a very minimal increase in > performance, if any. > > Be aware that I have no knowledge of any specific virus scanner that > does/does not work in a 64-bit environment - I'm just cautious because > this issue has bitten me before, and have come to think of 64-bit as > "option limiting". I only use 64-bit OSes when I have absolute > certainty that I will not need to rely on any closed-source vendor to > provide 64-bit support. > > Rick > Couldn't you just run the 32bit versions of the virus scanners? We're not talking about full 64 bit like Itaniums or any other number of other processors out there. We're just talking about 64 bit extended OSs. I run plenty of 32bit applications on my 64bit OS without any problems. Of course I have the 32bit and 64bit versions of all the libraries installed to do this. Richard From spamtrap71892316634 at anime.net Wed May 2 22:50:20 2007 From: spamtrap71892316634 at anime.net (Dan Hollis) Date: Wed May 2 22:50:23 2007 Subject: 32 bit distro or 64? In-Reply-To: <463900F6.1070103@yeticomputers.com> References: <463900F6.1070103@yeticomputers.com> Message-ID: On Wed, 2 May 2007, Rick Chadderdon wrote: > Be aware that I have no knowledge of any specific virus scanner that > does/does not work in a 64-bit environment - I'm just cautious because > this issue has bitten me before, and have come to think of 64-bit as > "option limiting". I only use 64-bit OSes when I have absolute > certainty that I will not need to rely on any closed-source vendor to > provide 64-bit support. I have never had any issues running 32bit apps on 64bit OS. -Dan From ms-list at alexb.ch Wed May 2 23:04:02 2007 From: ms-list at alexb.ch (Alex Broens) Date: Wed May 2 23:04:09 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: <463900B1.8080301@ecs.soton.ac.uk> References: <463900B1.8080301@ecs.soton.ac.uk> Message-ID: <46390AD2.8010208@alexb.ch> On 5/2/2007 11:20 PM, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Well, as someone else has already said, it's been released. > > Its list of requirements has grown quite a lot. In addition to whatever > else you already have from an existing SA install, you need to install > this load of Perl modules, in this order: > > YAML -- requires y\n in perl Makefile.PL > ExtUtils::CBuilder > ExtUtils::ParseXS > Module::Build > version > Net::DNS::Resolver::Programmable > Error > NetAddr::IP > Net::DNS >=0.58 > Data::Dump > Encode::Detect > Mail::SPF > Mail::SpamAssassin -- requires \n in perl Makefile.PL > > It puts in a v320.pre into /etc/mail/spamassassin and comes with a load > of new plugins. Some of them are loaded by the default supplied v320.pre > file, but here are the ones that aren't: > > Hashcash.pm Rule2XSBody.pm > ASN.pm SpamCop.pm > AutoLearnThreshold.pm SPF.pm > AWL.pm Test.pm > TextCat.pm > MIMEHeader.pm > BodyRuleBaseExtractor.pm OneLineBodyRuleType.pm URIDNSBL.pm > Pyzor.pm > DCC.pm Razor2.pm > RelayCountry.pm WhiteListSubject.pm > ReplaceTags.pm > > My next step is to read the man pages for all of these, and work out > which ones you probably want to load and which ones you don't, so that > my install script can set you up with a sensible system. One thing I'm > not installing is support for DKIM which, although available, requires > so many pre-requisites that it's not feasible for me to do here. You > have to start at the OpenSSL libraries and work your way up :-( > > Once I've got something working here, I'll write up an install script > for it all and wrap it into a package for you. > > Jules Julian One of the nices features SA 3.2 has is the shortcicuiting of rules. This may be a big resource saver and you may have to adapt MailScanner quite a bit to play with the shortcircuiting concept. Alex From root at doctor.nl2k.ab.ca Wed May 2 23:07:58 2007 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Wed May 2 23:10:35 2007 Subject: Bogus IPs in hearder Message-ID: <20070502220757.GD1334@doctor.nl2k.ab.ca> HEADERS!! I cannot type today. Still, can we use mailscanner and/or Spam Assassin to block out mail using and octet > 255 or < 0? -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From r.berber at computer.org Wed May 2 23:06:21 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Wed May 2 23:10:43 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: <463900B1.8080301@ecs.soton.ac.uk> References: <463900B1.8080301@ecs.soton.ac.uk> Message-ID: Julian Field wrote: [snip] > Once I've got something working here, I'll write up an install script > for it all and wrap it into a package for you. SA 3.2.0 seems to have a nasty bug that leaves temporary files, it would be better to wait for a package until the dust settles. -- Ren? Berber From doc at maddoc.net Wed May 2 23:11:08 2007 From: doc at maddoc.net (Doc Schneider) Date: Wed May 2 23:11:14 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: <463900B1.8080301@ecs.soton.ac.uk> References: <463900B1.8080301@ecs.soton.ac.uk> Message-ID: <46390C7C.70406@maddoc.net> Julian Field wrote: > Well, as someone else has already said, it's been released. > > Its list of requirements has grown quite a lot. In addition to whatever > else you already have from an existing SA install, you need to install > this load of Perl modules, in this order: > > YAML -- requires y\n in perl Makefile.PL > ExtUtils::CBuilder > ExtUtils::ParseXS > Module::Build > version > Net::DNS::Resolver::Programmable > Error > NetAddr::IP > Net::DNS >=0.58 > Data::Dump > Encode::Detect > Mail::SPF > Mail::SpamAssassin -- requires \n in perl Makefile.PL > > It puts in a v320.pre into /etc/mail/spamassassin and comes with a load > of new plugins. Some of them are loaded by the default supplied v320.pre > file, but here are the ones that aren't: > > Hashcash.pm Rule2XSBody.pm > ASN.pm SpamCop.pm > AutoLearnThreshold.pm SPF.pm > AWL.pm Test.pm > TextCat.pm > MIMEHeader.pm > BodyRuleBaseExtractor.pm OneLineBodyRuleType.pm URIDNSBL.pm > Pyzor.pm > DCC.pm Razor2.pm > RelayCountry.pm WhiteListSubject.pm > ReplaceTags.pm > > My next step is to read the man pages for all of these, and work out > which ones you probably want to load and which ones you don't, so that > my install script can set you up with a sensible system. One thing I'm > not installing is support for DKIM which, although available, requires > so many pre-requisites that it's not feasible for me to do here. You > have to start at the OpenSSL libraries and work your way up :-( > > Once I've got something working here, I'll write up an install script > for it all and wrap it into a package for you. > > Jules > Don't forget this new SA can compile the rules using sa-compile and needs re2c from http://re2c.sf.net/ sa-compile effectively speeds up spamassassin and while I didn't really write much about it when I did the "What's new" for SA, I think it is the best new feature! Good to see you getting back into the swing of things Jules. Take it from someone who knows, DO NOT over do it! -- -Doc Lincoln, NE. http://www.genealogyforyou.com/ http://www.cairnproductions.com/ From ms-list at alexb.ch Wed May 2 23:23:36 2007 From: ms-list at alexb.ch (Alex Broens) Date: Wed May 2 23:23:43 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: References: <463900B1.8080301@ecs.soton.ac.uk> Message-ID: <46390F68.8000002@alexb.ch> On 5/3/2007 12:06 AM, Ren? Berber wrote: > Julian Field wrote: > [snip] >> Once I've got something working here, I'll write up an install script >> for it all and wrap it into a package for you. > > SA 3.2.0 seems to have a nasty bug that leaves temporary files, it would > be better to wait for a package until the dust settles. Do you really know if its a spamd/spamc issue or no? Where are these supposed to be? I've been testing SA 3.2trunk/RCs/whatever & MS for ages and haven't seen no such files anywhere. btw: The person who opened http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5444 hasn't made a point of specifying how to reproduce it. Alex From doc at maddoc.net Wed May 2 23:32:16 2007 From: doc at maddoc.net (Doc Schneider) Date: Wed May 2 23:32:22 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: <46390F68.8000002@alexb.ch> References: <463900B1.8080301@ecs.soton.ac.uk> <46390F68.8000002@alexb.ch> Message-ID: <46391170.1070401@maddoc.net> Alex Broens wrote: > On 5/3/2007 12:06 AM, Ren? Berber wrote: >> Julian Field wrote: >> [snip] >>> Once I've got something working here, I'll write up an install script >>> for it all and wrap it into a package for you. >> >> SA 3.2.0 seems to have a nasty bug that leaves temporary files, it >> would be better to wait for a package until the dust settles. > > Do you really know if its a spamd/spamc issue or no? > Where are these supposed to be? > > > I've been testing SA 3.2trunk/RCs/whatever & MS for ages and haven't > seen no such files anywhere. > btw: > The person who opened > http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5444 hasn't made a > point of specifying how to reproduce it. > > > Alex > I followed this discussion on the sa-users list and it looks to me like it might be a MIMEDefang problem. I've also been testing MS and SA and never saw anything like this myself, either. -- -Doc Lincoln, NE. http://www.genealogyforyou.com/ http://www.cairnproductions.com/ From r.berber at computer.org Wed May 2 23:44:40 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Wed May 2 23:44:59 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: <46390F68.8000002@alexb.ch> References: <463900B1.8080301@ecs.soton.ac.uk> <46390F68.8000002@alexb.ch> Message-ID: Alex Broens wrote: > Do you really know if its a spamd/spamc issue or no? Spamc so far, but as one message on SA list stated it may have been a last minute change so I'm not sure if the problem is wider. [snip] -- Ren? Berber From hvdkooij at vanderkooij.org Wed May 2 23:46:27 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Wed May 2 23:46:56 2007 Subject: Bogus IPs in hearder In-Reply-To: <20070502220757.GD1334@doctor.nl2k.ab.ca> References: <20070502220757.GD1334@doctor.nl2k.ab.ca> Message-ID: On Wed, 2 May 2007, Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem wrote: > Still, can we use mailscanner and/or Spam Assassin to > block out mail using and octet > 255 or < 0? I think you will find these octets so rare they only hide out in a holy graal at the end of a rainbow but only on blue mondays. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From hvdkooij at vanderkooij.org Wed May 2 23:50:37 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Wed May 2 23:51:06 2007 Subject: RPM for milter-null? In-Reply-To: <4638E4B1.30809@pacific.net> References: <3BF93070B3D1B047BA7ABF612958950D018FB9D6@hcex.hartwellcorp.com> <4638E4B1.30809@pacific.net> Message-ID: On Wed, 2 May 2007, Ken A wrote: > Michael St. Laurent wrote: >> Does anyone know of an RPM or SRPM for the milter-null package? > > It gets compiled against libsnert (on which you only do 'make', not 'make > install') in com/snert/lib source tree, so there's no rpm. Just use the > source for both from snertsoft.com. Both are free. While it may suite some I found this a rather startling way in the onld sendmail days. It is among other things the reasons I abonded it. Being burnt too much with these package and do-it-yourself combinations I put in some effort to get a package supported into a repository to spare me the pain in the future. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From ryanw at falsehope.com Thu May 3 00:13:48 2007 From: ryanw at falsehope.com (Ryan Weaver) Date: Thu May 3 00:15:27 2007 Subject: RPM for milter-null? In-Reply-To: References: <3BF93070B3D1B047BA7ABF612958950D018FB9D6@hcex.hartwellcorp.com> <4638E4B1.30809@pacific.net> Message-ID: <002a01c78d0f$9616f020$c244d060$@com> In the archives of the list you will see that I got smacked down for simply providing a .spec for the building of a snertsoft program... However... if needed, contacting me offlist... Thanks, Ryan -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Hugo van der Kooij Sent: Wednesday, May 02, 2007 5:51 PM To: MailScanner discussion Subject: Re: RPM for milter-null? On Wed, 2 May 2007, Ken A wrote: > Michael St. Laurent wrote: >> Does anyone know of an RPM or SRPM for the milter-null package? > > It gets compiled against libsnert (on which you only do 'make', not 'make > install') in com/snert/lib source tree, so there's no rpm. Just use the > source for both from snertsoft.com. Both are free. While it may suite some I found this a rather startling way in the onld sendmail days. It is among other things the reasons I abonded it. Being burnt too much with these package and do-it-yourself combinations I put in some effort to get a package supported into a repository to spare me the pain in the future. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From ajs at vifilfell.is Thu May 3 00:28:11 2007 From: ajs at vifilfell.is (ajs@vifilfell.is) Date: Thu May 3 00:30:45 2007 Subject: No Programs allowed In-Reply-To: Message-ID: thanks for the tip. so far I've only seen the option to select between html and plain text for all internet mail, but I'll check it out. Scott Silva Sent by: mailscanner-bounces@lists.mailscanner.info 02.05.2007 18:08 Please respond to MailScanner discussion To mailscanner@lists.mailscanner.info cc Subject Re: No Programs allowed ajs@vifilfell.is spake the following on 5/2/2007 8:00 AM: > this is the case, Jon has tried the solution I pm-ed him and it works. > > I use Lotus for email and sometimes forget to switch to plain text when > sending email to mailing list, will try to remember it next time. > > cheers, asgeir, The last time I used Notes, you could set certain addresses to only get text mail. But that was a long time ago. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From ssilva at sgvwater.com Thu May 3 00:48:44 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 3 00:48:59 2007 Subject: No Programs allowed In-Reply-To: References: Message-ID: ajs@vifilfell.is spake the following on 5/2/2007 4:28 PM: > thanks for the tip. so far I've only seen the option to select between > html and plain text for all internet mail, but I'll check it out. > As I said, it was a long time ago. It might have been in the attributes for the address. Or I might just be mistaken, and probably had everything as text only. That is how long ago it was. Probably Notes 4.1 or so. I think I still have the box somewhere. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From res at ausics.net Thu May 3 00:52:43 2007 From: res at ausics.net (Res) Date: Thu May 3 00:52:54 2007 Subject: RPM for milter-null? In-Reply-To: <002a01c78d0f$9616f020$c244d060$@com> References: <3BF93070B3D1B047BA7ABF612958950D018FB9D6@hcex.hartwellcorp.com> <4638E4B1.30809@pacific.net> <002a01c78d0f$9616f020$c244d060$@com> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Wed, 2 May 2007, Ryan Weaver wrote: > In the archives of the list you will see that I got smacked down for simply > providing a .spec for the building of a snertsoft program... However... if > needed, contacting me offlist... Thats strange, most people who provide packages they dont charge for, are greatful of the provision of many different types of distributions, as it permits their software to be reached by those who otherwise would not touch it, or even be aware of it, be it for policy, or because of the desire to stick to RPM, like debian folk rather stick with DEB than sue sources. Their loss Ryan, you have provided many others for long time, and it's been welcomed and received by not only software programers, but the users, keep up the great work. - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGOSRNsWhAmSIQh7MRAo45AJ9nF8WFlaGlNnDbpfX4DwVjszHHrACgoH3R zlikQHYQZO06N/LsfgRNpTQ= =kwli -----END PGP SIGNATURE----- From a.peacock at chime.ucl.ac.uk Thu May 3 09:09:00 2007 From: a.peacock at chime.ucl.ac.uk (Anthony Peacock) Date: Thu May 3 09:09:37 2007 Subject: A lot of spam getting through In-Reply-To: <04D932B0071FE34FA63EBB1977B48D150281747A@woodenex.woodmaclaw.local> References: <04D932B0071FE34FA63EBB1977B48D150281747A@woodenex.woodmaclaw.local> Message-ID: <4639989C.9040204@chime.ucl.ac.uk> Billy A. Pumphrey wrote: >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Anthony Peacock >> Sent: Wednesday, May 02, 2007 4:53 AM >> To: MailScanner discussion >> Subject: Re: A lot of spam getting through >> So, help us out and show us the scores and headers from one that does >> get through. We might be able to see where they are failing then. >> >> Even better... Save one of the misdiagnosed emails as a text file, > post >> it to a web address and let us know. We can then run that email > through >> our systems and tell you what scores we get and what rules helped. >> > > I am having trouble getting the testing to work, or knowing how to test > it. I have saved some messages from Oulook with the extension of .msg. > When I run a spamassassin -t message.msg it returns a bunch of junk and > then the score: > > Content analysis details: (51.5 points, 5.0 required) > > pts rule name description > ---- ---------------------- > -------------------------------------------------- > -0.0 NO_RELAYS Informational: message was not relayed via > SMTP > 2.5 MISSING_HB_SEP Missing blank line between message header > and body > 2.3 MANGLED_DOSE BODY: mangled dose > 2.3 MANGLED_OFF BODY: mangled off > 2.3 MANGLED_YOUR BODY: mangled your > 2.3 MANGLED_FORM BODY: mangled form > 2.3 MANGLED_HERE BODY: mangled here > 2.3 MANGLED_HALF BODY: mangled half > 2.3 MANGLED_TIME BODY: mangled time > 2.3 MANGLED_MEDS BODY: mangled med(s) > 2.3 MANGLED_GIRL BODY: mangled girl(s) > 2.3 MANGLED_FROM BODY: mangled from > 2.3 MANGLED_LOVE BODY: mangled love > 2.3 MANGLED_TEXT BODY: mangled text > 2.3 MANGLED_LOOK BODY: mangled look(s) > 2.3 MANGLED_SPAM BODY: mangled spam > 2.3 MANGLED_PRIOR BODY: mangled prior > 2.3 MANGLED_PLEASE BODY: mangled please > 2.3 MANGLED_TRNFER BODY: mangled TRANSFER > 2.3 MANGLED_TOOL BODY: mangled tool > 3.5 BAYES_99 BODY: Bayesian spam probability is 99 to > 100% > [score: 1.0000] > 2.2 NULL_IN_BODY FULL: Message has NUL (ASCII 0) byte in > message > 1.8 MISSING_SUBJECT Missing Subject: header > 0.0 UPPERCASE_25_50 message body is 25-50% uppercase > 0.1 TO_CC_NONE No To: or Cc: header > -0.0 NO_RECEIVED Informational: message has no Received > headers > > (then some more junk) > [root@WoodenMS2 spamemail]# > PuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPu > TTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTT > YPuTTYPuTTYPuTTYPuTTYPuTTYTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPuTTYPu > > > Does the testing support .msg files? Also what is the best way to > convert the email to text and have it correct? I think the msg file format is an Outlook specific file format. You need to find a way to save the messages as plain text files with all the headers intact. -- Anthony Peacock CHIME, Royal Free & University College Medical School WWW: http://www.chime.ucl.ac.uk/~rmhiajp/ "If you have an apple and I have an apple and we exchange apples then you and I will still each have one apple. But if you have an idea and I have an idea and we exchange these ideas, then each of us will have two ideas." -- George Bernard Shaw From prandal at herefordshire.gov.uk Thu May 3 10:47:22 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Thu May 3 11:16:20 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: <463900B1.8080301@ecs.soton.ac.uk> References: <463900B1.8080301@ecs.soton.ac.uk> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA9223AF@HC-MBX02.herefordshire.gov.uk> Thanks for that, Jules. Basically, what I did was install spamassassin 3.2.0 using your installer and then used CPAN to install Mail::DKIM and Mail::SPF (and a host of dependencies). One thing I found was problems with DNS resolution after installing Mail::SPF from CPAN (all URIBLs failed). I think it's to do with Net::DNS and Net::DNS::Resolver::Programmable, and is probably an issue (reported on the spamassassin-users mailing list) to do with Mail::SPF-2.004 and Net::DNS::Resolver::Programmable-2.002. Mail::SPF-2.005 is due imminently to fix this. In the end to get it to work I had to uninstall any old perl-Net-DNS RPMs and any dependencies, and then force install both Net::DNS::Resolver::Programmable and Net::DNS. It wasn't easy and I'm still not entirely sure of the magical incantations which made it work. All this on CentOS 4.4 and an ancient Fedora Core 1 box. sa-compile works fine after downloading re2c-0.12.0-1.src.rpm sourceforge.net/projects/re2c and rpmbuilding it. Any rules_du_jour scripts and /etc/cron.daily/sa-update will need updating to do a sa-compile if you use it. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Julian Field > Sent: 02 May 2007 22:21 > To: MailScanner discussion > Subject: SpamAssassin 3.2.0 > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Well, as someone else has already said, it's been released. > > Its list of requirements has grown quite a lot. In addition > to whatever > else you already have from an existing SA install, you need > to install > this load of Perl modules, in this order: > > YAML -- requires y\n in perl Makefile.PL > ExtUtils::CBuilder > ExtUtils::ParseXS > Module::Build > version > Net::DNS::Resolver::Programmable > Error > NetAddr::IP > Net::DNS >=0.58 > Data::Dump > Encode::Detect > Mail::SPF > Mail::SpamAssassin -- requires \n in perl Makefile.PL > > It puts in a v320.pre into /etc/mail/spamassassin and comes > with a load > of new plugins. Some of them are loaded by the default > supplied v320.pre > file, but here are the ones that aren't: > > Hashcash.pm Rule2XSBody.pm > ASN.pm SpamCop.pm > AutoLearnThreshold.pm SPF.pm > AWL.pm Test.pm > TextCat.pm > MIMEHeader.pm > BodyRuleBaseExtractor.pm OneLineBodyRuleType.pm URIDNSBL.pm > Pyzor.pm > DCC.pm Razor2.pm > RelayCountry.pm WhiteListSubject.pm > ReplaceTags.pm > > My next step is to read the man pages for all of these, and work out > which ones you probably want to load and which ones you > don't, so that > my install script can set you up with a sensible system. One > thing I'm > not installing is support for DKIM which, although available, > requires > so many pre-requisites that it's not feasible for me to do here. You > have to start at the OpenSSL libraries and work your way up :-( > > Once I've got something working here, I'll write up an install script > for it all and wrap it into a package for you. > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: ISO-8859-1 > > wj8DBQFGOQEwEfZZRxQVtlQRArCWAJ95n3Z0uHjg/25LaIHPFUauWsZ+vACfYdtP > qjZF/RoldGlTZywtz3b9U/8= > =yA8+ > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From declan.grady at nuvotem.com Thu May 3 12:15:26 2007 From: declan.grady at nuvotem.com (Declan Grady) Date: Thu May 3 12:16:43 2007 Subject: Very newbie relaying question Message-ID: <1DF321991CD3084EAD65737D82C6D07E145A86@sbs1.nuvotem.local> Hi folks, I've just rebuilt my mailscanner+sendmail box using debian etch, and after a lot of head-scratching got it up & running ok. (Old box suffered hardware failure, was a redhat 7 with a lot of patches & updates, etc, but was handy for upgrading mailscanner from rpms.) While watching the spam messages, I've noticed quite a few supposedly coming from my own domain name. I'm 99% sure I can restrict it so that if the sender is supposed to be in my own domain, it must be from a local IP address, otherwise reject it. I have googled, but get lost in all the authentication stuff. My mailscanner box is a gateway - just takes incoming mail, scans & passes on to a windows exchange box, using a sendmail mailertable. What do I need to do to my sendmail config to permit mail from my domain to be only accepted from internal IP's ? I'm guessing I need to change my /etc/mail/access file somehow ? Currently it has (among other things) mydomain.com RELAY localhost.mydomain.com RELAY mail.mydomain.com RELAY mailserver.mydomain.com RELAY mydomain.ie RELAY exchange_server_name RELAY Obviously some of these are not necessary, and are from my tweaking it trying to get it working. Or, is there some clever way to do it. Thinking out loud, all mail from mydomain will come from the exchange server, which has a single fixed IP address - Mabye that is a way to do it ? Thanks for suggestions. From cleveland at winnefox.org Thu May 3 12:52:59 2007 From: cleveland at winnefox.org (Jody Cleveland) Date: Thu May 3 12:53:06 2007 Subject: MailScanner no longer scanning mail Message-ID: Hello, I updated to the latest version of MailScanner on my redhat 5.0 enterprise server, and it's not working properly. Mail is coming into the server, I can see 1500 messages in the postfix queue. But, they just sit there. I'm not seeing any error messages in the maillog. But, it does appear that MS restarts every 5 seconds. Any ideas what may be wrong? - jody From raymond at prolocation.net Thu May 3 12:56:56 2007 From: raymond at prolocation.net (Raymond Dijkxhoorn) Date: Thu May 3 12:56:56 2007 Subject: MailScanner no longer scanning mail In-Reply-To: References: Message-ID: Hi! > I updated to the latest version of MailScanner on my redhat 5.0 enterprise > server, and it's not working properly. > > Mail is coming into the server, I can see 1500 messages in the postfix > queue. But, they just sit there. I'm not seeing any error messages in the > maillog. But, it does appear that MS restarts every 5 seconds. > > Any ideas what may be wrong? Default answer... : change to debug mode and see what it outputs. Bye, Raymond. From cleveland at winnefox.org Thu May 3 13:16:43 2007 From: cleveland at winnefox.org (Jody Cleveland) Date: Thu May 3 13:16:49 2007 Subject: MailScanner no longer scanning mail In-Reply-To: Message-ID: Hello, > Default answer... : change to debug mode and see what it outputs. Ok, I switched to debug mode, and this is what I get: [root@destiny MailScanner]# service MailScanner start Starting MailScanner daemons: incoming postfix: [ OK ] outgoing postfix: [ OK ] MailScanner: In Debugging mode, not forking... And it just sits there. I sent a few messages to it, but after 10 minutes it still just sat there. So, I ctrl-z'd to get out of it and looked at the maillog. This is what it said: May 3 07:09:17 destiny postfix/postfix-script: starting the Postfix mail system May 3 07:09:17 destiny postfix/master[5525]: daemon started -- version 2.3.3, configuration /etc/postfix May 3 07:09:17 destiny postfix/qmgr[5535]: warning: bounce_queue_lifetime is larger than maximal_queue_lifetime - adjusting bounce_queue_lifetime May 3 07:09:19 destiny MailScanner[5543]: MailScanner E-Mail Virus Scanner version 4.59.4 starting... May 3 07:09:19 destiny MailScanner[5543]: Read 778 hostnames from the phishing whitelist May 3 07:09:19 destiny MailScanner[5543]: Config: calling custom init function SQLBlacklist May 3 07:09:19 destiny MailScanner[5543]: Starting up SQL Blacklist May 3 07:09:19 destiny MailScanner[5543]: Read 29 blacklist entries May 3 07:09:19 destiny MailScanner[5543]: Config: calling custom init function MailWatchLogging May 3 07:09:19 destiny MailScanner[5543]: Started SQL Logging child May 3 07:09:19 destiny MailScanner[5543]: Config: calling custom init function SQLWhitelist May 3 07:09:19 destiny MailScanner[5543]: Starting up SQL Whitelist May 3 07:09:19 destiny MailScanner[5543]: Read 59 whitelist entries May 3 07:09:19 destiny MailScanner[5543]: Using SpamAssassin results cache May 3 07:09:19 destiny MailScanner[5543]: Connected to SpamAssassin cache database May 3 07:09:19 destiny MailScanner[5543]: Enabling SpamAssassin auto-whitelist functionality... May 3 07:09:22 destiny MailScanner[5543]: lock.pl sees Config LockType = flock May 3 07:09:22 destiny MailScanner[5543]: lock.pl sees have_module = 0 May 3 07:09:22 destiny MailScanner[5543]: Using locktype = flock May 3 07:09:22 destiny MailScanner[5543]: New Batch: Found 1420 messages waiting May 3 07:09:22 destiny MailScanner[5543]: New Batch: Scanning 30 messages, 151181 bytes May 3 07:09:22 destiny MailScanner[5543]: Created attachment dirs for 30 messages May 3 07:09:43 destiny MailScanner[5543]: RBL Checks: returned 0 May 3 07:09:43 destiny MailScanner[5543]: SpamAssassin cache hit for message D20223E425E.0C4FB May 3 07:09:48 destiny postfix/smtpd[5556]: connect from unknown[203.188.225.208] May 3 07:09:50 destiny postfix/smtpd[5556]: 435F83E4380: client=unknown[203.188.225.208] May 3 07:09:50 destiny postfix/smtpd[5554]: connect from static-66-16-148-219.dsl.cavtel.net[66.16.148.219] May 3 07:09:50 destiny postfix/smtpd[5554]: E7C293E4382: client=static-66-16-148-219.dsl.cavtel.net[66.16.148.219] May 3 07:09:51 destiny postfix/cleanup[5571]: E7C293E4382: hold: header Received: from static-66-16-148-219.dsl.cavtel.net (static-66-16-148-219.dsl.cavtel.net [66.16.148.219])??by destiny.winnefox.org (Postfix) with SMTP id E7C293E4382??for to= proto=SMTP helo= May 3 07:09:51 destiny postfix/cleanup[5571]: E7C293E4382: message-id=<20070503120950.E7C293E4382@destiny.winnefox.org> May 3 07:09:51 destiny postfix/smtpd[5554]: disconnect from static-66-16-148-219.dsl.cavtel.net[66.16.148.219] Is that helpful at all? - jody From ms-list at alexb.ch Thu May 3 13:39:06 2007 From: ms-list at alexb.ch (Alex Broens) Date: Thu May 3 13:39:14 2007 Subject: MailScanner no longer scanning mail In-Reply-To: References: Message-ID: <4639D7EA.6090504@alexb.ch> On 5/3/2007 2:16 PM, Jody Cleveland wrote: > Hello, > >> Default answer... : change to debug mode and see what it outputs. > > Ok, I switched to debug mode, and this is what I get: > > [root@destiny MailScanner]# service MailScanner start > Starting MailScanner daemons: > incoming postfix: [ OK ] > outgoing postfix: [ OK ] > MailScanner: In Debugging mode, not forking... > > > And it just sits there. I sent a few messages to it, but after 10 minutes it > still just sat there. So, I ctrl-z'd to get out of it and looked at the > maillog. This is what it said: > > May 3 07:09:17 destiny postfix/postfix-script: starting the Postfix mail > system > May 3 07:09:17 destiny postfix/master[5525]: daemon started -- version > 2.3.3, configuration /etc/postfix > May 3 07:09:17 destiny postfix/qmgr[5535]: warning: bounce_queue_lifetime > is larger than maximal_queue_lifetime - adjusting bounce_queue_lifetime fix that and I'd bet it will work Alex From cleveland at winnefox.org Thu May 3 14:14:34 2007 From: cleveland at winnefox.org (Jody Cleveland) Date: Thu May 3 14:14:40 2007 Subject: MailScanner no longer scanning mail In-Reply-To: <4639D7EA.6090504@alexb.ch> Message-ID: On 5/3/07 7:39 AM, "Alex Broens" wrote: >> May 3 07:09:17 destiny postfix/postfix-script: starting the Postfix mail >> system >> May 3 07:09:17 destiny postfix/master[5525]: daemon started -- version >> 2.3.3, configuration /etc/postfix >> May 3 07:09:17 destiny postfix/qmgr[5535]: warning: bounce_queue_lifetime >> is larger than maximal_queue_lifetime - adjusting bounce_queue_lifetime > > fix that and I'd bet it will work Ok, I fixed that. If I tail the maillog, I can see mail come in and get processed. But, the queue just keeps filling, and nothing actually gets delivered. - jody From ms-list at alexb.ch Thu May 3 14:31:31 2007 From: ms-list at alexb.ch (Alex Broens) Date: Thu May 3 14:31:41 2007 Subject: MailScanner no longer scanning mail In-Reply-To: References: Message-ID: <4639E433.4020100@alexb.ch> On 5/3/2007 3:14 PM, Jody Cleveland wrote: > > > On 5/3/07 7:39 AM, "Alex Broens" wrote: > >>> May 3 07:09:17 destiny postfix/postfix-script: starting the Postfix mail >>> system >>> May 3 07:09:17 destiny postfix/master[5525]: daemon started -- version >>> 2.3.3, configuration /etc/postfix >>> May 3 07:09:17 destiny postfix/qmgr[5535]: warning: bounce_queue_lifetime >>> is larger than maximal_queue_lifetime - adjusting bounce_queue_lifetime >> fix that and I'd bet it will work > > Ok, I fixed that. If I tail the maillog, I can see mail come in and get > processed. But, the queue just keeps filling, and nothing actually gets > delivered. assuming postfixis correctly configured for postfix (permsisions wise)hot in the dark: From ms-list at alexb.ch Thu May 3 14:36:00 2007 From: ms-list at alexb.ch (Alex Broens) Date: Thu May 3 14:36:04 2007 Subject: MailScanner no longer scanning mail In-Reply-To: References: Message-ID: <4639E540.9070004@alexb.ch> On 5/3/2007 3:14 PM, Jody Cleveland wrote: > > > On 5/3/07 7:39 AM, "Alex Broens" wrote: > >>> May 3 07:09:17 destiny postfix/postfix-script: starting the Postfix mail >>> system >>> May 3 07:09:17 destiny postfix/master[5525]: daemon started -- version >>> 2.3.3, configuration /etc/postfix >>> May 3 07:09:17 destiny postfix/qmgr[5535]: warning: bounce_queue_lifetime >>> is larger than maximal_queue_lifetime - adjusting bounce_queue_lifetime >> fix that and I'd bet it will work > > Ok, I fixed that. If I tail the maillog, I can see mail come in and get > processed. But, the queue just keeps filling, and nothing actually gets > delivered. Opps - pressed wrong key - sent too fast! assuming postfix is correctly configured for MailScanner - queue path & permissions shot in the dark: try setting: MailScanner.conf # 5 for only one CPU Max Children = 10 # set to 10 if you have only one CPU Queue Scan Interval = 13 Max Unscanned Bytes Per Scan = 100m Max Unsafe Bytes Per Scan = 50m Max Unscanned Messages Per Scan = 5 Max Unsafe Messages Per Scan = 5 Alex From steinkel at pa.net Thu May 3 15:06:54 2007 From: steinkel at pa.net (Leland J. Steinke) Date: Thu May 3 15:08:12 2007 Subject: MailScanner no longer scanning mail In-Reply-To: <4639E540.9070004@alexb.ch> References: <4639E540.9070004@alexb.ch> Message-ID: <4639EC7E.5060108@pa.net> Another thing to try would be to kill the MailScanner processes running in the background and do "check_mailscanner" at the command line, so as to see all the helpful debug messages that will go whizzing by. Leland From support-lists at petdoctors.co.uk Thu May 3 15:04:58 2007 From: support-lists at petdoctors.co.uk (Nigel Kendrick) Date: Thu May 3 15:13:08 2007 Subject: A lot of spam getting through In-Reply-To: <4639989C.9040204@chime.ucl.ac.uk> Message-ID: <015701c78d8c$0893a4a0$0202fea9@support01> -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Anthony Peacock Sent: Thursday, May 03, 2007 9:09 AM To: MailScanner discussion Subject: Re: A lot of spam getting through > > Does the testing support .msg files? Also what is the best way to > convert the email to text and have it correct? I think the msg file format is an Outlook specific file format. You need to find a way to save the messages as plain text files with all the headers intact. Our corporate standard is Outlook, but if I want to check a message, I forward it to my 'spam@...' account and then pick it up in Thunderbird. Life gets easier then! From cleveland at winnefox.org Thu May 3 15:23:16 2007 From: cleveland at winnefox.org (Jody Cleveland) Date: Thu May 3 15:23:18 2007 Subject: MailScanner no longer scanning mail In-Reply-To: <4639EC7E.5060108@pa.net> Message-ID: On 5/3/07 9:06 AM, "Leland J. Steinke" wrote: > Another thing to try would be to kill the MailScanner processes running > in the background and do "check_mailscanner" at the command line, so as > to see all the helpful debug messages that will go whizzing by. That gave me this: [root@destiny ~]# check_mailscanner Starting MailScanner... Done. - jody From adrian at senn.ch Thu May 3 15:37:58 2007 From: adrian at senn.ch (Adrian Senn) Date: Thu May 3 15:38:02 2007 Subject: Postfix analyzer to blocking ip addresses Message-ID: <4639F3C6.1070401@senn.ch> Hello all I'm searching a script which has the possibility to write some ip addresses, which are sending to much spam, into the postscript reject files. The actual spam run is breaking the greylisting and i see a lot of log entries in the log from mailscanner. It would be very nice if there is something around the world :-) Regards Adrian From cleveland at winnefox.org Thu May 3 15:47:33 2007 From: cleveland at winnefox.org (Jody Cleveland) Date: Thu May 3 15:47:36 2007 Subject: MailScanner no longer scanning mail In-Reply-To: <4639E540.9070004@alexb.ch> Message-ID: On 5/3/07 8:36 AM, "Alex Broens" wrote: > Opps - pressed wrong key - sent too fast! > > assuming postfix is correctly configured for MailScanner - queue path & > permissions > > shot in the dark: > > try setting: > > MailScanner.conf > > # 5 for only one CPU > Max Children = 10 > > # set to 10 if you have only one CPU > Queue Scan Interval = 13 > > Max Unscanned Bytes Per Scan = 100m > Max Unsafe Bytes Per Scan = 50m > Max Unscanned Messages Per Scan = 5 > Max Unsafe Messages Per Scan = 5 My, how the floodgates have opened! That took care of it. And, now, MS is whittling away at the queue. With that said, why would those changes fix it? Is there something with the new version that changed something with that? - jody From mogens at fumlersoft.dk Thu May 3 15:48:14 2007 From: mogens at fumlersoft.dk (Mogens Melander) Date: Thu May 3 15:48:56 2007 Subject: Postfix analyzer to blocking ip addresses In-Reply-To: <4639F3C6.1070401@senn.ch> References: <4639F3C6.1070401@senn.ch> Message-ID: <2928.90.184.17.152.1178203694.squirrel@mail.fumlersoft.dk> On Thu, May 3, 2007 16:37, Adrian Senn wrote: > Hello all > > I'm searching a script which has the possibility to write some ip > addresses, which are sending to much spam, into the postscript > reject files. > > The actual spam run is breaking the greylisting and i see a lot of > log entries in the log from mailscanner. > > It would be very nice if there is something around the world :-) > > Regards Adrian Well, i'm having a lot of fun getting sshblack daemon to block all kinds of unwanted trafic. I'm shure it can be modified to do exactly what you want. Have a look at: http://www.pettingers.org/code/sshblack.html -- Later Mogens Melander +45 40 85 71 38 +66 870 133 224 -- This message has been scanned for viruses and dangerous content by OpenProtect(http://www.openprotect.com), and is believed to be clean. From MailScanner at ecs.soton.ac.uk Thu May 3 16:01:09 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 3 16:06:36 2007 Subject: A lot of spam getting through In-Reply-To: <015701c78d8c$0893a4a0$0202fea9@support01> References: <015701c78d8c$0893a4a0$0202fea9@support01> Message-ID: <4639F935.6080800@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Nigel Kendrick wrote: > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Anthony > Peacock > Sent: Thursday, May 03, 2007 9:09 AM > To: MailScanner discussion > Subject: Re: A lot of spam getting through > >> Does the testing support .msg files? Also what is the best way to >> convert the email to text and have it correct? >> > > I think the msg file format is an Outlook specific file format. You > need to find a way to save the messages as plain text files with all the > headers intact. > In Outlook, in the View menu, there is a View Options... option (at the bottom I think?). In there you can view the "Internet Source" of the message which is the raw text of the message including all headers. You can copy to the clipboard from there. I think that's where it is :-) > > > > Our corporate standard is Outlook, but if I want to check a message, I > forward it to my 'spam@...' account and then pick it up in Thunderbird. Life > gets easier then! > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGOfpdEfZZRxQVtlQRAjohAKD7hcbgDL29JdfgMMzp5j2SogFtagCfa8J1 eCDKxPslWB2lOUrioqjzO1E= =izJC -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ms-list at alexb.ch Thu May 3 16:07:11 2007 From: ms-list at alexb.ch (Alex Broens) Date: Thu May 3 16:07:19 2007 Subject: MailScanner no longer scanning mail In-Reply-To: References: Message-ID: <4639FA9F.6000808@alexb.ch> On 5/3/2007 4:47 PM, Jody Cleveland wrote: > On 5/3/07 8:36 AM, "Alex Broens" wrote: > >> Opps - pressed wrong key - sent too fast! >> >> assuming postfix is correctly configured for MailScanner - queue path & >> permissions >> >> shot in the dark: >> >> try setting: >> >> MailScanner.conf >> >> # 5 for only one CPU >> Max Children = 10 >> >> # set to 10 if you have only one CPU >> Queue Scan Interval = 13 >> >> Max Unscanned Bytes Per Scan = 100m >> Max Unsafe Bytes Per Scan = 50m >> Max Unscanned Messages Per Scan = 5 >> Max Unsafe Messages Per Scan = 5 > > My, how the floodgates have opened! > > That took care of it. And, now, MS is whittling away at the queue. > > With that said, why would those changes fix it? Is there something with the > new version that changed something with that? glad to hear your MS is purring again afaik, it comes to a point that if MS' threads doesn't get enough air between checking for msgs to process, they race to catch the same msg, and msgs get processed over and over again, till a msg has been processed a few hundred times and then finally delivered to the MTA. I've seen this happen with older versions, under a default config, as well so I don't think it has anything to do with th MS version - more a configuration/tuning thing. You'll need to play around with the threads and msgs per scan settings till you get the right balance for your hardware/traffic/bandwidth requirements. Alex From MailScanner at ecs.soton.ac.uk Thu May 3 16:06:11 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 3 16:12:34 2007 Subject: MailScanner no longer scanning mail In-Reply-To: References: Message-ID: <4639FA63.5000505@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Jody Cleveland wrote: > Hello, > > >> Default answer... : change to debug mode and see what it outputs. >> > > Ok, I switched to debug mode, and this is what I get: > > [root@destiny MailScanner]# service MailScanner start > Starting MailScanner daemons: > incoming postfix: [ OK ] > outgoing postfix: [ OK ] > MailScanner: In Debugging mode, not forking... > > > And it just sits there. I sent a few messages to it, but after 10 minutes it > still just sat there. So, I ctrl-z'd to get out of it and looked at the > maillog. This is what it said: > > May 3 07:09:17 destiny postfix/postfix-script: starting the Postfix mail > system > May 3 07:09:17 destiny postfix/master[5525]: daemon started -- version > 2.3.3, configuration /etc/postfix > May 3 07:09:17 destiny postfix/qmgr[5535]: warning: bounce_queue_lifetime > is larger than maximal_queue_lifetime - adjusting bounce_queue_lifetime > May 3 07:09:19 destiny MailScanner[5543]: MailScanner E-Mail Virus Scanner > version 4.59.4 starting... > May 3 07:09:19 destiny MailScanner[5543]: Read 778 hostnames from the > phishing whitelist > May 3 07:09:19 destiny MailScanner[5543]: Config: calling custom init > function SQLBlacklist > May 3 07:09:19 destiny MailScanner[5543]: Starting up SQL Blacklist > May 3 07:09:19 destiny MailScanner[5543]: Read 29 blacklist entries > May 3 07:09:19 destiny MailScanner[5543]: Config: calling custom init > function MailWatchLogging > May 3 07:09:19 destiny MailScanner[5543]: Started SQL Logging child > May 3 07:09:19 destiny MailScanner[5543]: Config: calling custom init > function SQLWhitelist > May 3 07:09:19 destiny MailScanner[5543]: Starting up SQL Whitelist > May 3 07:09:19 destiny MailScanner[5543]: Read 59 whitelist entries > May 3 07:09:19 destiny MailScanner[5543]: Using SpamAssassin results cache > May 3 07:09:19 destiny MailScanner[5543]: Connected to SpamAssassin cache > database > May 3 07:09:19 destiny MailScanner[5543]: Enabling SpamAssassin > auto-whitelist functionality... > May 3 07:09:22 destiny MailScanner[5543]: lock.pl sees Config LockType = > flock > May 3 07:09:22 destiny MailScanner[5543]: lock.pl sees have_module = 0 > May 3 07:09:22 destiny MailScanner[5543]: Using locktype = flock > May 3 07:09:22 destiny MailScanner[5543]: New Batch: Found 1420 messages > waiting > May 3 07:09:22 destiny MailScanner[5543]: New Batch: Scanning 30 messages, > 151181 bytes > May 3 07:09:22 destiny MailScanner[5543]: Created attachment dirs for 30 > messages > May 3 07:09:43 destiny MailScanner[5543]: RBL Checks: returned 0 > May 3 07:09:43 destiny MailScanner[5543]: SpamAssassin cache hit for > message D20223E425E.0C4FB > May 3 07:09:48 destiny postfix/smtpd[5556]: connect from > unknown[203.188.225.208] > May 3 07:09:50 destiny postfix/smtpd[5556]: 435F83E4380: > client=unknown[203.188.225.208] > May 3 07:09:50 destiny postfix/smtpd[5554]: connect from > static-66-16-148-219.dsl.cavtel.net[66.16.148.219] > May 3 07:09:50 destiny postfix/smtpd[5554]: E7C293E4382: > client=static-66-16-148-219.dsl.cavtel.net[66.16.148.219] > May 3 07:09:51 destiny postfix/cleanup[5571]: E7C293E4382: hold: header > Received: from static-66-16-148-219.dsl.cavtel.net > (static-66-16-148-219.dsl.cavtel.net [66.16.148.219])??by > destiny.winnefox.org (Postfix) with SMTP id E7C293E4382??for > static-66-16-148-219.dsl.cavtel.net[66.16.148.219]; > from= > to= proto=SMTP > helo= > May 3 07:09:51 destiny postfix/cleanup[5571]: E7C293E4382: > message-id=<20070503120950.E7C293E4382@destiny.winnefox.org> > May 3 07:09:51 destiny postfix/smtpd[5554]: disconnect from > static-66-16-148-219.dsl.cavtel.net[66.16.148.219] > > Is that helpful at all? > Do service MailScanner stop then wait a few seconds, then service MailScaner startin and that should start incoming mail going into the queue that feeds MailScanner, without starting MailScanner itself at all. So then do MailScanner -debug and see what it says. It will sit and wait until it has at least 1 message to process, then it will process them completely, then gracefully die of old age. Post the entire output of that command. Then service MailScanner stop again so the incoming queue doesn't keep building up. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGOfuIEfZZRxQVtlQRAiCpAKDXOPT7WwMDyKHwAvnNyAEMsS/DdwCg0z/L Zgkbp+dB9G++9uqTfaqLQ+8= =IDs4 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From mailscanner at yeticomputers.com Thu May 3 16:39:15 2007 From: mailscanner at yeticomputers.com (Rick Chadderdon) Date: Thu May 3 16:32:34 2007 Subject: 32 bit distro or 64? In-Reply-To: <463904BA.4040402@sendit.nodak.edu> References: <463900F6.1070103@yeticomputers.com> <463904BA.4040402@sendit.nodak.edu> Message-ID: <463A0223.3000803@yeticomputers.com> Richard Frovarp wrote: > Couldn't you just run the 32bit versions of the virus scanners? We're > not talking about full 64 bit like Itaniums or any other number of > other processors out there. We're just talking about 64 bit extended > OSs. I run plenty of 32bit applications on my 64bit OS without any > problems. Of course I have the 32bit and 64bit versions of all the > libraries installed to do this. > > Richard Yes. It is normally not a problem (although I would not say "never", since I have had issues with some apps simply not working in a 64-bit environment, 32-bit version or not) to run 32-bit apps. However, I don't really see the point of running a 64-bit OS if one is going to run a bunch of 32-bit apps for "compatibility". It's a personal call, of course. For mission critical apps, I prefer to run software than was designed specifically to work properly in the environment I'm using. But... I break that rule sometimes, so I guess I can't fault anyone else for doing so. :) Still, it is much easier to get support from a vendor if you're using their software the way that they intended. I can already hear, "Oh, I'm sorry, we don't support that product running on a 64-bit OS." Even if the problem you're having is not related to the OS at all. Just something to consider. Rick From carles at unlimitedmail.org Thu May 3 17:12:20 2007 From: carles at unlimitedmail.org (Carles Xavier Munyoz =?iso-8859-1?q?Bald=F3?=) Date: Thu May 3 17:12:38 2007 Subject: Very newbie relaying question In-Reply-To: <1DF321991CD3084EAD65737D82C6D07E145A86@sbs1.nuvotem.local> References: <1DF321991CD3084EAD65737D82C6D07E145A86@sbs1.nuvotem.local> Message-ID: <200705031812.20616.carles@unlimitedmail.org> Hi, You need to setup SPF in your domain's DNS database. More info in google ;-D Greetings. On Thursday 03 May 2007, Declan Grady wrote: > Hi folks, > I've just rebuilt my mailscanner+sendmail box using debian etch, and > after a lot of head-scratching got it up & running ok. > (Old box suffered hardware failure, was a redhat 7 with a lot of patches > & updates, etc, but was handy for upgrading mailscanner from rpms.) > > While watching the spam messages, I've noticed quite a few supposedly > coming from my own domain name. > > I'm 99% sure I can restrict it so that if the sender is supposed to be > in my own domain, it must be from a local IP address, otherwise reject > it. > > I have googled, but get lost in all the authentication stuff. > > My mailscanner box is a gateway - just takes incoming mail, scans & > passes on to a windows exchange box, using a sendmail mailertable. > > What do I need to do to my sendmail config to permit mail from my domain > to be only accepted from internal IP's ? > > I'm guessing I need to change my /etc/mail/access file somehow ? > Currently it has (among other things) > > mydomain.com RELAY > localhost.mydomain.com RELAY > mail.mydomain.com RELAY > mailserver.mydomain.com RELAY > mydomain.ie RELAY > exchange_server_name RELAY > > Obviously some of these are not necessary, and are from my tweaking it > trying to get it working. > > Or, is there some clever way to do it. > > > Thinking out loud, all mail from mydomain will come from the exchange > server, which has a single fixed IP address - Mabye that is a way to do > it ? > > Thanks for suggestions. -- --- Carles Xavier Munyoz Bald? cmunyoz@unlimitedmail.net http://www.unlimitedmail.net/ --- From r.berber at computer.org Thu May 3 18:19:01 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Thu May 3 18:19:20 2007 Subject: Very newbie relaying question In-Reply-To: <1DF321991CD3084EAD65737D82C6D07E145A86@sbs1.nuvotem.local> References: <1DF321991CD3084EAD65737D82C6D07E145A86@sbs1.nuvotem.local> Message-ID: Declan Grady wrote: [snip] > What do I need to do to my sendmail config to permit mail from my domain > to be only accepted from internal IP's ? > > I'm guessing I need to change my /etc/mail/access file somehow ? > Currently it has (among other things) > > mydomain.com RELAY > localhost.mydomain.com RELAY > mail.mydomain.com RELAY > mailserver.mydomain.com RELAY > mydomain.ie RELAY > exchange_server_name RELAY You are using the old syntax, which may not be what you want. If all your server IPs are public then you are on the right track, if your servers have internal/external addresses you are better off using the internal ones. An example of what you can do is access as: # Allow relying from LAN Connect:192.168.0 RELAY Connect:127.0.0.1 RELAY Connect:exchange_server_IP RELAY # Whitelist Connect:other_external_IP RELAY And don't forget to 'compile' access (i.e. makemap hash /etc/mail/access < /etc/mail/access). -- Ren? Berber From KGoods at AIAInsurance.com Thu May 3 18:18:25 2007 From: KGoods at AIAInsurance.com (Ken Goods) Date: Thu May 3 18:19:44 2007 Subject: Very newbie relaying question Message-ID: <13C0059880FDD3118DC600508B6D4A6D01C29372@aiainsurance.com> Declan Grady wrote: > Hi folks, > I've just rebuilt my mailscanner+sendmail box using debian etch, and > after a lot of head-scratching got it up & running ok. > (Old box suffered hardware failure, was a redhat 7 with a lot of > patches & updates, etc, but was handy for upgrading mailscanner from > rpms.) > > While watching the spam messages, I've noticed quite a few supposedly > coming from my own domain name. > Thanks for suggestions. If there really isn't any spam originating from your own domains, look into trusted networks, or even easier, just whitelist your domain(s). I've been running the same setup (e.g. MailScanner filter feeding an exchange box) for a couple years now so if you have any other questions feel free to contact me on list or directly. HTH Kind regards, Ken Ken Goods Network Administrator CropUSA Insurance, Inc. From lundin at fini.net Thu May 3 18:26:14 2007 From: lundin at fini.net (John Lundin) Date: Thu May 3 18:27:12 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: <463900B1.8080301@ecs.soton.ac.uk> References: <463900B1.8080301@ecs.soton.ac.uk> Message-ID: <20070503172614.GA31837@fini.net> On Wed, May 02, 2007 at 10:20:49PM +0100, Julian Field wrote: > Its list of requirements has grown quite a lot. In addition to whatever > else you already have from an existing SA install, you need to install > this load of Perl modules, in this order: > > ... One thing I'm not installing is support for DKIM which, although > available, requires so many pre-requisites that it's not feasible > for me to do here. FWIW, DAG's repository now contains SA3.2.0 and Encode::Detect and Mail::SPF -and- Mail::DKIM ! :-) So if you're running RHEL4 or Centos4, that's a place to look. http://dag.wieers.com/rpm/packages/ Unfortunately, they don't appear to have propagated to Dries' repository or even DAG's master rpmforge listing yet. The perl-Mail-DKIM source rpm compiled and appears to run on Fedora. re2c is available from sourceforge as a src.rpm. As such, it builds and runs under Fedora and Centos. Not using it in production yet. From spamtrap71892316634 at anime.net Thu May 3 18:42:02 2007 From: spamtrap71892316634 at anime.net (Dan Hollis) Date: Thu May 3 18:42:07 2007 Subject: 32 bit distro or 64? In-Reply-To: <463A0223.3000803@yeticomputers.com> References: <463900F6.1070103@yeticomputers.com> <463904BA.4040402@sendit.nodak.edu> <463A0223.3000803@yeticomputers.com> Message-ID: On Thu, 3 May 2007, Rick Chadderdon wrote: > Still, it is much easier to get support from a vendor if you're using > their software the way that they intended. I can already hear, "Oh, I'm > sorry, we don't support that product running on a 64-bit OS." Even if > the problem you're having is not related to the OS at all. Just > something to consider. In this case you vote with your wallet and find another vendor. Works for me anyway :) -Dan From jan-peter at koopmann.eu Thu May 3 18:53:06 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Thu May 3 18:53:15 2007 Subject: ANNOUNCE: MailScanner stable 4.59 In-Reply-To: <4635B2C4.50004@ecs.soton.ac.uk> References: <4635B2C4.50004@ecs.soton.ac.uk> Message-ID: On SHA1 wrote: > I have just released a new stable version, 4.59. The main new > features this month are > FreeBSD port has just been submitted. Thanks Julian! From amaclach at yahoo.co.uk Thu May 3 20:06:24 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Thu May 3 20:06:28 2007 Subject: Testing the anti-virus stack Message-ID: <642167.17343.qm@web26301.mail.ukl.yahoo.com> OK - I'm pulling what's left of my hair out here trying to test Avast. What I think is happening is that MailScanner is blocking all the test files before they get to the virus scanner. How do I know when the virus scanner has picked up a virus (Nothing in the maillog)?? I also need to get the output strings so that I can configure MailWatch for avastd. I've already turned clam off. If anyone has something infected feel free to send it to andy.mac@global-domination.org Cheers,Andy ----- Original Message ---- From: Dan Hollis To: MailScanner discussion Sent: Thursday, 3 May, 2007 6:42:02 PM Subject: Re: 32 bit distro or 64? On Thu, 3 May 2007, Rick Chadderdon wrote: > Still, it is much easier to get support from a vendor if you're using > their software the way that they intended. I can already hear, "Oh, I'm > sorry, we don't support that product running on a 64-bit OS." Even if > the problem you're having is not related to the OS at all. Just > something to consider. In this case you vote with your wallet and find another vendor. Works for me anyway :) -Dan -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From uxbod at splatnix.net Thu May 3 20:21:14 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Thu May 3 20:21:24 2007 Subject: Testing the anti-virus stack In-Reply-To: <642167.17343.qm@web26301.mail.ukl.yahoo.com> References: <642167.17343.qm@web26301.mail.ukl.yahoo.com> Message-ID: <051aabc2a3a191af981ddf4e54b7d2de@62.49.223.244> Why not run in debug mode and test with eicar.com ? On Thu, 3 May 2007 19:06:24 +0000 (GMT), Andrew MacLachlan wrote: > OK - I'm pulling what's left of my hair out here trying to test Avast. > What I think is happening is that MailScanner is blocking all the test > files before they get to the virus scanner. > > How do I know when the virus scanner has picked up a virus (Nothing in the > maillog)?? > I also need to get the output strings so that I can configure MailWatch > for avastd. I've already turned clam off. > > If anyone has something infected feel free to send it to > andy.mac@global-domination.org > > Cheers,Andy > > > ----- Original Message ---- > From: Dan Hollis > To: MailScanner discussion > Sent: Thursday, 3 May, 2007 6:42:02 PM > Subject: Re: 32 bit distro or 64? > > On Thu, 3 May 2007, Rick Chadderdon wrote: >> Still, it is much easier to get support from a vendor if you're using >> their software the way that they intended. I can already hear, "Oh, I'm >> sorry, we don't support that product running on a 64-bit OS." Even if >> the problem you're having is not related to the OS at all. Just >> something to consider. > > In this case you vote with your wallet and find another vendor. Works for > me anyway :) > > -Dan > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From dominian at slackadelic.com Thu May 3 21:44:29 2007 From: dominian at slackadelic.com (Matt Hayes) Date: Thu May 3 21:44:41 2007 Subject: Looks like permissions, but unsure where Message-ID: <463A49AD.9020203@slackadelic.com> Ok all, Just upgraded to the newest MailScanner, did everything like I normally do.. switched to clamd and I'm getting this: MailScanner[20004]: ./18D72272A.1574D.header: Unable to create temporary directory Now, at first I thought it was clamd, switched it to clamav and still getting the same thing. Any good ideas where to look? Thanks, Matt From dominian at slackadelic.com Thu May 3 22:16:59 2007 From: dominian at slackadelic.com (Matt Hayes) Date: Thu May 3 22:17:15 2007 Subject: [Solved] Looks like permissions, but unsure where In-Reply-To: <463A49AD.9020203@slackadelic.com> References: <463A49AD.9020203@slackadelic.com> Message-ID: <463A514B.1040909@slackadelic.com> Matt Hayes wrote: > Ok all, > > Just upgraded to the newest MailScanner, did everything like I normally > do.. switched to clamd and I'm getting this: > > MailScanner[20004]: ./18D72272A.1574D.header: Unable to create temporary > directory > > > Now, at first I thought it was clamd, switched it to clamav and still > getting the same thing. Any good ideas where to look? > > > > Thanks, > > Matt > Nevermind. If I had been a smart man and used DEBUGGING ... I would've found that it was looking to use /dev/shm to speed up the processing of the email. It seems with the new MailScanner it wants to use /dev/shm. What I found was that on whitelisted addresses I didn't get this error. On anything else, I did. So, once I mounted /dev/shm and all is well. Thanks, Matt From mailscanner at yeticomputers.com Thu May 3 22:17:38 2007 From: mailscanner at yeticomputers.com (Rick Chadderdon) Date: Thu May 3 22:17:48 2007 Subject: 32 bit distro or 64? In-Reply-To: References: <463900F6.1070103@yeticomputers.com> <463904BA.4040402@sendit.nodak.edu> <463A0223.3000803@yeticomputers.com> Message-ID: <463A5172.8090704@yeticomputers.com> Dan Hollis wrote: > On Thu, 3 May 2007, Rick Chadderdon wrote: >> Still, it is much easier to get support from a vendor if you're using >> their software the way that they intended. I can already hear, "Oh, I'm >> sorry, we don't support that product running on a 64-bit OS." Even if >> the problem you're having is not related to the OS at all. Just >> something to consider. > > In this case you vote with your wallet and find another vendor. Works > for me anyway :) Oh, absolutely. But, it doesn't stop it from being a genuine issue. And, sometimes, you'll find that there is *not* a vendor that offers the service/product you want, the way you want it. I'm a very independent person, so I'll do things my own way regardless of what support I can get. I do recognize, however, that this is not the best solution for everyone. And, being self-employed, I can only shoot myself in the foot. If you work for someone else, it's important to understand how they feel about such issues. "Sir, we have to switch away from "Company A" because I chose solution X, and they won't support it," just might cause a bit of a ruckus if the company has a lot of money tied up in Company A's products. The old "Nobody ever got fired for buying IBM" argument. Sadly, due to the typical corporate mindset, it has some merit. Rick From dominian at slackadelic.com Thu May 3 22:23:12 2007 From: dominian at slackadelic.com (Matt Hayes) Date: Thu May 3 22:23:26 2007 Subject: [Solved] Looks like permissions, but unsure where In-Reply-To: <463A514B.1040909@slackadelic.com> References: <463A49AD.9020203@slackadelic.com> <463A514B.1040909@slackadelic.com> Message-ID: <463A52C0.3060207@slackadelic.com> Matt Hayes wrote: > Matt Hayes wrote: >> Ok all, >> >> Just upgraded to the newest MailScanner, did everything like I >> normally do.. switched to clamd and I'm getting this: >> >> MailScanner[20004]: ./18D72272A.1574D.header: Unable to create >> temporary directory >> >> >> Now, at first I thought it was clamd, switched it to clamav and still >> getting the same thing. Any good ideas where to look? >> >> >> >> Thanks, >> >> Matt >> > > > Nevermind. If I had been a smart man and used DEBUGGING ... I would've > found that it was looking to use /dev/shm to speed up the processing of > the email. > > > It seems with the new MailScanner it wants to use /dev/shm. What I > found was that on whitelisted addresses I didn't get this error. On > anything else, I did. So, once I mounted /dev/shm and all is well. > Check that; check_mailscanner looks to see if /dev/shm is available.. if it does.. it forces SpamAssassin to use that instead. Dunno why this wasn't being used on the other install I had. -Matt From drew at technologytiger.net Thu May 3 23:02:44 2007 From: drew at technologytiger.net (Drew Marshall) Date: Thu May 3 23:03:08 2007 Subject: ANNOUNCE: MailScanner stable 4.59 In-Reply-To: References: <4635B2C4.50004@ecs.soton.ac.uk> Message-ID: On 3 May 2007, at 18:53, Koopmann, Jan-Peter wrote: > On SHA1 wrote: > >> I have just released a new stable version, 4.59. The main new >> features this month are >> > > FreeBSD port has just been submitted. Thanks Julian! Thanks JP. Could really do with that clamd option as the clamscan perl module has gone and broken on my box for no apparent reason (As my thread of the same subject says). Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by the Technology Tiger MailScanner. Further information can be found at www.technologytiger.net/policy Technology Tiger Limited is registered in Scotland with registration number: 310997 Registered Office 55-57 West High Street Inverurie AB51 3QQ From drew at technologytiger.net Thu May 3 23:06:52 2007 From: drew at technologytiger.net (Drew Marshall) Date: Thu May 3 23:07:17 2007 Subject: Looks like permissions, but unsure where In-Reply-To: <463A49AD.9020203@slackadelic.com> References: <463A49AD.9020203@slackadelic.com> Message-ID: <2F4FF868-1C27-4485-AF50-4EB5EB3D846C@technologytiger.net> On 3 May 2007, at 21:44, Matt Hayes wrote: > Ok all, > > Just upgraded to the newest MailScanner, did everything like I > normally do.. switched to clamd and I'm getting this: > > MailScanner[20004]: ./18D72272A.1574D.header: Unable to create > temporary directory > > > Now, at first I thought it was clamd, switched it to clamav and > still getting the same thing. Any good ideas where to look? Looks like a Postfix queue reference so I'll venture /var/spool/ MailScanner/incoming would be a good place to begin This is one of the complications of running Postfix. It's secure in so much as nothing has an elevated user status but it does make permissions a challenge particularly as Clam does the same thing and MailScanner needs to run a both. Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by the Technology Tiger MailScanner. Further information can be found at www.technologytiger.net/policy Technology Tiger Limited is registered in Scotland with registration number: 310997 Registered Office 55-57 West High Street Inverurie AB51 3QQ From alex at nkpanama.com Thu May 3 23:15:24 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Thu May 3 23:16:17 2007 Subject: Very newbie relaying question In-Reply-To: References: <1DF321991CD3084EAD65737D82C6D07E145A86@sbs1.nuvotem.local> Message-ID: <463A5EFC.2020007@nkpanama.com> Ren? Berber wrote: > You are using the old syntax, which may not be what you want. > > If all your server IPs are public then you are on the right track, if > your servers have internal/external addresses you are better off using > the internal ones. > > An example of what you can do is access as: > > # Allow relying from LAN > Connect:192.168.0 RELAY > Connect:127.0.0.1 RELAY > Connect:exchange_server_IP RELAY > # Whitelist > Connect:other_external_IP RELAY > You're assuming there is a zero percent chance any of the machines on the internal network may be spam zombies. This isn't usually true. You might want to look into SMTP AUTHentication and/or allow relaying only from the (ugh) exchange box, which should be set to only allow relaying from AUTHenticated users. From amaclach at yahoo.co.uk Fri May 4 00:33:53 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Fri May 4 00:33:55 2007 Subject: Testing the anti-virus stack Message-ID: <878270.64176.qm@web26304.mail.ukl.yahoo.com> OK - it's automagically started working. I got the output strings for avast by running an interactive cmdline scan against eicar.com. If anyone's interested they are: /tmp/eicar.com [infected by: EICAR Test-NOT virus!!] and the mailwatch mods (yes - I know - different list...) including the new clam strings in functions.php are: if(!defined(VIRUS_REGEX) || !DISTRIBUTED_SETUP) { switch($scanner=get_primary_scanner()) { case 'none': define(VIRUS_REGEX, '/^Dummy$/'); break; case 'sophos': define(VIRUS_REGEX, '/(>>>) Virus \'(\S+)\' found/'); break; case 'sophossavi': define(VIRUS_REGEX, '/(\S+) was infected by (\S+)/'); break; case 'clamav': define(VIRUS_REGEX, '/(.+) contains (\S+)/'); break; case 'clamd': define(VIRUS_REGEX, '/(.+) contains (\S+)/'); break; case 'clamavmodule': define(VIRUS_REGEX, '/(.+) was infected: (\S+)/'); break; case 'f-prot': define(VIRUS_REGEX, '/(.+) Infection: (\S+)/'); break; case 'mcafee': define(VIRUS_REGEX, '/(.+) Found the (\S+) virus !!!/'); break; case 'f-secure': define(VIRUS_REGEX, '/(.+) Infected: (\S+)/'); break; case 'trend': define(VIRUS_REGEX, '/(Found virus) (\S+) in file (\S+)/'); break; case 'bitdefender': define(VIRUS_REGEX, '/(\S+) Found virus (\S+)/'); break; case 'kaspersky-4.5': define(VIRUS_REGEX, '/(.+) INFECTED (\S+)/'); break; case 'etrust': define(VIRUS_REGEX, '/(\S+) is infected by virus: (\S+)/'); break; case 'avg': define(VIRUS_REGEX, '/(Found virus) (\S+) in file (\S+)/'); break; case 'avast': define(VIRUS_REGEX, '/(.+) [infected by: (\S+) virus!!]/'); break; case 'avastd': define(VIRUS_REGEX, '/(.+) [infected by: (\S+) virus!!]/'); break; default: die("Error:
\n Unable to select a regular expression for your primary virus scanner ($scanner) - please see the examples in functions.php to create one.\n"); break; } Hope this is of use to someone! Regards, Andy ----- Original Message ---- From: --[ UxBoD ]-- To: MailScanner discussion Sent: Thursday, 3 May, 2007 8:21:14 PM Subject: Re: Testing the anti-virus stack Why not run in debug mode and test with eicar.com ? On Thu, 3 May 2007 19:06:24 +0000 (GMT), Andrew MacLachlan wrote: > OK - I'm pulling what's left of my hair out here trying to test Avast. > What I think is happening is that MailScanner is blocking all the test > files before they get to the virus scanner. > > How do I know when the virus scanner has picked up a virus (Nothing in the > maillog)?? > I also need to get the output strings so that I can configure MailWatch > for avastd. I've already turned clam off. > > If anyone has something infected feel free to send it to > andy.mac@global-domination.org > > Cheers,Andy > > > ----- Original Message ---- > From: Dan Hollis > To: MailScanner discussion > Sent: Thursday, 3 May, 2007 6:42:02 PM > Subject: Re: 32 bit distro or 64? > > On Thu, 3 May 2007, Rick Chadderdon wrote: >> Still, it is much easier to get support from a vendor if you're using >> their software the way that they intended. I can already hear, "Oh, I'm >> sorry, we don't support that product running on a 64-bit OS." Even if >> the problem you're having is not related to the OS at all. Just >> something to consider. > > In this case you vote with your wallet and find another vendor. Works for > me anyway :) > > -Dan > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From alex at nkpanama.com Fri May 4 01:41:59 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Fri May 4 01:43:25 2007 Subject: Use of variables within archive rulesets Message-ID: <463A8157.2050209@nkpanama.com> I've got a few clients who choose to archive all their incoming and outgoing e-mail using the "Archive Mail =" function, using a ruleset such as: From: alice@domain.tld /home/archiveaccount/mail/outgoing/alice To: alice@domain.tld /home/archiveaccount/mail/incoming/alice FromOrTo: default /home/archiveaccount/mail/BCCs ... so that mail from alice and to alice goes to the "alice" IMAP-accessible "folder" on the "archiveaccount" user's account, and those that aren't covered by any of the rules (such as BCCs, users I've forgotten to add to the ruleset list, and funky NDRs and stuff) get archived to a separate "BCCs and such" account. I'd like to know if it would be possible to use some sort of variable (systemwide or generated) that would allow me to do something like: From: alice@domain.tld /home/archiveaccount/mail/%year%/%month%/outgoing/alice To: alice@domain.tld /home/archiveaccount/mail/%year%/%month%/incoming/alice How would one go about this? I believe I'd have to create the structure first and change the ownerships and permissions so that the user MailScanner runs under can write to it, and the "archiveaccount" user can read from it, but besides that I wouldn't know where to begin. Suggestions? From jcb at dream.com.ph Fri May 4 04:06:49 2007 From: jcb at dream.com.ph (jcb on dream) Date: Fri May 4 04:08:02 2007 Subject: whitelist mcp Message-ID: <000f01c78df9$41fdbe70$960bbdcb@jepoy> hi guys, i had mcp activated and since im managing a whitelist file for spamassassin, can i create the same config for mcp to point it on the same white list file for spamassassin? tnx. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070504/a11d9a14/attachment.html From mogens at fumlersoft.dk Fri May 4 09:27:53 2007 From: mogens at fumlersoft.dk (Mogens Melander) Date: Fri May 4 09:28:32 2007 Subject: Use of variables within archive rulesets In-Reply-To: <463A8157.2050209@nkpanama.com> References: <463A8157.2050209@nkpanama.com> Message-ID: <2252.90.184.17.152.1178267273.squirrel@mail.fumlersoft.dk> On Fri, May 4, 2007 02:41, Alex Neuman van der Hans wrote: > I've got a few clients who choose to archive all their incoming and > outgoing e-mail using the "Archive Mail =" function, using a ruleset > such as: > > From: alice@domain.tld /home/archiveaccount/mail/outgoing/alice > To: alice@domain.tld /home/archiveaccount/mail/incoming/alice > FromOrTo: default /home/archiveaccount/mail/BCCs > > ... so that mail from alice and to alice goes to the "alice" > IMAP-accessible "folder" on the "archiveaccount" user's account, and > those that aren't covered by any of the rules (such as BCCs, users I've > forgotten to add to the ruleset list, and funky NDRs and stuff) get > archived to a separate "BCCs and such" account. > > I'd like to know if it would be possible to use some sort of variable > (systemwide or generated) that would allow me to do something like: > > From: alice@domain.tld > /home/archiveaccount/mail/%year%/%month%/outgoing/alice > To: alice@domain.tld > /home/archiveaccount/mail/%year%/%month%/incoming/alice > > How would one go about this? I believe I'd have to create the structure > first and change the ownerships and permissions so that the user > MailScanner runs under can write to it, and the "archiveaccount" user > can read from it, but besides that I wouldn't know where to begin. > > Suggestions? How about a custom function ? Take a look at the MyExample.pm in CustomFinctions directory. Mine are located in: /usr/lib/MailScanner/MailScanner/CustomFunctions -- Later Mogens Melander +45 40 85 71 38 +66 870 133 224 -- This message has been scanned for viruses and dangerous content by OpenProtect(http://www.openprotect.com), and is believed to be clean. From pedretti at eco.unibs.it Fri May 4 11:36:13 2007 From: pedretti at eco.unibs.it (Fabio Pedretti) Date: Fri May 4 11:35:20 2007 Subject: Clamav suggestions Message-ID: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> I have some suggestions on using clamav in MailScanner on which I have already sent a mail some time ago: http://lists.mailscanner.info/pipermail/mailscanner/2007-March/071330.html 1) clamscan is called with the option --disable-summary , which is deprecated (at least since clamav 0.70, released on 2004-04-16). --no-summary should be used instead in SweepViruses.pm. 2) I noticed (as well as others: http://lists.mailscanner.info/pipermail/mailscanner/2007-April/072504.html ) that some phishing mail are not blocked (I am also using the signatures of sanesecurity). If I do a clamscan on the full original mail with headers, clamscan find the virus (I can provide a sample if needed). Seems the problem is that MailScanner extracts the content of the mail (body + attachment) and scans it, but some phishing mail are only detected if the full headers are present (in the clamav DB in the extended signature format, option 4 is for mail files, look at signatures.pdf in clamav source, and are detected only if full mail with headers is scanned). MailScanner should be modified so that all the original mail (with headers and without extracting attachment) should be passed to clamscan/clamd, so all virus can be catched. 3) Support for clamd trough clamdscan is nice, however, best would be to connect to clamd directly to its socket (or network socket) from MailScanner, without call clamdscan, and fallback to clamscan if clamd is not working. 4) Would be nice to have the possibility to quarantine only the entire message and not also the attachments: worse is that if there are some compressed files, the original file as well as the content are quarantined, doubling (or more) the space on the disk. Thanks, Fabio From ssilva at sgvwater.com Fri May 4 17:19:00 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Fri May 4 17:19:36 2007 Subject: Clamav suggestions In-Reply-To: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> Message-ID: Fabio Pedretti spake the following on 5/4/2007 3:36 AM: > I have some suggestions on using clamav in MailScanner on which I have > already sent a mail some time ago: > http://lists.mailscanner.info/pipermail/mailscanner/2007-March/071330.html > > 1) clamscan is called with the option --disable-summary , which is > deprecated (at least since clamav 0.70, released on 2004-04-16). > --no-summary should be used instead in SweepViruses.pm. > 2) I noticed (as well as others: > http://lists.mailscanner.info/pipermail/mailscanner/2007-April/072504.html > ) that some phishing mail are not blocked (I am also using > the signatures of sanesecurity). If I do a clamscan on the full > original mail with headers, clamscan find the virus (I can provide a > sample if needed). Seems the problem is that MailScanner extracts the > content of the mail (body + attachment) and scans it, but some > phishing mail are only detected if the full headers are present (in > the clamav DB in the extended signature format, option 4 is for mail > files, look at signatures.pdf in clamav source, and are detected only > if full mail with headers is scanned). > MailScanner should be modified so that all the original mail (with > headers and without extracting attachment) should be passed to > clamscan/clamd, so all virus can be catched. > 3) Support for clamd trough clamdscan is nice, however, best would be to > connect to clamd directly to its socket (or network socket) from > MailScanner, without call clamdscan, and fallback to clamscan if clamd > is not working. > 4) Would be nice to have the possibility to quarantine only the entire > message and not also the attachments: worse is that if there are some > compressed files, the original file as well as the content are > quarantined, doubling (or more) the space on the disk. > I'm sure Julian would welcome some tested patches. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From Richard.Frovarp at sendit.nodak.edu Fri May 4 17:25:46 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Fri May 4 17:25:50 2007 Subject: Clamav suggestions In-Reply-To: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> Message-ID: <463B5E8A.2080400@sendit.nodak.edu> Fabio Pedretti wrote: > > 3) Support for clamd trough clamdscan is nice, however, best would be > to connect to clamd directly to its socket (or network socket) from > MailScanner, without call clamdscan, and fallback to clamscan if clamd > is not working. Why not just run clamavmodule? From my understanding, the support for clamd was added so that those that didn't want to keep up with the Perl module required for clamavmodule would have something faster than clamscan. Any direct call to clamd from MailScanner would require a Perl module, so at that point you're losing the requirements benefit of running clamd. From mkettler at evi-inc.com Fri May 4 19:31:40 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Fri May 4 19:31:53 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: <463900B1.8080301@ecs.soton.ac.uk> References: <463900B1.8080301@ecs.soton.ac.uk> Message-ID: <463B7C0C.9000004@evi-inc.com> Julian Field wrote: > Well, as someone else has already said, it's been released. > > Its list of requirements has grown quite a lot. In addition to whatever > else you already have from an existing SA install, you need to install > this load of Perl modules, in this order: > > YAML -- requires y\n in perl Makefile.PL > ExtUtils::CBuilder > ExtUtils::ParseXS > Module::Build > version > Net::DNS::Resolver::Programmable > Error > NetAddr::IP > Net::DNS >=0.58 > Data::Dump > Encode::Detect > Mail::SPF > Mail::SpamAssassin -- requires \n in perl Makefile.PL > > It puts in a v320.pre into /etc/mail/spamassassin and comes with a load > of new plugins. Some of them are loaded by the default supplied v320.pre > file, but here are the ones that aren't: > > Hashcash.pm Rule2XSBody.pm > ASN.pm SpamCop.pm > AutoLearnThreshold.pm SPF.pm > AWL.pm Test.pm > TextCat.pm > MIMEHeader.pm > BodyRuleBaseExtractor.pm OneLineBodyRuleType.pm URIDNSBL.pm > Pyzor.pm > DCC.pm Razor2.pm > RelayCountry.pm WhiteListSubject.pm > ReplaceTags.pm Julian, Some of those plugins ARE loaded by default, but are loaded via older .pre files. And yes, SA does parse *ALL* of the .pre files, and you need to have ALL of them to work properly. The whole idea of the multiple .pre files is that as new plugins are added, SA doesn't have to do a config-merge. All it does is add the new .pre file that supports the new plugins. Your choices about what plugins from 3.1.0 or 3.0.0 to load won't be affected, and will remain in-place in your old .pre files. Of the above plugins: init.pre (SA 3.0.0) loads: URIDNSBL SPF v310.pre loads: Spamcop DCC (disabled by default) Pyzor Razor2 AWL AutoLearnThreshold TextCat (disabled by default) WhiteListSubject MimeHeader ReplaceTags DomainKeys (disabled by default) v312.pre loads: DKIM (disabled by default) V320.pre only handles the new plugins for 3.2.0, most of which are things that used to be hard-coded into EvalTests.pm. > > My next step is to read the man pages for all of these, and work out > which ones you probably want to load and which ones you don't, so that > my install script can set you up with a sensible system. You really shouldn't have to do that for all of them. Only look at the ones that aren't loaded by default. > One thing I'm > not installing is support for DKIM which, although available, requires > so many pre-requisites that it's not feasible for me to do here. You > have to start at the OpenSSL libraries and work your way up :-( Makes sense, that's a v312.pre thing. > > Once I've got something working here, I'll write up an install script > for it all and wrap it into a package for you. > > Jules > From jaearick at colby.edu Fri May 4 20:40:19 2007 From: jaearick at colby.edu (Jeff A. Earickson) Date: Fri May 4 20:40:35 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: <463900B1.8080301@ecs.soton.ac.uk> References: <463900B1.8080301@ecs.soton.ac.uk> Message-ID: On Wed, 2 May 2007, Julian Field wrote: > Date: Wed, 02 May 2007 22:20:49 +0100 > From: Julian Field > Reply-To: MailScanner discussion > To: MailScanner discussion > Subject: SpamAssassin 3.2.0 > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Well, as someone else has already said, it's been released. > > Its list of requirements has grown quite a lot. In addition to whatever > else you already have from an existing SA install, you need to install > this load of Perl modules, in this order: > > YAML -- requires y\n in perl Makefile.PL > ExtUtils::CBuilder > ExtUtils::ParseXS > Module::Build > version > Net::DNS::Resolver::Programmable > Error > NetAddr::IP > Net::DNS >=0.58 > Data::Dump > Encode::Detect > Mail::SPF > Mail::SpamAssassin -- requires \n in perl Makefile.PL I got it installed and running at my site. I had to install the perl modules above and then some (because I installed DKIM). I probably had to install or update 30+ perl modules. Wow. I also had to stare at the *.pre files. But it seems to work for me. (Solaris 10). Jeff Earickson Colby College From arto.saraniva at artio.net Fri May 4 21:16:23 2007 From: arto.saraniva at artio.net (Arto) Date: Fri May 4 21:16:20 2007 Subject: Clamav suggestions In-Reply-To: <463B5E8A.2080400@sendit.nodak.edu> References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> <463B5E8A.2080400@sendit.nodak.edu> Message-ID: Richard Frovarp wrote: > Fabio Pedretti wrote: >> >> 3) Support for clamd trough clamdscan is nice, however, best would be >> to connect to clamd directly to its socket (or network socket) from >> MailScanner, without call clamdscan, and fallback to clamscan if clamd >> is not working. > > Why not just run clamavmodule? From my understanding, the support for > clamd was added so that those that didn't want to keep up with the Perl > module required for clamavmodule would have something faster than > clamscan. Any direct call to clamd from MailScanner would require a Perl > module, so at that point you're losing the requirements benefit of > running clamd. FYI, we have used all of those during last three weeks. First clamav (indeed about two year before this period), then clamavmodule and during this week clamd. Our MX server passes normally about 10k mails/day (MS, postgrey, postfix and SA) and clamd is IMHO the most comfortable as regards load, memory and swap. The server is a vmware client (CentOS4.4 ) with 2 x 2,4 GHz and 775 Mb memory reserved to client. After start the swap is with clamd under 40 Mb and it will remain there. With clamavmodule and clamav the swap varies from 40 to 400 Mb and the load can be even over 20 with clamav. More details from our Cacti stats: http://www.artio.fi/.component/imageGenerator.php?fileName=%2Fwebroot%2Fweb%2Ffocus%2Fwww%2Fimnetti%2Fmedia%2F0%2F10841.png&cache=1&cachePrefix=.cache The first week was runned with clamav till midday of thursday, after that with clamavmodule and this week with clamd. With numbers this week (four workdays because of free Monday, otherwise typical): received: 33307 spam: 836 rejected: 163033 virus: 5 bounced: 150 sent: 8331 -arto From Richard.Frovarp at sendit.nodak.edu Fri May 4 21:38:53 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Fri May 4 21:38:56 2007 Subject: Clamav suggestions In-Reply-To: References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> <463B5E8A.2080400@sendit.nodak.edu> Message-ID: <463B99DD.4020900@sendit.nodak.edu> Arto wrote: > Richard Frovarp wrote: >> Fabio Pedretti wrote: >>> >>> 3) Support for clamd trough clamdscan is nice, however, best would >>> be to connect to clamd directly to its socket (or network socket) >>> from MailScanner, without call clamdscan, and fallback to clamscan >>> if clamd is not working. >> >> Why not just run clamavmodule? From my understanding, the support for >> clamd was added so that those that didn't want to keep up with the >> Perl module required for clamavmodule would have something faster >> than clamscan. Any direct call to clamd from MailScanner would >> require a Perl module, so at that point you're losing the >> requirements benefit of running clamd. > > FYI, we have used all of those during last three weeks. First clamav > (indeed about two year before this period), then clamavmodule and > during this week clamd. > > Our MX server passes normally about 10k mails/day (MS, postgrey, > postfix and SA) and clamd is IMHO the most comfortable as regards > load, memory and swap. The server is a vmware client (CentOS4.4 ) with > 2 x 2,4 GHz and 775 Mb memory reserved to client. After start the swap > is with clamd under 40 Mb and it will remain there. With clamavmodule > and clamav the swap varies from 40 to 400 Mb and the load can be even > over 20 with clamav. > > More details from our Cacti stats: > http://www.artio.fi/.component/imageGenerator.php?fileName=%2Fwebroot%2Fweb%2Ffocus%2Fwww%2Fimnetti%2Fmedia%2F0%2F10841.png&cache=1&cachePrefix=.cache > > The first week was runned with clamav till midday of thursday, after > that with clamavmodule and this week with clamd. > > With numbers this week (four workdays because of free Monday, > otherwise typical): > > received: 33307 > spam: 836 > rejected: 163033 > virus: 5 > bounced: 150 > sent: 8331 > > -arto > You may want to decrease the number of MailScanner processes running under Max Children. I've got a vmware guest with 1 GB of RAM. The host is a dual socket dual core 3.2 GHz Xeon. We're not see any swap at all running clamavmodule. However, I have Max Children set to 7. This particular scanner handles internal mail only and scan times are only a couple of seconds during the middle of the day with batch sizes of 1 or 2. From Monday to Thursday I see these numbers: Received: 202,866 Spam: 190 Virus: 456 From arto.saraniva at artio.net Fri May 4 21:45:04 2007 From: arto.saraniva at artio.net (Arto) Date: Fri May 4 21:45:04 2007 Subject: Clamav suggestions In-Reply-To: <463B99DD.4020900@sendit.nodak.edu> References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> <463B5E8A.2080400@sendit.nodak.edu> <463B99DD.4020900@sendit.nodak.edu> Message-ID: Richard Frovarp wrote: > Arto wrote: >> Richard Frovarp wrote: >>> Fabio Pedretti wrote: >>>> >>>> 3) Support for clamd trough clamdscan is nice, however, best would >>>> be to connect to clamd directly to its socket (or network socket) >>>> from MailScanner, without call clamdscan, and fallback to clamscan >>>> if clamd is not working. >>> >>> Why not just run clamavmodule? From my understanding, the support for >>> clamd was added so that those that didn't want to keep up with the >>> Perl module required for clamavmodule would have something faster >>> than clamscan. Any direct call to clamd from MailScanner would >>> require a Perl module, so at that point you're losing the >>> requirements benefit of running clamd. >> >> FYI, we have used all of those during last three weeks. First clamav >> (indeed about two year before this period), then clamavmodule and >> during this week clamd. >> >> Our MX server passes normally about 10k mails/day (MS, postgrey, >> postfix and SA) and clamd is IMHO the most comfortable as regards >> load, memory and swap. The server is a vmware client (CentOS4.4 ) with >> 2 x 2,4 GHz and 775 Mb memory reserved to client. After start the swap >> is with clamd under 40 Mb and it will remain there. With clamavmodule >> and clamav the swap varies from 40 to 400 Mb and the load can be even >> over 20 with clamav. >> >> More details from our Cacti stats: >> http://www.artio.fi/.component/imageGenerator.php?fileName=%2Fwebroot%2Fweb%2Ffocus%2Fwww%2Fimnetti%2Fmedia%2F0%2F10841.png&cache=1&cachePrefix=.cache >> >> The first week was runned with clamav till midday of thursday, after >> that with clamavmodule and this week with clamd. >> >> With numbers this week (four workdays because of free Monday, >> otherwise typical): >> >> received: 33307 >> spam: 836 >> rejected: 163033 >> virus: 5 >> bounced: 150 >> sent: 8331 >> >> -arto >> > > You may want to decrease the number of MailScanner processes running > under Max Children. I've got a vmware guest with 1 GB of RAM. The host > is a dual socket dual core 3.2 GHz Xeon. We're not see any swap at all > running clamavmodule. However, I have Max Children set to 7. This > particular scanner handles internal mail only and scan times are only a > couple of seconds during the middle of the day with batch sizes of 1 or Max Children = 10 (which should be the recommended value with 2 processors.) -arto From Richard.Frovarp at sendit.nodak.edu Fri May 4 21:47:57 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Fri May 4 21:48:00 2007 Subject: Clamav suggestions In-Reply-To: References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> <463B5E8A.2080400@sendit.nodak.edu> <463B99DD.4020900@sendit.nodak.edu> Message-ID: <463B9BFD.6020807@sendit.nodak.edu> Arto wrote: > Richard Frovarp wrote: >> Arto wrote: >>> Richard Frovarp wrote: >>>> Fabio Pedretti wrote: >>>>> >>>>> 3) Support for clamd trough clamdscan is nice, however, best would >>>>> be to connect to clamd directly to its socket (or network socket) >>>>> from MailScanner, without call clamdscan, and fallback to clamscan >>>>> if clamd is not working. >>>> >>>> Why not just run clamavmodule? From my understanding, the support >>>> for clamd was added so that those that didn't want to keep up with >>>> the Perl module required for clamavmodule would have something >>>> faster than clamscan. Any direct call to clamd from MailScanner >>>> would require a Perl module, so at that point you're losing the >>>> requirements benefit of running clamd. >>> >>> FYI, we have used all of those during last three weeks. First clamav >>> (indeed about two year before this period), then clamavmodule and >>> during this week clamd. >>> >>> Our MX server passes normally about 10k mails/day (MS, postgrey, >>> postfix and SA) and clamd is IMHO the most comfortable as regards >>> load, memory and swap. The server is a vmware client (CentOS4.4 ) >>> with 2 x 2,4 GHz and 775 Mb memory reserved to client. After start >>> the swap is with clamd under 40 Mb and it will remain there. With >>> clamavmodule and clamav the swap varies from 40 to 400 Mb and the >>> load can be even over 20 with clamav. >>> >>> More details from our Cacti stats: >>> http://www.artio.fi/.component/imageGenerator.php?fileName=%2Fwebroot%2Fweb%2Ffocus%2Fwww%2Fimnetti%2Fmedia%2F0%2F10841.png&cache=1&cachePrefix=.cache >>> >>> The first week was runned with clamav till midday of thursday, after >>> that with clamavmodule and this week with clamd. >>> >>> With numbers this week (four workdays because of free Monday, >>> otherwise typical): >>> >>> received: 33307 >>> spam: 836 >>> rejected: 163033 >>> virus: 5 >>> bounced: 150 >>> sent: 8331 >>> >>> -arto >>> >> >> You may want to decrease the number of MailScanner processes running >> under Max Children. I've got a vmware guest with 1 GB of RAM. The >> host is a dual socket dual core 3.2 GHz Xeon. We're not see any swap >> at all running clamavmodule. However, I have Max Children set to 7. >> This particular scanner handles internal mail only and scan times are >> only a couple of seconds during the middle of the day with batch >> sizes of 1 or > > Max Children = 10 (which should be the recommended value with 2 > processors.) > > -arto > That's assuming you have the RAM. Each of mine are about 80 MB in size, 10 of those would be 800 MB, which is more than you have allocated for RAM. From arto.saraniva at artio.net Fri May 4 21:50:12 2007 From: arto.saraniva at artio.net (Arto) Date: Fri May 4 21:50:09 2007 Subject: Clamav suggestions In-Reply-To: <463B9BFD.6020807@sendit.nodak.edu> References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> <463B5E8A.2080400@sendit.nodak.edu> <463B99DD.4020900@sendit.nodak.edu> <463B9BFD.6020807@sendit.nodak.edu> Message-ID: Richard Frovarp wrote: > Arto wrote: >> Richard Frovarp wrote: >>> Arto wrote: >>>> Richard Frovarp wrote: >>>>> Fabio Pedretti wrote: >>>>>> >>>>>> 3) Support for clamd trough clamdscan is nice, however, best would >>>>>> be to connect to clamd directly to its socket (or network socket) >>>>>> from MailScanner, without call clamdscan, and fallback to clamscan >>>>>> if clamd is not working. >>>>> >>>>> Why not just run clamavmodule? From my understanding, the support >>>>> for clamd was added so that those that didn't want to keep up with >>>>> the Perl module required for clamavmodule would have something >>>>> faster than clamscan. Any direct call to clamd from MailScanner >>>>> would require a Perl module, so at that point you're losing the >>>>> requirements benefit of running clamd. >>>> >>>> FYI, we have used all of those during last three weeks. First clamav >>>> (indeed about two year before this period), then clamavmodule and >>>> during this week clamd. >>>> >>>> Our MX server passes normally about 10k mails/day (MS, postgrey, >>>> postfix and SA) and clamd is IMHO the most comfortable as regards >>>> load, memory and swap. The server is a vmware client (CentOS4.4 ) >>>> with 2 x 2,4 GHz and 775 Mb memory reserved to client. After start >>>> the swap is with clamd under 40 Mb and it will remain there. With >>>> clamavmodule and clamav the swap varies from 40 to 400 Mb and the >>>> load can be even over 20 with clamav. >>>> >>>> More details from our Cacti stats: >>>> http://www.artio.fi/.component/imageGenerator.php?fileName=%2Fwebroot%2Fweb%2Ffocus%2Fwww%2Fimnetti%2Fmedia%2F0%2F10841.png&cache=1&cachePrefix=.cache >>>> >>>> The first week was runned with clamav till midday of thursday, after >>>> that with clamavmodule and this week with clamd. >>>> >>>> With numbers this week (four workdays because of free Monday, >>>> otherwise typical): >>>> >>>> received: 33307 >>>> spam: 836 >>>> rejected: 163033 >>>> virus: 5 >>>> bounced: 150 >>>> sent: 8331 >>>> >>>> -arto >>>> >>> >>> You may want to decrease the number of MailScanner processes running >>> under Max Children. I've got a vmware guest with 1 GB of RAM. The >>> host is a dual socket dual core 3.2 GHz Xeon. We're not see any swap >>> at all running clamavmodule. However, I have Max Children set to 7. >>> This particular scanner handles internal mail only and scan times are >>> only a couple of seconds during the middle of the day with batch >>> sizes of 1 or >> >> Max Children = 10 (which should be the recommended value with 2 >> processors.) >> >> -arto >> > That's assuming you have the RAM. Each of mine are about 80 MB in size, > 10 of those would be 800 MB, which is more than you have allocated for RAM. Ours are 54388 Mb. From arto.saraniva at artio.net Fri May 4 21:57:56 2007 From: arto.saraniva at artio.net (Arto) Date: Fri May 4 21:57:51 2007 Subject: Clamav suggestions In-Reply-To: References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> <463B5E8A.2080400@sendit.nodak.edu> <463B99DD.4020900@sendit.nodak.edu> <463B9BFD.6020807@sendit.nodak.edu> Message-ID: Arto wrote: > Richard Frovarp wrote: >> Arto wrote: >>> Richard Frovarp wrote: >>>> Arto wrote: >>>>> Richard Frovarp wrote: >>>>>> Fabio Pedretti wrote: >>>>>>> >>>>>>> 3) Support for clamd trough clamdscan is nice, however, best >>>>>>> would be to connect to clamd directly to its socket (or network >>>>>>> socket) from MailScanner, without call clamdscan, and fallback to >>>>>>> clamscan if clamd is not working. >>>>>> >>>>>> Why not just run clamavmodule? From my understanding, the support >>>>>> for clamd was added so that those that didn't want to keep up with >>>>>> the Perl module required for clamavmodule would have something >>>>>> faster than clamscan. Any direct call to clamd from MailScanner >>>>>> would require a Perl module, so at that point you're losing the >>>>>> requirements benefit of running clamd. >>>>> >>>>> FYI, we have used all of those during last three weeks. First >>>>> clamav (indeed about two year before this period), then >>>>> clamavmodule and during this week clamd. >>>>> >>>>> Our MX server passes normally about 10k mails/day (MS, postgrey, >>>>> postfix and SA) and clamd is IMHO the most comfortable as regards >>>>> load, memory and swap. The server is a vmware client (CentOS4.4 ) >>>>> with 2 x 2,4 GHz and 775 Mb memory reserved to client. After start >>>>> the swap is with clamd under 40 Mb and it will remain there. With >>>>> clamavmodule and clamav the swap varies from 40 to 400 Mb and the >>>>> load can be even over 20 with clamav. >>>>> >>>>> More details from our Cacti stats: >>>>> http://www.artio.fi/.component/imageGenerator.php?fileName=%2Fwebroot%2Fweb%2Ffocus%2Fwww%2Fimnetti%2Fmedia%2F0%2F10841.png&cache=1&cachePrefix=.cache >>>>> >>>>> The first week was runned with clamav till midday of thursday, >>>>> after that with clamavmodule and this week with clamd. >>>>> >>>>> With numbers this week (four workdays because of free Monday, >>>>> otherwise typical): >>>>> >>>>> received: 33307 >>>>> spam: 836 >>>>> rejected: 163033 >>>>> virus: 5 >>>>> bounced: 150 >>>>> sent: 8331 >>>>> >>>>> -arto >>>>> >>>> >>>> You may want to decrease the number of MailScanner processes running >>>> under Max Children. I've got a vmware guest with 1 GB of RAM. The >>>> host is a dual socket dual core 3.2 GHz Xeon. We're not see any swap >>>> at all running clamavmodule. However, I have Max Children set to 7. >>>> This particular scanner handles internal mail only and scan times >>>> are only a couple of seconds during the middle of the day with batch >>>> sizes of 1 or >>> >>> Max Children = 10 (which should be the recommended value with 2 >>> processors.) >>> >>> -arto >>> >> That's assuming you have the RAM. Each of mine are about 80 MB in >> size, 10 of those would be 800 MB, which is more than you have >> allocated for RAM. And sure I mean about 54 Mb. :-) From Richard.Frovarp at sendit.nodak.edu Fri May 4 22:07:01 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Fri May 4 22:07:04 2007 Subject: Clamav suggestions In-Reply-To: References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> <463B5E8A.2080400@sendit.nodak.edu> <463B99DD.4020900@sendit.nodak.edu> <463B9BFD.6020807@sendit.nodak.edu> Message-ID: <463BA075.5040004@sendit.nodak.edu> Arto wrote: > Arto wrote: >> Richard Frovarp wrote: >>> Arto wrote: >>>> Richard Frovarp wrote: >>>>> Arto wrote: >>>>>> Richard Frovarp wrote: >>>>>>> Fabio Pedretti wrote: >>>>>>>> >>>>>>>> 3) Support for clamd trough clamdscan is nice, however, best >>>>>>>> would be to connect to clamd directly to its socket (or network >>>>>>>> socket) from MailScanner, without call clamdscan, and fallback >>>>>>>> to clamscan if clamd is not working. >>>>>>> >>>>>>> Why not just run clamavmodule? From my understanding, the >>>>>>> support for clamd was added so that those that didn't want to >>>>>>> keep up with the Perl module required for clamavmodule would >>>>>>> have something faster than clamscan. Any direct call to clamd >>>>>>> from MailScanner would require a Perl module, so at that point >>>>>>> you're losing the requirements benefit of running clamd. >>>>>> >>>>>> FYI, we have used all of those during last three weeks. First >>>>>> clamav (indeed about two year before this period), then >>>>>> clamavmodule and during this week clamd. >>>>>> >>>>>> Our MX server passes normally about 10k mails/day (MS, postgrey, >>>>>> postfix and SA) and clamd is IMHO the most comfortable as regards >>>>>> load, memory and swap. The server is a vmware client (CentOS4.4 ) >>>>>> with 2 x 2,4 GHz and 775 Mb memory reserved to client. After >>>>>> start the swap is with clamd under 40 Mb and it will remain >>>>>> there. With clamavmodule and clamav the swap varies from 40 to >>>>>> 400 Mb and the load can be even over 20 with clamav. >>>>>> >>>>>> More details from our Cacti stats: >>>>>> http://www.artio.fi/.component/imageGenerator.php?fileName=%2Fwebroot%2Fweb%2Ffocus%2Fwww%2Fimnetti%2Fmedia%2F0%2F10841.png&cache=1&cachePrefix=.cache >>>>>> >>>>>> The first week was runned with clamav till midday of thursday, >>>>>> after that with clamavmodule and this week with clamd. >>>>>> >>>>>> With numbers this week (four workdays because of free Monday, >>>>>> otherwise typical): >>>>>> >>>>>> received: 33307 >>>>>> spam: 836 >>>>>> rejected: 163033 >>>>>> virus: 5 >>>>>> bounced: 150 >>>>>> sent: 8331 >>>>>> >>>>>> -arto >>>>>> >>>>> >>>>> You may want to decrease the number of MailScanner processes >>>>> running under Max Children. I've got a vmware guest with 1 GB of >>>>> RAM. The host is a dual socket dual core 3.2 GHz Xeon. We're not >>>>> see any swap at all running clamavmodule. However, I have Max >>>>> Children set to 7. This particular scanner handles internal mail >>>>> only and scan times are only a couple of seconds during the middle >>>>> of the day with batch sizes of 1 or >>>> >>>> Max Children = 10 (which should be the recommended value with 2 >>>> processors.) >>>> >>>> -arto >>>> >>> That's assuming you have the RAM. Each of mine are about 80 MB in >>> size, 10 of those would be 800 MB, which is more than you have >>> allocated for RAM. > > And sure I mean about 54 Mb. :-) > If you aren't actively swapping (to check: vmstat 5) it probably isn't a big deal. If you are actively swapping, back it off some. Other processes on the box also need memory. You'll get greater performance from fewer children and no swapping than greater children and some swapping. From ssilva at sgvwater.com Fri May 4 23:17:32 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Fri May 4 23:17:55 2007 Subject: Clamav suggestions In-Reply-To: References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> <463B5E8A.2080400@sendit.nodak.edu> <463B99DD.4020900@sendit.nodak.edu> Message-ID: <> >> You may want to decrease the number of MailScanner processes running >> under Max Children. I've got a vmware guest with 1 GB of RAM. The host >> is a dual socket dual core 3.2 GHz Xeon. We're not see any swap at all >> running clamavmodule. However, I have Max Children set to 7. This >> particular scanner handles internal mail only and scan times are only >> a couple of seconds during the middle of the day with batch sizes of 1 or > > Max Children = 10 (which should be the recommended value with 2 > processors.) > Don't forget the other recommendation: 1 GB ram per processor, especially with spamassassin. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From res at ausics.net Fri May 4 23:29:56 2007 From: res at ausics.net (Res) Date: Fri May 4 23:30:07 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: <463B7C0C.9000004@evi-inc.com> References: <463900B1.8080301@ecs.soton.ac.uk> <463B7C0C.9000004@evi-inc.com> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Fri, 4 May 2007, Matt Kettler wrote: > URIDNSBL I used to have this disabled for performance, for several versions, but as 3.20 cries like a baby unless its enabled, RDJ and sa-update refuse to run because of found scores for non existant plugins, I must admit I only looked at it for 2 minutes, but decided it was not worth the effort and just enabled the plugin, until I have time to find what else now needs disabling to shut it up :) Might look at it again on monday morning. - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGO7PmsWhAmSIQh7MRAhCoAJ9Wqn9SbNyLdarLnUUv/InE1T4K0wCdGYoM RDMoCPYan7wPupFNvfOAXGI= =/S4d -----END PGP SIGNATURE----- From wilson.galafassi at gmail.com Fri May 4 23:38:17 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Fri May 4 23:38:32 2007 Subject: use mailscanner only for reports Message-ID: <00a601c78e9c$eaa2f920$bfe8eb60$@com.br> Hello. It?s possible to use/configure mailscanner only for reporting mail traffic? Thanks Wilson From mkettler at evi-inc.com Fri May 4 23:39:07 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Fri May 4 23:39:17 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: References: <463900B1.8080301@ecs.soton.ac.uk> <463B7C0C.9000004@evi-inc.com> Message-ID: <463BB60B.3060608@evi-inc.com> Res wrote: > On Fri, 4 May 2007, Matt Kettler wrote: > >> URIDNSBL > > I used to have this disabled for performance, for several versions, but > as 3.20 cries like a baby unless its enabled, RDJ and sa-update refuse > to run because of found scores for non existant plugins, I must admit I > only looked at it for 2 minutes, but decided it was not worth the effort > and just enabled the plugin, until I have time to find what else now > needs disabling to shut it up :) Might look at it again on monday morning. > > Sounds like a bug in the conditionals that disable parts of the ruleset.. I'll look at it this weekend, time permitting.. If I can replicate it, I'll open a bug with the SA dev team. If it's something I can make patches for, I'll do that too. From prandal at herefordshire.gov.uk Fri May 4 23:54:29 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Fri May 4 23:54:42 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: <463B7C0C.9000004@evi-inc.com> References: <463900B1.8080301@ecs.soton.ac.uk> <463B7C0C.9000004@evi-inc.com> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA03CECE@HC-MBX02.herefordshire.gov.uk> The only thing which needs updating for a minimal install is Net::DNS up a version or two from 0.57. SA 3.2.0 will fall back to using Mail::SPF::Query if Mail::SPF is not available. However, I've been testing it with high volumes on an old Fedora Core 1 box and it's not happy - average message scan time is twice that of 3.1.8, and there's other weirdness. One side effect is MailScanner-mrtg's CPU load graph showing as zero when SA 3.2.0 is struggling under load on this box (though the load averages aren't higher than SA 3.1.8's under similar pressure). I suspect something's blocking when it shouldn't. A mystery which I really don't have the time to investigate. Cheers, Phil -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Matt Kettler Sent: 04 May 2007 19:32 To: MailScanner discussion Subject: Re: SpamAssassin 3.2.0 Julian Field wrote: > Well, as someone else has already said, it's been released. > > Its list of requirements has grown quite a lot. In addition to whatever > else you already have from an existing SA install, you need to install > this load of Perl modules, in this order: > > YAML -- requires y\n in perl Makefile.PL > ExtUtils::CBuilder > ExtUtils::ParseXS > Module::Build > version > Net::DNS::Resolver::Programmable > Error > NetAddr::IP > Net::DNS >=0.58 > Data::Dump > Encode::Detect > Mail::SPF > Mail::SpamAssassin -- requires \n in perl Makefile.PL > > It puts in a v320.pre into /etc/mail/spamassassin and comes with a load > of new plugins. Some of them are loaded by the default supplied v320.pre > file, but here are the ones that aren't: > > Hashcash.pm Rule2XSBody.pm > ASN.pm SpamCop.pm > AutoLearnThreshold.pm SPF.pm > AWL.pm Test.pm > TextCat.pm > MIMEHeader.pm > BodyRuleBaseExtractor.pm OneLineBodyRuleType.pm URIDNSBL.pm > Pyzor.pm > DCC.pm Razor2.pm > RelayCountry.pm WhiteListSubject.pm > ReplaceTags.pm Julian, Some of those plugins ARE loaded by default, but are loaded via older .pre files. And yes, SA does parse *ALL* of the .pre files, and you need to have ALL of them to work properly. The whole idea of the multiple .pre files is that as new plugins are added, SA doesn't have to do a config-merge. All it does is add the new .pre file that supports the new plugins. Your choices about what plugins from 3.1.0 or 3.0.0 to load won't be affected, and will remain in-place in your old .pre files. Of the above plugins: init.pre (SA 3.0.0) loads: URIDNSBL SPF v310.pre loads: Spamcop DCC (disabled by default) Pyzor Razor2 AWL AutoLearnThreshold TextCat (disabled by default) WhiteListSubject MimeHeader ReplaceTags DomainKeys (disabled by default) v312.pre loads: DKIM (disabled by default) V320.pre only handles the new plugins for 3.2.0, most of which are things that used to be hard-coded into EvalTests.pm. > > My next step is to read the man pages for all of these, and work out > which ones you probably want to load and which ones you don't, so that > my install script can set you up with a sensible system. You really shouldn't have to do that for all of them. Only look at the ones that aren't loaded by default. > One thing I'm > not installing is support for DKIM which, although available, requires > so many pre-requisites that it's not feasible for me to do here. You > have to start at the OpenSSL libraries and work your way up :-( Makes sense, that's a v312.pre thing. > > Once I've got something working here, I'll write up an install script > for it all and wrap it into a package for you. > > Jules > -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From amaclach at yahoo.co.uk Sat May 5 00:03:48 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Sat May 5 00:03:50 2007 Subject: Clamav suggestions Message-ID: <681587.85151.qm@web26302.mail.ukl.yahoo.com> This is all very well, but make sure your host has enough memory and you have vmware-tools installed and running otherwise ESX will page for you if it's short of memory - and that isn't pretty... CPU isn't that important with VMs - - I've never seen an ESX box max out it's processors unless it's already run out of physical memory. Regards, Andrew MacLachlan ----- Original Message ---- From: Scott Silva To: mailscanner@lists.mailscanner.info Sent: Friday, 4 May, 2007 11:17:32 PM Subject: Re: Clamav suggestions <> >> You may want to decrease the number of MailScanner processes running >> under Max Children. I've got a vmware guest with 1 GB of RAM. The host >> is a dual socket dual core 3.2 GHz Xeon. We're not see any swap at all >> running clamavmodule. However, I have Max Children set to 7. This >> particular scanner handles internal mail only and scan times are only >> a couple of seconds during the middle of the day with batch sizes of 1 or > > Max Children = 10 (which should be the recommended value with 2 > processors.) > Don't forget the other recommendation: 1 GB ram per processor, especially with spamassassin. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From mkettler at evi-inc.com Sat May 5 00:14:57 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Sat May 5 00:15:10 2007 Subject: use mailscanner only for reports In-Reply-To: <00a601c78e9c$eaa2f920$bfe8eb60$@com.br> References: <00a601c78e9c$eaa2f920$bfe8eb60$@com.br> Message-ID: <463BBE71.9010505@evi-inc.com> Wilson A. Galafassi Jr. wrote: > Hello. > > It?s possible to use/configure mailscanner only for reporting mail traffic? I'm not entirely sure I understand the question. MailScanner doesn't make any reports of a broad statistical nature, so you couldn't use it to make "just" make them, since it doesn't do that at all. Or are you looking to run mailscanner in some kind of way that detects mail viruses and spam, but only reports this to the system admin and doesn't modify the message? Or something entirely different? From mikej at rogers.com Sat May 5 01:30:31 2007 From: mikej at rogers.com (Mike Jakubik) Date: Sat May 5 01:32:28 2007 Subject: ANNOUNCE: MailScanner stable 4.59 In-Reply-To: References: <4635B2C4.50004@ecs.soton.ac.uk> Message-ID: <463BD027.3070009@rogers.com> Koopmann, Jan-Peter wrote: > On SHA1 wrote: > > >> I have just released a new stable version, 4.59. The main new >> features this month are >> >> > > FreeBSD port has just been submitted. Thanks Julian! > Just in time before the ports freeze! Thanks! Speaking of the new version, has anyone tried Postfix 2.4 yet? From bilias at edu.physics.uoc.gr Sat May 5 01:52:48 2007 From: bilias at edu.physics.uoc.gr (Kapetanakis Giannis) Date: Sat May 5 01:53:04 2007 Subject: use mailscanner only for reports In-Reply-To: <00a601c78e9c$eaa2f920$bfe8eb60$@com.br> References: <00a601c78e9c$eaa2f920$bfe8eb60$@com.br> Message-ID: On Fri, 4 May 2007, Wilson A. Galafassi Jr. wrote: > Hello. > > It?s possible to use/configure mailscanner only for reporting mail traffic? > Thanks > Wilson > Yes if you set the spam actions to deliver and do not change the subject of the mail. It will forward all mails, but it will first scan them and report. Giannis From wilson.galafassi at gmail.com Sat May 5 04:48:10 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Sat May 5 04:48:28 2007 Subject: RES: use mailscanner only for reports In-Reply-To: <463BBE71.9010505@evi-inc.com> References: <00a601c78e9c$eaa2f920$bfe8eb60$@com.br> <463BBE71.9010505@evi-inc.com> Message-ID: <00b201c78ec8$34cf4230$9e6dc690$@com.br> Hello. In this case i want to use mailscanner + mailwatch only to generate reports using mailwatch. It?s possible? The messages are scanned for spam and viruses in other (external) server, so my utilization is only for reports. Thanks wilson -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Matt Kettler Enviada em: sexta-feira, 4 de maio de 2007 20:15 Para: MailScanner discussion Assunto: Re: use mailscanner only for reports Wilson A. Galafassi Jr. wrote: > Hello. > > It?s possible to use/configure mailscanner only for reporting mail traffic? I'm not entirely sure I understand the question. MailScanner doesn't make any reports of a broad statistical nature, so you couldn't use it to make "just" make them, since it doesn't do that at all. Or are you looking to run mailscanner in some kind of way that detects mail viruses and spam, but only reports this to the system admin and doesn't modify the message? Or something entirely different? -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From dcmwai at pl.jaring.my Sat May 5 08:26:27 2007 From: dcmwai at pl.jaring.my (Chan Min Wai) Date: Sat May 5 08:27:16 2007 Subject: No Programs allowed In-Reply-To: <1178113173.14147.16.camel@viper.mbl.is> References: <1178113173.14147.16.camel@viper.mbl.is> Message-ID: <463C31A3.6050102@pl.jaring.my> Jon Bjorn Njalsson wrote: > Why does MS think msg-26670-41.txt is a program ? > > MailScanner: No programs allowed (msg-26670-41.txt) > > regards > Jon Bjorn > > I've face this problem once. The solution was to change how files read it. On my situation the files is encoded using UTF-8 in an email. This is the solution suggested. Create a scrip of replace File Command = /usr/local/bin/file inside /usr/local/bin/file /usr/bin/file -i $1 That will help to solve the issue. Regards, Min Wai From res at ausics.net Sat May 5 09:45:17 2007 From: res at ausics.net (Res) Date: Sat May 5 09:45:30 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: <463BB60B.3060608@evi-inc.com> References: <463900B1.8080301@ecs.soton.ac.uk> <463B7C0C.9000004@evi-inc.com> <463BB60B.3060608@evi-inc.com> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Thanks Matt If you can't reproduce it let me know, it must point to something else I've enabled I suppose. On Fri, 4 May 2007, Matt Kettler wrote: > Res wrote: >> On Fri, 4 May 2007, Matt Kettler wrote: >> >>> URIDNSBL >> >> I used to have this disabled for performance, for several versions, but >> as 3.20 cries like a baby unless its enabled, RDJ and sa-update refuse >> to run because of found scores for non existant plugins, I must admit I >> only looked at it for 2 minutes, but decided it was not worth the effort >> and just enabled the plugin, until I have time to find what else now >> needs disabling to shut it up :) Might look at it again on monday morning. >> >> > > Sounds like a bug in the conditionals that disable parts of the ruleset.. I'll > look at it this weekend, time permitting.. If I can replicate it, I'll open a > bug with the SA dev team. If it's something I can make patches for, I'll do that > too. > > - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGPEQfsWhAmSIQh7MRAqEBAJkB1hOne+klemVn33sHeLZe0FeShgCeJddM kvkigsKxFjkoNwAYsJWCzvM= =z2L8 -----END PGP SIGNATURE----- From MailScanner at ecs.soton.ac.uk Sat May 5 12:26:51 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat May 5 12:27:23 2007 Subject: Clamav suggestions In-Reply-To: References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> <463B5E8A.2080400@sendit.nodak.edu> Message-ID: <463C69FB.7080301@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Arto wrote: > Richard Frovarp wrote: >> Fabio Pedretti wrote: >>> >>> 3) Support for clamd trough clamdscan is nice, however, best would >>> be to connect to clamd directly to its socket (or network socket) >>> from MailScanner, without call clamdscan, and fallback to clamscan >>> if clamd is not working. >> >> Why not just run clamavmodule? From my understanding, the support for >> clamd was added so that those that didn't want to keep up with the >> Perl module required for clamavmodule would have something faster >> than clamscan. Any direct call to clamd from MailScanner would >> require a Perl module, so at that point you're losing the >> requirements benefit of running clamd. > > FYI, we have used all of those during last three weeks. First clamav > (indeed about two year before this period), then clamavmodule and > during this week clamd. > > Our MX server passes normally about 10k mails/day (MS, postgrey, > postfix and SA) and clamd is IMHO the most comfortable as regards > load, memory and swap. The server is a vmware client (CentOS4.4 ) with > 2 x 2,4 GHz and 775 Mb memory reserved to client. After start the swap > is with clamd under 40 Mb and it will remain there. With clamavmodule > and clamav the swap varies from 40 to 400 Mb and the load can be even > over 20 with clamav. With 2 CPU's I would recommend 2Gb of RAM and not just 775Mb. With that little, it's bound to swap. And swapping in a VM is very slow. Either give your VM a lot more RAM or decrease Max Children by quite a bit. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGPGoAEfZZRxQVtlQRArjuAJ0TLXKwPWs13OpgD7ZjNc2ZSiIqMACeIK9m pR2Q7BOP/jy6kF/JJgDxpCY= =Ypaq -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Sat May 5 12:42:06 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat May 5 12:42:40 2007 Subject: SpamAssassin 3.2.0 package Message-ID: <463C6D8E.5040802@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 My first version of a ClamAV + SpamAssassin 3.2.0 package is here: http://www.mailscanner.info/files/4/install-Clam-0.90.2-SA-3.2.0.tar.gz Please give it a try and tell me what you think. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGPG2SEfZZRxQVtlQRAp04AKDzcrpqjt9PQy1elmLrZ3brZ6n52QCg4XKf vKBeYc0ONuI/vrut9Eur8Yo= =fmSq -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From hvdkooij at vanderkooij.org Sat May 5 14:33:29 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sat May 5 14:34:06 2007 Subject: RES: use mailscanner only for reports In-Reply-To: <00b201c78ec8$34cf4230$9e6dc690$@com.br> References: <00a601c78e9c$eaa2f920$bfe8eb60$@com.br> <463BBE71.9010505@evi-inc.com> <00b201c78ec8$34cf4230$9e6dc690$@com.br> Message-ID: On Sat, 5 May 2007, Wilson A. Galafassi Jr. wrote: > In this case i want to use mailscanner + mailwatch only to generate reports > using mailwatch. It?s possible? The messages are scanned for spam and > viruses in other (external) server, so my utilization is only for reports. Just select deliver for all classes and be done with it. But I fail to see the use of this. Are the other solutions soo poor they can not provide you with this information? Why not park them outside next to the dustbin and let MailScanner + MailWatch do the job for you? Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From hvdkooij at vanderkooij.org Sat May 5 14:45:46 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sat May 5 14:46:22 2007 Subject: RES: use mailscanner only for reports In-Reply-To: <00b201c78ec8$34cf4230$9e6dc690$@com.br> References: <00a601c78e9c$eaa2f920$bfe8eb60$@com.br> <463BBE71.9010505@evi-inc.com> <00b201c78ec8$34cf4230$9e6dc690$@com.br> Message-ID: On Sat, 5 May 2007, Wilson A. Galafassi Jr. wrote: > In this case i want to use mailscanner + mailwatch only to generate reports > using mailwatch. It?s possible? The messages are scanned for spam and > viruses in other (external) server, so my utilization is only for reports. And here is an afterthought. What do you expect to learn if someone cleared out the wrong messages before they get to you? Then how can you tell the rate of SPAM vs HAM messages? Or how many three year old virus junk was taken from your SMTP stream. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From exp at protos.mine.nu Sat May 5 16:10:52 2007 From: exp at protos.mine.nu (Hans Bergman) Date: Sat May 5 16:11:29 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: <463C6D8E.5040802@ecs.soton.ac.uk> References: <463C6D8E.5040802@ecs.soton.ac.uk> Message-ID: <463C9E7C.7040600@protos.mine.nu> Julian Field skrev: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > My first version of a ClamAV + SpamAssassin 3.2.0 package is here: > http://www.mailscanner.info/files/4/install-Clam-0.90.2-SA-3.2.0.tar.gz > > Please give it a try and tell me what you think. > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: ISO-8859-1 > > wj8DBQFGPG2SEfZZRxQVtlQRAp04AKDzcrpqjt9PQy1elmLrZ3brZ6n52QCg4XKf > vKBeYc0ONuI/vrut9Eur8Yo= > =fmSq > -----END PGP SIGNATURE----- > > (1) Africa (2) Asia (3) Central America (4) Europe (5) North America (6) Oceania (7) South America Select your continent (or several nearby continents) [] Sorry! since you don't have any existing picks, you must make a geographic selection. (1) Africa (2) Asia (3) Central America (4) Europe (5) North America (6) Oceania (7) South America Select your continent (or several nearby continents) [] Sorry! since you don't have any existing picks, you must make a geographic selection. (1) Africa (2) Asia (3) Central America (4) Europe (5) North America (6) Oceania (7) South America Select your continent (or several nearby continents) [] Sorry! since you don't have any existing picks, you must make a geographic selection. Loops here!! -- Meddelandet har kontrollerats mot virus samt skadligt inneh?ll av MailScanner och f?rmodas vara s?kert. From rcooper at dwford.com Sat May 5 16:27:52 2007 From: rcooper at dwford.com (Rick Cooper) Date: Sat May 5 16:27:59 2007 Subject: Clamav suggestions In-Reply-To: <463B5E8A.2080400@sendit.nodak.edu> References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> <463B5E8A.2080400@sendit.nodak.edu> Message-ID: <085b01c78f29$f30cc540$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Richard Frovarp > Sent: Friday, May 04, 2007 12:26 PM > To: MailScanner discussion > Subject: Re: Clamav suggestions > > Fabio Pedretti wrote: > > > > 3) Support for clamd trough clamdscan is nice, however, > best would be > > to connect to clamd directly to its socket (or network socket) from > > MailScanner, without call clamdscan, and fallback to > clamscan if clamd > > is not working. > > Why not just run clamavmodule? From my understanding, the support for > clamd was added so that those that didn't want to keep up > with the Perl > module required for clamavmodule would have something faster than > clamscan. Any direct call to clamd from MailScanner would > require a Perl > module, so at that point you're losing the requirements benefit of > running clamd. [..] That isn't really accurate. When I remove the clamavmodule scanner from MailScanner I gain about 78mg of ram (with 3 children) which is certainly a benefit. Unless the clam team completely revises their clamd protocol (which hasn't happened as long as I can remember) then there is no concern about core library changes that break clamavmodule, another benefit. Unless the team changed the output regarding viruses detected a direct call would just work. I am in the process of incorporating a direct call to ClamD via sockets into my own MailScanner installs and it wouldn't require additional modules beyond IO::Socket::UNIX (could be done with just Socket but I prefer the IO::Socket::UNIX wrapper). Also handles both Unix sockets as well as Inet sockets. The benefit for someone like me is I use clamd with exim, so it's already running and wouldn't require additional resources and it's very fast (faster than calling clamdscan). It wouldn't require MailScanner to watch the clam data files as the freshclam process already notifies clamd as to changes. Anyone who is using clamdscan would certainly benefit by calling clamd directly rather than via any of the wrappers. As far as fallback is concerned I am inclined to add an options for a restart script if clamd is found to be down, or doesn't respond (properly) to PING. I have been very busy the last few months so I haven't gotten past a stand alone proof of concept perl program, but I am hoping to have it integrated in the next week or so time permitting. If Julian is interested I would certainly send patches to the list when I am satisfied. Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From wilson.galafassi at gmail.com Sat May 5 16:50:37 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Sat May 5 16:50:57 2007 Subject: RES: RES: use mailscanner only for reports In-Reply-To: References: <00a601c78e9c$eaa2f920$bfe8eb60$@com.br> <463BBE71.9010505@evi-inc.com> <00b201c78ec8$34cf4230$9e6dc690$@com.br> Message-ID: <001a01c78f2d$21b6d900$65248b00$@com.br> My external (valid) email Server Just use mailscanner to identify and block spam and viruses. I need to use the reports of mailwatch in the internal Server to catch all email traffic including local mail traffic. You understand me? Thanks Wilson -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Hugo van der Kooij Enviada em: s?bado, 5 de maio de 2007 10:46 Para: MailScanner discussion Assunto: Re: RES: use mailscanner only for reports On Sat, 5 May 2007, Wilson A. Galafassi Jr. wrote: > In this case i want to use mailscanner + mailwatch only to generate > reports using mailwatch. It?s possible? The messages are scanned for > spam and viruses in other (external) server, so my utilization is only for reports. And here is an afterthought. What do you expect to learn if someone cleared out the wrong messages before they get to you? Then how can you tell the rate of SPAM vs HAM messages? Or how many three year old virus junk was taken from your SMTP stream. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From MailScanner at ecs.soton.ac.uk Sat May 5 17:14:08 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat May 5 17:15:13 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: <463C9E7C.7040600@protos.mine.nu> References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> Message-ID: <463CAD50.3050806@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I have fixed this one. Module::Build was after Net::DNS::Resolver::Programmable instead of being before it. I have updated the package on the website. You should find this new one works just fine. Hans Bergman wrote: > Julian Field skrev: >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> My first version of a ClamAV + SpamAssassin 3.2.0 package is here: >> http://www.mailscanner.info/files/4/install-Clam-0.90.2-SA-3.2.0.tar.gz >> >> Please give it a try and tell me what you think. >> >> Jules >> >> - -- Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> MailScanner customisation, or any advanced system administration help? >> Contact me at Jules@Jules.FM >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> For all your IT requirements visit www.transtec.co.uk >> >> >> >> -----BEGIN PGP SIGNATURE----- >> Version: PGP Desktop 9.6.1 (Build 1012) >> Charset: ISO-8859-1 >> >> wj8DBQFGPG2SEfZZRxQVtlQRAp04AKDzcrpqjt9PQy1elmLrZ3brZ6n52QCg4XKf >> vKBeYc0ONuI/vrut9Eur8Yo= >> =fmSq >> -----END PGP SIGNATURE----- >> >> > > (1) Africa > (2) Asia > (3) Central America > (4) Europe > (5) North America > (6) Oceania > (7) South America > Select your continent (or several nearby continents) [] > Sorry! since you don't have any existing picks, you must make a > geographic selection. > > (1) Africa > (2) Asia > (3) Central America > (4) Europe > (5) North America > (6) Oceania > (7) South America > Select your continent (or several nearby continents) [] > Sorry! since you don't have any existing picks, you must make a > geographic selection. > > (1) Africa > (2) Asia > (3) Central America > (4) Europe > (5) North America > (6) Oceania > (7) South America > Select your continent (or several nearby continents) [] > Sorry! since you don't have any existing picks, you must make a > geographic selection. > > Loops here!! > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGPK10EfZZRxQVtlQRAkUsAJ4ouodrQgW3jMASSEy6w4da9jUZKACcDr0L LbPeS6xQws9UwvD8j42l/2Q= =9TZw -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Sat May 5 17:22:40 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat May 5 17:25:11 2007 Subject: Clamav suggestions In-Reply-To: <085b01c78f29$f30cc540$0301a8c0@SAHOMELT> References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> <463B5E8A.2080400@sendit.nodak.edu> <085b01c78f29$f30cc540$0301a8c0@SAHOMELT> Message-ID: <463CAF50.8030305@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Rick Cooper wrote: > > I am in the process of incorporating a direct call to ClamD via sockets into > my own MailScanner installs and it wouldn't require additional modules > beyond IO::Socket::UNIX (could be done with just Socket but I prefer the > IO::Socket::UNIX wrapper). Also handles both Unix sockets as well as Inet > sockets. > > The benefit for someone like me is I use clamd with exim, so it's already > running and wouldn't require additional resources and it's very fast (faster > than calling clamdscan). It wouldn't require MailScanner to watch the clam > data files as the freshclam process already notifies clamd as to changes. > Anyone who is using clamdscan would certainly benefit by calling clamd > directly rather than via any of the wrappers. > > As far as fallback is concerned I am inclined to add an options for a > restart script if clamd is found to be down, or doesn't respond (properly) > to PING. I have been very busy the last few months so I haven't gotten past > a stand alone proof of concept perl program, but I am hoping to have it > integrated in the next week or so time permitting. If Julian is interested I > would certainly send patches to the list when I am satisfied. > Yes, I welcome any contribution, so long as the patch isn't *too* big! :-) Please try to keep your patch as self-contained as possible, so you just, for example, rewrite the init code for the clamd parser and the output parser itself. Please just make it as clean and modular as you can. You can see from the rest of the code the type of Perl I write. I use the syntactical short-cut facilities in the language, I don't just write Java/C in Perl the way a lot of people do. And please don't feel upset if I take your code and appear to rewrite it :-) Thanks, Jules. > Rick > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGPK/MEfZZRxQVtlQRAlsXAKCFibv5MLP/+fZwto6JByw3nPt5JQCgyiBU 9TPh91uiEs2IfTSOU4Tf9dA= =DRtW -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Sat May 5 18:04:37 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat May 5 18:05:14 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: <463CAD50.3050806@ecs.soton.ac.uk> References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> <463CAD50.3050806@ecs.soton.ac.uk> Message-ID: <463CB925.2050609@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I have done some basic tests with my SpamAssassin 3.2.0 package and MailScanner 4.59 and it is working fine. I'll do some more tests of it and probably start using it on a production machine tomorrow if I feel so inclined (and there again I might well just put my feet up and watch TV). It's a public holiday this weekend (I think!) so by definition it should rain on Monday at least. :-) Jules. Julian Field wrote: > * PGP Signed: 05/05/07 at 17:14:44 > > I have fixed this one. Module::Build was after > Net::DNS::Resolver::Programmable instead of being before it. > I have updated the package on the website. You should find this new > one works just fine. > > > Hans Bergman wrote: >> Julian Field skrev: >>> -----BEGIN PGP SIGNED MESSAGE----- >>> Hash: SHA1 >>> >>> My first version of a ClamAV + SpamAssassin 3.2.0 package is here: >>> http://www.mailscanner.info/files/4/install-Clam-0.90.2-SA-3.2.0.tar.gz >>> >>> Please give it a try and tell me what you think. >>> >>> Jules >>> >>> - -- Julian Field MEng CITP >>> www.MailScanner.info >>> Buy the MailScanner book at www.MailScanner.info/store >>> >>> MailScanner customisation, or any advanced system administration help? >>> Contact me at Jules@Jules.FM >>> >>> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >>> For all your IT requirements visit www.transtec.co.uk >>> >>> >>> >>> -----BEGIN PGP SIGNATURE----- >>> Version: PGP Desktop 9.6.1 (Build 1012) >>> Charset: ISO-8859-1 >>> >>> wj8DBQFGPG2SEfZZRxQVtlQRAp04AKDzcrpqjt9PQy1elmLrZ3brZ6n52QCg4XKf >>> vKBeYc0ONuI/vrut9Eur8Yo= >>> =fmSq >>> -----END PGP SIGNATURE----- >>> >>> >> >> (1) Africa >> (2) Asia >> (3) Central America >> (4) Europe >> (5) North America >> (6) Oceania >> (7) South America >> Select your continent (or several nearby continents) [] >> Sorry! since you don't have any existing picks, you must make a >> geographic selection. >> >> (1) Africa >> (2) Asia >> (3) Central America >> (4) Europe >> (5) North America >> (6) Oceania >> (7) South America >> Select your continent (or several nearby continents) [] >> Sorry! since you don't have any existing picks, you must make a >> geographic selection. >> >> (1) Africa >> (2) Asia >> (3) Central America >> (4) Europe >> (5) North America >> (6) Oceania >> (7) South America >> Select your continent (or several nearby continents) [] >> Sorry! since you don't have any existing picks, you must make a >> geographic selection. >> >> Loops here!! >> >> > > Jules > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGPLktEfZZRxQVtlQRAhbVAKChfm6CpXtG2gYYgOrV07TNCSORnwCgiuQU VONO85De2EEz10EOxYYkcNM= =d69x -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From rcooper at dwford.com Sat May 5 19:23:22 2007 From: rcooper at dwford.com (Rick Cooper) Date: Sat May 5 19:24:39 2007 Subject: Clamav suggestions In-Reply-To: <463CAF50.8030305@ecs.soton.ac.uk> References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> <463B5E8A.2080400@sendit.nodak.edu><085b01c78f29$f30cc540$0301a8c0@SAHOMELT> <463CAF50.8030305@ecs.soton.ac.uk> Message-ID: <089801c78f42$78529500$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Julian Field > Sent: Saturday, May 05, 2007 12:23 PM > To: MailScanner discussion > Subject: Re: Clamav suggestions > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > [...] > Yes, I welcome any contribution, so long as the patch isn't > *too* big! :-) > Please try to keep your patch as self-contained as possible, so you > just, for example, rewrite the init code for the clamd parser and the > output parser itself. Please just make it as clean and modular as you > can. You can see from the rest of the code the type of Perl I > write. I > use the syntactical short-cut facilities in the language, I > don't just > write Java/C in Perl the way a lot of people do. And please > don't feel > upset if I take your code and appear to rewrite it :-) > > Thanks, > Jules. > I will have to try and rememeber the program flow, and look at the clamavmodule code and how it's called because this would work pretty much the same. It would be easy enough to make the output the same as the clamavmodule output so the same parser could be used if the current parser had some minor changes such as MailScanner::Log::InfoLog("ClamAVModule:: to MailScanner::Log::InfoLog("$Name:: would it not? I have already tried to make the code more like yours (from my unrar experience) such as "last if time > $TimeOut;" or "LogIt("ClamD Timed Out!\n") if $TimeOut < time && $Debug;". In any event you know I don't care if you rewrite everything.. It's your program ;-) The size should be pretty fair, the current stand alone proof of concept code is only 144 lines including a Logging function, line comments, 18 lines of description comments, the various "use " statements and debug and blank lines. I would expect the finished MS ready code would be half that, maybe less (even with comments). There would, of course, be additional config lines. I would expect you should have: clamd socket (IpAddr or full path to socket file) clamd port default 3310 clamd lock file (to check if clamd is even running) clamd timeout And would you want to scan an entire batch at once, or one message/dir at a time? I can even send you the stand alone code I have an let you play with it at your leasure if you wish. Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From alden at engineno9inc.com Sat May 5 20:12:57 2007 From: alden at engineno9inc.com (Alden Levy) Date: Sat May 5 20:13:07 2007 Subject: SMPID vs. INPID Message-ID: <002101c78f49$651fdcc0$5a01a8c0@AldenLap> I had a problem a long time ago on my old server that never got solved; unfortunately, it's reared it's ugly head on the new server (I had to copy over a file from the old server), and I'd like to put it to bed for good. Basically, when I start MS, all works well, but when I check status, I get an error # service MailScanner status Checking MailScanner daemons: MailScanner: [ OK ] incoming sendmail: [ FAIL ] outgoing sendmail: [ OK ] However, it works fine as it is. In order to get rid of the fail, though, I've been updating sendmail.in.pid with the proper pid, and everything works. I finally had a few minutes to track down the issue, and it seems that something (I did something??) confused SMPID and INPID in MailScanner_app_init. The relevant code is: In StartInSendmail: elif [ $MTA = 'sendmail' ]; then /usr/bin/newaliases > /dev/null 2>&1 if test -x /usr/bin/make -a -f /etc/mail/Makefile ; then make -C /etc/mail -s else for i in virtusertable access domaintable mailertable ; do if [ -f /etc/mail/$i ] ; then makemap hash /etc/mail/$i < /etc/mail/$i fi done fi $SENDMAIL -bd -OPrivacyOptions=noetrn \ -ODeliveryMode=queueonly \ -OQueueDirectory=$INQDIR \ -OPidFile=$INPID touch /var/run/sm-client.pid chown $MSPUSER:$MSPGROUP /var/run/sm-client.pid 2>/dev/null $SENDMAIL -L sm-msp-queue -Ac -q15m -OPidFile=$SMPID 2>/dev/null success echo And in status: status) # Work out if all of MailScanner is running echo 'Checking MailScanner daemons:' echo -n ' MailScanner: ' pid=`pidofproc MailScanner` if [ -z "$pid" ] ; then failure; else success; fi echo if [ $MTA = "sendmail" ]; then # Now the incoming sendmail echo -n ' incoming sendmail: ' pid=`head -1 $INPID` alive=`ps ax | awk '{ print $1 }' | grep '^'$pid'$'` #pid=`ps ax | egrep '\[sendmail\]|sendmai[l]: accepting connections'` if [ -z "$alive" ] ; then failure; else success; fi echo Please note that both $INPID and $SMPID (as well as /var/run/sm-client.pid) are referenced in StartInSendmail and only $INPID is checked in status. Any help would be greatly appreciated. For the record, I am running MS 4.68.9-1 and SA 3.18 on CentOS 4.4. Thanks, Alden Alden Levy Engine No. 9, Inc. 130 W. 57th Street, Suite 2F New York, NY 10019 (212) 981-1122 (212) 504-9598 fax From amaclach at yahoo.co.uk Sun May 6 00:55:38 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Sun May 6 00:55:40 2007 Subject: Strange clamd messages Message-ID: <711094.52154.qm@web26308.mail.ukl.yahoo.com> Has anyone experienced anything like this with clamd? It appears to be working but I'm concerned by the lstat() message... May 5 12:28:25 mail-gw MailScanner[1774]: Virus and Content Scanning: Starting May 5 12:28:25 mail-gw clamd[1543]: No stats for Database check - forcing reload May 5 12:28:25 mail-gw clamd[1543]: Reading databases from /var/lib/clamav May 5 12:28:27 mail-gw MailScanner[1774]: /var/spool/MailScanner/incoming/1774/.: lstat() failed. ERROR May 5 12:28:28 mail-gw MailScanner[1774]: Requeue: 5CE7527F11.91A87 to 9E60927F21 May 5 12:28:28 mail-gw MailScanner[1774]: Uninfected: Delivered 1 messages clamd is 0.90.2-1 on FC4 Cheers, Andy From r.berber at computer.org Sun May 6 01:47:46 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Sun May 6 01:46:53 2007 Subject: Strange clamd messages In-Reply-To: <711094.52154.qm@web26308.mail.ukl.yahoo.com> References: <711094.52154.qm@web26308.mail.ukl.yahoo.com> Message-ID: Andrew MacLachlan wrote: > Has anyone experienced anything like this with clamd? > It appears to be working but I'm concerned by the lstat() message... > > May 5 12:28:25 mail-gw MailScanner[1774]: Virus and Content Scanning: Starting > May 5 12:28:25 mail-gw clamd[1543]: No stats for Database check - forcing reload > May 5 12:28:25 mail-gw clamd[1543]: Reading databases from /var/lib/clamav > May 5 12:28:27 mail-gw MailScanner[1774]: /var/spool/MailScanner/incoming/1774/.: lstat() failed. ERROR > May 5 12:28:28 mail-gw MailScanner[1774]: Requeue: 5CE7527F11.91A87 to 9E60927F21 > May 5 12:28:28 mail-gw MailScanner[1774]: Uninfected: Delivered 1 messages Is not working, and the problem are permissions: clamd cannot see what's in the incomming directory, much less test it. -- Ren? Berber From jimc at laridian.com Sun May 6 02:56:38 2007 From: jimc at laridian.com (Jim Coates) Date: Sun May 6 03:01:08 2007 Subject: MailScanner failing to deliver In-Reply-To: Message-ID: <060701c78f81$c8fdae10$6501a8c0@zorak> Hey all... My host had to upgrade some things on our server and in the process upgraded MailScanner to the latest available from the ports tree (FreeBSD). The version is 4.50.15. Since the upgrade, its been having issues... it seems to receive email (I can tail the maillog and see stuff coming in), but it only delivers inbound and outbound for a short period of time. I then have to restart MailScanner, and it will once again deliver for just a short period of time. Another oddity... when tailing the maillog, I see MailScanne start multiple times... IE - it puts up the version info and the number of messages in queue etc... then a few seconds later I see the same thing twice more. Any ideas? I wasn't having these issues at all with the older version of MailScanner that I was running. Thank you in advance, Jim Coates From jimc at laridian.com Sun May 6 05:04:12 2007 From: jimc at laridian.com (Jim Coates) Date: Sun May 6 05:09:56 2007 Subject: MailScanner failing to deliver Message-ID: <06a301c78f93$9cd5cbd0$6501a8c0@zorak> I'm reposting this simply because I accidentally tagged it onto another thread.. sorry: Hey all... My host had to upgrade some things on our server and in the process upgraded MailScanner to the latest available from the ports tree (FreeBSD). The version is 4.50.15. Since the upgrade, its been having issues... it seems to receive email (I can tail the maillog and see stuff coming in), but it only delivers inbound and outbound for a short period of time. I then have to restart MailScanner, and it will once again deliver for just a short period of time. When it restarts (and seemingly before it fails too) there are a group of messages that get processed over and over. Another oddity... when tailing the maillog, I see MailScanner start multiple times... IE - it puts up the version info and the number of messages in queue etc... then a few seconds later I see the same thing twice more. Any ideas? I wasn't having these issues at all with the older version of MailScanner that I was running. NEW INFORMATION: when I do a "mailscanner --lint" it tells me the following: mail2# mailscanner --lint Read 701 hostnames from the phishing whitelist Config: calling custom init function MailWatchLogging Cannot write pid file , No such file or directory at /usr/local/sbin/mailscanner line 1238 Checking for SpamAssassin errors (if you use it)... Using SpamAssassin results cache Connected to SpamAssassin cache database SpamAssassin reported no errors. MailScanner.conf says "Virus Scanners = clamav" Found these virus scanners installed: clamavmodule mail2# I also had MailWatch installed, but the host recently upgraded MySQL and it has not worked since then. Not sure what the cause is or if its adding to this trouble. I do get a considerable amount of : May 5 22:56:57 mail2 MailScanner[98183]: Started SQL Logging child May 5 22:56:57 mail2 MailScanner[98106]: Started SQL Logging child May 5 22:56:58 mail2 MailScanner[58029]: Started SQL Logging child May 5 22:57:00 mail2 MailScanner[96343]: Started SQL Logging child May 5 22:57:08 mail2 MailScanner[98200]: Started SQL Logging child Basically I am having to restart it about every 30 minutes right now, so I'd love any help you can give me. Thank you in advance, Jim Coates -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070505/91d2265c/attachment.html From hvdkooij at vanderkooij.org Sun May 6 09:05:17 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sun May 6 09:05:49 2007 Subject: MailScanner failing to deliver In-Reply-To: <06a301c78f93$9cd5cbd0$6501a8c0@zorak> References: <06a301c78f93$9cd5cbd0$6501a8c0@zorak> Message-ID: On Sat, 5 May 2007, Jim Coates wrote: > My host had to upgrade some things on our server and in the process upgraded > MailScanner to the latest available from the ports tree (FreeBSD). The > version is 4.50.15. > > Since the upgrade, its been having issues... it seems to receive email (I > can tail the maillog and see stuff coming in), but it only delivers inbound > and outbound for a short period of time. I then have to restart MailScanner, > and it will once again deliver for just a short period of time. > > When it restarts (and seemingly before it fails too) there are a group of > messages that get processed over and over. > > Another oddity... when tailing the maillog, I see MailScanner start multiple > times... IE - it puts up the version info and the number of messages in > queue etc... then a few seconds later I see the same thing twice more. > > Any ideas? I wasn't having these issues at all with the older version of > MailScanner that I was running. > > NEW INFORMATION: when I do a "mailscanner --lint" it tells me the following: > > mail2# mailscanner --lint > Read 701 hostnames from the phishing whitelist > Config: calling custom init function MailWatchLogging > Cannot write pid file , No such file or directory at > /usr/local/sbin/mailscanner line 1238 I suggest you check this out and fix what is required to be fixed. > Checking for SpamAssassin errors (if you use it)... > Using SpamAssassin results cache > Connected to SpamAssassin cache database > SpamAssassin reported no errors. > MailScanner.conf says "Virus Scanners = clamav" > Found these virus scanners installed: clamavmodule > mail2# > > I also had MailWatch installed, but the host recently upgraded MySQL and it > has not worked since then. Not sure what the cause is or if its adding to > this trouble. I do get a considerable amount of : > > May 5 22:56:57 mail2 MailScanner[98183]: Started SQL Logging child > May 5 22:56:57 mail2 MailScanner[98106]: Started SQL Logging child > May 5 22:56:58 mail2 MailScanner[58029]: Started SQL Logging child > May 5 22:57:00 mail2 MailScanner[96343]: Started SQL Logging child > May 5 22:57:08 mail2 MailScanner[98200]: Started SQL Logging child > > Basically I am having to restart it about every 30 minutes right now, so I'd > love any help you can give me. If MailWatch is not working there is nothing to be lost from removing the MailWatch line(s) from your config now. See if it is degrading your MailScanner functionality. Did you go over the changelog to see if things changed from your old version to your current one? Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From amaclach at yahoo.co.uk Sun May 6 11:13:59 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Sun May 6 11:14:02 2007 Subject: Strange clamd messages Message-ID: <524616.6557.qm@web26315.mail.ukl.yahoo.com> Working properly now - Thanks for the pointer! Cheers, Andy ----- Original Message ---- From: Ren? Berber To: mailscanner@lists.mailscanner.info Sent: Sunday, 6 May, 2007 1:47:46 AM Subject: Re: Strange clamd messages Andrew MacLachlan wrote: > Has anyone experienced anything like this with clamd? > It appears to be working but I'm concerned by the lstat() message... > > May 5 12:28:25 mail-gw MailScanner[1774]: Virus and Content Scanning: Starting > May 5 12:28:25 mail-gw clamd[1543]: No stats for Database check - forcing reload > May 5 12:28:25 mail-gw clamd[1543]: Reading databases from /var/lib/clamav > May 5 12:28:27 mail-gw MailScanner[1774]: /var/spool/MailScanner/incoming/1774/.: lstat() failed. ERROR > May 5 12:28:28 mail-gw MailScanner[1774]: Requeue: 5CE7527F11.91A87 to 9E60927F21 > May 5 12:28:28 mail-gw MailScanner[1774]: Uninfected: Delivered 1 messages Is not working, and the problem are permissions: clamd cannot see what's in the incomming directory, much less test it. -- Ren? Berber -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Sun May 6 11:51:26 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun May 6 11:56:16 2007 Subject: HOWTO: Use re2c and compiled SpamAssassin rules Message-ID: <463DB32E.5070702@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 This is intended as a brief guide to using the program "re2c" to generate compiled rules which speeds up SpamAssassin quite a bit. Please can someone (who understands the wiki's text formatting system) upload this to the wiki for me! 1) Download the program "re2c" from "http://sourceforge.net/projects/re2c". If you are running an RPM-based system then download the .src.rpm file, else download the .tar.gz file. 2) Build "re2c". 2a) If you downloaded the .src.rpm file, then rpmbuild --rebuild re2c*.src.rpm cd /usr/src/redhat/RPMS/i386 (swap "redhat" for "packages" if that dir doesn't exist) rpm -Uvh re2c-0.12.0-1.i386.rpm (i.e. not the "debuginfo" version of the file) 2b) If you downloaded the .tar.gz file, then tar xzf re2c*tar*gz cd re2c* ./configure make make test make install 3) Compile the current set of SpamAssassin rules sa-compile 4) Tell SpamAssassin to use the compiled rules. Edit /etc/mail/spamassassin/v320.pre and uncomment the line loadplugin Mail::SpamAssassin::Plugin::Rule2XSBody by removing the "# " from the start of the line. 5) If you are using Rules-Du-Jour then tell it to recompile the rules after it downloads them. Edit the file /usr/bin/rules_du_jour and look for the line that contains SA_RESTART=" Change this line to say SA_RESTART="sa-compile && /etc/init.d/spamassassin restart"; 6) Restart MailScanner. If you have any problems, let the mailing list know. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGPbQxEfZZRxQVtlQRAiIDAJ96MwjVldiCLcqhPghe+iHdKdq+4wCdE94p J5dKYLH+ldoVOIqTR74s8Mo= =Z068 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From asakawa at quickd.net Sun May 6 13:08:11 2007 From: asakawa at quickd.net (asakawa) Date: Sun May 6 13:08:37 2007 Subject: can't detect avast Message-ID: <20070506210337.62F3.ASAKAWA@quickd.net> can't detect avast MailScanner --lint Creating hardcoded struct_flock subroutine for linux (Linux-type) MailScanner.conf says "Virus Scanners = antivir clamd bitdefender f-prot avg f-secure avast" Found these virus scanners installed: bitdefender, f-prot, clamav, f-secure, clamd, avg, antivir virus.scanners.conf avast /usr/lib/MailScanner/avast-wrapper /usr/bin/avast avastd /usr/lib/MailScanner/avastd-wrapper /usr/bin/avast [root@ns ~]# /usr/bin/avast -V avast: avast v1.0.8 VPS: 000714-0 (date: 15.02.2007) Copyright(C) 2003-2007. ALWIL Software. All rights reserved. Asakawa From ms-list at alexb.ch Sun May 6 13:47:49 2007 From: ms-list at alexb.ch (Alex Broens) Date: Sun May 6 13:47:52 2007 Subject: HOWTO: Use re2c and compiled SpamAssassin rules In-Reply-To: <463DB32E.5070702@ecs.soton.ac.uk> References: <463DB32E.5070702@ecs.soton.ac.uk> Message-ID: <463DCE75.7090905@alexb.ch> On 5/6/2007 12:51 PM, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > This is intended as a brief guide to using the program "re2c" to > generate compiled rules which speeds up SpamAssassin quite a bit. > > Please can someone (who understands the wiki's text formatting system) > upload this to the wiki for me! > > 1) Download the program "re2c" from > "http://sourceforge.net/projects/re2c". If you are running an RPM-based > system then download the .src.rpm file, else download the .tar.gz file. > 2) Build "re2c". > 2a) If you downloaded the .src.rpm file, then > rpmbuild --rebuild re2c*.src.rpm > cd /usr/src/redhat/RPMS/i386 (swap "redhat" for "packages" if > that dir doesn't exist) > rpm -Uvh re2c-0.12.0-1.i386.rpm (i.e. not the "debuginfo" version > of the file) > 2b) If you downloaded the .tar.gz file, then > tar xzf re2c*tar*gz > cd re2c* > ./configure > make > make test > make install > 3) Compile the current set of SpamAssassin rules > sa-compile > 4) Tell SpamAssassin to use the compiled rules. Edit > /etc/mail/spamassassin/v320.pre and uncomment the line > loadplugin Mail::SpamAssassin::Plugin::Rule2XSBody > by removing the "# " from the start of the line. > 5) If you are using Rules-Du-Jour then tell it to recompile the rules > after it downloads them. Edit the file /usr/bin/rules_du_jour and look > for the line that contains > SA_RESTART=" > Change this line to say > SA_RESTART="sa-compile && /etc/init.d/spamassassin restart"; > 6) Restart MailScanner. > > If you have any problems, let the mailing list know. Jules I'd say that if you use MS and RDJ the restart command should be SA_RESTART="sa-compile && /etc/init.d/MailScanner reload"; Alex From MailScanner at ecs.soton.ac.uk Sun May 6 13:50:40 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun May 6 13:51:08 2007 Subject: can't detect avast In-Reply-To: <20070506210337.62F3.ASAKAWA@quickd.net> References: <20070506210337.62F3.ASAKAWA@quickd.net> Message-ID: <463DCF20.8080706@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Your virus.scanners.conf is wrong. For the avast lines it should just be /usr. asakawa wrote: > can't detect avast > > MailScanner --lint > > Creating hardcoded struct_flock subroutine for linux (Linux-type) > MailScanner.conf says "Virus Scanners = antivir clamd bitdefender f-prot avg f-secure avast" > Found these virus scanners installed: bitdefender, f-prot, clamav, f-secure, clamd, avg, antivir > > virus.scanners.conf > > > avast /usr/lib/MailScanner/avast-wrapper /usr/bin/avast > avastd /usr/lib/MailScanner/avastd-wrapper /usr/bin/avast > > [root@ns ~]# /usr/bin/avast -V > avast: avast v1.0.8 > VPS: 000714-0 (date: 15.02.2007) > Copyright(C) 2003-2007. ALWIL Software. All rights reserved. > > > > Asakawa > > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGPc8jEfZZRxQVtlQRAo74AJ42Fegygf0xhnKx+LHuQWoy9qEcWQCg2PDP 0TGhQPJMr816K5pjxeNJ2GA= =U3OV -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From smlists at shaw.ca Sun May 6 14:40:37 2007 From: smlists at shaw.ca (Steve Mason) Date: Sun May 6 14:40:41 2007 Subject: MailScanner and Centos 5 In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA921765@HC-MBX02.herefordshire.gov.uk> References: <462BE389.7060802@shaw.ca> <7EF0EE5CB3B263488C8C18823239BEBA921765@HC-MBX02.herefordshire.gov.uk> Message-ID: <463DDAD5.5030405@shaw.ca> Thanks. I decided to go with 4.4, and it's up and running (except for FuzzyOCR which I'm leaving for another day) Steve From smlists at shaw.ca Sun May 6 14:42:50 2007 From: smlists at shaw.ca (Steve Mason) Date: Sun May 6 14:44:53 2007 Subject: Multi (split) image spam In-Reply-To: <462BE389.7060802@shaw.ca> References: <462BE389.7060802@shaw.ca> Message-ID: <463DDB5A.3050405@shaw.ca> Is anyone else seeing drug image spam with the .gif images split into 4 vertical strip files? Nice new tactic by the spammers.... any new methods to handle this yet? Thanks, Steve From uxbod at splatnix.net Sun May 6 14:57:52 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Sun May 6 14:55:47 2007 Subject: Multi (split) image spam In-Reply-To: <463DDB5A.3050405@shaw.ca> References: <462BE389.7060802@shaw.ca> <463DDB5A.3050405@shaw.ca> Message-ID: <20070506145752.5fa3f497@uxbod.splatnix.net> I haven't seen any of those yet Steve. Could you make one available for analysis ? All, FuzzyOCR is broke with SA 3.2.0 at the moment. Cheers, On Sun, 06 May 2007 07:42:50 -0600 Steve Mason wrote: > Is anyone else seeing drug image spam with the .gif images split > into 4 vertical strip files? > > Nice new tactic by the spammers.... any new methods to handle this > yet? > > Thanks, > > Steve -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 845 869 2749 // SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Sun May 6 14:59:32 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Sun May 6 14:57:27 2007 Subject: nod32-1.99 Message-ID: <20070506145932.1be9c82b@uxbod.splatnix.net> Julian, I am running this AV here and have had to add -b to the nod32-wrapper so that it performs a silent operation. ie. no licensing details being slapped into /var/log/messages, and MailScanner trying to scan that :) Maybe worth adding as a default too the wrapper ? Cheers, -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 845 869 2749 // SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From smlists at shaw.ca Sun May 6 15:10:23 2007 From: smlists at shaw.ca (Steve Mason) Date: Sun May 6 15:10:29 2007 Subject: Multi (split) image spam In-Reply-To: <20070506145752.5fa3f497@uxbod.splatnix.net> References: <462BE389.7060802@shaw.ca> <463DDB5A.3050405@shaw.ca> <20070506145752.5fa3f497@uxbod.splatnix.net> Message-ID: <463DE1CF.3050804@shaw.ca> --[ UxBoD ]-- wrote: > I haven't seen any of those yet Steve. Could you make one available > for analysis ? > > All, FuzzyOCR is broke with SA 3.2.0 at the moment. > > Cheers, > No problem.. wget http://www.masoncomputing.com/spamsamples/spam1.tar Steve From mkettler at evi-inc.com Sun May 6 18:39:24 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Sun May 6 18:39:34 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: References: <463900B1.8080301@ecs.soton.ac.uk> <463B7C0C.9000004@evi-inc.com> <463BB60B.3060608@evi-inc.com> Message-ID: <463E12CC.7080806@evi-inc.com> Yes, it's a genuine bug. I reproduced it at home and produced a patch, which I tried to send you a link to, but unfortunately you don't seem to accept mail from my home ISP (verizon). I don't have the link handy, so you'll have to dig around the SA bugzilla. It shouldn't be hard to find. Search for open bugs involving uridnsbl. Res wrote: > Thanks Matt > If you can't reproduce it let me know, it must point to something else > I've enabled I suppose. > > On Fri, 4 May 2007, Matt Kettler wrote: > >> Res wrote: >>> On Fri, 4 May 2007, Matt Kettler wrote: >>> >>>> URIDNSBL >>> >>> I used to have this disabled for performance, for several versions, but >>> as 3.20 cries like a baby unless its enabled, RDJ and sa-update refuse >>> to run because of found scores for non existant plugins, I must admit I >>> only looked at it for 2 minutes, but decided it was not worth the effort >>> and just enabled the plugin, until I have time to find what else now >>> needs disabling to shut it up :) Might look at it again on monday >>> morning. >>> >>> > >> Sounds like a bug in the conditionals that disable parts of the >> ruleset.. I'll >> look at it this weekend, time permitting.. If I can replicate it, I'll >> open a >> bug with the SA dev team. If it's something I can make patches for, >> I'll do that >> too. > > > From hvdkooij at vanderkooij.org Sun May 6 19:39:08 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sun May 6 19:39:44 2007 Subject: Multi (split) image spam In-Reply-To: <463DDB5A.3050405@shaw.ca> References: <462BE389.7060802@shaw.ca> <463DDB5A.3050405@shaw.ca> Message-ID: On Sun, 6 May 2007, Steve Mason wrote: > Is anyone else seeing drug image spam with the .gif images split into 4 > vertical strip files? > > Nice new tactic by the spammers.... any new methods to handle this yet? Perhaps the fact that they are in strip files? Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From hvdkooij at vanderkooij.org Sun May 6 19:42:18 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sun May 6 19:42:57 2007 Subject: Multi (split) image spam In-Reply-To: <463DE1CF.3050804@shaw.ca> References: <462BE389.7060802@shaw.ca> <463DDB5A.3050405@shaw.ca> <20070506145752.5fa3f497@uxbod.splatnix.net> <463DE1CF.3050804@shaw.ca> Message-ID: On Sun, 6 May 2007, Steve Mason wrote: > --[ UxBoD ]-- wrote: >> I haven't seen any of those yet Steve. Could you make one available >> for analysis ? >> >> All, FuzzyOCR is broke with SA 3.2.0 at the moment. >> >> Cheers, >> > No problem.. > wget http://www.masoncomputing.com/spamsamples/spam1.tar Great shooting Tex. ;-) I think we got a genuine logwatch report here. I think you need to check it. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From MailScanner at ecs.soton.ac.uk Sun May 6 20:24:37 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun May 6 20:26:44 2007 Subject: nod32-1.99 In-Reply-To: <20070506145932.1be9c82b@uxbod.splatnix.net> References: <20070506145932.1be9c82b@uxbod.splatnix.net> Message-ID: <463E2B75.7050102@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Thanks for that. I have added it to SweepViruses.pm. It will be in the next release. Cheers, Jules. - --[ UxBoD ]-- wrote: > Julian, > > I am running this AV here and have had to add -b to the nod32-wrapper > so that it performs a silent operation. ie. no licensing details being > slapped into /var/log/messages, and MailScanner trying to scan that :) > > Maybe worth adding as a default too the wrapper ? > > Cheers, > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGPivWEfZZRxQVtlQRAkxiAJ9+9OHQeqV1sHVBpFqsU1by6OVxOQCfUI39 dIvb3Fw1ZhpS3qsvJGvrhhE= =O4Sz -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From amaclach at yahoo.co.uk Sun May 6 22:16:43 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Sun May 6 22:16:46 2007 Subject: MailScanner and Centos 5 Message-ID: <802996.33232.qm@web26302.mail.ukl.yahoo.com> Fuzzy's a complete sh... to get right, but it's great once it's working properly and you have all the components installed (oh why can't someone put it all into a nice easy rpm...) I found Tesseract the worst... It just wouldn't build... Regards, Andrew MacLachlan H: +44 20 84677939 M: +44 7900 980314 E: amaclach@yahoo.co.uk ----- Original Message ---- From: Steve Mason To: MailScanner discussion Sent: Sunday, 6 May, 2007 2:40:37 PM Subject: Re: MailScanner and Centos 5 Thanks. I decided to go with 4.4, and it's up and running (except for FuzzyOCR which I'm leaving for another day) Steve -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From amaclach at yahoo.co.uk Sun May 6 22:22:20 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Sun May 6 22:22:22 2007 Subject: Multi (split) image spam Message-ID: <727373.44781.qm@web26307.mail.ukl.yahoo.com> Nope, but I've seen some quite cool wobbly lines just today - didn't fool Fuzzy though - an instant 6 points for that effort plus incidental scores giving it a total of 16 or so. Some of the spammers are doing resends though to get around greylisting - this is a worrying trend, however it also means that they can only send half as many from each bot... Maybe time to re-tune the greylisting software so it does a second 450 before it finally accepts a sender? Regards, Andrew MacLachlan H: +44 20 84677939 M: +44 7900 980314 E: amaclach@yahoo.co.uk ----- Original Message ---- From: Steve Mason To: MailScanner discussion Sent: Sunday, 6 May, 2007 2:42:50 PM Subject: Multi (split) image spam Is anyone else seeing drug image spam with the .gif images split into 4 vertical strip files? Nice new tactic by the spammers.... any new methods to handle this yet? Thanks, Steve -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From amaclach at yahoo.co.uk Sun May 6 22:24:17 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Sun May 6 22:24:19 2007 Subject: SpamAssassin 3.2.0 Message-ID: <963369.66510.qm@web26310.mail.ukl.yahoo.com> I can host that patch if you want. Andy ----- Original Message ---- From: Matt Kettler To: MailScanner discussion Sent: Sunday, 6 May, 2007 6:39:24 PM Subject: Re: SpamAssassin 3.2.0 Yes, it's a genuine bug. I reproduced it at home and produced a patch, which I tried to send you a link to, but unfortunately you don't seem to accept mail from my home ISP (verizon). I don't have the link handy, so you'll have to dig around the SA bugzilla. It shouldn't be hard to find. Search for open bugs involving uridnsbl. Res wrote: > Thanks Matt > If you can't reproduce it let me know, it must point to something else > I've enabled I suppose. > > On Fri, 4 May 2007, Matt Kettler wrote: > >> Res wrote: >>> On Fri, 4 May 2007, Matt Kettler wrote: >>> >>>> URIDNSBL >>> >>> I used to have this disabled for performance, for several versions, but >>> as 3.20 cries like a baby unless its enabled, RDJ and sa-update refuse >>> to run because of found scores for non existant plugins, I must admit I >>> only looked at it for 2 minutes, but decided it was not worth the effort >>> and just enabled the plugin, until I have time to find what else now >>> needs disabling to shut it up :) Might look at it again on monday >>> morning. >>> >>> > >> Sounds like a bug in the conditionals that disable parts of the >> ruleset.. I'll >> look at it this weekend, time permitting.. If I can replicate it, I'll >> open a >> bug with the SA dev team. If it's something I can make patches for, >> I'll do that >> too. > > > -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From hvdkooij at vanderkooij.org Sun May 6 23:07:18 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sun May 6 23:07:54 2007 Subject: Multi (split) image spam In-Reply-To: <727373.44781.qm@web26307.mail.ukl.yahoo.com> References: <727373.44781.qm@web26307.mail.ukl.yahoo.com> Message-ID: On Sun, 6 May 2007, Andrew MacLachlan wrote: > Some of the spammers are doing resends though to get around greylisting - this is a worrying trend, however it also means that they can only send half as many from each bot... > > Maybe time to re-tune the greylisting software so it does a second 450 before it finally accepts a sender? Most greylisting solutions I have seen use a time window. So you need to resend it after the timewindow or you will still hit the greylist. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From res at ausics.net Sun May 6 23:25:20 2007 From: res at ausics.net (Res) Date: Sun May 6 23:25:38 2007 Subject: Multi (split) image spam In-Reply-To: <727373.44781.qm@web26307.mail.ukl.yahoo.com> References: <727373.44781.qm@web26307.mail.ukl.yahoo.com> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sun, 6 May 2007, Andrew MacLachlan wrote: > Some of the spammers are doing resends though to get around greylisting This is one of the reasons I consider greylisting useless :) I've seen this from this part of the world (oceania/asia area) for about as long as greylisting came about. It's the same ol same ol, we do something to stop em, they circumvent it, we counter it and they will try counter it again, and so on and as grey listing is the most simplest thing to get around, i've always regarded it as a joke, and all it does it build up your own outgoing queues, this might be fine for those who do 1K messages a day but when you do millions, thats just not on, anyhow you might as well firewall off your primary MX making mail fail and force resend via secondary MX's. - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGPlXSsWhAmSIQh7MRAriLAKC1gppSuVoeUKFUBlkcft2Uza6OqQCfWQTM JvxRuyNv2n7IlyXHAPPulAM= =lBlX -----END PGP SIGNATURE----- From amaclach at yahoo.co.uk Sun May 6 23:31:23 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Sun May 6 23:31:25 2007 Subject: Clever bots - was Re: Multi (split) image spam Message-ID: <123569.36742.qm@web26303.mail.ukl.yahoo.com> That's right - most are 5 mins, which is about right for most MTAs first retry. Any decent greylister will tell an early retry to go away again, but either more spammers are using MTAs or the bots are getting cleverer. I'd say the latter is more likely. A cursory glance at a couple of spams from today gives me headers like this: X-Greylist: delayed 00:10:01 by SQLgrey-1.7.5 Received: from 89-172-120-92.adsl.net.t-com.hr (89-172-120-92.adsl.net.t-com.hr [89.172.120.92]) X-Greylist: delayed 00:10:02 by SQLgrey-1.7.5 Received: from 236.Red-81-36-176.dynamicIP.rima-tde.net (236.red-81-36-176.dynamicip.rima-tde.net [81.36.176.236]) Interestingly the delay was over 10 mins by a second or 2 - so this means that grey needs to extend to 11 mins... Not sure what the effect of this will be - is the bot smart enough to retry again if rejected at 10 mins? Andy ----- Original Message ---- From: Hugo van der Kooij To: MailScanner discussion Sent: Sunday, 6 May, 2007 11:07:18 PM Subject: Re: Multi (split) image spam On Sun, 6 May 2007, Andrew MacLachlan wrote: > Some of the spammers are doing resends though to get around greylisting - this is a worrying trend, however it also means that they can only send half as many from each bot... > > Maybe time to re-tune the greylisting software so it does a second 450 before it finally accepts a sender? Most greylisting solutions I have seen use a time window. So you need to resend it after the timewindow or you will still hit the greylist. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From res at ausics.net Sun May 6 23:32:09 2007 From: res at ausics.net (Res) Date: Sun May 6 23:32:25 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: <463E12CC.7080806@evi-inc.com> References: <463900B1.8080301@ecs.soton.ac.uk> <463B7C0C.9000004@evi-inc.com> <463BB60B.3060608@evi-inc.com> <463E12CC.7080806@evi-inc.com> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sun, 6 May 2007, Matt Kettler wrote: > Yes, it's a genuine bug. > > I reproduced it at home and produced a patch, which I tried to send you a link > to, but unfortunately you don't seem to accept mail from my home ISP (verizon). Thanks Matt, I'll have a look later this morning. BTW I wouldn't have got the mail anyway if you had got in as res@ is a list/newsgroup only account unless your mail is sorted into a list folder its /dev/null'd primarily because I've used this a/c on usenet for along time so would have to be in every spam list, sendmail/MS get rid of 99% of the junk, my pine filtering rules eliminate the remaining :) - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGPldrsWhAmSIQh7MRAgNtAJ9NsY9wb0MB1LjuojOGUj5PVxZ6VACdF/ON kFxrQGYHjp6Hy/pBJ6Go7Zk= =r1J5 -----END PGP SIGNATURE----- From amaclach at yahoo.co.uk Sun May 6 23:49:11 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Sun May 6 23:49:14 2007 Subject: Multi (split) image spam Message-ID: <694855.76046.qm@web26301.mail.ukl.yahoo.com> Not useless - just less effective - and no-one said it was the perfect solution - but it does effectively cut the number of spams a bot can send in half, which is always a good thing. Most spam is stopped dead in its tracks by greylisting and is a very effective (also efficient) method of cutting down on the amount of spam that MS has to process. > and all it does it build up your own outgoing queues Not sure how the logic on that one works... > you might as well firewall off your primary MX > making mail fail and force resend via secondary MX's. A bit extreme - and anyway spammers have been sending directly to secondaries for years as a lot of organisations don't have spam defences on them so the messages just sail on thru... As the old saying goes - defence in depth... -Andy ----- Original Message ---- From: Res To: MailScanner discussion Sent: Sunday, 6 May, 2007 11:25:20 PM Subject: Re: Multi (split) image spam -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sun, 6 May 2007, Andrew MacLachlan wrote: > Some of the spammers are doing resends though to get around greylisting This is one of the reasons I consider greylisting useless :) I've seen this from this part of the world (oceania/asia area) for about as long as greylisting came about. It's the same ol same ol, we do something to stop em, they circumvent it, we counter it and they will try counter it again, and so on and as grey listing is the most simplest thing to get around, i've always regarded it as a joke, and all it does it build up your own outgoing queues, this might be fine for those who do 1K messages a day but when you do millions, thats just not on, anyhow you might as well firewall off your primary MX making mail fail and force resend via secondary MX's. - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGPlXSsWhAmSIQh7MRAriLAKC1gppSuVoeUKFUBlkcft2Uza6OqQCfWQTM JvxRuyNv2n7IlyXHAPPulAM= =lBlX -----END PGP SIGNATURE----- -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From jaearick at colby.edu Mon May 7 03:09:36 2007 From: jaearick at colby.edu (Jeff A. Earickson) Date: Mon May 7 03:09:47 2007 Subject: Multi (split) image spam In-Reply-To: <694855.76046.qm@web26301.mail.ukl.yahoo.com> References: <694855.76046.qm@web26301.mail.ukl.yahoo.com> Message-ID: On Sun, 6 May 2007, Andrew MacLachlan wrote: > Subject: Re: Multi (split) image spam > > Not useless - just less effective - and no-one said it was the perfect solution - but it does effectively cut the number of spams a bot can send in half, which is always a good thing. > Most spam is stopped dead in its tracks by greylisting and is a very effective (also efficient) method of cutting down on the amount of spam that MS has to process. > >> and all it does it build up your own outgoing queues > Not sure how the logic on that one works... > >> you might as well firewall off your primary MX >> making mail fail and force resend via secondary MX's. > A bit extreme - and anyway spammers have been sending directly to secondaries for years as a lot of organisations don't have spam defences on them so the messages just sail on thru... I run smtptrapd (see http://smtptrapd.inodes.org/) on another box which is a secondary MX. It keeps the spammers busy and helps keep them away from my primary MX. If my primary is down, so what? The legit stuff will retry later. Jeff Earickson Colby College From hvdkooij at vanderkooij.org Mon May 7 06:41:03 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Mon May 7 06:41:38 2007 Subject: Clever bots - was Re: Multi (split) image spam In-Reply-To: <123569.36742.qm@web26303.mail.ukl.yahoo.com> References: <123569.36742.qm@web26303.mail.ukl.yahoo.com> Message-ID: On Sun, 6 May 2007, Andrew MacLachlan wrote: > That's right - most are 5 mins, which is about right for most MTAs first retry. > Any decent greylister will tell an early retry to go away again, but either more spammers are using MTAs or the bots are getting cleverer. I'd say the latter is more likely. > A cursory glance at a couple of spams from today gives me headers like this: > > X-Greylist: delayed 00:10:01 by SQLgrey-1.7.5 > > Received: from 89-172-120-92.adsl.net.t-com.hr (89-172-120-92.adsl.net.t-com.hr [89.172.120.92]) > > X-Greylist: delayed 00:10:02 by SQLgrey-1.7.5 > > Received: from 236.Red-81-36-176.dynamicIP.rima-tde.net (236.red-81-36-176.dynamicip.rima-tde.net [81.36.176.236]) > > Interestingly the delay was over 10 mins by a second or 2 - so this means that grey needs to extend to 11 mins... Not sure what the effect of this will be - is the bot smart enough to retry again if rejected at 10 mins? Given that disabling greylisting still results in a significant rise of traffic for MailScanner I would say it is a usefull addition to the bag of tricks at this time. At irregular intervals I play with some of them to see if disabling a restriction is having an effect. At this point I wrote a small script to report on greylisted entries daily and have added all the noisy entries to a static blacklist. The first way I added was abo.wanadoo.fr and it had an immediate impact. Wanadoo users will need to send through their ISP mailserver to get a message delivered. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) A: Yes. >Q: Are you sure? >>A: Because it reverses the logical flow of conversation. >>>Q: Why is top posting frowned upon? From res at ausics.net Mon May 7 10:10:11 2007 From: res at ausics.net (Res) Date: Mon May 7 10:10:22 2007 Subject: Multi (split) image spam In-Reply-To: <694855.76046.qm@web26301.mail.ukl.yahoo.com> References: <694855.76046.qm@web26301.mail.ukl.yahoo.com> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sun, 6 May 2007, Andrew MacLachlan wrote: >> and all it does it build up your own outgoing queues > Not sure how the logic on that one works... errr logic? WTF? if the queue cant send it right away it stays in the queue so lamelisted_mail+current_submissions=building_up_queue like I said it might be fine if you run a small office 1K emails p/day, but not when you do millions p/day, however I have tuned sendmail queue running so that new stuff goes first, I'm not going to allow new stuff to be delayed in oversized queue runners because some lamers server wont accept it on first attempt. - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGPuz2sWhAmSIQh7MRAhUsAJ0ZANXqiiOnAFGLv3e5mvUyUK3ZagCfeaJX koKex5fcZnwvDfx+GSV3wSM= =Byf/ -----END PGP SIGNATURE----- From uxbod at splatnix.net Mon May 7 12:59:47 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Mon May 7 12:57:43 2007 Subject: SA 3.2.0 Woes Message-ID: <20070507125947.05ede1ea@uxbod.splatnix.net> Hi, Not sure whether this is a issue or not, but since upgrading SA and MailScanner I never seem to get any hits via RBLs. I am using MailWatch and that just says "SpamAssassin Listed in RBL". Bayes never seems to trigger aswell now. Have others experienced anything like this ? TIA -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 845 869 2749 // SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From daniel.maher at ubisoft.com Mon May 7 13:46:29 2007 From: daniel.maher at ubisoft.com (Daniel Maher) Date: Mon May 7 13:46:33 2007 Subject: Multi (split) image spam In-Reply-To: <20070506145752.5fa3f497@uxbod.splatnix.net> Message-ID: <1E293D3FF63A3740B10AD5AAD88535D204D6D68B@UBIMAIL1.ubisoft.org> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- > Sent: May 6, 2007 9:58 AM > To: mailscanner@lists.mailscanner.info > Subject: Re: Multi (split) image spam > > I haven't seen any of those yet Steve. Could you make one available > for analysis ? > > All, FuzzyOCR is broke with SA 3.2.0 at the moment. > > Cheers, As I understand it, FuzzyOCR still works in 3.2.0, in that it detects and analyses images; what is broken is the output in the spam report. In fact, as I recall, Ren? Berber submitted a patch for it... I could be wrong, though. :P -- _ ?v? Daniel Maher /(_)\ Administrateur Syst?me Unix ^ ^ Unix System Administrator "How can a man choose between Fresh and Fly? And believe me, there IS a difference." - Crack Stuntman, 2007. From daniel.maher at ubisoft.com Mon May 7 15:18:34 2007 From: daniel.maher at ubisoft.com (Daniel Maher) Date: Mon May 7 15:18:37 2007 Subject: MailScanner and postfix 2.4 Message-ID: <1E293D3FF63A3740B10AD5AAD88535D204D6D84F@UBIMAIL1.ubisoft.org> Hello all, I would love to hear some first-hand accounts of people who are using MailScanner with Postfix 2.4. Does it work well? Are there any particular nuances which need to be addressed in specific? Does anybody have any horror stories? Thank you, all. -- _ ?v? Daniel Maher /(_)\ Administrateur Syst?me Unix ^ ^ Unix System Administrator "How can a man choose between Fresh and Fly? And believe me, there IS a difference." - Crack Stuntman, 2007. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070507/e4374a5d/attachment.html From mikael at syska.dk Mon May 7 15:28:40 2007 From: mikael at syska.dk (Mikael Syska) Date: Mon May 7 15:29:16 2007 Subject: MailScanner and postfix 2.4 In-Reply-To: <1E293D3FF63A3740B10AD5AAD88535D204D6D84F@UBIMAIL1.ubisoft.org> References: <1E293D3FF63A3740B10AD5AAD88535D204D6D84F@UBIMAIL1.ubisoft.org> Message-ID: <463F3798.4070809@syska.dk> Hey, Running with that setup soon ... Postfix 2.3.x for now ... but I will be upgrading to 2.4.x soon ... should there be anything since you ask ? or are you just worried about upgrading ? // ouT Daniel Maher wrote: > > Hello all, > > I would love to hear some first-hand accounts of people who are using > MailScanner with Postfix 2.4. Does it work well? Are there any > particular nuances which need to be addressed in specific? Does > anybody have any horror stories? > > Thank you, all. > > -- > > _ > ?v? Daniel Maher > /(_)\ Administrateur Syst?me Unix > ^ ^ Unix System Administrator > > //?How can a man choose between Fresh and Fly? And believe me, there > IS a difference.? ? Crack Stuntman, 2007.//// > From claude.gagne at multitech.qc.ca Mon May 7 15:31:32 2007 From: claude.gagne at multitech.qc.ca (=?windows-1252?Q?Claude_Gagn=E9?=) Date: Mon May 7 15:29:36 2007 Subject: MailScanner and postfix 2.4 In-Reply-To: <1E293D3FF63A3740B10AD5AAD88535D204D6D84F@UBIMAIL1.ubisoft.org> References: <1E293D3FF63A3740B10AD5AAD88535D204D6D84F@UBIMAIL1.ubisoft.org> Message-ID: <463F3844.5090101@multitech.qc.ca> Daniel Maher a ?crit : > > Hello all, > > I would love to hear some first-hand accounts of people who are using > MailScanner with Postfix 2.4. Does it work well? Are there any > particular nuances which need to be addressed in specific? Does > anybody have any horror stories? > > Thank you, all. > > -- > > _ > ?v? Daniel Maher > /(_)\ Administrateur Syst?me Unix > ^ ^ Unix System Administrator > > //?How can a man choose between Fresh and Fly? And believe me, there > IS a difference.? ? Crack Stuntman, 2007.//// > Works good for me so far. From dominian at slackadelic.com Mon May 7 15:37:19 2007 From: dominian at slackadelic.com (Matt Hayes) Date: Mon May 7 15:37:28 2007 Subject: MailScanner and postfix 2.4 In-Reply-To: <463F3844.5090101@multitech.qc.ca> References: <1E293D3FF63A3740B10AD5AAD88535D204D6D84F@UBIMAIL1.ubisoft.org> <463F3844.5090101@multitech.qc.ca> Message-ID: <463F399F.3010708@slackadelic.com> Claude Gagn? wrote: > Daniel Maher a ?crit : >> >> Hello all, >> >> I would love to hear some first-hand accounts of people who are using >> MailScanner with Postfix 2.4. Does it work well? Are there any >> particular nuances which need to be addressed in specific? Does >> anybody have any horror stories? >> >> Thank you, all. >> >> -- >> >> _ >> ?v? Daniel Maher >> /(_)\ Administrateur Syst?me Unix >> ^ ^ Unix System Administrator >> >> //?How can a man choose between Fresh and Fly? And believe me, there >> IS a difference.? ? Crack Stuntman, 2007.//// >> > Works good for me so far. Works fine for me as well. -Matt From glenn.steen at gmail.com Mon May 7 15:39:12 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Mon May 7 15:39:15 2007 Subject: MailScanner and postfix 2.4 In-Reply-To: <463F3844.5090101@multitech.qc.ca> References: <1E293D3FF63A3740B10AD5AAD88535D204D6D84F@UBIMAIL1.ubisoft.org> <463F3844.5090101@multitech.qc.ca> Message-ID: <223f97700705070739n3f1f319fo5a4c7fa27a93f933@mail.gmail.com> On 07/05/07, Claude Gagn? wrote: > Daniel Maher a ?crit : > > > > Hello all, > > > > I would love to hear some first-hand accounts of people who are using > > MailScanner with Postfix 2.4. Does it work well? Are there any > > particular nuances which need to be addressed in specific? Does > > anybody have any horror stories? > > > > Thank you, all. > > > > -- > > > > _ > > ?v? Daniel Maher > > /(_)\ Administrateur Syst?me Unix > > ^ ^ Unix System Administrator > > > > //"How can a man choose between Fresh and Fly? And believe me, there > > IS a difference." ? Crack Stuntman, 2007.//// > > > Works good for me so far. As it should... It is only if you a) use milters and b) those milters do full body edits... Then you can, and will, run into problems. If a) but not b) (that is: only header edits) then I've supplied some patches that should take care of this ... and a+b patches is in the works:-). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Mon May 7 15:43:44 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Mon May 7 15:43:47 2007 Subject: Clamav suggestions In-Reply-To: <089801c78f42$78529500$0301a8c0@SAHOMELT> References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> <463B5E8A.2080400@sendit.nodak.edu> <085b01c78f29$f30cc540$0301a8c0@SAHOMELT> <463CAF50.8030305@ecs.soton.ac.uk> <089801c78f42$78529500$0301a8c0@SAHOMELT> Message-ID: <223f97700705070743l47a131cayc53ff788c9642f37@mail.gmail.com> On 05/05/07, Rick Cooper wrote: > > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > > Of Julian Field > > Sent: Saturday, May 05, 2007 12:23 PM > > To: MailScanner discussion > > Subject: Re: Clamav suggestions > > > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: SHA1 > > > [...] > > > Yes, I welcome any contribution, so long as the patch isn't > > *too* big! :-) > > Please try to keep your patch as self-contained as possible, so you > > just, for example, rewrite the init code for the clamd parser and the > > output parser itself. Please just make it as clean and modular as you > > can. You can see from the rest of the code the type of Perl I > > write. I > > use the syntactical short-cut facilities in the language, I > > don't just > > write Java/C in Perl the way a lot of people do. And please > > don't feel > > upset if I take your code and appear to rewrite it :-) > > > > Thanks, > > Jules. > > > > I will have to try and rememeber the program flow, and look at the > clamavmodule code and how it's called because this would work pretty much > the same. It would be easy enough to make the output the same as the > clamavmodule output so the same parser could be used if the current parser > had some minor changes such as MailScanner::Log::InfoLog("ClamAVModule:: to > MailScanner::Log::InfoLog("$Name:: would it not? I have already tried to > make the code more like yours (from my unrar experience) such as "last if > time > $TimeOut;" or "LogIt("ClamD Timed Out!\n") if $TimeOut < time && > $Debug;". In any event you know I don't care if you rewrite everything.. > It's your program ;-) The size should be pretty fair, the current stand > alone proof of concept code is only 144 lines including a Logging function, > line comments, 18 lines of description comments, the various "use " > statements and debug and blank lines. I would expect the finished MS ready > code would be half that, maybe less (even with comments). There would, of > course, be additional config lines. I would expect you should have: > clamd socket (IpAddr or full path to socket file) > clamd port default 3310 > clamd lock file (to check if clamd is even running) > clamd timeout > > And would you want to scan an entire batch at once, or one message/dir at a > time? I can even send you the stand alone code I have an let you play with > it at your leasure if you wish. > > Rick Hey Rick, I'm pretty certain Jules isn't needling you about style.... Rather me and my "p record patches":-):-). Oh well, there is a reason I don't write "Programmer" on my cards anymore:-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From tmartins at gmail.com Mon May 7 16:18:17 2007 From: tmartins at gmail.com (Thiago Martins) Date: Mon May 7 16:18:20 2007 Subject: MailScanner and postfix 2.4 In-Reply-To: <223f97700705070739n3f1f319fo5a4c7fa27a93f933@mail.gmail.com> References: <1E293D3FF63A3740B10AD5AAD88535D204D6D84F@UBIMAIL1.ubisoft.org> <463F3844.5090101@multitech.qc.ca> <223f97700705070739n3f1f319fo5a4c7fa27a93f933@mail.gmail.com> Message-ID: I have MS + Postfix 2.4 + Postgrey working fine here. []?s Thiago On 5/7/07, Glenn Steen wrote: > > On 07/05/07, Claude Gagn? wrote: > > Daniel Maher a ?crit : > > > > > > Hello all, > > > > > > I would love to hear some first-hand accounts of people who are using > > > MailScanner with Postfix 2.4. Does it work well? Are there any > > > particular nuances which need to be addressed in specific? Does > > > anybody have any horror stories? > > > > > > Thank you, all. > > > > > > -- > > > > > > _ > > > ?v? Daniel Maher > > > /(_)\ Administrateur Syst?me Unix > > > ^ ^ Unix System Administrator > > > > > > //"How can a man choose between Fresh and Fly? And believe me, there > > > IS a difference." ? Crack Stuntman, 2007.//// > > > > > Works good for me so far. > > As it should... It is only if you a) use milters and b) those milters > do full body edits... Then you can, and will, run into problems. If a) > but not b) (that is: only header edits) then I've supplied some > patches that should take care of this ... and a+b patches is in the > works:-). > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070507/0687997a/attachment.html From ssilva at sgvwater.com Mon May 7 16:20:37 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 7 16:20:58 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: <463CB925.2050609@ecs.soton.ac.uk> References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> <463CAD50.3050806@ecs.soton.ac.uk> <463CB925.2050609@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 5/5/2007 10:04 AM: > I have done some basic tests with my SpamAssassin 3.2.0 package and > MailScanner 4.59 and it is working fine. > > I'll do some more tests of it and probably start using it on a > production machine tomorrow if I feel so inclined (and there again I > might well just put my feet up and watch TV). It's a public holiday this > weekend (I think!) so by definition it should rain on Monday at least. :-) > > Jules. Julian, I haven't had an opportunity to look at it yet, but are you or did you add an init script for clamd? I was going to throw one together if it didn't have one. But if it is already there, I won't bother. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From painethom at gmail.com Mon May 7 16:33:53 2007 From: painethom at gmail.com (Thom Paine) Date: Mon May 7 16:33:54 2007 Subject: New SA and Clam and MS 4.59.4-2 Message-ID: <9e1340d20705070833o682a3c08j2feadc9c3d4e2d51@mail.gmail.com> I am trying to update a server to all the latest patches, and I'm having trouble getting some stuff working. I have debug enabled in my mailscanner.conf file and when I try the clamavmodule I get libclamav warning, virus definitions are older than 7 days. I just successfully ran freshclam and I have defined my freshclam.conf and my clamd.conf to both point to /var/lib/clamav. The definitions downloaded no problem and are in that directory now. I tried testing the wrapper script for it but it is giving me an error as well. [root@mail MailScanner]# /usr/lib/MailScanner/clamav-wrapper /tmp /usr/lib/MailScanner/clamav-wrapper: line 162: /usr/bin/clamscan: No such file or directory however my clamscan is in /usr/local/bin. For some reason it's not looking there properly I guess. I haven't tested the SA stuff yet, as I seem to be held up with my clamav issues. Thanks. -- -=/>Thom From mkercher at nfsmith.com Mon May 7 16:34:32 2007 From: mkercher at nfsmith.com (Mike Kercher) Date: Mon May 7 16:38:12 2007 Subject: New SA and Clam and MS 4.59.4-2 References: <9e1340d20705070833o682a3c08j2feadc9c3d4e2d51@mail.gmail.com> Message-ID: <6DEF8ABC1767C045B91F42066D36358E3AEB@HOUPEX01.nfsmith.info> Thom Paine <> wrote on Monday, May 07, 2007 10:34 AM: : I am trying to update a server to all the latest patches, and I'm : having trouble getting some stuff working. : : I have debug enabled in my mailscanner.conf file and when I try the : clamavmodule I get libclamav warning, virus definitions are older : than 7 days. : I just successfully ran freshclam and I have defined my : freshclam.conf and my clamd.conf to both point to /var/lib/clamav. : The definitions downloaded no problem and are in that directory now. : : I tried testing the wrapper script for it but it is giving me an : error as well. : : [root@mail MailScanner]# /usr/lib/MailScanner/clamav-wrapper /tmp : /usr/lib/MailScanner/clamav-wrapper: line 162: /usr/bin/clamscan: No : such file or directory : : however my clamscan is in /usr/local/bin. For some reason it's not : looking there properly I guess. : : I haven't tested the SA stuff yet, as I seem to be held up with my : clamav issues. : : Thanks. : -- : -=/>Thom Do you have /usr/local/lib in /etc/ld.so.conf ? If not, add it and run ldconfig and try again. -Mike From painethom at gmail.com Mon May 7 16:43:33 2007 From: painethom at gmail.com (Thom Paine) Date: Mon May 7 16:43:36 2007 Subject: New SA and Clam and MS 4.59.4-2 In-Reply-To: <6DEF8ABC1767C045B91F42066D36358E3AEB@HOUPEX01.nfsmith.info> References: <9e1340d20705070833o682a3c08j2feadc9c3d4e2d51@mail.gmail.com> <6DEF8ABC1767C045B91F42066D36358E3AEB@HOUPEX01.nfsmith.info> Message-ID: <9e1340d20705070843h5e1a4b24l4e09b9dd91aca29c@mail.gmail.com> > Do you have /usr/local/lib in /etc/ld.so.conf ? > Yes, it is there. I forgot to say that I have RHEL 3 U8. Thanks. -- -=/>Thom From ssilva at sgvwater.com Mon May 7 16:43:58 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 7 16:44:12 2007 Subject: Multi (split) image spam In-Reply-To: References: <727373.44781.qm@web26307.mail.ukl.yahoo.com> Message-ID: Res spake the following on 5/6/2007 3:25 PM: > On Sun, 6 May 2007, Andrew MacLachlan wrote: > >> Some of the spammers are doing resends though to get around greylisting > > This is one of the reasons I consider greylisting useless :) > I've seen this from this part of the world (oceania/asia area) for about > as long as greylisting came about. > > It's the same ol same ol, we do something to stop em, they circumvent > it, we counter it and they will try counter it again, and so on and as > grey listing is the most simplest thing to get around, i've always > regarded it as a joke, and all it does it build up your own outgoing > queues, this might be fine for those who do 1K messages a day but when > you do millions, > thats just not on, anyhow you might as well firewall off your primary MX > making mail fail and force resend via secondary MX's. > > That won't even help, as most of my spam goes straight for the secondaries anyway. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From edwardbruce at sbcglobal.net Mon May 7 16:47:04 2007 From: edwardbruce at sbcglobal.net (Ed Bruce) Date: Mon May 7 16:47:10 2007 Subject: Multi (split) image spam In-Reply-To: References: <694855.76046.qm@web26301.mail.ukl.yahoo.com> Message-ID: <463F49F8.6080304@sbcglobal.net> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Res wrote: > On Sun, 6 May 2007, Andrew MacLachlan wrote: > >>> and all it does it build up your own outgoing queues >> Not sure how the logic on that one works... > > errr logic? WTF? if the queue cant send it right away it stays in the > queue so lamelisted_mail+current_submissions=building_up_queue > like I said it might be fine if you run a small office 1K emails p/day, > but not when you do millions p/day, however I have tuned sendmail queue > running so that new stuff goes first, I'm not going to allow new stuff > to be delayed in oversized queue runners because some lamers server wont > accept it on first attempt. > > Res I didn't understand what you meant at first. Well I may still not understand, but I'm guessing you are saying that if my MTA is running some sort of gray listing and your MTA attempts a connection it will cause your queues to back up??? I took your original message to mean that if I run gray listing then my queues would back up. That didn't seem to make much sense to me as I wouldn't gray list myself. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (Cygwin) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFGP0n4pdNaP9x3McgRArgZAKCRGB0GISE0JH2n0PF5lKidri3+OQCfXw9y KsDBaz/j6cFRsvK9ABgXEYk= =V5KN -----END PGP SIGNATURE----- From rpoe at plattesheriff.org Mon May 7 16:53:07 2007 From: rpoe at plattesheriff.org (Rob Poe) Date: Mon May 7 16:53:44 2007 Subject: Interesting need Message-ID: <463F0518.65ED.00A2.0@plattesheriff.org> This might not be so much a MailScanner function ... but I have a Linux / Sendmail / MailScanner box set up in front of a corporate mail system. It's doing the domain as relay-domains and mailertable. One of their users wants all of his EXTERNAL incoming mail to go to both HIM and his assistant. I tried with the aliases and virtusertable ... didn't work (just forwarded on to the corp mail system as if nothing was in there). Is this something I can do with a MailScanner rule? From mkettler at evi-inc.com Mon May 7 17:13:28 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Mon May 7 17:13:47 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: References: <463900B1.8080301@ecs.soton.ac.uk> <463B7C0C.9000004@evi-inc.com> <463BB60B.3060608@evi-inc.com> <463E12CC.7080806@evi-inc.com> Message-ID: <463F5028.9060201@evi-inc.com> Res wrote: > > On Sun, 6 May 2007, Matt Kettler wrote: > >> Yes, it's a genuine bug. > >> I reproduced it at home and produced a patch, which I tried to send >> you a link >> to, but unfortunately you don't seem to accept mail from my home ISP >> (verizon). > > Thanks Matt, I'll have a look later this morning. BTW I wouldn't have got > the mail anyway if you had got in as res@ is a list/newsgroup only > account unless your mail is sorted into a list folder its /dev/null'd > primarily because I've used this a/c on usenet for along time so would > have to be in every spam list, sendmail/MS get rid of 99% of the junk, > my pine filtering rules eliminate the remaining :) > Fair enough.. At home I don't use MailScanner, its a little bit of overkill for a single-user vpopmail setup, so I'm not subscribed to this list there, hence the off-list message. For reference, the bug is this one: http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5436 From MailScanner at ecs.soton.ac.uk Mon May 7 17:37:17 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 7 17:37:53 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> <463CAD50.3050806@ecs.soton.ac.uk> <463CB925.2050609@ecs.soton.ac.uk> Message-ID: <463F55BD.7080209@ecs.soton.ac.uk> Skipped content of type multipart/mixed-------------- next part -------------- A non-text attachment was scrubbed... Name: PGP.sig Type: application/pgp-signature Size: 195 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070507/b1c5ec58/PGP.bin From ssilva at sgvwater.com Mon May 7 17:42:44 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 7 17:43:01 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: <463F55BD.7080209@ecs.soton.ac.uk> References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> <463CAD50.3050806@ecs.soton.ac.uk> <463CB925.2050609@ecs.soton.ac.uk> <463F55BD.7080209@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 5/7/2007 9:37 AM: > > > Scott Silva wrote: >> Julian Field spake the following on 5/5/2007 10:04 AM: >> >>> I have done some basic tests with my SpamAssassin 3.2.0 package and >>> MailScanner 4.59 and it is working fine. >>> >>> I'll do some more tests of it and probably start using it on a >>> production machine tomorrow if I feel so inclined (and there again I >>> might well just put my feet up and watch TV). It's a public holiday >>> this weekend (I think!) so by definition it should rain on Monday at >>> least. :-) >>> >>> Jules. >>> >> Julian, >> I haven't had an opportunity to look at it yet, but are you or did you >> add an >> init script for clamd? I was going to throw one together if it didn't >> have >> one. But if it is already there, I won't bother. >> > No, I haven't done an init script for clamd. It should be easy enough to > knock one up based on the MailScanner ones. The SuSE and RedHat-based > ones need to be different, so if you fancy writing both based on the > MailScanner ones that would be great. > > Attached are the RedHat and SuSE init.d scripts for MailScanner itself > so you can see the differences needed. > > Obviously the clamd ones will be a lot shorter :-) > > Jules > I will get a Redhat script together asap. I will install SUSE in a VM to have something to test on for it. It might be a few days for that one. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From MailScanner at ecs.soton.ac.uk Mon May 7 17:40:33 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 7 17:43:12 2007 Subject: New SA and Clam and MS 4.59.4-2 In-Reply-To: <9e1340d20705070833o682a3c08j2feadc9c3d4e2d51@mail.gmail.com> References: <9e1340d20705070833o682a3c08j2feadc9c3d4e2d51@mail.gmail.com> Message-ID: <463F5681.3030301@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Thom Paine wrote: > I am trying to update a server to all the latest patches, and I'm > having trouble getting some stuff working. > > I have debug enabled in my mailscanner.conf file and when I try the > clamavmodule I get libclamav warning, virus definitions are older than > 7 days. > I just successfully ran freshclam and I have defined my freshclam.conf > and my clamd.conf to both point to /var/lib/clamav. The definitions > downloaded no problem and are in that directory now. > > I tried testing the wrapper script for it but it is giving me an error > as well. > > [root@mail MailScanner]# /usr/lib/MailScanner/clamav-wrapper /tmp > /usr/lib/MailScanner/clamav-wrapper: line 162: /usr/bin/clamscan: No > such file or directory The first command-line argument to all the -wrapper and -autoupdate scripts is the installation path for that scanner. MailScanner itself reads this from virus.scanners.conf. So if you want to run the wrapper by hand, then you need /usr/lib/MailScanner/clamav-wrapper /usr/local /tmp in order to scan /tmp, with ClamAV installed under /usr/local (which is where my ClamAV+SA package puts it, as that is the default installation location built into the ClamAV source code). Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGP1buEfZZRxQVtlQRArAlAKD8mEIJckSh7dGN09kXjbE+JsRyEACePad5 2xizdcIZAkPTcybj7L3gvCo= =YiUI -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From Richard.Frovarp at sendit.nodak.edu Mon May 7 17:53:15 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Mon May 7 17:53:19 2007 Subject: Multi (split) image spam In-Reply-To: References: <727373.44781.qm@web26307.mail.ukl.yahoo.com> Message-ID: <463F597B.6060608@sendit.nodak.edu> Scott Silva wrote: > Res spake the following on 5/6/2007 3:25 PM: > >> On Sun, 6 May 2007, Andrew MacLachlan wrote: >> >> >>> Some of the spammers are doing resends though to get around greylisting >>> >> This is one of the reasons I consider greylisting useless :) >> I've seen this from this part of the world (oceania/asia area) for about >> as long as greylisting came about. >> >> It's the same ol same ol, we do something to stop em, they circumvent >> it, we counter it and they will try counter it again, and so on and as >> grey listing is the most simplest thing to get around, i've always >> regarded it as a joke, and all it does it build up your own outgoing >> queues, this might be fine for those who do 1K messages a day but when >> you do millions, >> thats just not on, anyhow you might as well firewall off your primary MX >> making mail fail and force resend via secondary MX's. >> >> >> > That won't even help, as most of my spam goes straight for the secondaries anyway. > > Our primary is firewalled off. I have no clue as to how much spam it blocks. However, we have allowed the three large internal networks to go through the firewall. We did this because we were getting too much spam and our incoming queues were building up. People kind of expect that mail from the person sitting next to them to come through pretty quickly, and we were having trouble making that happen. Since our primary only processes mail from the networks my organization is associated with (the state, k12, and higher ed networks in the state), it can fire mail through very quickly. It might not be effective for stopping spam, but it certainly can help with processing delays of local mail. A subsequent upgrade to milter-greylist 3.0 resulted in massive speed improvements on the other machines to pretty much remove the queue build up. From Richard.Frovarp at sendit.nodak.edu Mon May 7 17:56:03 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Mon May 7 17:56:05 2007 Subject: New SA and Clam and MS 4.59.4-2 In-Reply-To: <9e1340d20705070833o682a3c08j2feadc9c3d4e2d51@mail.gmail.com> References: <9e1340d20705070833o682a3c08j2feadc9c3d4e2d51@mail.gmail.com> Message-ID: <463F5A23.7010204@sendit.nodak.edu> Thom Paine wrote: > I am trying to update a server to all the latest patches, and I'm > having trouble getting some stuff working. > > I have debug enabled in my mailscanner.conf file and when I try the > clamavmodule I get libclamav warning, virus definitions are older than > 7 days. > I just successfully ran freshclam and I have defined my freshclam.conf > and my clamd.conf to both point to /var/lib/clamav. The definitions > downloaded no problem and are in that directory now. > > I tried testing the wrapper script for it but it is giving me an error > as well. > > [root@mail MailScanner]# /usr/lib/MailScanner/clamav-wrapper /tmp > /usr/lib/MailScanner/clamav-wrapper: line 162: /usr/bin/clamscan: No > such file or directory > > however my clamscan is in /usr/local/bin. For some reason it's not > looking there properly I guess. > > I haven't tested the SA stuff yet, as I seem to be held up with my > clamav issues. > > Thanks. In MailScanner.conf: Monitors for ClamAV Updates = /usr/local/share/clamav/*.inc/* /usr/local/share/clamav/*.cvd From MailScanner at ecs.soton.ac.uk Mon May 7 18:04:16 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 7 18:07:52 2007 Subject: Interesting need In-Reply-To: <463F0518.65ED.00A2.0@plattesheriff.org> References: <463F0518.65ED.00A2.0@plattesheriff.org> Message-ID: <463F5C10.7080307@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Dead easy. Put a ruleset on "Archive Mail =". For example, say "theboss@yourdomain.com" wants all his incoming external mail to go to himself and "assistant@yourdomain.com". In MailScanner.conf, set Archive Mail = %rules-dir%/archive.mail.rules Put the ruleset in /etc/MailScanner/rules/archive.mail.rules. In this file, put: FromOrTo: default To: theboss@yourdomain.com assistant@yourdomain.com Then just force a MailScanner configuration reload with service MailScanner reload Rob Poe wrote: > This might not be so much a MailScanner function ... but > > I have a Linux / Sendmail / MailScanner box set up in front of a corporate mail system. It's doing the domain as relay-domains and mailertable. One of their users wants all of his EXTERNAL incoming mail to go to both HIM and his assistant. > > I tried with the aliases and virtusertable ... didn't work (just forwarded on to the corp mail system as if nothing was in there). > > Is this something I can do with a MailScanner rule? > > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGP1zKEfZZRxQVtlQRAjv8AJ9aKslrMJC6Od0vG1XaNRmQw1JboACbBZ+Z qWfLcoajUFGC5li684N5+2Q= =cwWu -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Mon May 7 19:17:00 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 7 19:17:39 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: <463F55BD.7080209@ecs.soton.ac.uk> References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> <463CAD50.3050806@ecs.soton.ac.uk> <463CB925.2050609@ecs.soton.ac.uk> <463F55BD.7080209@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 5/7/2007 9:37 AM: > > > Scott Silva wrote: >> Julian Field spake the following on 5/5/2007 10:04 AM: >> >>> I have done some basic tests with my SpamAssassin 3.2.0 package and >>> MailScanner 4.59 and it is working fine. >>> >>> I'll do some more tests of it and probably start using it on a >>> production machine tomorrow if I feel so inclined (and there again I >>> might well just put my feet up and watch TV). It's a public holiday >>> this weekend (I think!) so by definition it should rain on Monday at >>> least. :-) >>> >>> Jules. >>> >> Julian, >> I haven't had an opportunity to look at it yet, but are you or did you >> add an >> init script for clamd? I was going to throw one together if it didn't >> have >> one. But if it is already there, I won't bother. >> > No, I haven't done an init script for clamd. It should be easy enough to > knock one up based on the MailScanner ones. The SuSE and RedHat-based > ones need to be different, so if you fancy writing both based on the > MailScanner ones that would be great. > > Attached are the RedHat and SuSE init.d scripts for MailScanner itself > so you can see the differences needed. > > Obviously the clamd ones will be a lot shorter :-) > > Jules > In looking at this, there will need to be more than just an init script. There will need to be a clamd.conf file, and probably a logrotate script. I don't know how much extra stuff you want to add, but I'm game if you dont mind the extra fluff. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From rcooper at dwford.com Mon May 7 19:24:08 2007 From: rcooper at dwford.com (Rick Cooper) Date: Mon May 7 19:24:12 2007 Subject: Clamav suggestions In-Reply-To: <223f97700705070743l47a131cayc53ff788c9642f37@mail.gmail.com> References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it><463B5E8A.2080400@sendit.nodak.edu><085b01c78f29$f30cc540$0301a8c0@SAHOMELT><463CAF50.8030305@ecs.soton.ac.uk><089801c78f42$78529500$0301a8c0@SAHOMELT> <223f97700705070743l47a131cayc53ff788c9642f37@mail.gmail.com> Message-ID: <0ba101c790d4$e72226b0$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Glenn Steen > Sent: Monday, May 07, 2007 10:44 AM > To: MailScanner discussion > Subject: Re: Clamav suggestions > [..] > > Hey Rick, I'm pretty certain Jules isn't needling you about style.... > Rather me and my "p record patches":-):-). Oh well, there is a reason > I don't write "Programmer" on my cards anymore:-) > > Cheers > -- > -- Glenn > email: glenn < dot > steen < at > gmail < dot > com > work: glenn < dot > steen < at > ap1 < dot > se > -- Yeah, actually he is (good naturedly of course). Perl isn't my first choice for languages and most don't have the short circuiting that perl does so I have a tendency to write if (! $blather){ dothis; } Instead of unless $blather do this; A lot of the rewriting I did on the unrar stuff was done so the code flowed better with Julian's style, and since I could fall off the planet tomorrow I think it best to try and code things for his ease of reading not mine. I try and get close and he can change anything he likes from there, it's his program after all. I think I will be pretty close this time around because I am cheating. I decided I would take the core out of the clamavmodule core and wrap the socket programming around that so it's about the same except sending the "$dirname/$childname/$filename" to the clamavmodule instance it's sent to the clam socket, 45/50 lines of code are Julian's own so that should be pretty close to his style ;-) Besides that will allow reusing the clamavmodule parser code to keep the bloat down, if Julian approves, that is. Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From Denis.Beauchemin at USherbrooke.ca Mon May 7 19:54:08 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Mon May 7 19:54:28 2007 Subject: Updates Script to fetch Steve Basford's Phihing Sigs for ClamAV In-Reply-To: <86144ED6CE5B004DA23E1EAC0B569B580CC0B081@isabella.herefordshire.gov.uk> References: <86144ED6CE5B004DA23E1EAC0B569B580CC0B081@isabella.herefordshire.gov.uk> Message-ID: <463F75D0.40007@USherbrooke.ca> Randal, Phil a ?crit : > Folks, > > Steve Basford has a ClamAV phishing database over at > > http://www.sanesecurity.com/clamav/ > > and has recently updated his site to provide a gzipped version of the > file. > > The attached script is a modified version of the one I posted to this > list back in March. This version uses curl to fetch newer versions of > the gzipped database. > > Phil, Your script stopped working during lunchtime and when I got back there was a huge backlog on my servers. I found the following error message in my logs: ClamAV Module ERROR:: Could not load databases from /usr/local/share/clamav Turns out there was an empty definition file in Clam's directory: # cd /usr/local/share/clamav/ # ls -l total 16 drwxr-xr-x 2 clamav clamav 4096 May 7 14:09 daily.inc/ drwxr-xr-x 2 clamav clamav 4096 May 7 13:49 main.inc/ -rw------- 1 clamav clamav 208 May 7 14:09 mirrors.dat -rw-r--r-- 1 clamav clamav 0 May 7 12:25 phish.ndb -rw-r--r-- 1 root root 316 May 7 12:25 phish.ndb.gz I changed your script to get the definitions from a mirror (the recommended way nowadays). Take a look at http://sanesecurity.co.uk/clamav/downloads.htm I decided to use : phish_file=http://mirrors.dotsrc.org/clamav-sanesigs/$phish_gz There are other download scripts on this page: http://sanesecurity.co.uk/clamav/usage.htm Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3595 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070507/eb496a07/smime-0001.bin From alex at nkpanama.com Mon May 7 20:01:23 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Mon May 7 20:02:20 2007 Subject: Interesting need In-Reply-To: <463F5C10.7080307@ecs.soton.ac.uk> References: <463F0518.65ED.00A2.0@plattesheriff.org> <463F5C10.7080307@ecs.soton.ac.uk> Message-ID: <463F7783.7070608@nkpanama.com> Archive mail "forwards" email? I thought it only "archived" it... I would have used an "actions =" statement with "forward blabla@blablah.com" where blablah@blablah.com is an alias for both addresses. Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Dead easy. Put a ruleset on "Archive Mail =". > > For example, say "theboss@yourdomain.com" wants all his incoming > external mail to go to himself and "assistant@yourdomain.com". > > In MailScanner.conf, set > > Archive Mail = %rules-dir%/archive.mail.rules > > Put the ruleset in /etc/MailScanner/rules/archive.mail.rules. In this > file, put: > > FromOrTo: default > To: theboss@yourdomain.com assistant@yourdomain.com > > Then just force a MailScanner configuration reload with > > service MailScanner reload > > > Rob Poe wrote: > >> This might not be so much a MailScanner function ... but >> >> I have a Linux / Sendmail / MailScanner box set up in front of a corporate mail system. It's doing the domain as relay-domains and mailertable. One of their users wants all of his EXTERNAL incoming mail to go to both HIM and his assistant. >> >> I tried with the aliases and virtusertable ... didn't work (just forwarded on to the corp mail system as if nothing was in there). >> >> Is this something I can do with a MailScanner rule? >> >> >> >> >> > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: ISO-8859-1 > > wj8DBQFGP1zKEfZZRxQVtlQRAjv8AJ9aKslrMJC6Od0vG1XaNRmQw1JboACbBZ+Z > qWfLcoajUFGC5li684N5+2Q= > =cwWu > -----END PGP SIGNATURE----- > > From jimc at laridian.com Mon May 7 20:25:22 2007 From: jimc at laridian.com (Jim Coates) Date: Mon May 7 20:28:12 2007 Subject: MailScanner failing to deliver In-Reply-To: Message-ID: <00b901c790dd$76066050$6501a8c0@zorak> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Hugo van der Kooij > Sent: Sunday, May 06, 2007 3:05 AM > To: MailScanner discussion > Subject: Re: MailScanner failing to deliver > > > On Sat, 5 May 2007, Jim Coates wrote: > > > My host had to upgrade some things on our server and in the process > > upgraded MailScanner to the latest available from the ports tree > > (FreeBSD). The version is 4.50.15. > > > > Since the upgrade, its been having issues... it seems to > receive email > > (I can tail the maillog and see stuff coming in), but it > only delivers > > inbound and outbound for a short period of time. I then have to > > restart MailScanner, and it will once again deliver for > just a short > > period of time. > > > > When it restarts (and seemingly before it fails too) there > are a group > > of messages that get processed over and over. > > > > Another oddity... when tailing the maillog, I see MailScanner start > > multiple times... IE - it puts up the version info and the > number of > > messages in queue etc... then a few seconds later I see the > same thing > > twice more. > > > > Any ideas? I wasn't having these issues at all with the > older version > > of MailScanner that I was running. > > > > NEW INFORMATION: when I do a "mailscanner --lint" it tells me the > > following: > > > > mail2# mailscanner --lint > > Read 701 hostnames from the phishing whitelist > > Config: calling custom init function MailWatchLogging > > Cannot write pid file , No such file or directory at > > /usr/local/sbin/mailscanner line 1238 > > I suggest you check this out and fix what is required to be fixed. > > > Checking for SpamAssassin errors (if you use it)... > > Using SpamAssassin results cache > > Connected to SpamAssassin cache database > > SpamAssassin reported no errors. > > MailScanner.conf says "Virus Scanners = clamav" > > Found these virus scanners installed: clamavmodule > > mail2# > > > > I also had MailWatch installed, but the host recently > upgraded MySQL > > and it has not worked since then. Not sure what the cause is or if > > its adding to this trouble. I do get a considerable amount of : > > > > May 5 22:56:57 mail2 MailScanner[98183]: Started SQL Logging child > > May 5 22:56:57 mail2 MailScanner[98106]: Started SQL Logging child > > May 5 22:56:58 mail2 MailScanner[58029]: Started SQL Logging child > > May 5 22:57:00 mail2 MailScanner[96343]: Started SQL Logging child > > May 5 22:57:08 mail2 MailScanner[98200]: Started SQL Logging child > > > > Basically I am having to restart it about every 30 minutes > right now, > > so I'd love any help you can give me. > > If MailWatch is not working there is nothing to be lost from > removing the > MailWatch line(s) from your config now. See if it is degrading your > MailScanner functionality. > > Did you go over the changelog to see if things changed from your old > version to your current one? > > Hugo. Turns out it was MailWatch that was hanging up MailScanner. Haven't figured out why, but removing the MailWatchLogging line fixed it for now. Jim From MailScanner at ecs.soton.ac.uk Mon May 7 20:39:33 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 7 20:42:56 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> <463CAD50.3050806@ecs.soton.ac.uk> <463CB925.2050609@ecs.soton.ac.uk> <463F55BD.7080209@ecs.soton.ac.uk> Message-ID: <463F8075.60900@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Scott Silva wrote: > Julian Field spake the following on 5/7/2007 9:37 AM: > >> Scott Silva wrote: >> >>> Julian Field spake the following on 5/5/2007 10:04 AM: >>> >>> >>>> I have done some basic tests with my SpamAssassin 3.2.0 package and >>>> MailScanner 4.59 and it is working fine. >>>> >>>> I'll do some more tests of it and probably start using it on a >>>> production machine tomorrow if I feel so inclined (and there again I >>>> might well just put my feet up and watch TV). It's a public holiday >>>> this weekend (I think!) so by definition it should rain on Monday at >>>> least. :-) >>>> >>>> Jules. >>>> >>>> >>> Julian, >>> I haven't had an opportunity to look at it yet, but are you or did you >>> add an >>> init script for clamd? I was going to throw one together if it didn't >>> have >>> one. But if it is already there, I won't bother. >>> >>> >> No, I haven't done an init script for clamd. It should be easy enough to >> knock one up based on the MailScanner ones. The SuSE and RedHat-based >> ones need to be different, so if you fancy writing both based on the >> MailScanner ones that would be great. >> >> Attached are the RedHat and SuSE init.d scripts for MailScanner itself >> so you can see the differences needed. >> >> Obviously the clamd ones will be a lot shorter :-) >> >> Jules >> >> > In looking at this, there will need to be more than just an init script. There > will need to be a clamd.conf file, and probably a logrotate script. I don't > know how much extra stuff you want to add, but I'm game if you dont mind the > extra fluff. > Is it really true that no-one else has done a decent RPM of clamd yet? I would be surprised if Dag Wieers hasn't done one already, for starters. If there is one, why are we duplicating the effort? Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGP4EeEfZZRxQVtlQRAnIPAKCQnsIUEthWQbi2R6bbRiO7Q8DCnQCg6zXv y5RNQN2fTRygk4Xny1Opi64= =gz9L -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Mon May 7 20:46:54 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 7 20:47:47 2007 Subject: Interesting need In-Reply-To: <463F7783.7070608@nkpanama.com> References: <463F0518.65ED.00A2.0@plattesheriff.org> <463F5C10.7080307@ecs.soton.ac.uk> <463F7783.7070608@nkpanama.com> Message-ID: <463F822E.2010108@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Alex Neuman van der Hans wrote: > Archive mail "forwards" email? I thought it only "archived" it... RTFM my friend :-) Best regards, Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGP4I8EfZZRxQVtlQRAukRAJ4/kR547/Yym2whwfTU2xPp4w/AMgCfcwcM LvwmIoikao6OZY+E6MvOp94= =+Jsy -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Mon May 7 20:44:48 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 7 20:48:04 2007 Subject: Clamav suggestions In-Reply-To: <0ba101c790d4$e72226b0$0301a8c0@SAHOMELT> References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it><463B5E8A.2080400@sendit.nodak.edu><085b01c78f29$f30cc540$0301a8c0@SAHOMELT><463CAF50.8030305@ecs.soton.ac.uk><089801c78f42$78529500$0301a8c0@SAHOMELT> <223f97700705070743l47a131cayc53ff788c9642f37@mail.gmail.com> <0ba101c790d4$e72226b0$0301a8c0@SAHOMELT> Message-ID: <463F81B0.9010002@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Rick Cooper wrote: > > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf >> Of Glenn Steen >> Sent: Monday, May 07, 2007 10:44 AM >> To: MailScanner discussion >> Subject: Re: Clamav suggestions >> >> > [..] > >> Hey Rick, I'm pretty certain Jules isn't needling you about style.... >> Rather me and my "p record patches":-):-). Oh well, there is a reason >> I don't write "Programmer" on my cards anymore:-) >> >> Cheers >> -- >> -- Glenn >> email: glenn < dot > steen < at > gmail < dot > com >> work: glenn < dot > steen < at > ap1 < dot > se >> -- >> > > Yeah, actually he is (good naturedly of course). Perl isn't my first choice > for languages and most don't have the short circuiting that perl does so I > have a tendency to write > > if (! $blather){ > dothis; > } > > Instead of > unless $blather do this; > Personally I would "dothis unless $blather;". > A lot of the rewriting I did on the unrar stuff was done so the code flowed > better with Julian's style, and since I could fall off the planet tomorrow I > think it best to try and code things for his ease of reading not mine. Personal history has shown that I am considerably more likely to fall off the planet tomorrow than you are. My friends and I have this theory that I'm actually a cat, and therefore have 9 lives. I've used up 6 so far... :-) > I try > and get close and he can change anything he likes from there, it's his > program after all. > > I think I will be pretty close this time around because I am cheating. I > decided I would take the core out of the clamavmodule core and wrap the > socket programming around that so it's about the same except sending the > "$dirname/$childname/$filename" to the clamavmodule instance it's sent to > the clam socket, 45/50 lines of code are Julian's own so that should be > pretty close to his style ;-) Besides that will allow reusing the > clamavmodule parser code to keep the bloat down, if Julian approves, that > is. > Reusing the clamavmodule parser code sounds like a very good idea. Best regards, Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGP4I7EfZZRxQVtlQRAm4vAKDapzek6R32CBMQEzGrD3KepZjgMACeOdsB Vy0f9Ga6unwwkRaYHmTfxtk= =tOQo -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From doc at maddoc.net Mon May 7 20:50:03 2007 From: doc at maddoc.net (Doc Schneider) Date: Mon May 7 20:50:14 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: <463F8075.60900@ecs.soton.ac.uk> References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> <463CAD50.3050806@ecs.soton.ac.uk> <463CB925.2050609@ecs.soton.ac.uk> <463F55BD.7080209@ecs.soton.ac.uk> <463F8075.60900@ecs.soton.ac.uk> Message-ID: <463F82EB.9080404@maddoc.net> Julian Field wrote: > > > Scott Silva wrote: >> Julian Field spake the following on 5/7/2007 9:37 AM: > >>> Scott Silva wrote: >>> >>>> Julian Field spake the following on 5/5/2007 10:04 AM: >>>> >>>> >>>>> I have done some basic tests with my SpamAssassin 3.2.0 package and >>>>> MailScanner 4.59 and it is working fine. >>>>> >>>>> I'll do some more tests of it and probably start using it on a >>>>> production machine tomorrow if I feel so inclined (and there again I >>>>> might well just put my feet up and watch TV). It's a public holiday >>>>> this weekend (I think!) so by definition it should rain on Monday at >>>>> least. :-) >>>>> >>>>> Jules. >>>>> >>>>> >>>> Julian, >>>> I haven't had an opportunity to look at it yet, but are you or did you >>>> add an >>>> init script for clamd? I was going to throw one together if it didn't >>>> have >>>> one. But if it is already there, I won't bother. >>>> >>>> >>> No, I haven't done an init script for clamd. It should be easy enough to >>> knock one up based on the MailScanner ones. The SuSE and RedHat-based >>> ones need to be different, so if you fancy writing both based on the >>> MailScanner ones that would be great. >>> >>> Attached are the RedHat and SuSE init.d scripts for MailScanner itself >>> so you can see the differences needed. >>> >>> Obviously the clamd ones will be a lot shorter :-) >>> >>> Jules >>> >>> >> In looking at this, there will need to be more than just an init script. There >> will need to be a clamd.conf file, and probably a logrotate script. I don't >> know how much extra stuff you want to add, but I'm game if you dont mind the >> extra fluff. > > Is it really true that no-one else has done a decent RPM of clamd yet? I > would be surprised if Dag Wieers hasn't done one already, for starters. > If there is one, why are we duplicating the effort? > > Jules > Jules, Dag Wieers has a current rpm for clamav-0.90.2 was there less than 24 hours after it was released. -- -Doc Lincoln, NE. http://www.genealogyforyou.com/ http://www.cairnproductions.com/ From ssilva at sgvwater.com Mon May 7 21:02:17 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 7 21:07:42 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: <463F8075.60900@ecs.soton.ac.uk> References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> <463CAD50.3050806@ecs.soton.ac.uk> <463CB925.2050609@ecs.soton.ac.uk> <463F55BD.7080209@ecs.soton.ac.uk> <463F8075.60900@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 5/7/2007 12:39 PM: > > > Scott Silva wrote: >> Julian Field spake the following on 5/7/2007 9:37 AM: > >>> Scott Silva wrote: >>> >>>> Julian Field spake the following on 5/5/2007 10:04 AM: >>>> >>>> >>>>> I have done some basic tests with my SpamAssassin 3.2.0 package and >>>>> MailScanner 4.59 and it is working fine. >>>>> >>>>> I'll do some more tests of it and probably start using it on a >>>>> production machine tomorrow if I feel so inclined (and there again I >>>>> might well just put my feet up and watch TV). It's a public holiday >>>>> this weekend (I think!) so by definition it should rain on Monday at >>>>> least. :-) >>>>> >>>>> Jules. >>>>> >>>>> >>>> Julian, >>>> I haven't had an opportunity to look at it yet, but are you or did you >>>> add an >>>> init script for clamd? I was going to throw one together if it didn't >>>> have >>>> one. But if it is already there, I won't bother. >>>> >>>> >>> No, I haven't done an init script for clamd. It should be easy enough to >>> knock one up based on the MailScanner ones. The SuSE and RedHat-based >>> ones need to be different, so if you fancy writing both based on the >>> MailScanner ones that would be great. >>> >>> Attached are the RedHat and SuSE init.d scripts for MailScanner itself >>> so you can see the differences needed. >>> >>> Obviously the clamd ones will be a lot shorter :-) >>> >>> Jules >>> >>> >> In looking at this, there will need to be more than just an init script. There >> will need to be a clamd.conf file, and probably a logrotate script. I don't >> know how much extra stuff you want to add, but I'm game if you dont mind the >> extra fluff. > > Is it really true that no-one else has done a decent RPM of clamd yet? I > would be surprised if Dag Wieers hasn't done one already, for starters. > If there is one, why are we duplicating the effort? > > Jules > I was thinking the same thing in the last hour or so. I am leaning to Dag's or Axel's rpm's. I just need to find all the old stuff and delete it so I don't get any duplication or problems later. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Mon May 7 22:07:40 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 7 22:08:09 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: <463F8075.60900@ecs.soton.ac.uk> References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> <463CAD50.3050806@ecs.soton.ac.uk> <463CB925.2050609@ecs.soton.ac.uk> <463F55BD.7080209@ecs.soton.ac.uk> <463F8075.60900@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 5/7/2007 12:39 PM: > > > Scott Silva wrote: >> Julian Field spake the following on 5/7/2007 9:37 AM: > >>> Scott Silva wrote: >>> >>>> Julian Field spake the following on 5/5/2007 10:04 AM: >>>> >>>> >>>>> I have done some basic tests with my SpamAssassin 3.2.0 package and >>>>> MailScanner 4.59 and it is working fine. >>>>> >>>>> I'll do some more tests of it and probably start using it on a >>>>> production machine tomorrow if I feel so inclined (and there again I >>>>> might well just put my feet up and watch TV). It's a public holiday >>>>> this weekend (I think!) so by definition it should rain on Monday at >>>>> least. :-) >>>>> >>>>> Jules. >>>>> >>>>> >>>> Julian, >>>> I haven't had an opportunity to look at it yet, but are you or did you >>>> add an >>>> init script for clamd? I was going to throw one together if it didn't >>>> have >>>> one. But if it is already there, I won't bother. >>>> >>>> >>> No, I haven't done an init script for clamd. It should be easy enough to >>> knock one up based on the MailScanner ones. The SuSE and RedHat-based >>> ones need to be different, so if you fancy writing both based on the >>> MailScanner ones that would be great. >>> >>> Attached are the RedHat and SuSE init.d scripts for MailScanner itself >>> so you can see the differences needed. >>> >>> Obviously the clamd ones will be a lot shorter :-) >>> >>> Jules >>> >>> >> In looking at this, there will need to be more than just an init script. There >> will need to be a clamd.conf file, and probably a logrotate script. I don't >> know how much extra stuff you want to add, but I'm game if you dont mind the >> extra fluff. > > Is it really true that no-one else has done a decent RPM of clamd yet? I > would be surprised if Dag Wieers hasn't done one already, for starters. > If there is one, why are we duplicating the effort? > > Jules > I would be happy if I could just get the clamavmodule running on the system that seems hosed. I still haven't seen any kind of code to give me a better idea of where it is bombing. I will try another --debug run later tonite, but can't stop the server until after 17:00 hours local. Clamscan works OK, but when the upgrade first applied, the bad system couldn't even run clamscan. Maybe the module isn't pointing at the correct library? I will do a force install of the clamavmodule before the debug run, although I thought I did already. Never mind now -- force install from cpan would fail tests and not re-install, but compiling from the Mail::Clamav tarball finally kicked the POS into gear. And this is the busier of the 2 servers. The load is already dropping. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From amaclach at yahoo.co.uk Mon May 7 22:09:03 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Mon May 7 22:09:06 2007 Subject: Multi (split) image spam Message-ID: <795384.84076.qm@web26315.mail.ukl.yahoo.com> Thanks Ed - That was my take as well. To be fair, I can see both sides of the argument, however I consider greylisting to still be an essential tool in the fight against spam. As always there are many different implementations and each has it's pros and cons. I have yet to see the perfect greylist implementation, but there has been some good work done by someone in Japan who modified postgrey so that it would only greylist dynamic addresses (determined by regex). Although this is nowhere near perfect it is certainly a step in the right direction (and should keep Res happy as well as his mailservers would be unlikely to be hit.) by adding some intelligence to the default postgrey implementation - which is a fairly blunt -yet effective instrument. No reply earlier to this to avoid a flame war which is never a good look! -Andy ----- Original Message ---- From: Ed Bruce To: MailScanner discussion Sent: Monday, 7 May, 2007 4:47:04 PM Subject: Re: Multi (split) image spam -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Res wrote: > On Sun, 6 May 2007, Andrew MacLachlan wrote: > >>> and all it does it build up your own outgoing queues >> Not sure how the logic on that one works... > > errr logic? WTF? if the queue cant send it right away it stays in the > queue so lamelisted_mail+current_submissions=building_up_queue > like I said it might be fine if you run a small office 1K emails p/day, > but not when you do millions p/day, however I have tuned sendmail queue > running so that new stuff goes first, I'm not going to allow new stuff > to be delayed in oversized queue runners because some lamers server wont > accept it on first attempt. > > Res I didn't understand what you meant at first. Well I may still not understand, but I'm guessing you are saying that if my MTA is running some sort of gray listing and your MTA attempts a connection it will cause your queues to back up??? I took your original message to mean that if I run gray listing then my queues would back up. That didn't seem to make much sense to me as I wouldn't gray list myself. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (Cygwin) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFGP0n4pdNaP9x3McgRArgZAKCRGB0GISE0JH2n0PF5lKidri3+OQCfXw9y KsDBaz/j6cFRsvK9ABgXEYk= =V5KN -----END PGP SIGNATURE----- -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From amaclach at yahoo.co.uk Mon May 7 22:14:26 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Mon May 7 22:14:28 2007 Subject: Interesting need Message-ID: <589025.24756.qm@web26311.mail.ukl.yahoo.com> Or if you use Exchange internally - setup a rule, that way you can also forward all internal messages. (no anti exchange rants please - It's paid many of my bills...) ----- Original Message ---- From: Julian Field To: MailScanner discussion Sent: Monday, 7 May, 2007 8:46:54 PM Subject: Re: Interesting need -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Alex Neuman van der Hans wrote: > Archive mail "forwards" email? I thought it only "archived" it... RTFM my friend :-) Best regards, Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGP4I8EfZZRxQVtlQRAukRAJ4/kR547/Yym2whwfTU2xPp4w/AMgCfcwcM LvwmIoikao6OZY+E6MvOp94= =+Jsy -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From amaclach at yahoo.co.uk Mon May 7 22:21:36 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Mon May 7 22:21:38 2007 Subject: SpamAssassin 3.2.0 package Message-ID: <106296.50838.qm@web26314.mail.ukl.yahoo.com> Dag has one and it works just fine. ----- Original Message ---- From: Julian Field To: MailScanner discussion Sent: Monday, 7 May, 2007 8:39:33 PM Subject: Re: SpamAssassin 3.2.0 package -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Scott Silva wrote: > Julian Field spake the following on 5/7/2007 9:37 AM: > >> Scott Silva wrote: >> >>> Julian Field spake the following on 5/5/2007 10:04 AM: >>> >>> >>>> I have done some basic tests with my SpamAssassin 3.2.0 package and >>>> MailScanner 4.59 and it is working fine. >>>> >>>> I'll do some more tests of it and probably start using it on a >>>> production machine tomorrow if I feel so inclined (and there again I >>>> might well just put my feet up and watch TV). It's a public holiday >>>> this weekend (I think!) so by definition it should rain on Monday at >>>> least. :-) >>>> >>>> Jules. >>>> >>>> >>> Julian, >>> I haven't had an opportunity to look at it yet, but are you or did you >>> add an >>> init script for clamd? I was going to throw one together if it didn't >>> have >>> one. But if it is already there, I won't bother. >>> >>> >> No, I haven't done an init script for clamd. It should be easy enough to >> knock one up based on the MailScanner ones. The SuSE and RedHat-based >> ones need to be different, so if you fancy writing both based on the >> MailScanner ones that would be great. >> >> Attached are the RedHat and SuSE init.d scripts for MailScanner itself >> so you can see the differences needed. >> >> Obviously the clamd ones will be a lot shorter :-) >> >> Jules >> >> > In looking at this, there will need to be more than just an init script. There > will need to be a clamd.conf file, and probably a logrotate script. I don't > know how much extra stuff you want to add, but I'm game if you dont mind the > extra fluff. > Is it really true that no-one else has done a decent RPM of clamd yet? I would be surprised if Dag Wieers hasn't done one already, for starters. If there is one, why are we duplicating the effort? Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGP4EeEfZZRxQVtlQRAnIPAKCQnsIUEthWQbi2R6bbRiO7Q8DCnQCg6zXv y5RNQN2fTRygk4Xny1Opi64= =gz9L -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Mon May 7 22:21:36 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 7 22:22:44 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: <463F82EB.9080404@maddoc.net> References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> <463CAD50.3050806@ecs.soton.ac.uk> <463CB925.2050609@ecs.soton.ac.uk> <463F55BD.7080209@ecs.soton.ac.uk> <463F8075.60900@ecs.soton.ac.uk> <463F82EB.9080404@maddoc.net> Message-ID: <463F9860.1060003@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Doc Schneider wrote: > Julian Field wrote: > >> Scott Silva wrote: >> >>> Julian Field spake the following on 5/7/2007 9:37 AM: >>> >>>> Scott Silva wrote: >>>> >>>> >>>>> Julian Field spake the following on 5/5/2007 10:04 AM: >>>>> >>>>> >>>>> >>>>>> I have done some basic tests with my SpamAssassin 3.2.0 package and >>>>>> MailScanner 4.59 and it is working fine. >>>>>> >>>>>> I'll do some more tests of it and probably start using it on a >>>>>> production machine tomorrow if I feel so inclined (and there again I >>>>>> might well just put my feet up and watch TV). It's a public holiday >>>>>> this weekend (I think!) so by definition it should rain on Monday at >>>>>> least. :-) >>>>>> >>>>>> Jules. >>>>>> >>>>>> >>>>>> >>>>> Julian, >>>>> I haven't had an opportunity to look at it yet, but are you or did you >>>>> add an >>>>> init script for clamd? I was going to throw one together if it didn't >>>>> have >>>>> one. But if it is already there, I won't bother. >>>>> >>>>> >>>>> >>>> No, I haven't done an init script for clamd. It should be easy enough to >>>> knock one up based on the MailScanner ones. The SuSE and RedHat-based >>>> ones need to be different, so if you fancy writing both based on the >>>> MailScanner ones that would be great. >>>> >>>> Attached are the RedHat and SuSE init.d scripts for MailScanner itself >>>> so you can see the differences needed. >>>> >>>> Obviously the clamd ones will be a lot shorter :-) >>>> >>>> Jules >>>> >>>> >>>> >>> In looking at this, there will need to be more than just an init script. There >>> will need to be a clamd.conf file, and probably a logrotate script. I don't >>> know how much extra stuff you want to add, but I'm game if you dont mind the >>> extra fluff. >>> >> Is it really true that no-one else has done a decent RPM of clamd yet? I >> would be surprised if Dag Wieers hasn't done one already, for starters. >> If there is one, why are we duplicating the effort? >> >> Jules >> >> > > Jules, > > Dag Wieers has a current rpm for clamav-0.90.2 was there less than 24 > hours after it was released. > > I have just added considerably to the Clam+SA install.sh script. It now asks you whether you want it to install ClamAV or not. If it doesn't install it for you, it asks you where ClamAV is installed. It has sensible defaults set, so you can just do what it suggests. I'll give it another test in the morning to check it all works (getting late now) and will post it on the website if it all goes okay. Then you can still use my package to install the ClamAV perl module and SpamAssassin without necessarily having to install another copy of ClamAV that you didn't want, if you want to use an RPM of it. That way no-one has to duplicate any effort writing yet another RPM of ClamAV. :-) Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGP5iHEfZZRxQVtlQRAsHrAKCftgE9qQRNdsr1zV4vQkO1EmJtGwCgsh0e sqTKuI8ts170Dv+LZi7/3eQ= =GKJC -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From glenn.steen at gmail.com Mon May 7 22:42:40 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Mon May 7 22:42:43 2007 Subject: Interesting need In-Reply-To: <463F822E.2010108@ecs.soton.ac.uk> References: <463F0518.65ED.00A2.0@plattesheriff.org> <463F5C10.7080307@ecs.soton.ac.uk> <463F7783.7070608@nkpanama.com> <463F822E.2010108@ecs.soton.ac.uk> Message-ID: <223f97700705071442w106785bu1a9a50405476f9cb@mail.gmail.com> On 07/05/07, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Alex Neuman van der Hans wrote: > > Archive mail "forwards" email? I thought it only "archived" it... > RTFM my friend :-) Yes I did, and I have a question...Wouldn't using Archive Mail forwarding include all the spam etc? Call me crazy (who knows, I might be:-) but in that sense I'd go for Alex suggestion...;) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From mkettler at evi-inc.com Mon May 7 22:59:44 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Mon May 7 22:59:55 2007 Subject: SA 3.2.0 Woes In-Reply-To: <20070507125947.05ede1ea@uxbod.splatnix.net> References: <20070507125947.05ede1ea@uxbod.splatnix.net> Message-ID: <463FA150.5070909@evi-inc.com> --[ UxBoD ]-- wrote: > Hi, > > Not sure whether this is a issue or not, but since upgrading SA and > MailScanner I never seem to get any hits via RBLs. I am using MailWatch > and that just says "SpamAssassin Listed in RBL". Bayes never seems to > trigger aswell now. > > Have others experienced anything like this ? I've not tried 3.2.0 with MailScanner. However, this sounds like it might be a purely spamassassin issue. You might want to try running the following basic debugging steps: First, run "spamassassin --lint", and make sure it's got nothing to complain about in your config files. It should just exit quietly. I strongly recommend doing this first, as the version with debug below often spits out so much text it becomes easy to miss the important warning messages. Second, run "spamassassin --lint -D" and take a look if SA thinks network tests are enabled. It might be that your version of Net::DNS isn't new enough for 3.2's needs, and thus this feature is disabled. Ditto bayes and your version of DB_File and/or DBI. As a further check of bayes, try a "sa-learn --dump magic" and see if sa can make sense of the bayes DB at all. From ssilva at sgvwater.com Mon May 7 23:21:33 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 7 23:25:12 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: <463CB925.2050609@ecs.soton.ac.uk> References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> <463CAD50.3050806@ecs.soton.ac.uk> <463CB925.2050609@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 5/5/2007 10:04 AM: > I have done some basic tests with my SpamAssassin 3.2.0 package and > MailScanner 4.59 and it is working fine. > > I'll do some more tests of it and probably start using it on a > production machine tomorrow if I feel so inclined (and there again I > might well just put my feet up and watch TV). It's a public holiday this > weekend (I think!) so by definition it should rain on Monday at least. :-) > > Jules. I hope you voted for putting your feet up and watching the TV!! ;-P -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Mon May 7 23:30:52 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 7 23:31:11 2007 Subject: Multi (split) image spam In-Reply-To: <795384.84076.qm@web26315.mail.ukl.yahoo.com> References: <795384.84076.qm@web26315.mail.ukl.yahoo.com> Message-ID: Andrew MacLachlan spake the following on 5/7/2007 2:09 PM: > Thanks Ed - That was my take as well. > To be fair, I can see both sides of the argument, however I consider greylisting to still be an essential tool in the fight against spam. As always there are many different implementations and each has it's pros and cons. > I have yet to see the perfect greylist implementation, but there has been some good work done by someone in Japan who modified postgrey so that it would only greylist dynamic addresses (determined by regex). Although this is nowhere near perfect it is certainly a step in the right direction (and should keep Res happy as well as his mailservers would be unlikely to be hit.) by adding some intelligence to the default postgrey implementation - which is a fairly blunt -yet effective instrument. > > No reply earlier to this to avoid a flame war which is never a good look! If you just reject mail from dynamic ip's unless it is authenticated roaming users, you will be better off. I still think that if you need a mail server, you need a static address or a smarthost that is on one. There is no good reason (IMHO) besides the costs to try and serve mail from a dynamic IP, unless your ISP will not sell or rent you a static address. When we upgraded from a SDSL circuit to a T1, we went from a /24 block to to a /19 block at each site. I didn't ask for the 64 addresses, they just didn't want to split the block any smaller. And they gave me the reverse mappings also, so I can't complain. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From gmane at tippingmar.com Mon May 7 23:34:48 2007 From: gmane at tippingmar.com (Mark Nienberg) Date: Mon May 7 23:35:11 2007 Subject: writing to /var/spool/MailScanner/incoming Message-ID: I have /var/spool/MailScanner/incoming mounted as tmpfs. I have a mail related script (duplicate msg remover) that could benefit from writing to tmpfs instead of physical disk. Is it OK for my script to use some space in MailScanner/incoming or does MailScanner only expect to see it's own stuff in there? Thanks, Mark From ssilva at sgvwater.com Mon May 7 23:36:56 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 7 23:40:17 2007 Subject: SA 3.2.0 Woes In-Reply-To: <463FA150.5070909@evi-inc.com> References: <20070507125947.05ede1ea@uxbod.splatnix.net> <463FA150.5070909@evi-inc.com> Message-ID: Matt Kettler spake the following on 5/7/2007 2:59 PM: > --[ UxBoD ]-- wrote: >> Hi, >> >> Not sure whether this is a issue or not, but since upgrading SA and >> MailScanner I never seem to get any hits via RBLs. I am using MailWatch >> and that just says "SpamAssassin Listed in RBL". Bayes never seems to >> trigger aswell now. >> >> Have others experienced anything like this ? > > I've not tried 3.2.0 with MailScanner. However, this sounds like it might be a > purely spamassassin issue. > > You might want to try running the following basic debugging steps: > > First, run "spamassassin --lint", and make sure it's got nothing to complain > about in your config files. It should just exit quietly. I strongly recommend > doing this first, as the version with debug below often spits out so much text > it becomes easy to miss the important warning messages. > > Second, run "spamassassin --lint -D" and take a look if SA thinks network tests > are enabled. It might be that your version of Net::DNS isn't new enough for > 3.2's needs, and thus this feature is disabled. Ditto bayes and your version of > DB_File and/or DBI. Does 3.2.0 do network tests in a lint? Because 3.1.8 didn't unless you piped a message through it. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Mon May 7 23:40:14 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 7 23:45:07 2007 Subject: Interesting need In-Reply-To: <223f97700705071442w106785bu1a9a50405476f9cb@mail.gmail.com> References: <463F0518.65ED.00A2.0@plattesheriff.org> <463F5C10.7080307@ecs.soton.ac.uk> <463F7783.7070608@nkpanama.com> <463F822E.2010108@ecs.soton.ac.uk> <223f97700705071442w106785bu1a9a50405476f9cb@mail.gmail.com> Message-ID: Glenn Steen spake the following on 5/7/2007 2:42 PM: > On 07/05/07, Julian Field wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> >> >> Alex Neuman van der Hans wrote: >> > Archive mail "forwards" email? I thought it only "archived" it... >> RTFM my friend :-) > > Yes I did, and I have a question...Wouldn't using Archive Mail > forwarding include all the spam etc? Call me crazy (who knows, I might > be:-) but in that sense I'd go for Alex suggestion...;) > > Cheers I think the archive mail option would be for those organizations that are required to keep "everything" that crosses their gateway. So unless you can stop it at the MTA, you would have to keep it. I would rather use a forward at the non-spam actions also if it were up to me, and I had no legal requirement to keep everything. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Mon May 7 23:43:37 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 7 23:50:04 2007 Subject: Interesting need In-Reply-To: <589025.24756.qm@web26311.mail.ukl.yahoo.com> References: <589025.24756.qm@web26311.mail.ukl.yahoo.com> Message-ID: Andrew MacLachlan spake the following on 5/7/2007 2:14 PM: > Or if you use Exchange internally - setup a rule, that way you can also forward all internal messages. (no anti exchange rants please - It's paid many of my bills...) > No anti-exchange rants here, you administer what the check signers want to run. I am fending off a possible move to Exchange or Notes. I am hoping that they will wince at the costs. They pay me anyway, and I have told them that they would need to add a warm body for either option. I don't have any time left in the day. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From mkettler at evi-inc.com Mon May 7 23:58:57 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Tue May 8 00:18:19 2007 Subject: SA 3.2.0 Woes In-Reply-To: References: <20070507125947.05ede1ea@uxbod.splatnix.net> <463FA150.5070909@evi-inc.com> Message-ID: <463FAF31.7060800@evi-inc.com> Scott Silva wrote: > Matt Kettler spake the following on 5/7/2007 2:59 PM: >> --[ UxBoD ]-- wrote: >>> Hi, >>> >>> Not sure whether this is a issue or not, but since upgrading SA and >>> MailScanner I never seem to get any hits via RBLs. I am using MailWatch >>> and that just says "SpamAssassin Listed in RBL". Bayes never seems to >>> trigger aswell now. >>> >>> Have others experienced anything like this ? >> I've not tried 3.2.0 with MailScanner. However, this sounds like it might be a >> purely spamassassin issue. >> >> You might want to try running the following basic debugging steps: >> >> First, run "spamassassin --lint", and make sure it's got nothing to complain >> about in your config files. It should just exit quietly. I strongly recommend >> doing this first, as the version with debug below often spits out so much text >> it becomes easy to miss the important warning messages. >> >> Second, run "spamassassin --lint -D" and take a look if SA thinks network tests >> are enabled. It might be that your version of Net::DNS isn't new enough for >> 3.2's needs, and thus this feature is disabled. Ditto bayes and your version of >> DB_File and/or DBI. > > Does 3.2.0 do network tests in a lint? Because 3.1.8 didn't unless you piped a > message through it. > Gah! you're right, forgot about that. You'd have to do a "spamassassin -D < sample-spam.txt >/dev/null" From ssilva at sgvwater.com Tue May 8 00:18:43 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 8 00:18:54 2007 Subject: writing to /var/spool/MailScanner/incoming In-Reply-To: References: Message-ID: Mark Nienberg spake the following on 5/7/2007 3:34 PM: > I have /var/spool/MailScanner/incoming mounted as tmpfs. > > I have a mail related script (duplicate msg remover) that could benefit > from writing to tmpfs instead of physical disk. Is it OK for my script > to use some space in MailScanner/incoming or does MailScanner only > expect to see it's own stuff in there? > > Thanks, > Mark > You could have another mountpoint to tmpfs if you want. They would be separate filesystems to the OS, but would still only use the same total amount of ram. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From res at ausics.net Tue May 8 00:36:15 2007 From: res at ausics.net (Res) Date: Tue May 8 00:36:26 2007 Subject: Multi (split) image spam In-Reply-To: <463F49F8.6080304@sbcglobal.net> References: <694855.76046.qm@web26301.mail.ukl.yahoo.com> <463F49F8.6080304@sbcglobal.net> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Mon, 7 May 2007, Ed Bruce wrote: >> errr logic? WTF? if the queue cant send it right away it stays in the >> queue so lamelisted_mail+current_submissions=building_up_queue >> like I said it might be fine if you run a small office 1K emails p/day, >> but not when you do millions p/day, however I have tuned sendmail queue >> running so that new stuff goes first, I'm not going to allow new stuff >> to be delayed in oversized queue runners because some lamers server wont >> accept it on first attempt. >> >> > > Res I didn't understand what you meant at first. Well I may still not > understand, but I'm guessing you are saying that if my MTA is running > some sort of gray listing and your MTA attempts a connection it will > cause your queues to back up??? Correct, this affects the sending MTA, not the recipient server. > I took your original message to mean that if I run gray listing then my > queues would back up. That didn't seem to make much sense to me as I > wouldn't gray list myself. LOL no it wouldnt :) - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD4DBQFGP7fxsWhAmSIQh7MRAv85AJdZBssbVh0cfXdri+cUzCpPcQO7AJ47E5mQ xo21w0V79ggqYrCTM2AO8g== =56s9 -----END PGP SIGNATURE----- From res at ausics.net Tue May 8 00:40:11 2007 From: res at ausics.net (Res) Date: Tue May 8 00:40:19 2007 Subject: SpamAssassin 3.2.0 In-Reply-To: <463F5028.9060201@evi-inc.com> References: <463900B1.8080301@ecs.soton.ac.uk> <463B7C0C.9000004@evi-inc.com> <463BB60B.3060608@evi-inc.com> <463E12CC.7080806@evi-inc.com> <463F5028.9060201@evi-inc.com> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Mon, 7 May 2007, Matt Kettler wrote: Thanks Matt. > For reference, the bug is this one: > > http://issues.apache.org/SpamAssassin/show_bug.cgi?id=5436 - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGP7jdsWhAmSIQh7MRAh8cAJ4o9u7LI6VJuKQazRYZ5lF34AhqwgCfUs1f dvD/trShOTp0NycaYOg6M3Q= =pynS -----END PGP SIGNATURE----- From res at ausics.net Tue May 8 00:52:30 2007 From: res at ausics.net (Res) Date: Tue May 8 00:52:40 2007 Subject: Interesting need In-Reply-To: References: <463F0518.65ED.00A2.0@plattesheriff.org> <463F5C10.7080307@ecs.soton.ac.uk> <463F7783.7070608@nkpanama.com> <463F822E.2010108@ecs.soton.ac.uk> <223f97700705071442w106785bu1a9a50405476f9cb@mail.gmail.com> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Mon, 7 May 2007, Scott Silva wrote: > I think the archive mail option would be for those organizations that are > required to keep "everything" that crosses their gateway. So unless you can Not to mention for obtaining copies of mail sent from/to a norti user that the feds have an interest in :) and with the forwarding ability they get it all in real time. - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGP7vAsWhAmSIQh7MRAqlgAJ9cq6M330IfKjOSgA4+B1DC0kfmigCfYTnO 1i7vLA+s2UB08lqxcOVQICQ= =hOg0 -----END PGP SIGNATURE----- From amaclach at yahoo.co.uk Tue May 8 00:58:41 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Tue May 8 00:58:44 2007 Subject: Multi (split) image spam Message-ID: <38033.93041.qm@web26312.mail.ukl.yahoo.com> It is true that there is no good reason to use dynamic addresses (for obvious reasons), however some ISPs refuse to update the reverse mappings so that even though an address is static, it still appears to be dynamic because of the netblock and reverse mapping. While it could be argued that smarthosts are the correct way for small businesses to send mail, depending on the provider these can be worse than dynamic for RBLs etc! ----- Original Message ---- From: Scott Silva To: mailscanner@lists.mailscanner.info Sent: Monday, 7 May, 2007 11:30:52 PM Subject: Re: Multi (split) image spam Andrew MacLachlan spake the following on 5/7/2007 2:09 PM: > Thanks Ed - That was my take as well. > To be fair, I can see both sides of the argument, however I consider greylisting to still be an essential tool in the fight against spam. As always there are many different implementations and each has it's pros and cons. > I have yet to see the perfect greylist implementation, but there has been some good work done by someone in Japan who modified postgrey so that it would only greylist dynamic addresses (determined by regex). Although this is nowhere near perfect it is certainly a step in the right direction (and should keep Res happy as well as his mailservers would be unlikely to be hit.) by adding some intelligence to the default postgrey implementation - which is a fairly blunt -yet effective instrument. > > No reply earlier to this to avoid a flame war which is never a good look! If you just reject mail from dynamic ip's unless it is authenticated roaming users, you will be better off. I still think that if you need a mail server, you need a static address or a smarthost that is on one. There is no good reason (IMHO) besides the costs to try and serve mail from a dynamic IP, unless your ISP will not sell or rent you a static address. When we upgraded from a SDSL circuit to a T1, we went from a /24 block to to a /19 block at each site. I didn't ask for the 64 addresses, they just didn't want to split the block any smaller. And they gave me the reverse mappings also, so I can't complain. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From info at ittsl.com Tue May 8 05:03:31 2007 From: info at ittsl.com (=?ISO-8859-1?Q?ittsl01=20?=) Date: Tue May 8 01:03:40 2007 Subject: Automated Reply from ittsl01 Message-ID: <200705080403.l4843VtQ016175@server30055.uk2net.com> ITTSL is out of the office until 14th May on Business in Europe. If you require urgent assistance, please a problem ticket at http://www.ittsl.net and we will respond to as soon as possible. Many Thanks. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From amaclach at yahoo.co.uk Tue May 8 01:04:25 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Tue May 8 01:04:27 2007 Subject: Interesting need Message-ID: <65028.16389.qm@web26307.mail.ukl.yahoo.com> lol - Exchange isn't too bad to run, but it needs a specialist - not just someone to do a next, next, next install and hope it's still working in a year. Maybe Zimbra? ----- Original Message ---- From: Scott Silva To: mailscanner@lists.mailscanner.info Sent: Monday, 7 May, 2007 11:43:37 PM Subject: Re: Interesting need Andrew MacLachlan spake the following on 5/7/2007 2:14 PM: > Or if you use Exchange internally - setup a rule, that way you can also forward all internal messages. (no anti exchange rants please - It's paid many of my bills...) > No anti-exchange rants here, you administer what the check signers want to run. I am fending off a possible move to Exchange or Notes. I am hoping that they will wince at the costs. They pay me anyway, and I have told them that they would need to add a warm body for either option. I don't have any time left in the day. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From alden at engineno9inc.com Tue May 8 01:11:09 2007 From: alden at engineno9inc.com (Alden Levy) Date: Tue May 8 01:11:19 2007 Subject: SMPID vs. INPID Message-ID: <005b01c79105$617db200$5e01a8c0@AldenLap> I'm still scratching my head over this one. Would someone with a Redhat install please post the relevant lines of their MailScanner_app_init, so I can compare it to mine? >Basically, when I start MS, all works well, but when I check status, I get >an error ># service MailScanner status >Checking MailScanner daemons: > MailScanner: [ OK ] > incoming sendmail: [ FAIL ] > outgoing sendmail: [ OK ] > >However, it works fine as it is. In order to get rid of the fail, though, >I've been updating sendmail.in.pid with the proper pid, and everything >works. > >I finally had a few minutes to track down the issue, and it seems that >something (I did something??) confused SMPID and INPID in >MailScanner_app_init. > >The relevant code is: >In StartInSendmail: > elif [ $MTA = 'sendmail' ]; then > /usr/bin/newaliases > /dev/null 2>&1 > if test -x /usr/bin/make -a -f /etc/mail/Makefile ; then > make -C /etc/mail -s > else > for i in virtusertable access domaintable mailertable ; do > if [ -f /etc/mail/$i ] ; then > makemap hash /etc/mail/$i < /etc/mail/$i > fi > done > fi > $SENDMAIL -bd -OPrivacyOptions=noetrn \ > -ODeliveryMode=queueonly \ > -OQueueDirectory=$INQDIR \ > -OPidFile=$INPID > touch /var/run/sm-client.pid > chown $MSPUSER:$MSPGROUP /var/run/sm-client.pid 2>/dev/null > $SENDMAIL -L sm-msp-queue -Ac -q15m -OPidFile=$SMPID 2>/dev/null > success > echo > >And in status: > status) > # Work out if all of MailScanner is running > echo 'Checking MailScanner daemons:' > echo -n ' MailScanner: ' > pid=`pidofproc MailScanner` > if [ -z "$pid" ] ; then failure; else success; fi > echo > if [ $MTA = "sendmail" ]; then > # Now the incoming sendmail > echo -n ' incoming sendmail: ' > pid=`head -1 $INPID` > alive=`ps ax | awk '{ print $1 }' | grep '^'$pid'$'` > #pid=`ps ax | egrep '\[sendmail\]|sendmai[l]: accepting >connections'` > if [ -z "$alive" ] ; then failure; else success; fi > echo > Thanks, Alden Alden Levy Engine No. 9, Inc. 130 W. 57th Street, Suite 2F New York, NY 10019 (212) 981-1122 (212) 504-9598 fax From mkettler at evi-inc.com Tue May 8 01:25:26 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Tue May 8 01:25:37 2007 Subject: Automated Reply from ittsl01 In-Reply-To: <200705080403.l4843VtQ016175@server30055.uk2net.com> References: <200705080403.l4843VtQ016175@server30055.uk2net.com> Message-ID: <463FC376.6020103@evi-inc.com> ittsl01 wrote: > ITTSL is out of the office until 14th May on Business in Europe. If you require urgent assistance, please a problem ticket at http://www.ittsl.net and we will respond to as soon as possible. Many Thanks. Hmm, should we ALL go and open tickets? :) From tenderby at mailwash.com.au Tue May 8 05:39:52 2007 From: tenderby at mailwash.com.au (Tony Enderby) Date: Tue May 8 05:40:26 2007 Subject: FuzzyOCR SA 3.20 Message-ID: <200705080440.l484eA1u014384@mail.mailwash.com.au> Hi All, Just wondering if anyone knows of a workaround for the FuzzyOCR prob with the latest version of SpamAssassin. Post upgrade I tried the test emails that ship with the latest FuzzyOCR distribution and am not getting any output in the returned spam report. Thanks in advance. Tony. ----------------------------------------------------------------------------------- Scanned by MailWash Australia - http://www.mailwash.com.au ----------------------------------------------------------------------------------- -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070508/ee7f7d6b/attachment.html From r.berber at computer.org Tue May 8 05:58:23 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Tue May 8 05:56:31 2007 Subject: FuzzyOCR SA 3.20 In-Reply-To: <200705080440.l484eA1u014384@mail.mailwash.com.au> References: <200705080440.l484eA1u014384@mail.mailwash.com.au> Message-ID: Tony Enderby wrote: > Just wondering if anyone knows of a workaround for the FuzzyOCR prob > with the latest version of SpamAssassin. > > Post upgrade I tried the test emails that ship with the latest FuzzyOCR > distribution and am not getting any output in the returned spam report. You mean no details in the report? That can be fixed by changing line 932 of FuzzyOcr.pm (version 3.5.1) : - $pms->_handle_hit( "FUZZY_OCR", $score, "BODY: ", + $pms->_handle_hit( "FUZZY_OCR", $score, "BODY: ", "rawbody", There are other problems brought by changes in SA, like formatting of the report being lost (since 3.1.8, thanks to Util::wrap()), and when the image is known to be spam there is no detail in the report. -- Ren? Berber From tenderby at mailwash.com.au Tue May 8 06:34:57 2007 From: tenderby at mailwash.com.au (Tony Enderby) Date: Tue May 8 06:35:33 2007 Subject: FuzzyOCR SA 3.20 In-Reply-To: Message-ID: <200705080535.l485ZFDe019297@mail.mailwash.com.au> Many thanks, working a treat again. Tony. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Ren? Berber Sent: Tuesday, May 08, 2007 2:58 PM To: mailscanner@lists.mailscanner.info Subject: Re: FuzzyOCR SA 3.20 Tony Enderby wrote: > Just wondering if anyone knows of a workaround for the FuzzyOCR prob > with the latest version of SpamAssassin. > > Post upgrade I tried the test emails that ship with the latest FuzzyOCR > distribution and am not getting any output in the returned spam report. You mean no details in the report? That can be fixed by changing line 932 of FuzzyOcr.pm (version 3.5.1) : - $pms->_handle_hit( "FUZZY_OCR", $score, "BODY: ", + $pms->_handle_hit( "FUZZY_OCR", $score, "BODY: ", "rawbody", There are other problems brought by changes in SA, like formatting of the report being lost (since 3.1.8, thanks to Util::wrap()), and when the image is known to be spam there is no detail in the report. -- Ren? Berber -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ---------------------------------------------------------------------------- ------- Scanned by MailWash Australia - http://www.mailwash.com.au ---------------------------------------------------------------------------- ------- ----------------------------------------------------------------------------------- Scanned by MailWash Australia - http://www.mailwash.com.au ----------------------------------------------------------------------------------- From alvaro at hostalia.com Tue May 8 09:04:35 2007 From: alvaro at hostalia.com (=?ISO-8859-15?Q?Alvaro_Mar=EDn?=) Date: Tue May 8 09:04:40 2007 Subject: Error with SA 3.2.0 Message-ID: <46402F13.5090602@hostalia.com> Hello, I've upgraded SA to 3.2.0 version and MailScanner doesn't check/deliver messages. Running in debug mode, I get: ... [31624] dbg: config: score set 3 chosen. [31624] dbg: message: main message type: text/plain [31624] dbg: message: ---- MIME PARSER START ---- [31624] dbg: message: parsing normal part [31624] dbg: message: ---- MIME PARSER END ---- check: no loaded plugin implements 'check_main': cannot scan! at /usr/lib/perl5/site_perl/5.8.7/Mail/SpamAssassin/PerMsgStatus.pm line 164. Failed. Any idea about this? If I downgrade to SA 3.1.8 all runs fine Thanks! Regards, -- Alvaro Mar?n Illera Hostalia Internet www.hostalia.com From drew at technologytiger.net Tue May 8 09:10:10 2007 From: drew at technologytiger.net (Drew Marshall) Date: Tue May 8 09:10:16 2007 Subject: Automated Reply from ittsl01 In-Reply-To: <463FC376.6020103@evi-inc.com> References: <200705080403.l4843VtQ016175@server30055.uk2net.com> <463FC376.6020103@evi-inc.com> Message-ID: On 8 May 2007, at 01:25, Matt Kettler wrote: > ittsl01 wrote: >> ITTSL is out of the office until 14th May on Business in Europe. >> If you require urgent assistance, please a problem ticket at >> http://www.ittsl.net and we will respond to as soon as possible. >> Many Thanks. > > Hmm, should we ALL go and open tickets? :) It IS tempting... Dear problem dept How do I set my out of office up? Regards ... :-) Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by the Technology Tiger MailScanner. Further information can be found at www.technologytiger.net/policy Technology Tiger Limited is registered in Scotland with registration number: 310997 Registered Office 55-57 West High Street Inverurie AB51 3QQ From glenn.steen at gmail.com Tue May 8 09:27:08 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue May 8 09:27:13 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> <463CAD50.3050806@ecs.soton.ac.uk> <463CB925.2050609@ecs.soton.ac.uk> Message-ID: <223f97700705080127t2b5436e9m8fd50d8bbf481eb4@mail.gmail.com> On 08/05/07, Scott Silva wrote: > Julian Field spake the following on 5/5/2007 10:04 AM: > > I have done some basic tests with my SpamAssassin 3.2.0 package and > > MailScanner 4.59 and it is working fine. > > > > I'll do some more tests of it and probably start using it on a > > production machine tomorrow if I feel so inclined (and there again I > > might well just put my feet up and watch TV). It's a public holiday this > > weekend (I think!) so by definition it should rain on Monday at least. :-) > > > > Jules. > I hope you voted for putting your feet up and watching the TV!! ;-P You are not alone in hoping that Scott! It's not that we want you to be bored Jules, nor that we don't appreciate the effort you make... We kind of want you to stick around for the long run, more than giving the immediate fix... Essentially see us as your virtual mother hens;-) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From list-mailscanner at linguaphone.com Tue May 8 09:32:51 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue May 8 09:33:22 2007 Subject: Multi (split) image spam In-Reply-To: <38033.93041.qm@web26312.mail.ukl.yahoo.com> References: <38033.93041.qm@web26312.mail.ukl.yahoo.com> Message-ID: <1178613171.30898.3.camel@gblades-suse.linguaphone-intranet.co.uk> Does anyone have an example of one of these spams? I was thinking it should be possible to write a rule to detect these as there is no real reason why two images should be directly next to each other. From glenn.steen at gmail.com Tue May 8 09:47:02 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue May 8 09:47:06 2007 Subject: Multi (split) image spam In-Reply-To: <1178613171.30898.3.camel@gblades-suse.linguaphone-intranet.co.uk> References: <38033.93041.qm@web26312.mail.ukl.yahoo.com> <1178613171.30898.3.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <223f97700705080147s448b9553p856f0f02984d1584@mail.gmail.com> On 08/05/07, Gareth wrote: > Does anyone have an example of one of these spams? > > I was thinking it should be possible to write a rule to detect these as > there is no real reason why two images should be directly next to each > other. ... Apart from (decidedly crappy, but still) tabulated "layouting" in HTML mails? -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From jim.barber at ddihealth.com Tue May 8 09:51:54 2007 From: jim.barber at ddihealth.com (Jim Barber) Date: Tue May 8 09:52:29 2007 Subject: Multi (split) image spam In-Reply-To: <1178613171.30898.3.camel@gblades-suse.linguaphone-intranet.co.uk> References: <38033.93041.qm@web26312.mail.ukl.yahoo.com> <1178613171.30898.3.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <46403A2A.5010407@ddihealth.com> I don't know if it's possible or not, but perhaps these images could be stitched together into one large image before they are presented to FuzzyOCR. That would probably take a bit of work as you'd need to know from the layout how to stitch the images together (side-by-side? top-to-bottom? 2x2, etc). But once stitched and passed to FuzzyOCR it should then be able to extract complete words from the final image. ---------- Jim Barber DDI Health Gareth wrote: > Does anyone have an example of one of these spams? > > I was thinking it should be possible to write a rule to detect these as > there is no real reason why two images should be directly next to each > other. > From alvaro at hostalia.com Tue May 8 09:53:57 2007 From: alvaro at hostalia.com (=?ISO-8859-15?Q?Alvaro_Mar=EDn?=) Date: Tue May 8 09:54:02 2007 Subject: Error with SA 3.2.0 In-Reply-To: <46402F13.5090602@hostalia.com> References: <46402F13.5090602@hostalia.com> Message-ID: <46403AA5.10709@hostalia.com> Hello again, > check: no loaded plugin implements 'check_main': cannot scan! at > /usr/lib/perl5/site_perl/5.8.7/Mail/SpamAssassin/PerMsgStatus.pm line 164. > Failed. Copying v320.pre to /usr/share/spamassassin solves the problem but I've changed SpamAssassin Local Rules Dir and know runs fine. Regards, -- Alvaro Mar?n Illera Hostalia Internet www.hostalia.com From martinh at solidstatelogic.com Tue May 8 09:54:52 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Tue May 8 09:54:54 2007 Subject: Interesting need In-Reply-To: <463F0518.65ED.00A2.0@plattesheriff.org> Message-ID: Rob As others have said, surely this is down to the 'corporate email server' to handle? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Rob Poe > Sent: 07 May 2007 16:53 > To: MailScanner discussion > Subject: Interesting need > > This might not be so much a MailScanner function ... but > > I have a Linux / Sendmail / MailScanner box set up in front of a corporate > mail system. It's doing the domain as relay-domains and mailertable. One > of their users wants all of his EXTERNAL incoming mail to go to both HIM > and his assistant. > > I tried with the aliases and virtusertable ... didn't work (just forwarded > on to the corp mail system as if nothing was in there). > > Is this something I can do with a MailScanner rule? > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From MailScanner at ecs.soton.ac.uk Tue May 8 11:15:06 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 8 11:16:44 2007 Subject: writing to /var/spool/MailScanner/incoming In-Reply-To: References: Message-ID: <46404DAA.9040900@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Why not just do another tmpfs mount somewhere else as well? It's quite reasonable in most circumstances to mount /tmp on tmpfs and then use a subdirectory of that. Mark Nienberg wrote: > I have /var/spool/MailScanner/incoming mounted as tmpfs. > > I have a mail related script (duplicate msg remover) that could > benefit from writing to tmpfs instead of physical disk. Is it OK for > my script to use some space in MailScanner/incoming or does > MailScanner only expect to see it's own stuff in there? > > Thanks, > Mark > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGQE3oEfZZRxQVtlQRAiRGAJ0dNjZyHdVEk98CQpBc6ttdXgui8wCfX3L8 8JEO9/ba0pBGIpFZ3BnUzG8= =+inB -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From hvdkooij at vanderkooij.org Tue May 8 13:19:08 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue May 8 13:19:39 2007 Subject: Error with SA 3.2.0 In-Reply-To: <46402F13.5090602@hostalia.com> References: <46402F13.5090602@hostalia.com> Message-ID: On Tue, 8 May 2007, Alvaro Mar?n wrote: > I've upgraded SA to 3.2.0 version and MailScanner doesn't check/deliver > messages. Running in debug mode, I get: > > ... > [31624] dbg: config: score set 3 chosen. > [31624] dbg: message: main message type: text/plain > [31624] dbg: message: ---- MIME PARSER START ---- > [31624] dbg: message: parsing normal part > [31624] dbg: message: ---- MIME PARSER END ---- > check: no loaded plugin implements 'check_main': cannot scan! at > /usr/lib/perl5/site_perl/5.8.7/Mail/SpamAssassin/PerMsgStatus.pm line 164. > Failed. > > Any idea about this? If I downgrade to SA 3.1.8 all runs fine I just did an update and noticed it did not work well. I then did run the -lint option through MailWatch. It showed 75 lines with scores no longer in use. Once I got rid of those I just needed to restart the proper service to get it all going. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From hvdkooij at vanderkooij.org Tue May 8 13:20:53 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue May 8 13:21:24 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: <223f97700705080127t2b5436e9m8fd50d8bbf481eb4@mail.gmail.com> References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> <463CAD50.3050806@ecs.soton.ac.uk> <463CB925.2050609@ecs.soton.ac.uk> <223f97700705080127t2b5436e9m8fd50d8bbf481eb4@mail.gmail.com> Message-ID: On Tue, 8 May 2007, Glenn Steen wrote: > It's not that we want you to be bored Jules, nor that we don't > appreciate the effort you make... We kind of want you to stick around > for the long run, more than giving the immediate fix... Essentially > see us as your virtual mother hens;-) Somehow I have a problem picturing Jules as a chick ;-) Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From MailScanner at ecs.soton.ac.uk Tue May 8 13:34:11 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 8 13:34:59 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> <463CAD50.3050806@ecs.soton.ac.uk> <463CB925.2050609@ecs.soton.ac.uk> <223f97700705080127t2b5436e9m8fd50d8bbf481eb4@mail.gmail.com> Message-ID: <46406E43.6040609@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hugo van der Kooij wrote: > On Tue, 8 May 2007, Glenn Steen wrote: > >> It's not that we want you to be bored Jules, nor that we don't >> appreciate the effort you make... We kind of want you to stick around >> for the long run, more than giving the immediate fix... Essentially >> see us as your virtual mother hens;-) > > Somehow I have a problem picturing Jules as a chick ;-) Quack? Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGQG5HEfZZRxQVtlQRApQqAKCs2RXY9MsliQFjSZnuUookEUq/fQCgh+wb szANL0FvwkGpcRuehWPwWos= =U17m -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From glenn.steen at gmail.com Tue May 8 13:48:47 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue May 8 13:48:51 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> <463CAD50.3050806@ecs.soton.ac.uk> <463CB925.2050609@ecs.soton.ac.uk> <223f97700705080127t2b5436e9m8fd50d8bbf481eb4@mail.gmail.com> Message-ID: <223f97700705080548w5738443fx175119f359a8766e@mail.gmail.com> On 08/05/07, Hugo van der Kooij wrote: > On Tue, 8 May 2007, Glenn Steen wrote: > > > It's not that we want you to be bored Jules, nor that we don't > > appreciate the effort you make... We kind of want you to stick around > > for the long run, more than giving the immediate fix... Essentially > > see us as your virtual mother hens;-) > > Somehow I have a problem picturing Jules as a chick ;-) > But not us others, Eh...? ... :-D Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Tue May 8 13:53:43 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue May 8 13:53:47 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: <46406E43.6040609@ecs.soton.ac.uk> References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> <463CAD50.3050806@ecs.soton.ac.uk> <463CB925.2050609@ecs.soton.ac.uk> <223f97700705080127t2b5436e9m8fd50d8bbf481eb4@mail.gmail.com> <46406E43.6040609@ecs.soton.ac.uk> Message-ID: <223f97700705080553q79f19096v7b0f704032014b6f@mail.gmail.com> On 08/05/07, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Hugo van der Kooij wrote: > > On Tue, 8 May 2007, Glenn Steen wrote: > > > >> It's not that we want you to be bored Jules, nor that we don't > >> appreciate the effort you make... We kind of want you to stick around > >> for the long run, more than giving the immediate fix... Essentially > >> see us as your virtual mother hens;-) > > > > Somehow I have a problem picturing Jules as a chick ;-) > Quack? Straight from chick to duck....I'm not sure exactly how to treat that typing ailment... Perhaps you've overindulged in infomercials, perhaps an overdose of West Wing... Best take to more and call us in the morning...:-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From root at doctor.nl2k.ab.ca Tue May 8 14:44:37 2007 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Tue May 8 14:51:21 2007 Subject: New 550s getting automagically placed into access file Message-ID: <20070508134436.GB29293@doctor.nl2k.ab.ca> I know there are 3 new packages out for MailScanner, spamd and clamd however I cannot determine with is adding to the /etc/mail/access file 550 We do not accept junk mail . I need to turn of this feature as it block transmission from secondary to primary. Also I am running Botnet 0.7 . -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From paul.hutchings at mira.co.uk Tue May 8 15:05:25 2007 From: paul.hutchings at mira.co.uk (Paul Hutchings) Date: Tue May 8 15:05:32 2007 Subject: Permissions to use Clamd with Postfix? Message-ID: As subject really, I'm a little confused. I'm running MailScanner with Postfix and would like to be able to use ClamD simply as I presume it's going to be faster than Clamscan. My "run as" user/group is Postfix. The permissions on /var/incoming/mail are postfix.postfix. What do I need to do to make MailScanner work with Clamd as at the moment when I try it I simply get an "/var/spool/MailScanner/incoming/14276/.: lstat() failed. ERROR" or similar. TIA, Paul Paul Hutchings Network Administrator, MIRA Ltd. Tel: 44 (0)24 7635 5378 Fax: 44 (0)24 7635 8378 mailto:paul.hutchings@mira.co.uk -- MIRA Ltd. Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. Registered in England No. 402570 VAT Registration GB 114 5409 96 The contents of this e-mail are confidential and are solely for the use of the intended recipient. If you receive this e-mail in error, please delete it and notify us either by e-mail, telephone or fax. You should not copy, forward or otherwise disclose the content of the e-mail as this is prohibited. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070508/cc997d31/attachment.html From uxbod at splatnix.net Tue May 8 15:10:39 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Tue May 8 15:10:45 2007 Subject: Permissions to use Clamd with Postfix? In-Reply-To: References: Message-ID: <71fd9958f73f0cdb9bc160af3e176412@62.49.223.244> Personally I added clamav to the postfix group. and also set the following in MailScanner.conf :- Incoming Work User = clamav Incoming Work Permissions = 0660 Seems to be running okay. On Tue, 8 May 2007 15:05:25 +0100, "Paul Hutchings" wrote: > As subject really, I'm a little confused. I'm running MailScanner with > Postfix and would like to be able to use ClamD simply as I presume it's > going to be faster than Clamscan. > > > > My "run as" user/group is Postfix. The permissions on > /var/incoming/mail are postfix.postfix. > > > > What do I need to do to make MailScanner work with Clamd as at the > moment when I try it I simply get an > "/var/spool/MailScanner/incoming/14276/.: lstat() failed. ERROR" or > similar. > > > > TIA, > > Paul > > > > Paul Hutchings > > Network Administrator, MIRA Ltd. > > Tel: 44 (0)24 7635 5378 > > Fax: 44 (0)24 7635 8378 > > mailto:paul.hutchings@mira.co.uk > > > > > -- > MIRA Ltd. > > Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. > > Registered in England No. 402570 > VAT Registration GB 114 5409 96 > > The contents of this e-mail are confidential and are solely for the use of > the intended recipient. > If you receive this e-mail in error, please delete it and notify us either > by e-mail, telephone or fax. > You should not copy, forward or otherwise disclose the content of the > e-mail as this is prohibited. > > > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From daniel.maher at ubisoft.com Tue May 8 15:14:30 2007 From: daniel.maher at ubisoft.com (Daniel Maher) Date: Tue May 8 15:14:33 2007 Subject: Permissions to use Clamd with Postfix? In-Reply-To: Message-ID: <1E293D3FF63A3740B10AD5AAD88535D204DC3453@UBIMAIL1.ubisoft.org> ________________________________________ From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Paul Hutchings Sent: May 8, 2007 10:05 AM To: MailScanner discussion Subject: Permissions to use Clamd with Postfix? As subject really, I'm a little confused.? I'm running MailScanner with Postfix and would like to be able to use ClamD simply as I presume it's going to be faster than Clamscan. My "run as" user/group is Postfix.? The permissions on /var/incoming/mail are postfix.postfix. What do I need to do to make MailScanner work with Clamd as at the moment when I try it I simply get an "/var/spool/MailScanner/incoming/14276/.: lstat() failed. ERROR" or similar. Clamd is likely running as user "clamav", which doesn't have read permissions for the incoming directory. ________________________________________ The solution is twofold: 1. Change your "run as" options to use to "postfix.clamav" 2. Change the ownership of incoming to postfix.clamav, and give it group read perms I had to setgid the incoming directory in order to make sure that the runtime dirs under incoming actually had their ownership set properly, but ymmv. Cheers! -- _ ?v? Daniel Maher /(_)\ Administrateur Syst?me Unix ^ ^ Unix System Administrator "How can a man choose between Fresh and Fly? And believe me, there IS a difference." - Crack Stuntman, 2007. From Richard.Frovarp at sendit.nodak.edu Tue May 8 15:21:40 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Tue May 8 15:21:44 2007 Subject: writing to /var/spool/MailScanner/incoming In-Reply-To: References: Message-ID: <46408774.1060606@sendit.nodak.edu> Mark Nienberg wrote: > I have /var/spool/MailScanner/incoming mounted as tmpfs. > > I have a mail related script (duplicate msg remover) that could > benefit from writing to tmpfs instead of physical disk. Is it OK for > my script to use some space in MailScanner/incoming or does > MailScanner only expect to see it's own stuff in there? > > Thanks, > Mark > Isn't this really dangerous? If you lose power or reboot the machine without an empty incoming queue, you will lose messages. To reboot you would have to stop the incoming mail process, let MailScanner clean out the queue, then reboot. Or am I missing something that would prevent you from losing messages? From ugob at lubik.ca Tue May 8 15:35:24 2007 From: ugob at lubik.ca (Ugo Bellavance) Date: Tue May 8 15:36:01 2007 Subject: New 550s getting automagically placed into access file In-Reply-To: <20070508134436.GB29293@doctor.nl2k.ab.ca> References: <20070508134436.GB29293@doctor.nl2k.ab.ca> Message-ID: Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem wrote: > I know there are 3 new packages out for MailScanner, spamd and clamd > however I cannot determine with is adding to the /etc/mail/access file > 550 We do not accept junk mail . > > I need to turn of this feature as it block transmission from secondary to primary. > > Also I am running Botnet 0.7 . > This is probably more a third-party program: Vispan. From lists at jfworks.net Tue May 8 15:41:48 2007 From: lists at jfworks.net (James) Date: Tue May 8 15:41:54 2007 Subject: New 550s getting automagically placed into access file In-Reply-To: <20070508134436.GB29293@doctor.nl2k.ab.ca> References: <20070508134436.GB29293@doctor.nl2k.ab.ca> Message-ID: <46408C2C.8070608@jfworks.net> Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem wrote: > I know there are 3 new packages out for MailScanner, spamd and clamd > however I cannot determine with is adding to the /etc/mail/access file > 550 We do not accept junk mail . > > I need to turn of this feature as it block transmission from secondary to primary. > > Also I am running Botnet 0.7 . > > As far as I know MailScanner doesn't write to the access file or at least has never in my case. From ugob at lubik.ca Tue May 8 15:43:12 2007 From: ugob at lubik.ca (Ugo Bellavance) Date: Tue May 8 15:43:50 2007 Subject: writing to /var/spool/MailScanner/incoming In-Reply-To: <46408774.1060606@sendit.nodak.edu> References: <46408774.1060606@sendit.nodak.edu> Message-ID: Richard Frovarp wrote: > > Isn't this really dangerous? If you lose power or reboot the machine > without an empty incoming queue, you will lose messages. To reboot you > would have to stop the incoming mail process, let MailScanner clean out > the queue, then reboot. Or am I missing something that would prevent you > from losing messages? Messages stays in the MTA inbound queue until processed. They are copied to /var/spool/MailScanner/incoming, processed and it is copied to the outbound MTA queue once processed. Once copied in the outbount queue, it is deleted from the inbound queue. I think this is in the MAQ... ugo From Richard.Frovarp at sendit.nodak.edu Tue May 8 15:51:04 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Tue May 8 15:51:07 2007 Subject: writing to /var/spool/MailScanner/incoming In-Reply-To: References: <46408774.1060606@sendit.nodak.edu> Message-ID: <46408E58.2000800@sendit.nodak.edu> Ugo Bellavance wrote: > Richard Frovarp wrote: >> >> Isn't this really dangerous? If you lose power or reboot the machine >> without an empty incoming queue, you will lose messages. To reboot >> you would have to stop the incoming mail process, let MailScanner >> clean out the queue, then reboot. Or am I missing something that >> would prevent you from losing messages? > > Messages stays in the MTA inbound queue until processed. They are > copied to /var/spool/MailScanner/incoming, processed and it is copied > to the outbound MTA queue once processed. Once copied in the outbount > queue, it is deleted from the inbound queue. > > I think this is in the MAQ... > > ugo > Right and if /var/spool/MailScanner/incoming is in tempfs, the only place it exists is in RAM. The state of RAM goes away during reboot or power loss. Hence it is really dangerous to have incoming in tempfs. If that queue isn't empty when the state is lost, messages will be lost. From mkercher at nfsmith.com Tue May 8 15:52:01 2007 From: mkercher at nfsmith.com (Mike Kercher) Date: Tue May 8 15:55:44 2007 Subject: writing to /var/spool/MailScanner/incoming References: <46408774.1060606@sendit.nodak.edu> <46408E58.2000800@sendit.nodak.edu> Message-ID: <6DEF8ABC1767C045B91F42066D36358E3AF6@HOUPEX01.nfsmith.info> Richard Frovarp <> wrote on Tuesday, May 08, 2007 9:51 AM: : Ugo Bellavance wrote: :: Richard Frovarp wrote: ::: ::: Isn't this really dangerous? If you lose power or reboot the machine ::: without an empty incoming queue, you will lose messages. To reboot ::: you would have to stop the incoming mail process, let MailScanner ::: clean out the queue, then reboot. Or am I missing something that ::: would prevent you from losing messages? :: :: Messages stays in the MTA inbound queue until processed. They are :: copied to /var/spool/MailScanner/incoming, processed and it is copied :: to the outbound MTA queue once processed. Once copied in the :: outbount queue, it is deleted from the inbound queue. :: :: I think this is in the MAQ... :: :: ugo :: : Right and if /var/spool/MailScanner/incoming is in tempfs, the only : place it exists is in RAM. The state of RAM goes away during reboot : or power loss. Hence it is really dangerous to have incoming in : tempfs. If that queue isn't empty when the state is lost, messages : will be lost. I think he's talking about /var/spool/mqueue.in -Mike From paul.hutchings at mira.co.uk Tue May 8 16:00:46 2007 From: paul.hutchings at mira.co.uk (Paul Hutchings) Date: Tue May 8 16:00:54 2007 Subject: Permissions to use Clamd with Postfix? References: <1E293D3FF63A3740B10AD5AAD88535D204DC3453@UBIMAIL1.ubisoft.org> Message-ID: Ok so two answers two methods. Who's right? :-) Paul Hutchings Network Administrator, MIRA Ltd. Tel: 44 (0)24 7635 5378 Fax: 44 (0)24 7635 8378 mailto:paul.hutchings@mira.co.uk -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Daniel Maher Sent: 08 May 2007 15:15 To: MailScanner discussion Subject: RE: Permissions to use Clamd with Postfix? ________________________________________ From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Paul Hutchings Sent: May 8, 2007 10:05 AM To: MailScanner discussion Subject: Permissions to use Clamd with Postfix? As subject really, I'm a little confused.? I'm running MailScanner with Postfix and would like to be able to use ClamD simply as I presume it's going to be faster than Clamscan. My "run as" user/group is Postfix.? The permissions on /var/incoming/mail are postfix.postfix. What do I need to do to make MailScanner work with Clamd as at the moment when I try it I simply get an "/var/spool/MailScanner/incoming/14276/.: lstat() failed. ERROR" or similar. Clamd is likely running as user "clamav", which doesn't have read permissions for the incoming directory. ________________________________________ The solution is twofold: 1. Change your "run as" options to use to "postfix.clamav" 2. Change the ownership of incoming to postfix.clamav, and give it group read perms I had to setgid the incoming directory in order to make sure that the runtime dirs under incoming actually had their ownership set properly, but ymmv. Cheers! -- _ ?v? Daniel Maher /(_)\ Administrateur Syst?me Unix ^ ^ Unix System Administrator "How can a man choose between Fresh and Fly? And believe me, there IS a difference." - Crack Stuntman, 2007. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MIRA Ltd. Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. Registered in England No. 402570 VAT Registration GB 114 5409 96 The contents of this e-mail are confidential and are solely for the use of the intended recipient. If you receive this e-mail in error, please delete it and notify us either by e-mail, telephone or fax. You should not copy, forward or otherwise disclose the content of the e-mail as this is prohibited. From rcooper at dwford.com Tue May 8 16:01:16 2007 From: rcooper at dwford.com (Rick Cooper) Date: Tue May 8 16:01:21 2007 Subject: writing to /var/spool/MailScanner/incoming In-Reply-To: <46408E58.2000800@sendit.nodak.edu> References: <46408774.1060606@sendit.nodak.edu> <46408E58.2000800@sendit.nodak.edu> Message-ID: <0ced01c79181$babd3800$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Richard Frovarp > Sent: Tuesday, May 08, 2007 10:51 AM > To: MailScanner discussion > Subject: Re: writing to /var/spool/MailScanner/incoming > > Ugo Bellavance wrote: > > Richard Frovarp wrote: > >> > >> Isn't this really dangerous? If you lose power or reboot > the machine > >> without an empty incoming queue, you will lose messages. To reboot > >> you would have to stop the incoming mail process, let MailScanner > >> clean out the queue, then reboot. Or am I missing something that > >> would prevent you from losing messages? > > > > Messages stays in the MTA inbound queue until processed. They are > > copied to /var/spool/MailScanner/incoming, processed and it > is copied > > to the outbound MTA queue once processed. Once copied in > the outbount > > queue, it is deleted from the inbound queue. > > > > I think this is in the MAQ... > > > > ugo > > > Right and if /var/spool/MailScanner/incoming is in tempfs, the only > place it exists is in RAM. The state of RAM goes away during > reboot or > power loss. Hence it is really dangerous to have incoming in > tempfs. If > that queue isn't empty when the state is lost, messages will be lost. > -- Only half correct. The MailScanner queue is lost but the MTA queue is still intact. When MailScanner restarts it will process all the MTA's queue again so everything lost in the MailScanner working dir is rebuilt anyway. Nothing in the MTA queue is touched until it's in the MTA outbound queue. Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From daniel.maher at ubisoft.com Tue May 8 16:06:26 2007 From: daniel.maher at ubisoft.com (Daniel Maher) Date: Tue May 8 16:06:28 2007 Subject: Permissions to use Clamd with Postfix? In-Reply-To: Message-ID: <1E293D3FF63A3740B10AD5AAD88535D204DC3577@UBIMAIL1.ubisoft.org> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Paul Hutchings > Sent: May 8, 2007 11:01 AM > To: MailScanner discussion > Subject: RE: Permissions to use Clamd with Postfix? > > Ok so two answers two methods. Who's right? :-) Thanks to the swiss-army-knife style of Linux, we're both correct. There are likely even other options. :P -- _ ?v? Daniel Maher /(_)\ Administrateur Syst?me Unix ^ ^ Unix System Administrator "How can a man choose between Fresh and Fly? And believe me, there IS a difference." - Crack Stuntman, 2007. From Richard.Frovarp at sendit.nodak.edu Tue May 8 16:06:54 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Tue May 8 16:06:57 2007 Subject: writing to /var/spool/MailScanner/incoming In-Reply-To: <6DEF8ABC1767C045B91F42066D36358E3AF6@HOUPEX01.nfsmith.info> References: <46408774.1060606@sendit.nodak.edu> <46408E58.2000800@sendit.nodak.edu> <6DEF8ABC1767C045B91F42066D36358E3AF6@HOUPEX01.nfsmith.info> Message-ID: <4640920E.5080801@sendit.nodak.edu> Mike Kercher wrote: > Richard Frovarp <> wrote on Tuesday, May 08, 2007 9:51 AM: > > : Ugo Bellavance wrote: > :: Richard Frovarp wrote: > ::: > ::: Isn't this really dangerous? If you lose power or reboot the machine > ::: without an empty incoming queue, you will lose messages. To reboot > ::: you would have to stop the incoming mail process, let MailScanner > ::: clean out the queue, then reboot. Or am I missing something that > ::: would prevent you from losing messages? > :: > :: Messages stays in the MTA inbound queue until processed. They are > :: copied to /var/spool/MailScanner/incoming, processed and it is copied > :: to the outbound MTA queue once processed. Once copied in the > :: outbount queue, it is deleted from the inbound queue. > :: > :: I think this is in the MAQ... > :: > :: ugo > :: > : Right and if /var/spool/MailScanner/incoming is in tempfs, the only > : place it exists is in RAM. The state of RAM goes away during reboot > : or power loss. Hence it is really dangerous to have incoming in > : tempfs. If that queue isn't empty when the state is lost, messages > : will be lost. > > I think he's talking about /var/spool/mqueue.in > > -Mike > Yeah, that's what I was thinking of. Sorry. More sleep would be good. Richard From root at doctor.nl2k.ab.ca Tue May 8 16:00:22 2007 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Tue May 8 16:07:13 2007 Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically placed into access file] Message-ID: <20070508150022.GA20343@doctor.nl2k.ab.ca> I have to resend this as I found in my logs the mailscanner.info mailserver got listed as below. ----- Forwarded message from "Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem" ----- Date: Tue, 8 May 2007 07:44:36 -0600 From: "Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem" To: mailscanner@lists.mailscanner.info Subject: New 550s getting automagically placed into access file User-Agent: Mutt/1.5.12-2006-07-14 I know there are 3 new packages out for MailScanner, spamd and clamd however I cannot determine with is adding to the /etc/mail/access file 550 We do not accept junk mail . I need to turn of this feature as it block transmission from secondary to primary. Also I am running Botnet 0.7 . ----- End forwarded message ----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From martinh at solidstatelogic.com Tue May 8 16:27:29 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Tue May 8 16:27:43 2007 Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically placed into access file] In-Reply-To: <20070508150022.GA20343@doctor.nl2k.ab.ca> Message-ID: Dave There's a CustomFunction called IPBlock that will update this list based on number of messages received from an ip-address..... Normally it's attached to "Always Looked Up Last" in the following manner inside MailScanner.conf.. Always Looked Up Last = &IPBlock -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Dave Shariff Yadallee - > System Administrator a.k.a. The Root of the Problem > Sent: 08 May 2007 16:00 > To: mailscanner@lists.mailscanner.info > Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically placed > into access file] > > I have to resend this as I found in my logs the mailscanner.info > mailserver > got listed as below. > > ----- Forwarded message from "Dave Shariff Yadallee - System > Administrator a.k.a. The Root of the Problem" --- > -- > > Date: Tue, 8 May 2007 07:44:36 -0600 > From: "Dave Shariff Yadallee - System Administrator a.k.a. The Root of > the Problem" > To: mailscanner@lists.mailscanner.info > Subject: New 550s getting automagically placed into access file > User-Agent: Mutt/1.5.12-2006-07-14 > > I know there are 3 new packages out for MailScanner, spamd and clamd > however I cannot determine with is adding to the /etc/mail/access file > 550 We do not accept junk mail . > > I need to turn of this feature as it block transmission from secondary to > primary. > > Also I am running Botnet 0.7 . > > ----- End forwarded message ----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From root at doctor.nl2k.ab.ca Tue May 8 16:29:18 2007 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Tue May 8 16:33:06 2007 Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically placed into access file] In-Reply-To: References: <20070508150022.GA20343@doctor.nl2k.ab.ca> Message-ID: <20070508152917.GA736@doctor.nl2k.ab.ca> On Tue, May 08, 2007 at 04:27:29PM +0100, Martin.Hepworth wrote: > Dave > > There's a CustomFunction called IPBlock that will update this list based > on number of messages received from an ip-address..... > > Normally it's attached to "Always Looked Up Last" in the following > manner inside MailScanner.conf.. > > Always Looked Up Last = &IPBlock > > My setting is: Always Looked Up Last = no > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Dave Shariff Yadallee - > > System Administrator a.k.a. The Root of the Problem > > Sent: 08 May 2007 16:00 > > To: mailscanner@lists.mailscanner.info > > Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically > placed > > into access file] > > > > I have to resend this as I found in my logs the mailscanner.info > > mailserver > > got listed as below. > > > > ----- Forwarded message from "Dave Shariff Yadallee - System > > Administrator a.k.a. The Root of the Problem" > --- > > -- > > > > Date: Tue, 8 May 2007 07:44:36 -0600 > > From: "Dave Shariff Yadallee - System Administrator a.k.a. The Root > of > > the Problem" > > To: mailscanner@lists.mailscanner.info > > Subject: New 550s getting automagically placed into access file > > User-Agent: Mutt/1.5.12-2006-07-14 > > > > I know there are 3 new packages out for MailScanner, spamd and clamd > > however I cannot determine with is adding to the /etc/mail/access file > > 550 We do not accept junk mail . > > > > I need to turn of this feature as it block transmission from secondary > to > > primary. > > > > Also I am running Botnet 0.7 . > > > > ----- End forwarded message ----- > > > > -- > > This message has been scanned for viruses and > > dangerous content by MailScanner, and is > > believed to be clean. > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > From root at doctor.nl2k.ab.ca Tue May 8 16:48:12 2007 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Tue May 8 16:56:34 2007 Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically placed into access file] In-Reply-To: References: <20070508150022.GA20343@doctor.nl2k.ab.ca> Message-ID: <20070508154810.GA7356@doctor.nl2k.ab.ca> On Tue, May 08, 2007 at 04:27:29PM +0100, Martin.Hepworth wrote: > Dave > > There's a CustomFunction called IPBlock that will update this list based > on number of messages received from an ip-address..... > > Normally it's attached to "Always Looked Up Last" in the following > manner inside MailScanner.conf.. > > Always Looked Up Last = &IPBlock > As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: As I said this is set to no; however, when I did a tail on /etc/mail/acess I got: 66.220.2.220 550 Persistent Virus Source 212.122.114.249 550 Persistent Virus Source 85.68.131.183 550 Persistent Virus Source 69.11.213.106 550 Persistent Virus Source 66.201.40.102 550 Persistent Virus Source 85.2.209.213 550 Persistent Virus Source 83.112.32.94 550 Persistent Virus Source 200.62.150.49 550 We do not accept junk mail 89.24.82.141 550 We do not accept junk mail All that has changed recently is clamd from 0.88.7 to 0.90.2 spamd from 3.1.X to 3.2.0 and MailScanner 4.58.9 to 4.59.4-2 just this weekend. I would like to turn off the 550 We do not accept junk mail feature as I would term it to be buggy, however the Presistent Virus Source can stay for now; get rid of the fraud/Virus mail thank you. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Dave Shariff Yadallee - > > System Administrator a.k.a. The Root of the Problem > > Sent: 08 May 2007 16:00 > > To: mailscanner@lists.mailscanner.info > > Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically > placed > > into access file] > > > > I have to resend this as I found in my logs the mailscanner.info > > mailserver > > got listed as below. > > > > ----- Forwarded message from "Dave Shariff Yadallee - System > > Administrator a.k.a. The Root of the Problem" > --- > > -- > > > > Date: Tue, 8 May 2007 07:44:36 -0600 > > From: "Dave Shariff Yadallee - System Administrator a.k.a. The Root > of > > the Problem" > > To: mailscanner@lists.mailscanner.info > > Subject: New 550s getting automagically placed into access file > > User-Agent: Mutt/1.5.12-2006-07-14 > > > > I know there are 3 new packages out for MailScanner, spamd and clamd > > however I cannot determine with is adding to the /etc/mail/access file > > 550 We do not accept junk mail . > > > > I need to turn of this feature as it block transmission from secondary > to > > primary. > > > > Also I am running Botnet 0.7 . > > > > ----- End forwarded message ----- > > > > -- > > This message has been scanned for viruses and > > dangerous content by MailScanner, and is > > believed to be clean. > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From mkercher at nfsmith.com Tue May 8 17:06:46 2007 From: mkercher at nfsmith.com (Mike Kercher) Date: Tue May 8 17:10:33 2007 Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically placedinto access file] References: <20070508150022.GA20343@doctor.nl2k.ab.ca> <20070508154810.GA7356@doctor.nl2k.ab.ca> Message-ID: <6DEF8ABC1767C045B91F42066D36358E3AF7@HOUPEX01.nfsmith.info> Dave Shariff Yadallee - System Administrator a.k.a. The Root of theProblem <> wrote on Tuesday, May 08, 2007 10:48 AM: : On Tue, May 08, 2007 at 04:27:29PM +0100, Martin.Hepworth wrote: :: Dave :: :: There's a CustomFunction called IPBlock that will update this list :: based on number of messages received from an ip-address..... :: :: Normally it's attached to "Always Looked Up Last" in the following :: manner inside MailScanner.conf.. :: :: Always Looked Up Last = &IPBlock :: : : : : : As I said this is set to no; : however, when I did a tail on /etc/mail/acess I got: : : : 66.220.2.220 550 Persistent Virus Source : 212.122.114.249 550 Persistent Virus Source : 85.68.131.183 550 Persistent Virus Source : 69.11.213.106 550 Persistent Virus Source : 66.201.40.102 550 Persistent Virus Source : 85.2.209.213 550 Persistent Virus Source : 83.112.32.94 550 Persistent Virus Source : 200.62.150.49 550 We do not accept junk mail : 89.24.82.141 550 We do not accept junk mail : : : All that has changed recently is : : clamd from 0.88.7 to 0.90.2 : spamd from 3.1.X to 3.2.0 : : and : : MailScanner 4.58.9 to 4.59.4-2 just this weekend. : : : I would like to turn off the 550 We do not accept junk mail : feature as I would term it to be buggy, however the : Presistent Virus Source can stay for now; get rid of the fraud/Virus : mail thank you. : :: :: -- :: Martin Hepworth :: Snr Systems Administrator :: Solid State Logic :: Tel: +44 (0)1865 842300 :: ::: -----Original Message----- ::: From: mailscanner-bounces@lists.mailscanner.info ::: [mailto:mailscanner- bounces@lists.mailscanner.info] On Behalf Of ::: Dave Shariff Yadallee - System Administrator a.k.a. The Root of the ::: Problem ::: Sent: 08 May 2007 16:00 ::: To: mailscanner@lists.mailscanner.info ::: Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically ::: placed into access file] ::: ::: I have to resend this as I found in my logs the mailscanner.info ::: mailserver got listed as below. ::: ::: ----- Forwarded message from "Dave Shariff Yadallee - System ::: Administrator a.k.a. The Root of the Problem" ::: --- -- ::: ::: Date: Tue, 8 May 2007 07:44:36 -0600 ::: From: "Dave Shariff Yadallee - System Administrator a.k.a. The ::: Root of the Problem" ::: To: mailscanner@lists.mailscanner.info ::: Subject: New 550s getting automagically placed into access file ::: User-Agent: Mutt/1.5.12-2006-07-14 ::: ::: I know there are 3 new packages out for MailScanner, spamd and clamd ::: however I cannot determine with is adding to the /etc/mail/access ::: file 550 We do not accept junk mail . ::: ::: I need to turn of this feature as it block transmission from ::: secondary to primary. ::: ::: Also I am running Botnet 0.7 . ::: ::: ----- End forwarded message ----- Are you running Vispan? -Mike From amaclach at yahoo.co.uk Tue May 8 17:35:19 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Tue May 8 17:35:21 2007 Subject: Permissions to use Clamd with Postfix? Message-ID: <892920.61461.qm@web26309.mail.ukl.yahoo.com> You can also chmod 755 /var/spool/MailScanner and MailScanner/incoming. The correct answer is the one that works. ----- Original Message ---- From: Paul Hutchings To: MailScanner discussion Sent: Tuesday, 8 May, 2007 4:00:46 PM Subject: RE: Permissions to use Clamd with Postfix? Ok so two answers two methods. Who's right? :-) Paul Hutchings Network Administrator, MIRA Ltd. Tel: 44 (0)24 7635 5378 Fax: 44 (0)24 7635 8378 mailto:paul.hutchings@mira.co.uk -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Daniel Maher Sent: 08 May 2007 15:15 To: MailScanner discussion Subject: RE: Permissions to use Clamd with Postfix? ________________________________________ From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Paul Hutchings Sent: May 8, 2007 10:05 AM To: MailScanner discussion Subject: Permissions to use Clamd with Postfix? As subject really, I'm a little confused. I'm running MailScanner with Postfix and would like to be able to use ClamD simply as I presume it's going to be faster than Clamscan. My "run as" user/group is Postfix. The permissions on /var/incoming/mail are postfix.postfix. What do I need to do to make MailScanner work with Clamd as at the moment when I try it I simply get an "/var/spool/MailScanner/incoming/14276/.: lstat() failed. ERROR" or similar. Clamd is likely running as user "clamav", which doesn't have read permissions for the incoming directory. ________________________________________ The solution is twofold: 1. Change your "run as" options to use to "postfix.clamav" 2. Change the ownership of incoming to postfix.clamav, and give it group read perms I had to setgid the incoming directory in order to make sure that the runtime dirs under incoming actually had their ownership set properly, but ymmv. Cheers! -- _ ?v? Daniel Maher /(_)\ Administrateur Syst?me Unix ^ ^ Unix System Administrator "How can a man choose between Fresh and Fly? And believe me, there IS a difference." - Crack Stuntman, 2007. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MIRA Ltd. Watling Street, Nuneaton, Warwickshire, CV10 0TU, England. Registered in England No. 402570 VAT Registration GB 114 5409 96 The contents of this e-mail are confidential and are solely for the use of the intended recipient. If you receive this e-mail in error, please delete it and notify us either by e-mail, telephone or fax. You should not copy, forward or otherwise disclose the content of the e-mail as this is prohibited. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Tue May 8 17:50:48 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 8 17:52:10 2007 Subject: writing to /var/spool/MailScanner/incoming In-Reply-To: <46408774.1060606@sendit.nodak.edu> References: <46408774.1060606@sendit.nodak.edu> Message-ID: <4640AA68.8050305@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Richard Frovarp wrote: > Mark Nienberg wrote: >> I have /var/spool/MailScanner/incoming mounted as tmpfs. >> >> I have a mail related script (duplicate msg remover) that could >> benefit from writing to tmpfs instead of physical disk. Is it OK for >> my script to use some space in MailScanner/incoming or does >> MailScanner only expect to see it's own stuff in there? >> >> Thanks, >> Mark >> > > Isn't this really dangerous? If you lose power or reboot the machine > without an empty incoming queue, you will lose messages. To reboot you > would have to stop the incoming mail process, let MailScanner clean > out the queue, then reboot. Or am I missing something that would > prevent you from losing messages? It is perfectly safe. The name "incoming" is probably not the best thing I could have called it, with hindsight. It is actually the working directory used by MailScanner while it is in the middle of processing the messages. There is always either (a) a copy in mqueue.in or (b) a copy in mqueue.in and mqueue or (c) a copy in mqueue. There is no time at which there is no copy on disk. There is *always* a copy on a disk-based filesystem, so it is perfectly safe. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGQKqcEfZZRxQVtlQRAlOPAJoD45xf592WtAT/vgtZO1JsTlSdTgCgr5eh RJVrQFW4ZjdsiRAK1OJ2JDA= =qbRN -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From list-mailscanner at linguaphone.com Tue May 8 18:33:06 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue May 8 18:33:14 2007 Subject: FuzzyOcr customisations Message-ID: Thought people might be interested in the forum at http://www.freespamfilter.org/forum/viewforum.php?f=25 where there are some good tips for customising FuzzyOcr. Today I have also had a stab at creating an image utility which can be added to a scanset to hopefully improve its detection. Basically it works by producing a grayscale image which contains the differences between a pixel and the average colour over the whole image (rgb calculated separately) You can see a couple of examples and download and have a play with it yourself on my webpage at http://www.gbnetwork.co.uk/mailscanner/gbpgmdiff/ It is still very much a work in progress and I haven't even got round to putting it into one of my scansets yet. From hvdkooij at vanderkooij.org Tue May 8 18:54:22 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue May 8 18:54:55 2007 Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically placed into access file] In-Reply-To: <20070508154810.GA7356@doctor.nl2k.ab.ca> References: <20070508150022.GA20343@doctor.nl2k.ab.ca> <20070508154810.GA7356@doctor.nl2k.ab.ca> Message-ID: On Tue, 8 May 2007, Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem wrote: > On Tue, May 08, 2007 at 04:27:29PM +0100, Martin.Hepworth wrote: >> Dave >> >> There's a CustomFunction called IPBlock that will update this list based >> on number of messages received from an ip-address..... >> >> Normally it's attached to "Always Looked Up Last" in the following >> manner inside MailScanner.conf.. >> >> Always Looked Up Last = &IPBlock >> > > As I said this is set to no; > however, when I did a tail on /etc/mail/acess I got: > > > > As I said this is set to no; > however, when I did a tail on /etc/mail/acess I got: > > > > As I said this is set to no; > however, when I did a tail on /etc/mail/acess I got: ..... (Zillion more of these removed) I am not exactly what is happening on your system. But I would start scanning for other roots. I have strong reservations if someone starts to send email as root. To troubleshoot the issue I would round up the usual suspects and start grepping some files for the exact string. Then I would set the file readonly to see who is complaining. I think with these two steps you should have a reasonable chang to find out who is adding the entries. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From ssilva at sgvwater.com Tue May 8 19:03:44 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 8 19:04:25 2007 Subject: SpamAssassin 3.2.0 package In-Reply-To: <223f97700705080127t2b5436e9m8fd50d8bbf481eb4@mail.gmail.com> References: <463C6D8E.5040802@ecs.soton.ac.uk> <463C9E7C.7040600@protos.mine.nu> <463CAD50.3050806@ecs.soton.ac.uk> <463CB925.2050609@ecs.soton.ac.uk> <223f97700705080127t2b5436e9m8fd50d8bbf481eb4@mail.gmail.com> Message-ID: Glenn Steen spake the following on 5/8/2007 1:27 AM: > On 08/05/07, Scott Silva wrote: >> Julian Field spake the following on 5/5/2007 10:04 AM: >> > I have done some basic tests with my SpamAssassin 3.2.0 package and >> > MailScanner 4.59 and it is working fine. >> > >> > I'll do some more tests of it and probably start using it on a >> > production machine tomorrow if I feel so inclined (and there again I >> > might well just put my feet up and watch TV). It's a public holiday >> this >> > weekend (I think!) so by definition it should rain on Monday at >> least. :-) >> > >> > Jules. >> I hope you voted for putting your feet up and watching the TV!! ;-P > You are not alone in hoping that Scott! > It's not that we want you to be bored Jules, nor that we don't > appreciate the effort you make... We kind of want you to stick around > for the long run, more than giving the immediate fix... Essentially > see us as your virtual mother hens;-) > And he never calls! How about some nice chicken soup! ;-) -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Tue May 8 19:08:38 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 8 19:10:18 2007 Subject: SMPID vs. INPID In-Reply-To: <005b01c79105$617db200$5e01a8c0@AldenLap> References: <005b01c79105$617db200$5e01a8c0@AldenLap> Message-ID: Alden Levy spake the following on 5/7/2007 5:11 PM: > I'm still scratching my head over this one. Would someone with a Redhat > install please post the relevant lines of their MailScanner_app_init, so I > can compare it to mine? > Here are the init scripts for RedHat and SUSE as given to me by Julian yesterday. Maybe you can find what is wrong with yours. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! -------------- next part -------------- A non-text attachment was scrubbed... Name: init.scripts.tgz Type: application/x-compressed Size: 4188 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070508/499cdc91/init.scripts.bin From ssilva at sgvwater.com Tue May 8 19:13:27 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 8 19:15:14 2007 Subject: Interesting need In-Reply-To: References: <463F0518.65ED.00A2.0@plattesheriff.org> <463F5C10.7080307@ecs.soton.ac.uk> <463F7783.7070608@nkpanama.com> <463F822E.2010108@ecs.soton.ac.uk> <223f97700705071442w106785bu1a9a50405476f9cb@mail.gmail.com> Message-ID: Res spake the following on 5/7/2007 4:52 PM: > On Mon, 7 May 2007, Scott Silva wrote: > >> I think the archive mail option would be for those organizations that are >> required to keep "everything" that crosses their gateway. So unless >> you can > > Not to mention for obtaining copies of mail sent from/to a norti user > that the feds have an interest in :) and with the forwarding ability > they get it all in real time. > > > I really have to hope that I don't ever have that problem. Besides, the feds can set up a Carnivore and get everything they want anyway. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Tue May 8 19:17:41 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 8 19:20:30 2007 Subject: Automated Reply from ittsl01 In-Reply-To: References: <200705080403.l4843VtQ016175@server30055.uk2net.com> <463FC376.6020103@evi-inc.com> Message-ID: Drew Marshall spake the following on 5/8/2007 1:10 AM: > On 8 May 2007, at 01:25, Matt Kettler wrote: > >> ittsl01 wrote: >>> ITTSL is out of the office until 14th May on Business in Europe. If >>> you require urgent assistance, please a problem ticket at >>> http://www.ittsl.net and we will respond to as soon as possible. Many >>> Thanks. >> >> Hmm, should we ALL go and open tickets? :) > > It IS tempting... > > Dear problem dept > > How do I set my out of office up? > > Regards ... > > :-) Not going to get a good answer for that one IMHO! ;-P -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From alden at engineno9inc.com Tue May 8 19:34:28 2007 From: alden at engineno9inc.com (Alden Levy) Date: Tue May 8 19:34:42 2007 Subject: SMPID vs. INPID Message-ID: <002101c7919f$83cb39f0$5a01a8c0@AldenLap> Scott Silva wrote the following on Tue May 8 19:08:38 IST 2007 >Alden Levy spake the following on 5/7/2007 5:11 PM: >> I'm still scratching my head over this one. Would someone with a Redhat >> install please post the relevant lines of their MailScanner_app_init, so I >> can compare it to mine? >> >Here are the init scripts for RedHat and SUSE as given to me by Julian yesterday. > Maybe you can find what is wrong with yours. > >-- > >MailScanner is like deodorant... >You hope everybody uses it, and >you notice quickly if they don't!!!! >-------------- next part -------------- >A non-text attachment was scrubbed... >Name: init.scripts.tgz >Type: application/x-compressed >Size: 4188 bytes >Desc: not available >Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070508/499 cdc91/init.scripts.bin Thanks for this. Now, I'm really confused; the RedHat init script is identical to the one I'm using. Does anyone have an idea of where else I should look? (Quick recap: /var/run/sendmail.in.pid is not getting updated, so /etc/init.d/MailScanner status lists incoming sendmail as failed. sm-client.pid looks fine, though.) Thanks, Alden From root at doctor.nl2k.ab.ca Tue May 8 19:36:53 2007 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Tue May 8 19:41:31 2007 Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically placedinto access file] In-Reply-To: <6DEF8ABC1767C045B91F42066D36358E3AF7@HOUPEX01.nfsmith.info> References: <20070508154810.GA7356@doctor.nl2k.ab.ca> <6DEF8ABC1767C045B91F42066D36358E3AF7@HOUPEX01.nfsmith.info> Message-ID: <20070508183652.GA26936@doctor.nl2k.ab.ca> On Tue, May 08, 2007 at 11:06:46AM -0500, Mike Kercher wrote: > Dave Shariff Yadallee - System Administrator a.k.a. The Root of > theProblem <> wrote on Tuesday, May 08, 2007 10:48 AM: > > : On Tue, May 08, 2007 at 04:27:29PM +0100, Martin.Hepworth wrote: > :: Dave > :: > :: There's a CustomFunction called IPBlock that will update this list > :: based on number of messages received from an ip-address..... > :: > :: Normally it's attached to "Always Looked Up Last" in the following > :: manner inside MailScanner.conf.. > :: > :: Always Looked Up Last = &IPBlock > :: > : > > : > : > : > : As I said this is set to no; > : however, when I did a tail on /etc/mail/acess I got: > : > : > : 66.220.2.220 550 Persistent Virus Source > : 212.122.114.249 550 Persistent Virus Source > : 85.68.131.183 550 Persistent Virus Source > : 69.11.213.106 550 Persistent Virus Source > : 66.201.40.102 550 Persistent Virus Source > : 85.2.209.213 550 Persistent Virus Source > : 83.112.32.94 550 Persistent Virus Source > : 200.62.150.49 550 We do not accept junk mail > : 89.24.82.141 550 We do not accept junk mail > : > : > : All that has changed recently is > : > : clamd from 0.88.7 to 0.90.2 > : spamd from 3.1.X to 3.2.0 > : > : and > : > : MailScanner 4.58.9 to 4.59.4-2 just this weekend. > : > : > : I would like to turn off the 550 We do not accept junk mail > : feature as I would term it to be buggy, however the > : Presistent Virus Source can stay for now; get rid of the fraud/Virus > : mail thank you. > : > :: > :: -- > :: Martin Hepworth > :: Snr Systems Administrator > :: Solid State Logic > :: Tel: +44 (0)1865 842300 > :: > ::: -----Original Message----- > ::: From: mailscanner-bounces@lists.mailscanner.info > ::: [mailto:mailscanner- bounces@lists.mailscanner.info] On Behalf Of > ::: Dave Shariff Yadallee - System Administrator a.k.a. The Root of the > ::: Problem > ::: Sent: 08 May 2007 16:00 > ::: To: mailscanner@lists.mailscanner.info > ::: Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically > ::: placed into access file] > ::: > ::: I have to resend this as I found in my logs the mailscanner.info > ::: mailserver got listed as below. > ::: > ::: ----- Forwarded message from "Dave Shariff Yadallee - System > ::: Administrator a.k.a. The Root of the Problem" > ::: --- -- > ::: > ::: Date: Tue, 8 May 2007 07:44:36 -0600 > ::: From: "Dave Shariff Yadallee - System Administrator a.k.a. The > ::: Root of the Problem" > ::: To: mailscanner@lists.mailscanner.info > ::: Subject: New 550s getting automagically placed into access file > ::: User-Agent: Mutt/1.5.12-2006-07-14 > ::: > ::: I know there are 3 new packages out for MailScanner, spamd and clamd > ::: however I cannot determine with is adding to the /etc/mail/access > ::: file 550 We do not accept junk mail . > ::: > ::: I need to turn of this feature as it block transmission from > ::: secondary to primary. > ::: > ::: Also I am running Botnet 0.7 . > ::: > ::: ----- End forwarded message ----- > > Are you running Vispan? > Yes Vispan 3.0 > -Mike > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From hvdkooij at vanderkooij.org Tue May 8 20:09:32 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue May 8 20:10:06 2007 Subject: SMPID vs. INPID In-Reply-To: <002101c7919f$83cb39f0$5a01a8c0@AldenLap> References: <002101c7919f$83cb39f0$5a01a8c0@AldenLap> Message-ID: On Tue, 8 May 2007, Alden Levy wrote: > Thanks for this. Now, I'm really confused; the RedHat init script is > identical to the one I'm using. > > Does anyone have an idea of where else I should look? (Quick recap: > /var/run/sendmail.in.pid is not getting updated, so /etc/init.d/MailScanner > status lists incoming sendmail as failed. sm-client.pid looks fine, > though.) If you stop MailScanner the PID file should be gone. If not then you should remove it by hand and see if it happens to get recreated at startup. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From alden at engineno9inc.com Tue May 8 20:16:08 2007 From: alden at engineno9inc.com (Alden Levy) Date: Tue May 8 20:16:23 2007 Subject: SMPID vs. INPID Message-ID: <000901c791a5$55ceb530$5a01a8c0@AldenLap> Hugo van der Kooij wrote on Tue May 8 20:09:32 IST 2007 >On Tue, 8 May 2007, Alden Levy wrote: > >> Thanks for this. Now, I'm really confused; the RedHat init script is >> identical to the one I'm using. >> >> Does anyone have an idea of where else I should look? (Quick recap: >> /var/run/sendmail.in.pid is not getting updated, so /etc/init.d/MailScanner >> status lists incoming sendmail as failed. sm-client.pid looks fine, >> though.) > >If you stop MailScanner the PID file should be gone. If not then you >should remove it by hand and see if it happens to get recreated at >startup. > >Hugo. > >-- > hvdkooij at vanderkooij.org http://hugo.vanderkooij.org/ > This message is using 100% recycled electrons. Well, that was a mistake! Now after removing the file by hand, and restarting, I run status and get: Checking MailScanner daemons: MailScanner: [ OK ] incoming sendmail: head: cannot open `/var/run/sendmail.in.pid' for reading: No such file or directory [FAILED] outgoing sendmail: [ OK ] Any other thoughts? Thanks, Alden From dnsadmin at 1bigthink.com Tue May 8 20:33:10 2007 From: dnsadmin at 1bigthink.com (dnsadmin 1bigthink.com) Date: Tue May 8 20:33:31 2007 Subject: Interesting need In-Reply-To: References: <463F0518.65ED.00A2.0@plattesheriff.org> <463F5C10.7080307@ecs.soton.ac.uk> <463F7783.7070608@nkpanama.com> <463F822E.2010108@ecs.soton.ac.uk> <223f97700705071442w106785bu1a9a50405476f9cb@mail.gmail.com> Message-ID: <200705081933.l48JXUwY016426@mxt.1bigthink.com> At 02:13 PM 5/8/2007, you wrote: >Res spake the following on 5/7/2007 4:52 PM: > > On Mon, 7 May 2007, Scott Silva wrote: > > > >> I think the archive mail option would be for those organizations that are > >> required to keep "everything" that crosses their gateway. So unless > >> you can > > > > Not to mention for obtaining copies of mail sent from/to a norti user > > that the feds have an interest in :) and with the forwarding ability > > they get it all in real time. > > > > > > >I really have to hope that I don't ever have that problem. Besides, the feds >can set up a Carnivore and get everything they want anyway. >-- Carnivore is so '90's We're on son of TIA now! I'll bet it can sniff a packet before you even thought what to type! >MailScanner is like deodorant... >You hope everybody uses it, and >you notice quickly if they don't!!!! Yes it is! Please keep that in your sigs unless or until you think up one as witty! From ssilva at sgvwater.com Tue May 8 21:08:43 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 8 21:11:50 2007 Subject: SMPID vs. INPID In-Reply-To: <000901c791a5$55ceb530$5a01a8c0@AldenLap> References: <000901c791a5$55ceb530$5a01a8c0@AldenLap> Message-ID: Alden Levy spake the following on 5/8/2007 12:16 PM: > Hugo van der Kooij wrote on Tue May 8 20:09:32 IST 2007 >> On Tue, 8 May 2007, Alden Levy wrote: >> >>> Thanks for this. Now, I'm really confused; the RedHat init script is >>> identical to the one I'm using. >>> >>> Does anyone have an idea of where else I should look? (Quick recap: >>> /var/run/sendmail.in.pid is not getting updated, so > /etc/init.d/MailScanner >>> status lists incoming sendmail as failed. sm-client.pid looks fine, >>> though.) >> If you stop MailScanner the PID file should be gone. If not then you >> should remove it by hand and see if it happens to get recreated at >> startup. >> >> Hugo. >> >> -- >> hvdkooij at vanderkooij.org http://hugo.vanderkooij.org/ >> This message is using 100% recycled electrons. > > Well, that was a mistake! Now after removing the file by hand, and > restarting, I run status and get: > Checking MailScanner daemons: > MailScanner: [ OK ] > incoming sendmail: head: cannot open `/var/run/sendmail.in.pid' for > reading: No such file or directory > [FAILED] > outgoing sendmail: [ OK ] > > > Any other thoughts? > Thanks, > Alden > Your init script could be either damaged, or an old version. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Tue May 8 21:11:25 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 8 21:15:06 2007 Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically placedinto access file] In-Reply-To: <20070508183652.GA26936@doctor.nl2k.ab.ca> References: <20070508154810.GA7356@doctor.nl2k.ab.ca> <6DEF8ABC1767C045B91F42066D36358E3AF7@HOUPEX01.nfsmith.info> <20070508183652.GA26936@doctor.nl2k.ab.ca> Message-ID: Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem spake the following on 5/8/2007 11:36 AM: > On Tue, May 08, 2007 at 11:06:46AM -0500, Mike Kercher wrote: >> Dave Shariff Yadallee - System Administrator a.k.a. The Root of >> theProblem <> wrote on Tuesday, May 08, 2007 10:48 AM: >> >> : On Tue, May 08, 2007 at 04:27:29PM +0100, Martin.Hepworth wrote: >> :: Dave >> :: >> :: There's a CustomFunction called IPBlock that will update this list >> :: based on number of messages received from an ip-address..... >> :: >> :: Normally it's attached to "Always Looked Up Last" in the following >> :: manner inside MailScanner.conf.. >> :: >> :: Always Looked Up Last = &IPBlock >> :: >> : >> >> : >> : >> : >> : As I said this is set to no; >> : however, when I did a tail on /etc/mail/acess I got: >> : >> : >> : 66.220.2.220 550 Persistent Virus Source >> : 212.122.114.249 550 Persistent Virus Source >> : 85.68.131.183 550 Persistent Virus Source >> : 69.11.213.106 550 Persistent Virus Source >> : 66.201.40.102 550 Persistent Virus Source >> : 85.2.209.213 550 Persistent Virus Source >> : 83.112.32.94 550 Persistent Virus Source >> : 200.62.150.49 550 We do not accept junk mail >> : 89.24.82.141 550 We do not accept junk mail >> : >> : >> : All that has changed recently is >> : >> : clamd from 0.88.7 to 0.90.2 >> : spamd from 3.1.X to 3.2.0 >> : >> : and >> : >> : MailScanner 4.58.9 to 4.59.4-2 just this weekend. >> : >> : >> : I would like to turn off the 550 We do not accept junk mail >> : feature as I would term it to be buggy, however the >> : Presistent Virus Source can stay for now; get rid of the fraud/Virus >> : mail thank you. >> : >> :: >> :: -- >> :: Martin Hepworth >> :: Snr Systems Administrator >> :: Solid State Logic >> :: Tel: +44 (0)1865 842300 >> :: >> ::: -----Original Message----- >> ::: From: mailscanner-bounces@lists.mailscanner.info >> ::: [mailto:mailscanner- bounces@lists.mailscanner.info] On Behalf Of >> ::: Dave Shariff Yadallee - System Administrator a.k.a. The Root of the >> ::: Problem >> ::: Sent: 08 May 2007 16:00 >> ::: To: mailscanner@lists.mailscanner.info >> ::: Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically >> ::: placed into access file] >> ::: >> ::: I have to resend this as I found in my logs the mailscanner.info >> ::: mailserver got listed as below. >> ::: >> ::: ----- Forwarded message from "Dave Shariff Yadallee - System >> ::: Administrator a.k.a. The Root of the Problem" >> ::: --- -- >> ::: >> ::: Date: Tue, 8 May 2007 07:44:36 -0600 >> ::: From: "Dave Shariff Yadallee - System Administrator a.k.a. The >> ::: Root of the Problem" >> ::: To: mailscanner@lists.mailscanner.info >> ::: Subject: New 550s getting automagically placed into access file >> ::: User-Agent: Mutt/1.5.12-2006-07-14 >> ::: >> ::: I know there are 3 new packages out for MailScanner, spamd and clamd >> ::: however I cannot determine with is adding to the /etc/mail/access >> ::: file 550 We do not accept junk mail . >> ::: >> ::: I need to turn of this feature as it block transmission from >> ::: secondary to primary. >> ::: >> ::: Also I am running Botnet 0.7 . >> ::: >> ::: ----- End forwarded message ----- >> >> Are you running Vispan? >> > > Yes Vispan 3.0 > That is what is adding those entries. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Tue May 8 21:13:28 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 8 21:20:08 2007 Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically placedinto access file] In-Reply-To: <20070508183652.GA26936@doctor.nl2k.ab.ca> References: <20070508154810.GA7356@doctor.nl2k.ab.ca> <6DEF8ABC1767C045B91F42066D36358E3AF7@HOUPEX01.nfsmith.info> <20070508183652.GA26936@doctor.nl2k.ab.ca> Message-ID: Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem spake the following on 5/8/2007 11:36 AM: > On Tue, May 08, 2007 at 11:06:46AM -0500, Mike Kercher wrote: >> Dave Shariff Yadallee - System Administrator a.k.a. The Root of >> theProblem <> wrote on Tuesday, May 08, 2007 10:48 AM: >> >> : On Tue, May 08, 2007 at 04:27:29PM +0100, Martin.Hepworth wrote: >> :: Dave >> :: >> :: There's a CustomFunction called IPBlock that will update this list >> :: based on number of messages received from an ip-address..... >> :: >> :: Normally it's attached to "Always Looked Up Last" in the following >> :: manner inside MailScanner.conf.. >> :: >> :: Always Looked Up Last = &IPBlock >> :: >> : >> >> : >> : >> : >> : As I said this is set to no; >> : however, when I did a tail on /etc/mail/acess I got: >> : >> : >> : 66.220.2.220 550 Persistent Virus Source >> : 212.122.114.249 550 Persistent Virus Source >> : 85.68.131.183 550 Persistent Virus Source >> : 69.11.213.106 550 Persistent Virus Source >> : 66.201.40.102 550 Persistent Virus Source >> : 85.2.209.213 550 Persistent Virus Source >> : 83.112.32.94 550 Persistent Virus Source >> : 200.62.150.49 550 We do not accept junk mail >> : 89.24.82.141 550 We do not accept junk mail >> : >> : >> : All that has changed recently is >> : >> : clamd from 0.88.7 to 0.90.2 >> : spamd from 3.1.X to 3.2.0 >> : >> : and >> : >> : MailScanner 4.58.9 to 4.59.4-2 just this weekend. >> : >> : >> : I would like to turn off the 550 We do not accept junk mail >> : feature as I would term it to be buggy, however the >> : Presistent Virus Source can stay for now; get rid of the fraud/Virus >> : mail thank you. >> : >> :: >> :: -- >> :: Martin Hepworth >> :: Snr Systems Administrator >> :: Solid State Logic >> :: Tel: +44 (0)1865 842300 >> :: >> ::: -----Original Message----- >> ::: From: mailscanner-bounces@lists.mailscanner.info >> ::: [mailto:mailscanner- bounces@lists.mailscanner.info] On Behalf Of >> ::: Dave Shariff Yadallee - System Administrator a.k.a. The Root of the >> ::: Problem >> ::: Sent: 08 May 2007 16:00 >> ::: To: mailscanner@lists.mailscanner.info >> ::: Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically >> ::: placed into access file] >> ::: >> ::: I have to resend this as I found in my logs the mailscanner.info >> ::: mailserver got listed as below. >> ::: >> ::: ----- Forwarded message from "Dave Shariff Yadallee - System >> ::: Administrator a.k.a. The Root of the Problem" >> ::: --- -- >> ::: >> ::: Date: Tue, 8 May 2007 07:44:36 -0600 >> ::: From: "Dave Shariff Yadallee - System Administrator a.k.a. The >> ::: Root of the Problem" >> ::: To: mailscanner@lists.mailscanner.info >> ::: Subject: New 550s getting automagically placed into access file >> ::: User-Agent: Mutt/1.5.12-2006-07-14 >> ::: >> ::: I know there are 3 new packages out for MailScanner, spamd and clamd >> ::: however I cannot determine with is adding to the /etc/mail/access >> ::: file 550 We do not accept junk mail . >> ::: >> ::: I need to turn of this feature as it block transmission from >> ::: secondary to primary. >> ::: >> ::: Also I am running Botnet 0.7 . >> ::: >> ::: ----- End forwarded message ----- >> >> Are you running Vispan? >> > > Yes Vispan 3.0 > Sorry, hit send too fast. You need to fix the whitelisting in the vispan.conf file if you want to spare your secondaries. And make sure your secondaries are in the spamassassin trusted networks to help with the scoring. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From mkercher at nfsmith.com Tue May 8 21:19:30 2007 From: mkercher at nfsmith.com (Mike Kercher) Date: Tue May 8 21:23:12 2007 Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically placedinto access file] References: <20070508154810.GA7356@doctor.nl2k.ab.ca> <6DEF8ABC1767C045B91F42066D36358E3AF7@HOUPEX01.nfsmith.info><20070508183652.GA26936@doctor.nl2k.ab.ca> Message-ID: <6DEF8ABC1767C045B91F42066D36358E3AFF@HOUPEX01.nfsmith.info> Scott Silva <> wrote on Tuesday, May 08, 2007 3:11 PM: : Dave Shariff Yadallee - System Administrator a.k.a. The Root of the : Problem spake the following on 5/8/2007 11:36 AM: :: On Tue, May 08, 2007 at 11:06:46AM -0500, Mike Kercher wrote: ::: Dave Shariff Yadallee - System Administrator a.k.a. The Root of ::: theProblem <> wrote on Tuesday, May 08, 2007 10:48 AM: ::: :::: On Tue, May 08, 2007 at 04:27:29PM +0100, Martin.Hepworth wrote: ::::: Dave ::::: ::::: There's a CustomFunction called IPBlock that will update this list ::::: based on number of messages received from an ip-address..... ::::: ::::: Normally it's attached to "Always Looked Up Last" in the following ::::: manner inside MailScanner.conf.. ::::: ::::: Always Looked Up Last = &IPBlock ::::: :::: ::: :::: :::: :::: :::: As I said this is set to no; :::: however, when I did a tail on /etc/mail/acess I got: :::: :::: :::: 66.220.2.220 550 Persistent Virus Source :::: 212.122.114.249 550 Persistent Virus Source :::: 85.68.131.183 550 Persistent Virus Source :::: 69.11.213.106 550 Persistent Virus Source :::: 66.201.40.102 550 Persistent Virus Source :::: 85.2.209.213 550 Persistent Virus Source :::: 83.112.32.94 550 Persistent Virus Source :::: 200.62.150.49 550 We do not accept junk mail :::: 89.24.82.141 550 We do not accept junk mail :::: :::: :::: All that has changed recently is :::: :::: clamd from 0.88.7 to 0.90.2 :::: spamd from 3.1.X to 3.2.0 :::: :::: and :::: :::: MailScanner 4.58.9 to 4.59.4-2 just this weekend. :::: :::: :::: I would like to turn off the 550 We do not accept junk mail :::: feature as I would term it to be buggy, however the :::: Presistent Virus Source can stay for now; get rid of the :::: fraud/Virus mail thank you. :::: ::::: ::::: -- ::::: Martin Hepworth ::::: Snr Systems Administrator ::::: Solid State Logic ::::: Tel: +44 (0)1865 842300 ::::: :::::: -----Original Message----- :::::: From: mailscanner-bounces@lists.mailscanner.info :::::: [mailto:mailscanner- bounces@lists.mailscanner.info] On Behalf Of :::::: Dave Shariff Yadallee - System Administrator a.k.a. The Root of :::::: the Problem Sent: 08 May 2007 16:00 :::::: To: mailscanner@lists.mailscanner.info :::::: Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically :::::: placed into access file] :::::: :::::: I have to resend this as I found in my logs the mailscanner.info :::::: mailserver got listed as below. :::::: :::::: ----- Forwarded message from "Dave Shariff Yadallee - System :::::: Administrator a.k.a. The Root of the Problem" :::::: --- -- :::::: :::::: Date: Tue, 8 May 2007 07:44:36 -0600 :::::: From: "Dave Shariff Yadallee - System Administrator a.k.a. The :::::: Root of the Problem" :::::: To: mailscanner@lists.mailscanner.info :::::: Subject: New 550s getting automagically placed into access file :::::: User-Agent: Mutt/1.5.12-2006-07-14 :::::: :::::: I know there are 3 new packages out for MailScanner, spamd and :::::: clamd however I cannot determine with is adding to the :::::: /etc/mail/access file 550 We do not accept junk mail . :::::: :::::: I need to turn of this feature as it block transmission from :::::: secondary to primary. :::::: :::::: Also I am running Botnet 0.7 . :::::: :::::: ----- End forwarded message ----- ::: ::: Are you running Vispan? ::: :: :: Yes Vispan 3.0 :: : That is what is adding those entries. : : -- : That is correct. There is a setting in the .conf file to use or not to use the access file. -Mike From ssilva at sgvwater.com Tue May 8 21:10:13 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 8 21:25:10 2007 Subject: Interesting need In-Reply-To: <200705081933.l48JXUwY016426@mxt.1bigthink.com> References: <463F0518.65ED.00A2.0@plattesheriff.org> <463F5C10.7080307@ecs.soton.ac.uk> <463F7783.7070608@nkpanama.com> <463F822E.2010108@ecs.soton.ac.uk> <223f97700705071442w106785bu1a9a50405476f9cb@mail.gmail.com> <200705081933.l48JXUwY016426@mxt.1bigthink.com> Message-ID: dnsadmin 1bigthink.com spake the following on 5/8/2007 12:33 PM: > At 02:13 PM 5/8/2007, you wrote: > >> Res spake the following on 5/7/2007 4:52 PM: >> > On Mon, 7 May 2007, Scott Silva wrote: >> > >> >> I think the archive mail option would be for those organizations >> that are >> >> required to keep "everything" that crosses their gateway. So unless >> >> you can >> > >> > Not to mention for obtaining copies of mail sent from/to a norti user >> > that the feds have an interest in :) and with the forwarding ability >> > they get it all in real time. >> > >> > >> > >> I really have to hope that I don't ever have that problem. Besides, >> the feds >> can set up a Carnivore and get everything they want anyway. >> -- > > Carnivore is so '90's We're on son of TIA now! I'll bet it can sniff a > packet before you even thought what to type! > >> MailScanner is like deodorant... >> You hope everybody uses it, and >> you notice quickly if they don't!!!! > > Yes it is! Please keep that in your sigs unless or until you think up > one as witty! I don't think it is as popular on the mimedefang list ;-) -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ajos1 at onion.demon.co.uk Tue May 8 21:53:46 2007 From: ajos1 at onion.demon.co.uk (ajos1@onion.demon.co.uk) Date: Tue May 8 21:54:06 2007 Subject: No VirusScan on Local Messages... Message-ID: - I have been trying to find the answer myself... but I know as soon as I send this... it will appear on the next page I look at (well I hope)! Basically we have had a problem with MySql failing and we have MailWatch... so we are getting zillons of messages being generated... because MailWatch cannot write to MySql... now that is not really the problem (though it would be good not to have these warning messages). The problem is that these locally produced warning messages are slowing down the machine to a grinding halt when they are VirusChecked... ClamAv being the main SLOW SLOW culprit. I am trying to find out how to set up the system to NOT VIRUSCAN the locally produced warning messages... and to deliver them straight to the root/localhost account. Thanks in Advance-o... Ajos1 == ===================================================================== = = "The council has asked residents with Christmas trees that are = unsuitable for use as maypoles to chop them up and put them in = recycling bins to be collected after the holiday." = = Need help dealing with Parking Tickets, Bailiffs, Capita or NTL... = Call... +44 8457 90 90 90 http://www.samaritans.org/ = ===================================================================== From dominian at slackadelic.com Tue May 8 22:09:52 2007 From: dominian at slackadelic.com (Matt Hayes) Date: Tue May 8 22:09:57 2007 Subject: No VirusScan on Local Messages... In-Reply-To: References: Message-ID: <4640E720.9060606@slackadelic.com> ajos1@onion.demon.co.uk wrote: > - > > I have been trying to find the answer myself... but I know as soon as I send this... it will appear on the next page I look at (well I hope)! > > Basically we have had a problem with MySql failing and we have MailWatch... so we are getting zillons of messages being generated... because MailWatch cannot write to MySql... now that is not really the problem (though it would be good not to have these warning messages). > > The problem is that these locally produced warning messages are slowing down the machine to a grinding halt when they are VirusChecked... ClamAv being the main SLOW SLOW culprit. > > I am trying to find out how to set up the system to NOT VIRUSCAN the locally produced warning messages... and to deliver them straight to the root/localhost account. > > Thanks in Advance-o... Ajos1 > Search for "Scan Messages =" in your MailScanner.conf And put: Scan Messages = %rules-dir%/scan.messages.rules And in the %rules-dir% create scan.messages.rules with the following: From: 127.0.0.1 no FromOrTo: default yes Save, restart MailScanner. -Matt From gmane at tippingmar.com Tue May 8 22:35:48 2007 From: gmane at tippingmar.com (Mark Nienberg) Date: Tue May 8 22:36:03 2007 Subject: writing to /var/spool/MailScanner/incoming In-Reply-To: <46404DAA.9040900@ecs.soton.ac.uk> References: <46404DAA.9040900@ecs.soton.ac.uk> Message-ID: Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Why not just do another tmpfs mount somewhere else as well? It's quite > reasonable in most circumstances to mount /tmp on tmpfs and then use a > subdirectory of that. > Well OK, that is probably the cleanest solution. I was tying to shortcut a bit. Thanks, Mark From alden at engineno9inc.com Tue May 8 23:09:15 2007 From: alden at engineno9inc.com (Alden Levy) Date: Tue May 8 23:09:30 2007 Subject: SMPID vs. INPID Message-ID: <000001c791bd$84f120b0$7100000a@AldenLap> Scott Silva ssilva wrote on Tue May 8 21:08:43 IST 2007 >Alden Levy spake the following on 5/8/2007 12:16 PM: >> Hugo van der Kooij wrote on Tue May 8 20:09:32 IST 2007 >>> On Tue, 8 May 2007, Alden Levy wrote: >>> >>>> Thanks for this. Now, I'm really confused; the RedHat init script is >>>> identical to the one I'm using. >>>> >>>> Does anyone have an idea of where else I should look? (Quick recap: >>>> /var/run/sendmail.in.pid is not getting updated, so >> /etc/init.d/MailScanner >>>> status lists incoming sendmail as failed. sm-client.pid looks fine, >>>> though.) >>> If you stop MailScanner the PID file should be gone. If not then you >>> should remove it by hand and see if it happens to get recreated at >>> startup. >>> >>> Hugo. >>> >>> -- >>> hvdkooij at vanderkooij.org http://hugo.vanderkooij.org/ >>> This message is using 100% recycled electrons. >> >> Well, that was a mistake! Now after removing the file by hand, and >> restarting, I run status and get: >> Checking MailScanner daemons: >> MailScanner: [ OK ] >> incoming sendmail: head: cannot open `/var/run/sendmail.in.pid' for >> reading: No such file or directory >> [FAILED] >> outgoing sendmail: [ OK ] >> >> >> Any other thoughts? >> Thanks, >> Alden >> >Your init script could be either damaged, or an old version. But I did a diff on my init script and the RedHat script you sent earlier today, and there is no difference. Can it still be corrupted? I was wondering if I should look elsewhere, or just try to reinstall. Thanks, Alden From mogens at fumlersoft.dk Tue May 8 23:16:44 2007 From: mogens at fumlersoft.dk (Mogens Melander) Date: Tue May 8 23:17:14 2007 Subject: SMPID vs. INPID In-Reply-To: <000901c791a5$55ceb530$5a01a8c0@AldenLap> References: <000901c791a5$55ceb530$5a01a8c0@AldenLap> Message-ID: <1326.90.184.17.152.1178662604.squirrel@mail.fumlersoft.dk> On Tue, May 8, 2007 21:16, Alden Levy wrote: > Hugo van der Kooij wrote on Tue May 8 20:09:32 IST 2007 >>On Tue, 8 May 2007, Alden Levy wrote: >> >>> Thanks for this. Now, I'm really confused; the RedHat init script is >>> identical to the one I'm using. >>> >>> Does anyone have an idea of where else I should look? (Quick recap: >>> /var/run/sendmail.in.pid is not getting updated, so > /etc/init.d/MailScanner >>> status lists incoming sendmail as failed. sm-client.pid looks fine, >>> though.) >> >>If you stop MailScanner the PID file should be gone. If not then you >>should remove it by hand and see if it happens to get recreated at >>startup. >> >>Hugo. >> >>-- >> hvdkooij at vanderkooij.org http://hugo.vanderkooij.org/ >> This message is using 100% recycled electrons. > > Well, that was a mistake! Now after removing the file by hand, and > restarting, I run status and get: > Checking MailScanner daemons: > MailScanner: [ OK ] > incoming sendmail: head: cannot open `/var/run/sendmail.in.pid' > for > reading: No such file or directory > [FAILED] > outgoing sendmail: [ OK ] > > > Any other thoughts? > Thanks, > Alden Well, it's not enough to stop MailScanner. You got to stop Sendmail too :) Then you can rm .pid files, and start again. -- Later Mogens Melander +45 40 85 71 38 +66 870 133 224 -- This message has been scanned for viruses and dangerous content by OpenProtect(http://www.openprotect.com), and is believed to be clean. From root at doctor.nl2k.ab.ca Tue May 8 23:12:44 2007 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Tue May 8 23:51:45 2007 Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically placedinto access file] In-Reply-To: References: <20070508154810.GA7356@doctor.nl2k.ab.ca> <6DEF8ABC1767C045B91F42066D36358E3AF7@HOUPEX01.nfsmith.info> <20070508183652.GA26936@doctor.nl2k.ab.ca> Message-ID: <20070508221244.GB14816@doctor.nl2k.ab.ca> On Tue, May 08, 2007 at 01:11:25PM -0700, Scott Silva wrote: > Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem > spake the following on 5/8/2007 11:36 AM: > > On Tue, May 08, 2007 at 11:06:46AM -0500, Mike Kercher wrote: > >> Dave Shariff Yadallee - System Administrator a.k.a. The Root of > >> theProblem <> wrote on Tuesday, May 08, 2007 10:48 AM: > >> > >> : On Tue, May 08, 2007 at 04:27:29PM +0100, Martin.Hepworth wrote: > >> :: Dave > >> :: > >> :: There's a CustomFunction called IPBlock that will update this list > >> :: based on number of messages received from an ip-address..... > >> :: > >> :: Normally it's attached to "Always Looked Up Last" in the following > >> :: manner inside MailScanner.conf.. > >> :: > >> :: Always Looked Up Last = &IPBlock > >> :: > >> : > >> > >> : > >> : > >> : > >> : As I said this is set to no; > >> : however, when I did a tail on /etc/mail/acess I got: > >> : > >> : > >> : 66.220.2.220 550 Persistent Virus Source > >> : 212.122.114.249 550 Persistent Virus Source > >> : 85.68.131.183 550 Persistent Virus Source > >> : 69.11.213.106 550 Persistent Virus Source > >> : 66.201.40.102 550 Persistent Virus Source > >> : 85.2.209.213 550 Persistent Virus Source > >> : 83.112.32.94 550 Persistent Virus Source > >> : 200.62.150.49 550 We do not accept junk mail > >> : 89.24.82.141 550 We do not accept junk mail > >> : > >> : > >> : All that has changed recently is > >> : > >> : clamd from 0.88.7 to 0.90.2 > >> : spamd from 3.1.X to 3.2.0 > >> : > >> : and > >> : > >> : MailScanner 4.58.9 to 4.59.4-2 just this weekend. > >> : > >> : > >> : I would like to turn off the 550 We do not accept junk mail > >> : feature as I would term it to be buggy, however the > >> : Presistent Virus Source can stay for now; get rid of the fraud/Virus > >> : mail thank you. > >> : > >> :: > >> :: -- > >> :: Martin Hepworth > >> :: Snr Systems Administrator > >> :: Solid State Logic > >> :: Tel: +44 (0)1865 842300 > >> :: > >> ::: -----Original Message----- > >> ::: From: mailscanner-bounces@lists.mailscanner.info > >> ::: [mailto:mailscanner- bounces@lists.mailscanner.info] On Behalf Of > >> ::: Dave Shariff Yadallee - System Administrator a.k.a. The Root of the > >> ::: Problem > >> ::: Sent: 08 May 2007 16:00 > >> ::: To: mailscanner@lists.mailscanner.info > >> ::: Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically > >> ::: placed into access file] > >> ::: > >> ::: I have to resend this as I found in my logs the mailscanner.info > >> ::: mailserver got listed as below. > >> ::: > >> ::: ----- Forwarded message from "Dave Shariff Yadallee - System > >> ::: Administrator a.k.a. The Root of the Problem" > >> ::: --- -- > >> ::: > >> ::: Date: Tue, 8 May 2007 07:44:36 -0600 > >> ::: From: "Dave Shariff Yadallee - System Administrator a.k.a. The > >> ::: Root of the Problem" > >> ::: To: mailscanner@lists.mailscanner.info > >> ::: Subject: New 550s getting automagically placed into access file > >> ::: User-Agent: Mutt/1.5.12-2006-07-14 > >> ::: > >> ::: I know there are 3 new packages out for MailScanner, spamd and clamd > >> ::: however I cannot determine with is adding to the /etc/mail/access > >> ::: file 550 We do not accept junk mail . > >> ::: > >> ::: I need to turn of this feature as it block transmission from > >> ::: secondary to primary. > >> ::: > >> ::: Also I am running Botnet 0.7 . > >> ::: > >> ::: ----- End forwarded message ----- > >> > >> Are you running Vispan? > >> > > > > Yes Vispan 3.0 > > > That is what is adding those entries. > > -- > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > And tweaked accordingly. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From root at doctor.nl2k.ab.ca Tue May 8 23:14:22 2007 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Tue May 8 23:51:51 2007 Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically placedinto access file] In-Reply-To: References: <20070508154810.GA7356@doctor.nl2k.ab.ca> <6DEF8ABC1767C045B91F42066D36358E3AF7@HOUPEX01.nfsmith.info> <20070508183652.GA26936@doctor.nl2k.ab.ca> Message-ID: <20070508221422.GC14816@doctor.nl2k.ab.ca> On Tue, May 08, 2007 at 01:13:28PM -0700, Scott Silva wrote: > Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem > spake the following on 5/8/2007 11:36 AM: > > On Tue, May 08, 2007 at 11:06:46AM -0500, Mike Kercher wrote: > >> Dave Shariff Yadallee - System Administrator a.k.a. The Root of > >> theProblem <> wrote on Tuesday, May 08, 2007 10:48 AM: > >> > >> : On Tue, May 08, 2007 at 04:27:29PM +0100, Martin.Hepworth wrote: > >> :: Dave > >> :: > >> :: There's a CustomFunction called IPBlock that will update this list > >> :: based on number of messages received from an ip-address..... > >> :: > >> :: Normally it's attached to "Always Looked Up Last" in the following > >> :: manner inside MailScanner.conf.. > >> :: > >> :: Always Looked Up Last = &IPBlock > >> :: > >> : > >> > >> : > >> : > >> : > >> : As I said this is set to no; > >> : however, when I did a tail on /etc/mail/acess I got: > >> : > >> : > >> : 66.220.2.220 550 Persistent Virus Source > >> : 212.122.114.249 550 Persistent Virus Source > >> : 85.68.131.183 550 Persistent Virus Source > >> : 69.11.213.106 550 Persistent Virus Source > >> : 66.201.40.102 550 Persistent Virus Source > >> : 85.2.209.213 550 Persistent Virus Source > >> : 83.112.32.94 550 Persistent Virus Source > >> : 200.62.150.49 550 We do not accept junk mail > >> : 89.24.82.141 550 We do not accept junk mail > >> : > >> : > >> : All that has changed recently is > >> : > >> : clamd from 0.88.7 to 0.90.2 > >> : spamd from 3.1.X to 3.2.0 > >> : > >> : and > >> : > >> : MailScanner 4.58.9 to 4.59.4-2 just this weekend. > >> : > >> : > >> : I would like to turn off the 550 We do not accept junk mail > >> : feature as I would term it to be buggy, however the > >> : Presistent Virus Source can stay for now; get rid of the fraud/Virus > >> : mail thank you. > >> : > >> :: > >> :: -- > >> :: Martin Hepworth > >> :: Snr Systems Administrator > >> :: Solid State Logic > >> :: Tel: +44 (0)1865 842300 > >> :: > >> ::: -----Original Message----- > >> ::: From: mailscanner-bounces@lists.mailscanner.info > >> ::: [mailto:mailscanner- bounces@lists.mailscanner.info] On Behalf Of > >> ::: Dave Shariff Yadallee - System Administrator a.k.a. The Root of the > >> ::: Problem > >> ::: Sent: 08 May 2007 16:00 > >> ::: To: mailscanner@lists.mailscanner.info > >> ::: Subject: [root@doctor.nl2k.ab.ca: New 550s getting automagically > >> ::: placed into access file] > >> ::: > >> ::: I have to resend this as I found in my logs the mailscanner.info > >> ::: mailserver got listed as below. > >> ::: > >> ::: ----- Forwarded message from "Dave Shariff Yadallee - System > >> ::: Administrator a.k.a. The Root of the Problem" > >> ::: --- -- > >> ::: > >> ::: Date: Tue, 8 May 2007 07:44:36 -0600 > >> ::: From: "Dave Shariff Yadallee - System Administrator a.k.a. The > >> ::: Root of the Problem" > >> ::: To: mailscanner@lists.mailscanner.info > >> ::: Subject: New 550s getting automagically placed into access file > >> ::: User-Agent: Mutt/1.5.12-2006-07-14 > >> ::: > >> ::: I know there are 3 new packages out for MailScanner, spamd and clamd > >> ::: however I cannot determine with is adding to the /etc/mail/access > >> ::: file 550 We do not accept junk mail . > >> ::: > >> ::: I need to turn of this feature as it block transmission from > >> ::: secondary to primary. > >> ::: > >> ::: Also I am running Botnet 0.7 . > >> ::: > >> ::: ----- End forwarded message ----- > >> > >> Are you running Vispan? > >> > > > > Yes Vispan 3.0 > > > Sorry, hit send too fast. You need to fix the whitelisting in the vispan.conf > file if you want to spare your secondaries. And make sure your secondaries are > in the spamassassin trusted networks to help with the scoring. > > -- > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > Not to worry, thanks to everyone here, it is done. > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ssilva at sgvwater.com Wed May 9 00:17:19 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed May 9 00:17:38 2007 Subject: SMPID vs. INPID In-Reply-To: <000001c791bd$84f120b0$7100000a@AldenLap> References: <000001c791bd$84f120b0$7100000a@AldenLap> Message-ID: Alden Levy spake the following on 5/8/2007 3:09 PM: > Scott Silva ssilva wrote on Tue May 8 21:08:43 IST 2007 >> Alden Levy spake the following on 5/8/2007 12:16 PM: >>> Hugo van der Kooij wrote on Tue May 8 20:09:32 IST 2007 >>>> On Tue, 8 May 2007, Alden Levy wrote: >>>> >>>>> Thanks for this. Now, I'm really confused; the RedHat init script is >>>>> identical to the one I'm using. >>>>> >>>>> Does anyone have an idea of where else I should look? (Quick recap: >>>>> /var/run/sendmail.in.pid is not getting updated, so >>> /etc/init.d/MailScanner >>>>> status lists incoming sendmail as failed. sm-client.pid looks fine, >>>>> though.) >>>> If you stop MailScanner the PID file should be gone. If not then you >>>> should remove it by hand and see if it happens to get recreated at >>>> startup. >>>> >>>> Hugo. >>>> >>>> -- >>>> hvdkooij at vanderkooij.org http://hugo.vanderkooij.org/ >>>> This message is using 100% recycled electrons. >>> Well, that was a mistake! Now after removing the file by hand, and >>> restarting, I run status and get: >>> Checking MailScanner daemons: >>> MailScanner: [ OK ] >>> incoming sendmail: head: cannot open `/var/run/sendmail.in.pid' > for >>> reading: No such file or directory >>> [FAILED] >>> outgoing sendmail: [ OK ] >>> >>> >>> Any other thoughts? >>> Thanks, >>> Alden >>> >> Your init script could be either damaged, or an old version. > > But I did a diff on my init script and the RedHat script you sent earlier > today, and there is no difference. Can it still be corrupted? > > I was wondering if I should look elsewhere, or just try to reinstall. > > Thanks, > Alden > You do have sendmail disabled, don't you? -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From alden at engineno9inc.com Wed May 9 03:39:42 2007 From: alden at engineno9inc.com (Alden Levy) Date: Wed May 9 03:39:58 2007 Subject: SMPID vs. INPID Message-ID: <001b01c791e3$4c9d7620$7100000a@AldenLap> >Scott Silva ssilva wrote on Wed May 9 00:17:19 IST 2007 >>Scott Silva ssilva wrote on Tue May 8 21:08:43 IST 2007 >>>Alden Levy spake the following on 5/8/2007 12:16 PM: >>>> Hugo van der Kooij wrote on Tue May 8 20:09:32 IST 2007 >>>>> On Tue, 8 May 2007, Alden Levy wrote: >>>>> >>>>>> Thanks for this. Now, I'm really confused; the RedHat init script is >>>>>> identical to the one I'm using. >>>>>> >>>>>> Does anyone have an idea of where else I should look? (Quick recap: >>>>>> /var/run/sendmail.in.pid is not getting updated, so >>>>>> /etc/init.d/MailScanner >>>>>> status lists incoming sendmail as failed. sm-client.pid looks fine, >>>>>> though.) >>>>> If you stop MailScanner the PID file should be gone. If not then you >>>>> should remove it by hand and see if it happens to get recreated at >>>>> startup. >>>>> >>>>> Hugo. >>>>> >>>>> -- >>>>> hvdkooij at vanderkooij.org http://hugo.vanderkooij.org/ >>>>> This message is using 100% recycled electrons. >>>> >>>> Well, that was a mistake! Now after removing the file by hand, and >>>> restarting, I run status and get: >>>> Checking MailScanner daemons: >>>> MailScanner: [ OK ] >>>> incoming sendmail: head: cannot open `/var/run/sendmail.in.pid' for >>>> reading: No such file or directory >>>> [FAILED] >>>> outgoing sendmail: [ OK ] >>>> >>>> >>>> Any other thoughts? >>>> Thanks, >>>> Alden >>>> >>>Your init script could be either damaged, or an old version. >> >>But I did a diff on my init script and the RedHat script you sent earlier >>today, and there is no difference. Can it still be corrupted? >> >>I was wondering if I should look elsewhere, or just try to reinstall. >> >>Thanks, >>Alden >> >You do have sendmail disabled, don't you? Yep. But I'm going to double check, anyway. I've done "chkconfig sendmail off" a few times, but I'll try again. However, when I start sendmail, I have 3 instances running: # ps aux|grep sendmail root 23940 0.0 0.0 9092 1888 ? Ss 22:36 0:00 sendmail: accepting connections smmsp 23944 0.0 0.0 6940 1656 ? Ss 22:36 0:00 sendmail: Queue runner@00:15:00 for /var/spool/clientmqueue root 23949 0.0 0.0 8296 1780 ? Ss 22:36 0:00 sendmail: Queue runner@00:15:00 for /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue The first one doesn't stop when I service MailScanner stop, and I have to issue a service sendmail stop in order to kill it. Curiouser and curiouser... Is this good/bad/indifferent? I've been seeing this for a while, as this was what I had on my old server, but I don't remember what was running when it was working properly. From ssilva at sgvwater.com Wed May 9 04:40:53 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed May 9 04:41:06 2007 Subject: SMPID vs. INPID In-Reply-To: <001b01c791e3$4c9d7620$7100000a@AldenLap> References: <001b01c791e3$4c9d7620$7100000a@AldenLap> Message-ID: Alden Levy spake the following on 5/8/2007 7:39 PM: >> Scott Silva ssilva wrote on Wed May 9 00:17:19 IST 2007 >>> Scott Silva ssilva wrote on Tue May 8 21:08:43 IST 2007 >>>> Alden Levy spake the following on 5/8/2007 12:16 PM: >>>>> Hugo van der Kooij wrote on Tue May 8 20:09:32 IST 2007 >>>>>> On Tue, 8 May 2007, Alden Levy wrote: >>>>>> >>>>>>> Thanks for this. Now, I'm really confused; the RedHat init script is >>>>>>> identical to the one I'm using. >>>>>>> >>>>>>> Does anyone have an idea of where else I should look? (Quick recap: >>>>>>> /var/run/sendmail.in.pid is not getting updated, so >>>>>>> /etc/init.d/MailScanner >>>>>>> status lists incoming sendmail as failed. sm-client.pid looks fine, >>>>>>> though.) >>>>>> If you stop MailScanner the PID file should be gone. If not then you >>>>>> should remove it by hand and see if it happens to get recreated at >>>>>> startup. >>>>>> >>>>>> Hugo. >>>>>> >>>>>> -- >>>>>> hvdkooij at vanderkooij.org http://hugo.vanderkooij.org/ >>>>>> This message is using 100% recycled electrons. >>>>> Well, that was a mistake! Now after removing the file by hand, and >>>>> restarting, I run status and get: >>>>> Checking MailScanner daemons: >>>>> MailScanner: [ OK ] >>>>> incoming sendmail: head: cannot open > `/var/run/sendmail.in.pid' for >>>>> reading: No such file or directory >>>>> [FAILED] >>>>> outgoing sendmail: [ OK ] >>>>> >>>>> >>>>> Any other thoughts? >>>>> Thanks, >>>>> Alden >>>>> >>>> Your init script could be either damaged, or an old version. >>> But I did a diff on my init script and the RedHat script you sent earlier >>> today, and there is no difference. Can it still be corrupted? >>> >>> I was wondering if I should look elsewhere, or just try to reinstall. >>> >>> Thanks, >>> Alden >>> >> You do have sendmail disabled, don't you? > > Yep. But I'm going to double check, anyway. I've done "chkconfig sendmail > off" a few times, but I'll try again. > > However, when I start sendmail, I have 3 instances running: > # ps aux|grep sendmail > root 23940 0.0 0.0 9092 1888 ? Ss 22:36 0:00 sendmail: > accepting connections > > smmsp 23944 0.0 0.0 6940 1656 ? Ss 22:36 0:00 sendmail: > Queue runner@00:15:00 for /var/spool/clientmqueue > root 23949 0.0 0.0 8296 1780 ? Ss 22:36 0:00 sendmail: > Queue runner@00:15:00 for > /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue > > The first one doesn't stop when I service MailScanner stop, and I have to > issue a service sendmail stop in order to kill it. > > Curiouser and curiouser... Is this good/bad/indifferent? I've been seeing > this for a while, as this was what I had on my old server, but I don't > remember what was running when it was working properly. > > Look in /etc/sysconfig for a MailScanner.rpmnew. Maybe you have an old version in there. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From cplists at princeservices.com Wed May 9 04:44:48 2007 From: cplists at princeservices.com (Cameron B. Prince) Date: Wed May 9 04:44:54 2007 Subject: MailScanner w/ Qmail / Plesk Message-ID: Hey guys, I have a new dedicated server with Plesk. I originally purchased the SpamAssassin and Dr. Web anti-virus plugins but they just don't compare to MailScanner w/ MailWatch. I followed the instructions to setup MailScanner with Qmail here: http://qms.ausics.net/ I verified all the perl modules and checked the updates to the MailScanner.conf file. When I started MailScanner the init script complained that the MTA was invalid. I started Qmail manually and sent a test message. When the message hit the SMTP I got a queue error returned to the client. I ran this command and the queue errors went away: chmod u+s /var/qmail/bin/qmail-queue Now a test message produces this in the log: relaylock: /var/qmail/bin/relaylock: mail from xxx.xxx.xxx.xxx:61451 (my.domain.com) MailScanner[6489]: New Batch: Scanning 1 messages, 668 bytes MailScanner[6489]: SpamAssassin cache hit for message 7064403 MailScanner[6489]: Virus and Content Scanning: Starting MailScanner[6489]: Uninfected: Delivered 1 messages MailScanner[6489]: Logging message 7064403 to SQL MailScanner[6451]: 7064403: Logged to MailWatch SQL When I checked the other mailbox for the message I found that it was never received. I enabled debugging and got this output when I tried another test message: /usr/sbin/MailScanner In Debugging mode, not forking... Ignore errors about failing to find EOCD signature format error: file is too short at /usr/sbin/MailScanner line 832 Stopping now as you are debugging me. commit ineffective with AutoCommit enabled at /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, line 34. Commmit ineffective while AutoCommit is on at /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, line 34. I know this patch for Qmail is pretty old and I wonder if this is the cause or if it's more likely to be a problem with the Plesk version of Qmail. Can anyone give me some ideas to troubleshoot this? Thanks, Cameron PS Here's the output of a lint test: /usr/sbin/MailScanner --lint Read 764 hostnames from the phishing whitelist Config: calling custom init function SQLBlacklist Config: calling custom init function MailWatchLogging Config: calling custom init function SQLWhitelist Checking version numbers... Version number in MailScanner.conf (4.58.9) is correct. MailScanner setting GID to (2520) MailScanner setting UID to (2520) Checking for SpamAssassin errors (if you use it)... Using SpamAssassin results cache Connected to SpamAssassin cache database SpamAssassin reported no errors. lock.pl sees Config LockType = flock lock.pl sees have_module = 0 Using locktype = flock MailScanner.conf says "Virus Scanners = f-prot" Found these virus scanners installed: f-prot From prandal at herefordshire.gov.uk Wed May 9 06:04:40 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Wed May 9 06:04:49 2007 Subject: SA 3.2.0 Woes In-Reply-To: <20070507125947.05ede1ea@uxbod.splatnix.net> References: <20070507125947.05ede1ea@uxbod.splatnix.net> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA03CED1@HC-MBX02.herefordshire.gov.uk> I found that the the speed halved with SA 3.2.0 on a Fedora Core 1 test box. I was getting lots of dnsrbl timeouts which I didn't get with SA 3.1.8. What's your rbl_timeout set to? Does increasing that value make a difference? Cheers, Phil -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- Sent: 07 May 2007 13:00 To: MailScanner discussion Subject: SA 3.2.0 Woes Hi, Not sure whether this is a issue or not, but since upgrading SA and MailScanner I never seem to get any hits via RBLs. I am using MailWatch and that just says "SpamAssassin Listed in RBL". Bayes never seems to trigger aswell now. Have others experienced anything like this ? TIA -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 845 869 2749 // SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From hvdkooij at vanderkooij.org Wed May 9 07:05:17 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Wed May 9 07:05:47 2007 Subject: SMPID vs. INPID In-Reply-To: <001b01c791e3$4c9d7620$7100000a@AldenLap> References: <001b01c791e3$4c9d7620$7100000a@AldenLap> Message-ID: On Tue, 8 May 2007, Alden Levy wrote: >> Scott Silva ssilva wrote on Wed May 9 00:17:19 IST 2007 >> You do have sendmail disabled, don't you? > > Yep. But I'm going to double check, anyway. I've done "chkconfig sendmail > off" a few times, but I'll try again. That will NOT stop a running service. Just prevent it from starting again if you reboot the system. You need to stop the service manualy as well with `service sendmail stop`. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From alex at nkpanama.com Wed May 9 08:23:42 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Wed May 9 08:24:37 2007 Subject: Archive Mail Settings Message-ID: <464176FE.60807@nkpanama.com> According to mailscanner.conf, # Any of the items above can contain the magic string _DATE_ in them # which will be replaced with the current date in yyyymmdd format. # This will make archive-rolling and maintenance much easier, as you can # guarantee that yesterday's mail archive will not be in active use today. Could it be possible to modify _DATE_ so that it only shows yyyymm instead? That way monthly archives would be a cinch. I have *no* idea how to do this in perl (only thing I know about perl is how to "try to" install modules using CPAN), but I'm sure a kind soul here would know how to do a sed incantation that would make this possible. From uxbod at splatnix.net Wed May 9 09:16:27 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Wed May 9 09:16:31 2007 Subject: FuzzyOcr customisations In-Reply-To: References: Message-ID: <1a4a684c8ab130c556e463c9cc909041@62.49.223.244> Very clever indeed Sir. Thats really cool, got me thinking now ;) On Tue, 8 May 2007 18:33:06 +0100, "Gareth" wrote: > Thought people might be interested in the forum at > http://www.freespamfilter.org/forum/viewforum.php?f=25 where there are > some > good tips for customising FuzzyOcr. > > Today I have also had a stab at creating an image utility which can be > added > to a scanset to hopefully improve its detection. Basically it works by > producing a grayscale image which contains the differences between a pixel > and the average colour over the whole image (rgb calculated separately) > > You can see a couple of examples and download and have a play with it > yourself on my webpage at > http://www.gbnetwork.co.uk/mailscanner/gbpgmdiff/ > It is still very much a work in progress and I haven't even got round to > putting it into one of my scansets yet. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From amaclach at yahoo.co.uk Wed May 9 09:46:15 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Wed May 9 09:46:16 2007 Subject: FuzzyOcr customisations Message-ID: <209489.14074.qm@web26301.mail.ukl.yahoo.com> I'd use it... ----- Original Message ---- From: --[ UxBoD ]-- To: MailScanner discussion Sent: Wednesday, 9 May, 2007 9:16:27 AM Subject: Re: FuzzyOcr customisations Very clever indeed Sir. Thats really cool, got me thinking now ;) On Tue, 8 May 2007 18:33:06 +0100, "Gareth" wrote: > Thought people might be interested in the forum at > http://www.freespamfilter.org/forum/viewforum.php?f=25 where there are > some > good tips for customising FuzzyOcr. > > Today I have also had a stab at creating an image utility which can be > added > to a scanset to hopefully improve its detection. Basically it works by > producing a grayscale image which contains the differences between a pixel > and the average colour over the whole image (rgb calculated separately) > > You can see a couple of examples and download and have a play with it > yourself on my webpage at > http://www.gbnetwork.co.uk/mailscanner/gbpgmdiff/ > It is still very much a work in progress and I haven't even got round to > putting it into one of my scansets yet. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From pedretti at eco.unibs.it Wed May 9 09:55:22 2007 From: pedretti at eco.unibs.it (Fabio Pedretti) Date: Wed May 9 09:53:45 2007 Subject: Clamav suggestions In-Reply-To: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> Message-ID: <20070509105522.y9h0nbimg4kg0oks@luna.eco.unibs.it> > 2) I noticed (as well as others: > http://lists.mailscanner.info/pipermail/mailscanner/2007-April/072504.html > ) that some phishing mail are not blocked (I am also using > the signatures of sanesecurity). If I do a clamscan on the full > original mail with headers, clamscan find the virus (I can provide a > sample if needed). Seems the problem is that MailScanner extracts the > content of the mail (body + attachment) and scans it, but some > phishing mail are only detected if the full headers are present (in > the clamav DB in the extended signature format, option 4 is for mail > files, look at signatures.pdf in clamav source, and are detected only > if full mail with headers is scanned). > MailScanner should be modified so that all the original mail (with > headers and without extracting attachment) should be passed to > clamscan/clamd, so all virus can be catched. To try the problem send a mail with the following text: 2.83:9999/webscrr/ind on a MailScanner with clamav mail server. The mail does not get filtered. However if you do a clamscan on the received mail, you get: test.eml: Email.Phishing.Pay-20 FOUND From list-mailscanner at linguaphone.com Wed May 9 10:49:45 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed May 9 10:49:56 2007 Subject: FuzzyOcr customisations In-Reply-To: <1a4a684c8ab130c556e463c9cc909041@62.49.223.244> References: <1a4a684c8ab130c556e463c9cc909041@62.49.223.244> Message-ID: <1178704185.905.19.camel@gblades-suse.linguaphone-intranet.co.uk> I have version 0.2 available now and the wrapper script now takes the threshold as a parameter. There is a 3rd example image included (and on my website) which requires a slightly lower threshold in order to give the best results. Unforunetly even with the cleaned images ocrad and gocr still dont appear to be able to recognise the images very well. I think the problem with the first two is that the letters touch each other but I dont know why the 3rd doesn't work. Perhaps its an issue with the font. On Wed, 2007-05-09 at 09:16, --[ UxBoD ]-- wrote: > Very clever indeed Sir. Thats really cool, got me thinking now ;) > > On Tue, 8 May 2007 18:33:06 +0100, "Gareth" wrote: > > Thought people might be interested in the forum at > > http://www.freespamfilter.org/forum/viewforum.php?f=25 where there are > > some > > good tips for customising FuzzyOcr. > > > > Today I have also had a stab at creating an image utility which can be > > added > > to a scanset to hopefully improve its detection. Basically it works by > > producing a grayscale image which contains the differences between a pixel > > and the average colour over the whole image (rgb calculated separately) > > > > You can see a couple of examples and download and have a play with it > > yourself on my webpage at > > http://www.gbnetwork.co.uk/mailscanner/gbpgmdiff/ > > It is still very much a work in progress and I haven't even got round to > > putting it into one of my scansets yet. > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > -- > > This message has been scanned for viruses and dangerous content by > > MailScanner, and is > > believed to be clean. > -- > --[ UxBoD ]-- > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > > > -- > This message has been scanned for viruses and dangerous content by MailScanner, and is > believed to be clean. From gmourani at prival.ca Wed May 9 13:38:05 2007 From: gmourani at prival.ca (Gerhard Mourani) Date: Wed May 9 13:38:29 2007 Subject: Issue with Blackberry Message-ID: <3123E1B72B666243917E340F3C8FD4A10696E3@privaldc2003.prival.local> Hello, I'm using MailScanner + Postfix + SpamAssassin on Linux and having strange issues with email coming from blackberry servers, here how the received email look like: Subject: Re: Hand Mixer Trial-Produce Report \Ib?HTjy?Z.hm%yXxj?'p?'wJI+{E+.1I?U)?g?g*"(tjdj?6V??6 R w&FR FR&GbV v F2fVC ________________________________ 6wB 6VRB &W&o??G2 W&vVB 6RVVFVBf"7[1] FW7Fp??F0?? ________________________________ V&V6? &GV7B ________________________________ vW" ________________________________ 6V6 ________________________________ 2?F&V7B?S ________________________________ SB ________________________________ ##r ________________________________ s3r[1]??&v ________________________________ W76vR?g&?[1]$FfBVr" ________________________________ FfBVt VIFVw&W26?FFSGVR ________________________________ ________________________________ ________________________________ # ________________________________ ________________________________ r ________________________________ ##?F&fW&F" ________________________________ fW&FF?VIFVw&W26&W&2&W&" ________________________________ W&2 &W&VIFVw&W26?63&FFv"" ________________________________ FFv$VIFVw&W26%6Tr" ________________________________ 6Rt 6V626&V&V" ________________________________ V&V6 6V626'6G&'W&F" ________________________________ 6G&'W&FVIFVw&W26&VWB" ________________________________ VWBGW&W6vTVIFVw&W26&VFV" ________________________________ VFV6 VVIFVw&W266TVIFVw&W26&V'F" ________________________________ zV'FVIFVw&W26$FR" ________________________________ zFRWG64VIFVw&W 26&FfBGW&" ________________________________ FfBGW&VIFVw&W26%F" ________________________________ FTVIFVw&W26'o R" ________________________________ oTVIFVw&W26&66r" ________________________________ ?66tVIFVw&W26&'R" ________________________________ 'TVIFVw&W26$66R" ________________________________ 66VF v?v6%6&?R" ________________________________ F?6$6" ________________________________ ?6Fv?v6&VfVr" ________________________________ VfVtF?6?7V&V7C ________________________________ B ________________________________ ?W"G& &GV6R&W'@??FV" ________________________________ fW&FW&2V6R 6VRB?W" G& &GV7" &W'B7V7F &W7VB2fVB&W7B &Vv&G2FfBVpVIFR ________________________________ w&W[1] ________________________________ 2 ________________________________ 6 ________________________________ ff6P&S ________________________________ b3 ________________________________ ________________________________ cs#cV?VIFW2?6 ________________________________ c26? ________________________________ FVIFW2?6 ________________________________ c26R#FfBVtVIFVw&W26 ________________________________ FFfBVtVIFVw&W26vV'6FS wwrVIFVw&W26 ________________________________ ?GG ________________________________ wwrVIFVw&W26%F2Vf76?R6F26fFVFf&FFVFVBof" FR W6Rb FR W'6VB&fR ________________________________ b R&RB FRFVFVB &V6VBb F2Vf76?R" FRVVR"vVB &W76&Rf"FVIfW&rB F FRFVFVB &V6VB R&RW&V'FfVB FBF76V?F"6 |*[1]b F2Vf76?\*[1]2 7G&7Fo &&FVB ________________________________ b RfR &V6VfVB F2Vf76?RW'&" V6R &WGW& F W2C ________________________________ sR6RGR ________________________________ g&W&R ________________________________ G&R ________________________________ G&VVV&V2*[1] ________________________________ 6F ________________________________ 4" ________________________________ 5,*[1]'fC ________________________________ SB? ________________________________ rS#s " F FR 6VFW"w2VFG&W72F6FVB&fR Gerhard, -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070509/0200447e/attachment.html From Olaf.Ohlenmacher at colt.net Wed May 9 13:42:15 2007 From: Olaf.Ohlenmacher at colt.net (Ohlenmacher, Olaf) Date: Wed May 9 13:42:18 2007 Subject: Attachment filename filter rules (sophisticated) Message-ID: <08AD7B42A2698345BA90F9E33A46F2C401AC8394@ULPGCTMVMAI003.EU.COLT> Hello, we drop attachments by filenames extentions. Nowerdays attachment filenames are MIME-coded so that Umlauts and other special characters can be handled in a 7-Bit clean way. My question: Are the regular expressions applied to the decoded filenames or are they applied to the encoded filenames. Background: I have found binary-UTF-8 encoded attachment filenames in the wild which looks like =?UTF-8?B?ZGFzIGlzdCBlaW4gw6TDtsO8w58gdGVzdGZpbGUgbWl0?= =?UTF-8?B?IHNvbmRlcnplaWNoZW4gMTIzNDU2Nzg5MC56aXA=?= which is a file with the name "das ist ein ???? testfile mit sonderzeichen 1234567890.zip". These binary-coded MIME are not regular, so they can not be parsed from regular expressions. Best regards, Olaf Ohlenmacher -- COLT Telecom GmbH, Herriotstra?e 4, 60528 Frankfurt/Main, Deutschland * Tel +49 (0)69 56606 0 * Fax +49 (0)69 56606 2222 * Gesch?ftsf?hrer: Detlef Spang (Vors.), Albertus Marinus Oosterom, Rita Thies * Amtsgericht Frankfurt/Main HRB 53898 * USt.-IdNr. DE 220 772 475 ************************************************************************************* The message is intended for the named addressee only and may not be disclosed to or used by anyone else, nor may it be copied in any way. The contents of this message and its attachments are confidential and may also be subject to legal privilege. If you are not the named addressee and/or have received this message in error, please advise us by e-mailing security@colt.net and delete the message and any attachments without retaining any copies. Internet communications are not secure and COLT does not accept responsibility for this message, its contents nor responsibility for any viruses. No contracts can be created or varied on behalf of COLT Telecommunications, its subsidiaries or affiliates ("COLT") and any other party by email Communications unless expressly agreed in writing with such other party. Please note that incoming emails will be automatically scanned to eliminate potential viruses and unsolicited promotional emails. For more information refer to www.colt.net or contact us on +44(0)20 7390 3900. From uxbod at splatnix.net Wed May 9 14:07:47 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Wed May 9 14:08:00 2007 Subject: Issue with Blackberry In-Reply-To: <3123E1B72B666243917E340F3C8FD4A10696E3@privaldc2003.prival.local> References: <3123E1B72B666243917E340F3C8FD4A10696E3@privaldc2003.prival.local> Message-ID: <4717144a9438363409909b0a056c183b@62.49.223.244> Would be useful to see the actual headers, especially the MIME section. On Wed, 9 May 2007 08:38:05 -0400, "Gerhard Mourani" wrote: > Hello, > > > > I'm using MailScanner + Postfix + SpamAssassin on Linux and having strange > issues with email coming from blackberry servers, here how the received > email look like: > > > > Subject: Re: Hand Mixer Trial-Produce Report > > > > \Ib?HTjy?Z.hm%yXxj?'p?'wJI+{E+.1I?U)?g?g*"(tjdj?6V??6 R w&FR FR&GbV > v F2fVC > ________________________________ > > 6wB 6VRB > > > > &W&o??G2 W&vVB 6RVVFVBf"7[1] FW7Fp??F0?? > ________________________________ > > V&V6? &GV7B > ________________________________ > > vW" > ________________________________ > > 6V6 > ________________________________ > > 2?F&V7B?S > ________________________________ > > SB > ________________________________ > > ##r > ________________________________ > > s3r[1]??&v > ________________________________ > > W76vR?g&?[1]$FfBVr" > ________________________________ > > FfBVt VIFVw&W26?FFSGVR > ________________________________ > > ________________________________ > > ________________________________ > > # > ________________________________ > > ________________________________ > > r > ________________________________ > > ##?F&fW&F" > ________________________________ > > fW&FF?VIFVw&W26&W&2&W&" > ________________________________ > > W&2 &W&VIFVw&W26?63&FFv"" > ________________________________ > > FFv$VIFVw&W26%6Tr" > ________________________________ > > 6Rt 6V626&V&V" > ________________________________ > > V&V6 6V626'6G&'W&F" > ________________________________ > > 6G&'W&FVIFVw&W26&VWB" > ________________________________ > > VWBGW&W6vTVIFVw&W26&VFV" > ________________________________ > > VFV6 VVIFVw&W266TVIFVw&W26&V'F" > ________________________________ > > zV'FVIFVw&W26$FR" > ________________________________ > > zFRWG64VIFVw&W 26&FfBGW&" > ________________________________ > > FfBGW&VIFVw&W26%F" > ________________________________ > > FTVIFVw&W26'o R" > ________________________________ > > oTVIFVw&W26&66r" > ________________________________ > > ?66tVIFVw&W26&'R" > ________________________________ > > 'TVIFVw&W26$66R" > ________________________________ > > 66VF v?v6%6&?R" > ________________________________ > > F?6$6" > ________________________________ > > ?6Fv?v6&VfVr" > ________________________________ > > VfVtF?6?7V&V7C > ________________________________ > > B > ________________________________ > > ?W"G& &GV6R&W'@??FV" > ________________________________ > > fW&FW&2V6R 6VRB?W" G& > > > > &GV7" &W'B7V7F &W7VB2fVB&W7B &Vv&G2FfBVpVIFR > ________________________________ > > w&W[1] > ________________________________ > > 2 > ________________________________ > > 6 > ________________________________ > > ff6P&S > ________________________________ > > b3 > ________________________________ > > ________________________________ > > cs#cV?VIFW2?6 > ________________________________ > > c26? > ________________________________ > > FVIFW2?6 > ________________________________ > > c26R#FfBVtVIFVw&W26 > ________________________________ > > FFfBVtVIFVw&W26vV'6FS wwrVIFVw&W26 > ________________________________ > > ?GG > ________________________________ > > wwrVIFVw&W26%F2Vf76?R6F26fFVFf&FFVFVBof" FR W6Rb FR W'6VB&fR > ________________________________ > > b R&RB FRFVFVB &V6VBb F2Vf76?R" FRVVR"vVB &W76&Rf"FVIfW&rB > F FRFVFVB &V6VB R&RW&V'FfVB FBF76V?F"6 |*[1]b F2Vf76?\*[1]2 > 7G&7Fo > > > > &&FVB > ________________________________ > > b RfR &V6VfVB F2Vf76?RW'&" V6R &WGW& F W2C > ________________________________ > > sR6RGR > ________________________________ > > g&W&R > ________________________________ > > G&R > ________________________________ > > G&VVV&V2*[1] > ________________________________ > > 6F > ________________________________ > > 4" > ________________________________ > > 5,*[1]'fC > ________________________________ > > SB? > ________________________________ > > rS#s " F FR 6VFW"w2VFG&W72F6FVB&fR > > > > Gerhard, > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From gmourani at prival.ca Wed May 9 14:26:31 2007 From: gmourani at prival.ca (Gerhard Mourani) Date: Wed May 9 14:27:00 2007 Subject: Issue with Blackberry In-Reply-To: <4717144a9438363409909b0a056c183b@62.49.223.244> Message-ID: <3123E1B72B666243917E340F3C8FD4A10696E7@privaldc2003.prival.local> Here what users sent to me. Also this is what I've in the -> /etc/postfix/header_checks file /^Received: (.*?) by eliteclassics.com(.*?)/ REJECT /^Received:/ HOLD Now the headers: A problem was found in an Email message you sent. This Email scanner intercepted it and stopped the entire message reaching its destination. The problem was reported to be: Disallowed breakage found in header name - potential virus Please contact your IT support personnel with any queries regarding this policy. Your message was sent with the following envelope: MAIL FROM: carla.redman@elitegroupinc.ca RCPT TO: joshua.levin@myexchangehosting.net ... and with the following headers: --- MAILFROM: carla.redman@elitegroupinc.ca Delivered-To: jwlevinp-joshua.levin@jwlevinpartners.com Received: (qmail 55802 invoked from network); 4 May 2007 18:37:42 -0000 Received: from unknown (HELO mail.eliteclassics.com) (149.99.191.243) by host355.ipowerweb.com with SMTP; 4 May 2007 18:37:42 -0000 Received: from EXECDanny (office.eliteclassics.com [149.99.191.242]) by mail.eliteclassics.com (Postfix) with ESMTP id CEC964DEC for ; Fri, 4 May 2007 14:40:18 -0400 (EDT) Return-Receipt-To: "Carla Redman" Reply-To: From: "Carla Redman" To: "'Levin, Joshua'" References: <435DF58A933BA74397B42CDEB8145A860B8C4AE3@ex9.hostedexchange.local> Subject: RE: feb 07 flights .xls Date: Fri, 4 May 2007 14:45:04 -0400 Organization: Elite Group Message-ID: MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0003_01C78E5A.CD761FE0" X-Mailer: Microsoft Office Outlook 11 Thread-Index: AceCyu12JEluHxWIQ7ClFI22mBkHtgAghwiAAA0iz+AAAC8ZAAK8H9XgAAIRniA= In-Reply-To: <435DF58A933BA74397B42CDEB8145A860B8C4AE3@ex9.hostedexchange.local> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 Disposition-Notification-To: "Carla Redman" X-Elite Group, Inc.-MailScanner: Found to be clean X-Elite Group, Inc.-MailScanner-From: carla.redman@elitegroupinc.ca X-Spam-Status: No Thanks, -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- Sent: Wednesday, May 09, 2007 9:08 AM To: MailScanner discussion Subject: Re: Issue with Blackberry Would be useful to see the actual headers, especially the MIME section. On Wed, 9 May 2007 08:38:05 -0400, "Gerhard Mourani" wrote: > Hello, > > > > I'm using MailScanner + Postfix + SpamAssassin on Linux and having strange > issues with email coming from blackberry servers, here how the received > email look like: > > > > Subject: Re: Hand Mixer Trial-Produce Report > > > > \Ib?HTjy?Z.hm%yXxj?'p?'wJI+{E+.1I?U)?g?g*"(tjdj?6V??6 R w&FR FR&GbV > v F2fVC > ________________________________ > > 6wB 6VRB > > > > &W&o??G2 W&vVB 6RVVFVBf"7[1] FW7Fp??F0?? > ________________________________ > > V&V6? &GV7B > ________________________________ > > vW" > ________________________________ > > 6V6 > ________________________________ > > 2?F&V7B?S > ________________________________ > > SB > ________________________________ > > ##r > ________________________________ > > s3r[1]??&v > ________________________________ > > W76vR?g&?[1]$FfBVr" > ________________________________ > > FfBVt VIFVw&W26?FFSGVR > ________________________________ > > ________________________________ > > ________________________________ > > # > ________________________________ > > ________________________________ > > r > ________________________________ > > ##?F&fW&F" > ________________________________ > > fW&FF?VIFVw&W26&W&2&W&" > ________________________________ > > W&2 &W&VIFVw&W26?63&FFv"" > ________________________________ > > FFv$VIFVw&W26%6Tr" > ________________________________ > > 6Rt 6V626&V&V" > ________________________________ > > V&V6 6V626'6G&'W&F" > ________________________________ > > 6G&'W&FVIFVw&W26&VWB" > ________________________________ > > VWBGW&W6vTVIFVw&W26&VFV" > ________________________________ > > VFV6 VVIFVw&W266TVIFVw&W26&V'F" > ________________________________ > > zV'FVIFVw&W26$FR" > ________________________________ > > zFRWG64VIFVw&W 26&FfBGW&" > ________________________________ > > FfBGW&VIFVw&W26%F" > ________________________________ > > FTVIFVw&W26'o R" > ________________________________ > > oTVIFVw&W26&66r" > ________________________________ > > ?66tVIFVw&W26&'R" > ________________________________ > > 'TVIFVw&W26$66R" > ________________________________ > > 66VF v?v6%6&?R" > ________________________________ > > F?6$6" > ________________________________ > > ?6Fv?v6&VfVr" > ________________________________ > > VfVtF?6?7V&V7C > ________________________________ > > B > ________________________________ > > ?W"G& &GV6R&W'@??FV" > ________________________________ > > fW&FW&2V6R 6VRB?W" G& > > > > &GV7" &W'B7V7F &W7VB2fVB&W7B &Vv&G2FfBVpVIFR > ________________________________ > > w&W[1] > ________________________________ > > 2 > ________________________________ > > 6 > ________________________________ > > ff6P&S > ________________________________ > > b3 > ________________________________ > > ________________________________ > > cs#cV?VIFW2?6 > ________________________________ > > c26? > ________________________________ > > FVIFW2?6 > ________________________________ > > c26R#FfBVtVIFVw&W26 > ________________________________ > > FFfBVtVIFVw&W26vV'6FS wwrVIFVw&W26 > ________________________________ > > ?GG > ________________________________ > > wwrVIFVw&W26%F2Vf76?R6F26fFVFf&FFVFVBof" FR W6Rb FR W'6VB&fR > ________________________________ > > b R&RB FRFVFVB &V6VBb F2Vf76?R" FRVVR"vVB &W76&Rf"FVIfW&rB > F FRFVFVB &V6VB R&RW&V'FfVB FBF76V?F"6 |*[1]b F2Vf76?\*[1]2 > 7G&7Fo > > > > &&FVB > ________________________________ > > b RfR &V6VfVB F2Vf76?RW'&" V6R &WGW& F W2C > ________________________________ > > sR6RGR > ________________________________ > > g&W&R > ________________________________ > > G&R > ________________________________ > > G&VVV&V2*[1] > ________________________________ > > 6F > ________________________________ > > 4" > ________________________________ > > 5,*[1]'fC > ________________________________ > > SB? > ________________________________ > > rS#s " F FR 6VFW"w2VFG&W72F6FVB&fR > > > > Gerhard, > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Wed May 9 15:02:12 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Wed May 9 15:02:22 2007 Subject: Issue with Blackberry In-Reply-To: <3123E1B72B666243917E340F3C8FD4A10696E7@privaldc2003.prival.local> References: <3123E1B72B666243917E340F3C8FD4A10696E7@privaldc2003.prival.local> Message-ID: <2e62294734b80b9df1c58b9ec14d633c@62.49.223.244> The headers do not look right to me, and I reckon that funny content you are seeing is the .xls attachment. I know you say that it has been sent via a Blackberry but the headers are for Outlook V11 ? On Wed, 9 May 2007 09:26:31 -0400, "Gerhard Mourani" wrote: > Here what users sent to me. Also this is what I've in the -> > /etc/postfix/header_checks file > /^Received: (.*?) by eliteclassics.com(.*?)/ REJECT > /^Received:/ HOLD > > Now the headers: > A problem was found in an Email message you sent. > This Email scanner intercepted it and stopped the entire message > reaching its destination. > > The problem was reported to be: > > Disallowed breakage found in header name - potential virus > > > Please contact your IT support personnel with any queries regarding this > policy. > > > Your message was sent with the following envelope: > > MAIL FROM: carla.redman@elitegroupinc.ca > RCPT TO: joshua.levin@myexchangehosting.net > > ... and with the following headers: > > --- > MAILFROM: carla.redman@elitegroupinc.ca > Delivered-To: jwlevinp-joshua.levin@jwlevinpartners.com > Received: (qmail 55802 invoked from network); 4 May 2007 18:37:42 -0000 > Received: from unknown (HELO mail.eliteclassics.com) (149.99.191.243) > by host355.ipowerweb.com with SMTP; 4 May 2007 18:37:42 -0000 > Received: from EXECDanny (office.eliteclassics.com [149.99.191.242]) > by mail.eliteclassics.com (Postfix) with ESMTP id CEC964DEC > for ; Fri, 4 May 2007 14:40:18 > -0400 (EDT) > Return-Receipt-To: "Carla Redman" > Reply-To: > From: "Carla Redman" > To: "'Levin, Joshua'" > References: > Ps0BAAAAAA==@elitegroupinc.ca> > <435DF58A933BA74397B42CDEB8145A860B8C4AE3@ex9.hostedexchange.local> > Subject: RE: feb 07 flights .xls > Date: Fri, 4 May 2007 14:45:04 -0400 > Organization: Elite Group > Message-ID: > nvYBAAAAAA==@elitegroupinc.ca> > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_NextPart_000_0003_01C78E5A.CD761FE0" > X-Mailer: Microsoft Office Outlook 11 > Thread-Index: > AceCyu12JEluHxWIQ7ClFI22mBkHtgAghwiAAA0iz+AAAC8ZAAK8H9XgAAIRniA= > In-Reply-To: > <435DF58A933BA74397B42CDEB8145A860B8C4AE3@ex9.hostedexchange.local> > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 > Disposition-Notification-To: "Carla Redman" > > X-Elite Group, Inc.-MailScanner: Found to be clean > X-Elite Group, Inc.-MailScanner-From: carla.redman@elitegroupinc.ca > X-Spam-Status: No > > Thanks, > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD > ]-- > Sent: Wednesday, May 09, 2007 9:08 AM > To: MailScanner discussion > Subject: Re: Issue with Blackberry > > Would be useful to see the actual headers, especially the MIME section. > > On Wed, 9 May 2007 08:38:05 -0400, "Gerhard Mourani" > wrote: >> Hello, >> >> >> >> I'm using MailScanner + Postfix + SpamAssassin on Linux and having > strange >> issues with email coming from blackberry servers, here how the received >> email look like: >> >> >> >> Subject: Re: Hand Mixer Trial-Produce Report >> >> >> >> \Ib?HTjy?Z.hm%yXxj?'p?'wJI+{E+.1I?U)?g?g*"(tjdj?6V??6 R w&FR > FR&GbV >> v F2fVC >> ________________________________ >> >> 6wB 6VRB >> >> >> >> &W&o??G2 W&vVB 6RVVFVBf"7[1] FW7Fp??F0?? >> ________________________________ >> >> V&V6? &GV7B >> ________________________________ >> >> vW" >> ________________________________ >> >> 6V6 >> ________________________________ >> >> 2?F&V7B?S >> ________________________________ >> >> SB >> ________________________________ >> >> ##r >> ________________________________ >> >> s3r[1]??&v >> ________________________________ >> >> W76vR?g&?[1]$FfBVr" >> ________________________________ >> >> FfBVt VIFVw&W26?FFSGVR >> ________________________________ >> >> ________________________________ >> >> ________________________________ >> >> # >> ________________________________ >> >> ________________________________ >> >> r >> ________________________________ >> >> ##?F&fW&F" >> ________________________________ >> >> fW&FF?VIFVw&W26&W&2&W&" >> ________________________________ >> >> W&2 &W&VIFVw&W26?63&FFv"" >> ________________________________ >> >> FFv$VIFVw&W26%6Tr" >> ________________________________ >> >> 6Rt 6V626&V&V" >> ________________________________ >> >> V&V6 6V626'6G&'W&F" >> ________________________________ >> >> 6G&'W&FVIFVw&W26&VWB" >> ________________________________ >> >> VWBGW&W6vTVIFVw&W26&VFV" >> ________________________________ >> >> VFV6 VVIFVw&W266TVIFVw&W26&V'F" >> ________________________________ >> >> zV'FVIFVw&W26$FR" >> ________________________________ >> >> zFRWG64VIFVw&W 26&FfBGW&" >> ________________________________ >> >> FfBGW&VIFVw&W26%F" >> ________________________________ >> >> FTVIFVw&W26'o R" >> ________________________________ >> >> oTVIFVw&W26&66r" >> ________________________________ >> >> ?66tVIFVw&W26&'R" >> ________________________________ >> >> 'TVIFVw&W26$66R" >> ________________________________ >> >> 66VF v?v6%6&?R" >> ________________________________ >> >> F?6$6" >> ________________________________ >> >> ?6Fv?v6&VfVr" >> ________________________________ >> >> VfVtF?6?7V&V7C >> ________________________________ >> >> B >> ________________________________ >> >> ?W"G& &GV6R&W'@??FV" >> ________________________________ >> >> fW&FW&2V6R 6VRB?W" G& >> >> >> >> &GV7" &W'B7V7F &W7VB2fVB&W7B &Vv&G2FfBVpVIFR >> ________________________________ >> >> w&W[1] >> ________________________________ >> >> 2 >> ________________________________ >> >> 6 >> ________________________________ >> >> ff6P&S >> ________________________________ >> >> b3 >> ________________________________ >> >> ________________________________ >> >> cs#cV?VIFW2?6 >> ________________________________ >> >> c26? >> ________________________________ >> >> FVIFW2?6 >> ________________________________ >> >> c26R#FfBVtVIFVw&W26 >> ________________________________ >> >> FFfBVtVIFVw&W26vV'6FS wwrVIFVw&W26 >> ________________________________ >> >> ?GG >> ________________________________ >> >> wwrVIFVw&W26%F2Vf76?R6F26fFVFf&FFVFVBof" FR W6Rb FR W'6VB&fR > >> ________________________________ >> >> b R&RB FRFVFVB &V6VBb F2Vf76?R" FRVVR"vVB > &W76&Rf"FVIfW&rB >> F FRFVFVB &V6VB R&RW&V'FfVB FBF76V?F"6 |*[1]b F2Vf76?\*[1]2 >> 7G&7Fo >> >> >> >> &&FVB >> ________________________________ >> >> b RfR &V6VfVB F2Vf76?RW'&" V6R &WGW& F W2C >> ________________________________ >> >> sR6RGR >> ________________________________ >> >> g&W&R >> ________________________________ >> >> G&R >> ________________________________ >> >> G&VVV&V2*[1] >> ________________________________ >> >> 6F >> ________________________________ >> >> 4" >> ________________________________ >> >> 5,*[1]'fC >> ________________________________ >> >> SB? >> ________________________________ >> >> rS#s " F FR 6VFW"w2VFG&W72F6FVB&fR >> >> >> >> Gerhard, >> >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> >> >> > -- > --[ UxBoD ]-- > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From glenn.steen at gmail.com Wed May 9 15:02:39 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed May 9 15:02:43 2007 Subject: Issue with Blackberry In-Reply-To: <3123E1B72B666243917E340F3C8FD4A10696E7@privaldc2003.prival.local> References: <4717144a9438363409909b0a056c183b@62.49.223.244> <3123E1B72B666243917E340F3C8FD4A10696E7@privaldc2003.prival.local> Message-ID: <223f97700705090702p2eb83a1ak634477c2b1a2caca@mail.gmail.com> On 09/05/07, Gerhard Mourani wrote: > Here what users sent to me. Also this is what I've in the -> /etc/postfix/header_checks file (snip) > X-Elite Group, Inc.-MailScanner: Found to be clean > X-Elite Group, Inc.-MailScanner-From: carla.redman@elitegroupinc.ca Read the comment above where you set your %org-name% and amend it according to that. whitespace (and some other caracters) are not allowed in headers (the lval ...), so you cant have that... Set it to something like EliteGroupInc and you should be fine. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From gmourani at prival.ca Wed May 9 15:09:49 2007 From: gmourani at prival.ca (Gerhard Mourani) Date: Wed May 9 15:10:12 2007 Subject: Issue with Blackberry In-Reply-To: <2e62294734b80b9df1c58b9ec14d633c@62.49.223.244> Message-ID: <3123E1B72B666243917E340F3C8FD4A10696EC@privaldc2003.prival.local> Yes, sorry I've sent the wrong message, this one is another problem and it's related to remote qmail server saying -> 'Disallowed breakage found in header name - potential virus' when receiving emails from this domain running MailScanner. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- Sent: Wednesday, May 09, 2007 10:02 AM To: MailScanner discussion Subject: RE: Issue with Blackberry The headers do not look right to me, and I reckon that funny content you are seeing is the .xls attachment. I know you say that it has been sent via a Blackberry but the headers are for Outlook V11 ? On Wed, 9 May 2007 09:26:31 -0400, "Gerhard Mourani" wrote: > Here what users sent to me. Also this is what I've in the -> > /etc/postfix/header_checks file > /^Received: (.*?) by eliteclassics.com(.*?)/ REJECT > /^Received:/ HOLD > > Now the headers: > A problem was found in an Email message you sent. > This Email scanner intercepted it and stopped the entire message > reaching its destination. > > The problem was reported to be: > > Disallowed breakage found in header name - potential virus > > > Please contact your IT support personnel with any queries regarding this > policy. > > > Your message was sent with the following envelope: > > MAIL FROM: carla.redman@elitegroupinc.ca > RCPT TO: joshua.levin@myexchangehosting.net > > ... and with the following headers: > > --- > MAILFROM: carla.redman@elitegroupinc.ca > Delivered-To: jwlevinp-joshua.levin@jwlevinpartners.com > Received: (qmail 55802 invoked from network); 4 May 2007 18:37:42 -0000 > Received: from unknown (HELO mail.eliteclassics.com) (149.99.191.243) > by host355.ipowerweb.com with SMTP; 4 May 2007 18:37:42 -0000 > Received: from EXECDanny (office.eliteclassics.com [149.99.191.242]) > by mail.eliteclassics.com (Postfix) with ESMTP id CEC964DEC > for ; Fri, 4 May 2007 14:40:18 > -0400 (EDT) > Return-Receipt-To: "Carla Redman" > Reply-To: > From: "Carla Redman" > To: "'Levin, Joshua'" > References: > Ps0BAAAAAA==@elitegroupinc.ca> > <435DF58A933BA74397B42CDEB8145A860B8C4AE3@ex9.hostedexchange.local> > Subject: RE: feb 07 flights .xls > Date: Fri, 4 May 2007 14:45:04 -0400 > Organization: Elite Group > Message-ID: > nvYBAAAAAA==@elitegroupinc.ca> > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_NextPart_000_0003_01C78E5A.CD761FE0" > X-Mailer: Microsoft Office Outlook 11 > Thread-Index: > AceCyu12JEluHxWIQ7ClFI22mBkHtgAghwiAAA0iz+AAAC8ZAAK8H9XgAAIRniA= > In-Reply-To: > <435DF58A933BA74397B42CDEB8145A860B8C4AE3@ex9.hostedexchange.local> > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 > Disposition-Notification-To: "Carla Redman" > > X-Elite Group, Inc.-MailScanner: Found to be clean > X-Elite Group, Inc.-MailScanner-From: carla.redman@elitegroupinc.ca > X-Spam-Status: No > > Thanks, > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD > ]-- > Sent: Wednesday, May 09, 2007 9:08 AM > To: MailScanner discussion > Subject: Re: Issue with Blackberry > > Would be useful to see the actual headers, especially the MIME section. > > On Wed, 9 May 2007 08:38:05 -0400, "Gerhard Mourani" > wrote: >> Hello, >> >> >> >> I'm using MailScanner + Postfix + SpamAssassin on Linux and having > strange >> issues with email coming from blackberry servers, here how the received >> email look like: >> >> >> >> Subject: Re: Hand Mixer Trial-Produce Report >> >> >> >> \Ib?HTjy?Z.hm%yXxj?'p?'wJI+{E+.1I?U)?g?g*"(tjdj?6V??6 R w&FR > FR&GbV >> v F2fVC >> ________________________________ >> >> 6wB 6VRB >> >> >> >> &W&o??G2 W&vVB 6RVVFVBf"7[1] FW7Fp??F0?? >> ________________________________ >> >> V&V6? &GV7B >> ________________________________ >> >> vW" >> ________________________________ >> >> 6V6 >> ________________________________ >> >> 2?F&V7B?S >> ________________________________ >> >> SB >> ________________________________ >> >> ##r >> ________________________________ >> >> s3r[1]??&v >> ________________________________ >> >> W76vR?g&?[1]$FfBVr" >> ________________________________ >> >> FfBVt VIFVw&W26?FFSGVR >> ________________________________ >> >> ________________________________ >> >> ________________________________ >> >> # >> ________________________________ >> >> ________________________________ >> >> r >> ________________________________ >> >> ##?F&fW&F" >> ________________________________ >> >> fW&FF?VIFVw&W26&W&2&W&" >> ________________________________ >> >> W&2 &W&VIFVw&W26?63&FFv"" >> ________________________________ >> >> FFv$VIFVw&W26%6Tr" >> ________________________________ >> >> 6Rt 6V626&V&V" >> ________________________________ >> >> V&V6 6V626'6G&'W&F" >> ________________________________ >> >> 6G&'W&FVIFVw&W26&VWB" >> ________________________________ >> >> VWBGW&W6vTVIFVw&W26&VFV" >> ________________________________ >> >> VFV6 VVIFVw&W266TVIFVw&W26&V'F" >> ________________________________ >> >> zV'FVIFVw&W26$FR" >> ________________________________ >> >> zFRWG64VIFVw&W 26&FfBGW&" >> ________________________________ >> >> FfBGW&VIFVw&W26%F" >> ________________________________ >> >> FTVIFVw&W26'o R" >> ________________________________ >> >> oTVIFVw&W26&66r" >> ________________________________ >> >> ?66tVIFVw&W26&'R" >> ________________________________ >> >> 'TVIFVw&W26$66R" >> ________________________________ >> >> 66VF v?v6%6&?R" >> ________________________________ >> >> F?6$6" >> ________________________________ >> >> ?6Fv?v6&VfVr" >> ________________________________ >> >> VfVtF?6?7V&V7C >> ________________________________ >> >> B >> ________________________________ >> >> ?W"G& &GV6R&W'@??FV" >> ________________________________ >> >> fW&FW&2V6R 6VRB?W" G& >> >> >> >> &GV7" &W'B7V7F &W7VB2fVB&W7B &Vv&G2FfBVpVIFR >> ________________________________ >> >> w&W[1] >> ________________________________ >> >> 2 >> ________________________________ >> >> 6 >> ________________________________ >> >> ff6P&S >> ________________________________ >> >> b3 >> ________________________________ >> >> ________________________________ >> >> cs#cV?VIFW2?6 >> ________________________________ >> >> c26? >> ________________________________ >> >> FVIFW2?6 >> ________________________________ >> >> c26R#FfBVtVIFVw&W26 >> ________________________________ >> >> FFfBVtVIFVw&W26vV'6FS wwrVIFVw&W26 >> ________________________________ >> >> ?GG >> ________________________________ >> >> wwrVIFVw&W26%F2Vf76?R6F26fFVFf&FFVFVBof" FR W6Rb FR W'6VB&fR > >> ________________________________ >> >> b R&RB FRFVFVB &V6VBb F2Vf76?R" FRVVR"vVB > &W76&Rf"FVIfW&rB >> F FRFVFVB &V6VB R&RW&V'FfVB FBF76V?F"6 |*[1]b F2Vf76?\*[1]2 >> 7G&7Fo >> >> >> >> &&FVB >> ________________________________ >> >> b RfR &V6VfVB F2Vf76?RW'&" V6R &WGW& F W2C >> ________________________________ >> >> sR6RGR >> ________________________________ >> >> g&W&R >> ________________________________ >> >> G&R >> ________________________________ >> >> G&VVV&V2*[1] >> ________________________________ >> >> 6F >> ________________________________ >> >> 4" >> ________________________________ >> >> 5,*[1]'fC >> ________________________________ >> >> SB? >> ________________________________ >> >> rS#s " F FR 6VFW"w2VFG&W72F6FVB&fR >> >> >> >> Gerhard, >> >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> >> >> > -- > --[ UxBoD ]-- > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From gmourani at prival.ca Wed May 9 15:15:34 2007 From: gmourani at prival.ca (Gerhard Mourani) Date: Wed May 9 15:16:03 2007 Subject: Issue with Blackberry In-Reply-To: <223f97700705090702p2eb83a1ak634477c2b1a2caca@mail.gmail.com> Message-ID: <3123E1B72B666243917E340F3C8FD4A10696ED@privaldc2003.prival.local> Thanks, Yes I remember now, never use white space. Cheers, -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Glenn Steen Sent: Wednesday, May 09, 2007 10:03 AM To: MailScanner discussion Subject: Re: Issue with Blackberry On 09/05/07, Gerhard Mourani wrote: > Here what users sent to me. Also this is what I've in the -> /etc/postfix/header_checks file (snip) > X-Elite Group, Inc.-MailScanner: Found to be clean > X-Elite Group, Inc.-MailScanner-From: carla.redman@elitegroupinc.ca Read the comment above where you set your %org-name% and amend it according to that. whitespace (and some other caracters) are not allowed in headers (the lval ...), so you cant have that... Set it to something like EliteGroupInc and you should be fine. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From Denis.Beauchemin at USherbrooke.ca Wed May 9 15:43:43 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Wed May 9 15:44:05 2007 Subject: Attachment filename filter rules (sophisticated) In-Reply-To: <08AD7B42A2698345BA90F9E33A46F2C401AC8394@ULPGCTMVMAI003.EU.COLT> References: <08AD7B42A2698345BA90F9E33A46F2C401AC8394@ULPGCTMVMAI003.EU.COLT> Message-ID: <4641DE1F.20108@USherbrooke.ca> Ohlenmacher, Olaf a ?crit : > Hello, > we drop attachments by filenames extentions. Nowerdays attachment filenames are MIME-coded so that Umlauts and other special characters can be handled in a 7-Bit clean way. > > My question: > Are the regular expressions applied to the decoded filenames or are they applied to the encoded filenames. > I just tested it and it was blocked. Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3595 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070509/cfc5d9b7/smime.bin From alden at engineno9inc.com Wed May 9 15:49:17 2007 From: alden at engineno9inc.com (Alden Levy) Date: Wed May 9 15:49:33 2007 Subject: SMPID vs. INPID Message-ID: <001f01c79249$38dfd6d0$7100000a@AldenLap> Scott Silva ssilva wrote on Wed May 9 04:40:53 IST 2007 >Alden Levy spake the following on 5/8/2007 7:39 PM: >>> Scott Silva ssilva wrote on Wed May 9 00:17:19 IST 2007 >>>> Scott Silva ssilva wrote on Tue May 8 21:08:43 IST 2007 >>>>> Alden Levy spake the following on 5/8/2007 12:16 PM: >>>>>> Hugo van der Kooij wrote on Tue May 8 20:09:32 IST 2007 >>>>>>> On Tue, 8 May 2007, Alden Levy wrote: >>>>>>> >>>>>>>> Thanks for this. Now, I'm really confused; the RedHat init script is >>>>>>>> identical to the one I'm using. >>>>>>>> >>>>>>>> Does anyone have an idea of where else I should look? (Quick recap: >>>>>>>> /var/run/sendmail.in.pid is not getting updated, so >>>>>>>> /etc/init.d/MailScanner >>>>>>>> status lists incoming sendmail as failed. sm-client.pid looks fine, >>>>>>>> though.) >>>>>>> If you stop MailScanner the PID file should be gone. If not then you >>>>>>> should remove it by hand and see if it happens to get recreated at >>>>>>> startup. >>>>>>> >>>>>>> Hugo. >>>>>>> >>>>>>> -- >>>>>>> hvdkooij at vanderkooij.org http://hugo.vanderkooij.org/ >>>>>>> This message is using 100% recycled electrons. >>>>>> Well, that was a mistake! Now after removing the file by hand, and >>>>>> restarting, I run status and get: >>>>>> Checking MailScanner daemons: >>>>>> MailScanner: [ OK ] >>>>>> incoming sendmail: head: cannot open >> `/var/run/sendmail.in.pid' for >>>>>> reading: No such file or directory >>>>>> [FAILED] >>>>>> outgoing sendmail: [ OK ] >>>>>> >>>>>> >>>>>> Any other thoughts? >>>>>> Thanks, >>>>>> Alden >>>>> >>>> Your init script could be either damaged, or an old version. >>>> But I did a diff on my init script and the RedHat script you sent earlier >>>> today, and there is no difference. Can it still be corrupted? >>>> >>>> I was wondering if I should look elsewhere, or just try to reinstall. >>>> >>>> Thanks, >>>> Alden >>>> >>> You do have sendmail disabled, don't you? >> >> Yep. But I'm going to double check, anyway. I've done "chkconfig sendmail >> off" a few times, but I'll try again. >> >> However, when I start sendmail, I have 3 instances running: >> # ps aux|grep sendmail >> root 23940 0.0 0.0 9092 1888 ? Ss 22:36 0:00 sendmail: >> accepting connections >> >> smmsp 23944 0.0 0.0 6940 1656 ? Ss 22:36 0:00 sendmail: >> Queue runner at 00:15:00 for /var/spool/clientmqueue >> root 23949 0.0 0.0 8296 1780 ? Ss 22:36 0:00 sendmail: >> Queue runner at 00:15:00 for >> /home/virtual/FILESYSTEMTEMPLATE/services/sendmail/mqueue >> >> The first one doesn't stop when I service MailScanner stop, and I have to >> issue a service sendmail stop in order to kill it. >> >> Curiouser and curiouser... Is this good/bad/indifferent? I've been seeing >> this for a while, as this was what I had on my old server, but I don't >> remember what was running when it was working properly. >> >> >Look in /etc/sysconfig for a MailScanner.rpmnew. Maybe you have an old version >in there. I've looked, and there is no MailScanner.rpmnew in /etc/sysconfig. The original file has a date stamp of Feb 1, which predates my server setup, but I *believe* is the date of the release of the version I'm using. Here's the file contents (with settings for other MTAs removed): # Put in here all the settings for your particular mail system so that # MailScanner's init.d script can run it all for you. # # # Are you running Postfix, sendmail, Exim or ZMailer? # # Don't set it by hand, we now auto-detect it from MailScanner.conf # MTA=sendmail # MTA=postfix # MTA=exim # MTA=zmailer # Extract setting for MTA from MailScanner.conf MTA=`perl -n -e 'print "$_" if chomp && s/^\s*MTA\s*=\s*([a-zA-Z]+)/$1/ && ($_=lc($_))' /etc/MailScanner/MailScanner.conf` # # Cron job update_virus_scanners settings # UPDATEMAXDELAY=600 # Maximum delay before running cron job to avoid server peaks # # Cron job sa-update settings # SAUPDATE=/usr/bin/sa-update # Location of sa-update program # # MailScanner Settings # #WORKDIR=/var/spool/MailScanner/incoming # Where the temp MailScanner files live # Extract settings for "Incoming Work Dir" and "Incoming Queue Dir" WORKDIR=`perl -n -e 'print "$_" if chomp && s/^\s*Incoming\s*Work\s*Dir\s*=\s*(\S+)/$1/i' /etc/MailScanner/MailScanner.conf` INQDIR=`perl -n -e 'print "$_" if chomp && s/^\s*Incoming\s*Queue\s*Dir\s*=\s*(\S+)/$1/i' /etc/MailScanner/MailScanner.conf` QUARDIR=`perl -n -e 'print "$_" if chomp && s/^\s*Quarantine\s*Dir\s*=\s*(\S+)/$1/i' /etc/MailScanner/MailScanner.conf` RUNAS=`perl -n -e 'print "$_" if chomp && s/^\s*Run\s*As\s*User\s*=\s*(\S+)/$1/i' /etc/MailScanner/MailScanner.conf` RESTART_DELAY=10 # Pause time between stop and start when restarting #perl -e 'print "***WORKDIR='$WORKDIR'***\n***INQDIR='$INQDIR'***\n";' # # Sendmail Settings # SENDMAIL=/usr/sbin/sendmail QUEUETIME=15m #INQDIR=/var/spool/mqueue.in INPID=/var/run/sendmail.in.pid OUTPID=/var/run/sendmail.out.pid SMPID=/var/run/sm-client.pid MSPUSER=smmsp # User for mail submission queue runner MSPGROUP=smmsp # Group for mail submission queue runner Thanks, Alden From pravin.rane at gmail.com Wed May 9 18:28:33 2007 From: pravin.rane at gmail.com (Pravin Rane) Date: Wed May 9 18:28:36 2007 Subject: MailScanner w/ Qmail / Plesk In-Reply-To: References: Message-ID: <13c021a90705091028p6103e38cw179eb8d4e1660102@mail.gmail.com> Try to inject mail using /var/qmail/bin/qmail-inject.mailscanner */var/qmail/bin/qmail-inject.mailscanner user@mydomain.com < name_of_the_file* and see whether that mail is getting pushed to /var/qmail/queue directory On 5/9/07, Cameron B. Prince wrote: > > Hey guys, > > I have a new dedicated server with Plesk. I originally purchased the > SpamAssassin and Dr. Web anti-virus plugins but they just don't compare to > MailScanner w/ MailWatch. > > I followed the instructions to setup MailScanner with Qmail here: > > http://qms.ausics.net/ > > I verified all the perl modules and checked the updates to the > MailScanner.conf file. When I started MailScanner the init script > complained > that the MTA was invalid. I started Qmail manually and sent a test > message. > When the message hit the SMTP I got a queue error returned to the client. > > I ran this command and the queue errors went away: > > chmod u+s /var/qmail/bin/qmail-queue > > Now a test message produces this in the log: > > relaylock: /var/qmail/bin/relaylock: mail from xxx.xxx.xxx.xxx:61451 > (my.domain.com) > MailScanner[6489]: New Batch: Scanning 1 messages, 668 bytes > MailScanner[6489]: SpamAssassin cache hit for message 7064403 > MailScanner[6489]: Virus and Content Scanning: Starting > MailScanner[6489]: Uninfected: Delivered 1 messages > MailScanner[6489]: Logging message 7064403 to SQL > MailScanner[6451]: 7064403: Logged to MailWatch SQL > > When I checked the other mailbox for the message I found that it was never > received. I enabled debugging and got this output when I tried another > test > message: > > /usr/sbin/MailScanner > In Debugging mode, not forking... > Ignore errors about failing to find EOCD signature > format error: file is too short > at /usr/sbin/MailScanner line 832 > Stopping now as you are debugging me. > commit ineffective with AutoCommit enabled at > /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, > line 34. > Commmit ineffective while AutoCommit is on at > /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, > line 34. > > > > I know this patch for Qmail is pretty old and I wonder if this is the > cause > or if it's more likely to be a problem with the Plesk version of Qmail. > Can > anyone give me some ideas to troubleshoot this? > > > Thanks, > Cameron > > > > PS Here's the output of a lint test: > > /usr/sbin/MailScanner --lint > Read 764 hostnames from the phishing whitelist > Config: calling custom init function SQLBlacklist > Config: calling custom init function MailWatchLogging > Config: calling custom init function SQLWhitelist > Checking version numbers... > Version number in MailScanner.conf (4.58.9) is correct. > MailScanner setting GID to (2520) > MailScanner setting UID to (2520) > > Checking for SpamAssassin errors (if you use it)... > Using SpamAssassin results cache > Connected to SpamAssassin cache database > SpamAssassin reported no errors. > lock.pl sees Config LockType = flock > lock.pl sees have_module = 0 > Using locktype = flock > MailScanner.conf says "Virus Scanners = f-prot" > Found these virus scanners installed: f-prot > > > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- Regards Pravin -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070509/ff157793/attachment.html From gmourani at prival.ca Wed May 9 19:27:35 2007 From: gmourani at prival.ca (Gerhard Mourani) Date: Wed May 9 19:29:25 2007 Subject: Issue with Blackberry Message-ID: <3123E1B72B666243917E340F3C8FD4A1069703@privaldc2003.prival.local> Ok, here an emails being sent from a users blackberry. Return-Path: X-Original-To: todd.savage@elitegroupinc.ca Delivered-To: todd.savage@elitegroupinc.ca Received: from smtp04.bis.na.blackberry.com (smtp04.bis.na.blackberry.com [216.9.248.51]) by mail.eliteclassics.com (Postfix) with ESMTP id 04231C549; Wed, 9 May 2007 14:02:10 -0400 (EDT) Message-ID: <344973756-1178733913-cardhu_blackberry.rim.net-1567301641-@bxe017-cell02.bisx.prod.on.blackberry> Reply-To: katie.papoutsis@elitegroupinc.ca Sensitivity: Normal Importance: Normal To: "Todd Savage" Subject: Fw: From: "=?UTF-8?B?S2F0aWUgUGFwb3V0c2lz?=" Date: Wed, 9 May 2007 18:05:39 +0000 Content-type: text/plain MIME-Version: 1.0 X-EliteGroupInc-MailScanner: Found to be clean X-EliteGroupInc-MailScanner-From: katie.papoutsis@elitegroupinc.ca X-Spam-Status: No -----Original Message----- From: Gerhard Mourani Sent: Wednesday, May 09, 2007 9:27 AM To: 'MailScanner discussion' Subject: RE: Issue with Blackberry Here what users sent to me. Also this is what I've in the -> /etc/postfix/header_checks file /^Received: (.*?) by eliteclassics.com(.*?)/ REJECT /^Received:/ HOLD Now the headers: A problem was found in an Email message you sent. This Email scanner intercepted it and stopped the entire message reaching its destination. The problem was reported to be: Disallowed breakage found in header name - potential virus Please contact your IT support personnel with any queries regarding this policy. Your message was sent with the following envelope: MAIL FROM: carla.redman@elitegroupinc.ca RCPT TO: joshua.levin@myexchangehosting.net ... and with the following headers: --- MAILFROM: carla.redman@elitegroupinc.ca Delivered-To: jwlevinp-joshua.levin@jwlevinpartners.com Received: (qmail 55802 invoked from network); 4 May 2007 18:37:42 -0000 Received: from unknown (HELO mail.eliteclassics.com) (149.99.191.243) by host355.ipowerweb.com with SMTP; 4 May 2007 18:37:42 -0000 Received: from EXECDanny (office.eliteclassics.com [149.99.191.242]) by mail.eliteclassics.com (Postfix) with ESMTP id CEC964DEC for ; Fri, 4 May 2007 14:40:18 -0400 (EDT) Return-Receipt-To: "Carla Redman" Reply-To: From: "Carla Redman" To: "'Levin, Joshua'" References: <435DF58A933BA74397B42CDEB8145A860B8C4AE3@ex9.hostedexchange.local> Subject: RE: feb 07 flights .xls Date: Fri, 4 May 2007 14:45:04 -0400 Organization: Elite Group Message-ID: MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0003_01C78E5A.CD761FE0" X-Mailer: Microsoft Office Outlook 11 Thread-Index: AceCyu12JEluHxWIQ7ClFI22mBkHtgAghwiAAA0iz+AAAC8ZAAK8H9XgAAIRniA= In-Reply-To: <435DF58A933BA74397B42CDEB8145A860B8C4AE3@ex9.hostedexchange.local> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 Disposition-Notification-To: "Carla Redman" X-Elite Group, Inc.-MailScanner: Found to be clean X-Elite Group, Inc.-MailScanner-From: carla.redman@elitegroupinc.ca X-Spam-Status: No Thanks, -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- Sent: Wednesday, May 09, 2007 9:08 AM To: MailScanner discussion Subject: Re: Issue with Blackberry Would be useful to see the actual headers, especially the MIME section. On Wed, 9 May 2007 08:38:05 -0400, "Gerhard Mourani" wrote: > Hello, > > > > I'm using MailScanner + Postfix + SpamAssassin on Linux and having strange > issues with email coming from blackberry servers, here how the received > email look like: > > > > Subject: Re: Hand Mixer Trial-Produce Report > > > > \Ib?HTjy?Z.hm%yXxj?'p?'wJI+{E+.1I?U)?g?g*"(tjdj?6V??6 R w&FR FR&GbV > v F2fVC > ________________________________ > > 6wB 6VRB > > > > &W&o??G2 W&vVB 6RVVFVBf"7[1] FW7Fp??F0?? > ________________________________ > > V&V6? &GV7B > ________________________________ > > vW" > ________________________________ > > 6V6 > ________________________________ > > 2?F&V7B?S > ________________________________ > > SB > ________________________________ > > ##r > ________________________________ > > s3r[1]??&v > ________________________________ > > W76vR?g&?[1]$FfBVr" > ________________________________ > > FfBVt VIFVw&W26?FFSGVR > ________________________________ > > ________________________________ > > ________________________________ > > # > ________________________________ > > ________________________________ > > r > ________________________________ > > ##?F&fW&F" > ________________________________ > > fW&FF?VIFVw&W26&W&2&W&" > ________________________________ > > W&2 &W&VIFVw&W26?63&FFv"" > ________________________________ > > FFv$VIFVw&W26%6Tr" > ________________________________ > > 6Rt 6V626&V&V" > ________________________________ > > V&V6 6V626'6G&'W&F" > ________________________________ > > 6G&'W&FVIFVw&W26&VWB" > ________________________________ > > VWBGW&W6vTVIFVw&W26&VFV" > ________________________________ > > VFV6 VVIFVw&W266TVIFVw&W26&V'F" > ________________________________ > > zV'FVIFVw&W26$FR" > ________________________________ > > zFRWG64VIFVw&W 26&FfBGW&" > ________________________________ > > FfBGW&VIFVw&W26%F" > ________________________________ > > FTVIFVw&W26'o R" > ________________________________ > > oTVIFVw&W26&66r" > ________________________________ > > ?66tVIFVw&W26&'R" > ________________________________ > > 'TVIFVw&W26$66R" > ________________________________ > > 66VF v?v6%6&?R" > ________________________________ > > F?6$6" > ________________________________ > > ?6Fv?v6&VfVr" > ________________________________ > > VfVtF?6?7V&V7C > ________________________________ > > B > ________________________________ > > ?W"G& &GV6R&W'@??FV" > ________________________________ > > fW&FW&2V6R 6VRB?W" G& > > > > &GV7" &W'B7V7F &W7VB2fVB&W7B &Vv&G2FfBVpVIFR > ________________________________ > > w&W[1] > ________________________________ > > 2 > ________________________________ > > 6 > ________________________________ > > ff6P&S > ________________________________ > > b3 > ________________________________ > > ________________________________ > > cs#cV?VIFW2?6 > ________________________________ > > c26? > ________________________________ > > FVIFW2?6 > ________________________________ > > c26R#FfBVtVIFVw&W26 > ________________________________ > > FFfBVtVIFVw&W26vV'6FS wwrVIFVw&W26 > ________________________________ > > ?GG > ________________________________ > > wwrVIFVw&W26%F2Vf76?R6F26fFVFf&FFVFVBof" FR W6Rb FR W'6VB&fR > ________________________________ > > b R&RB FRFVFVB &V6VBb F2Vf76?R" FRVVR"vVB &W76&Rf"FVIfW&rB > F FRFVFVB &V6VB R&RW&V'FfVB FBF76V?F"6 |*[1]b F2Vf76?\*[1]2 > 7G&7Fo > > > > &&FVB > ________________________________ > > b RfR &V6VfVB F2Vf76?RW'&" V6R &WGW& F W2C > ________________________________ > > sR6RGR > ________________________________ > > g&W&R > ________________________________ > > G&R > ________________________________ > > G&VVV&V2*[1] > ________________________________ > > 6F > ________________________________ > > 4" > ________________________________ > > 5,*[1]'fC > ________________________________ > > SB? > ________________________________ > > rS#s " F FR 6VFW"w2VFG&W72F6FVB&fR > > > > Gerhard, > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From cplists at princeservices.com Wed May 9 19:50:46 2007 From: cplists at princeservices.com (Cameron B. Prince) Date: Wed May 9 19:50:56 2007 Subject: MailScanner w/ Qmail / Plesk ( format error: file is too short ) In-Reply-To: <13c021a90705091028p6103e38cw179eb8d4e1660102@mail.gmail.com> Message-ID: Hi Pravin, Thanks for your reply... I did some further testing after reading your post. When I send a message to the Qmail SMTP server a file is created as follows: maillog: May 9 13:41:38 relaylock: /var/qmail/bin/relaylock: mail from xxx.xxx.xxx.xxx:62279 (my.domain.com) path: /var/qmail/queue.in/mess/14 file: -rw-r--r-- 1 qmailq nofiles 669 May 9 13:41 7064533 I ran the inject command as you directed and the message is sent and received in the other mailbox: command: /var/qmail/bin/qmail-inject.mailscanner cprince@princeinternet.com < 7064533 maillog: May 9 13:45:38 qmail: 1178736338.084522 new msg 7064535 May 9 13:45:38 qmail: 1178736338.084561 info msg 7064535: bytes 737 from qp 12777 uid 0 May 9 13:45:38 qmail: 1178736338.087267 starting delivery 3: msg 7064535 to local 1-cprince@domain.com May 9 13:45:38 qmail: 1178736338.087284 status: local 1/10 remote 0/20 May 9 13:45:38 qmail: 1178736338.091709 delivery 3: success: did_1+0+1/ May 9 13:45:38 qmail: 1178736338.091730 status: local 0/10 remote 0/20 May 9 13:45:38 qmail: 1178736338.091742 end msg 7064535 Once I run MailScanner, it reads the file in the queue but fails with the same error: /usr/sbin/MailScanner In Debugging mode, not forking... Ignore errors about failing to find EOCD signature format error: file is too short at /usr/sbin/MailScanner line 832 Stopping now as you are debugging me. commit ineffective with AutoCommit enabled at /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, line 34. Commmit ineffective while AutoCommit is on at /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, line 34. Do you have any other thoughts? Thanks, Cameron On 5/9/07 12:28 PM, "Pravin Rane" wrote: > Try to inject mail using /var/qmail/bin/qmail-inject.mailscanner > /var/qmail/bin/qmail-inject.mailscanner user@mydomain.com < name_of_the_file > and see whether that mail is getting pushed to /var/qmail/queue directory > > > > > On 5/9/07, Cameron B. Prince wrote: >> Hey guys, >> >> I have a new dedicated server with Plesk. I originally purchased the >> SpamAssassin and Dr. Web anti-virus plugins but they just don't compare to >> MailScanner w/ MailWatch. >> >> I followed the instructions to setup MailScanner with Qmail here: >> >> http://qms.ausics.net/ >> >> I verified all the perl modules and checked the updates to the >> MailScanner.conf file. When I started MailScanner the init script complained >> that the MTA was invalid. I started Qmail manually and sent a test message. >> When the message hit the SMTP I got a queue error returned to the client. >> >> I ran this command and the queue errors went away: >> >> chmod u+s /var/qmail/bin/qmail-queue >> >> Now a test message produces this in the log: >> >> relaylock: /var/qmail/bin/relaylock: mail from xxx.xxx.xxx.xxx :61451 >> (my.domain.com ) >> MailScanner[6489]: New Batch: Scanning 1 messages, 668 bytes >> MailScanner[6489]: SpamAssassin cache hit for message 7064403 >> MailScanner[6489]: Virus and Content Scanning: Starting >> MailScanner[6489]: Uninfected: Delivered 1 messages >> MailScanner[6489]: Logging message 7064403 to SQL >> MailScanner[6451]: 7064403: Logged to MailWatch SQL >> >> When I checked the other mailbox for the message I found that it was never >> received. I enabled debugging and got this output when I tried another test >> message: >> >> /usr/sbin/MailScanner >> In Debugging mode, not forking... >> Ignore errors about failing to find EOCD signature >> format error: file is too short >> at /usr/sbin/MailScanner line 832 >> Stopping now as you are debugging me. >> commit ineffective with AutoCommit enabled at >> /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, >> line 34. >> Commmit ineffective while AutoCommit is on at >> /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, >> line 34. >> >> >> >> I know this patch for Qmail is pretty old and I wonder if this is the cause >> or if it's more likely to be a problem with the Plesk version of Qmail. Can >> anyone give me some ideas to troubleshoot this? >> >> >> Thanks, >> Cameron >> >> >> >> PS Here's the output of a lint test: >> >> /usr/sbin/MailScanner --lint >> Read 764 hostnames from the phishing whitelist >> Config: calling custom init function SQLBlacklist >> Config: calling custom init function MailWatchLogging >> Config: calling custom init function SQLWhitelist >> Checking version numbers... >> Version number in MailScanner.conf (4.58.9) is correct. >> MailScanner setting GID to (2520) >> MailScanner setting UID to (2520) >> >> Checking for SpamAssassin errors (if you use it)... >> Using SpamAssassin results cache >> Connected to SpamAssassin cache database >> SpamAssassin reported no errors. >> lock.pl sees Config LockType = flock >> lock.pl sees have_module = 0 >> Using locktype = flock >> MailScanner.conf says "Virus Scanners = f-prot" >> Found these virus scanners installed: f-prot >> >> >> >> >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> >> Support MailScanner development - buy the book off the website! > > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070509/3afaea79/attachment.html From MailScanner at ecs.soton.ac.uk Wed May 9 20:26:48 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 9 20:28:17 2007 Subject: Clamav suggestions In-Reply-To: <20070509105522.y9h0nbimg4kg0oks@luna.eco.unibs.it> References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> <20070509105522.y9h0nbimg4kg0oks@luna.eco.unibs.it> Message-ID: <46422078.6000508@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Fabio Pedretti wrote: >> 2) I noticed (as well as others: >> http://lists.mailscanner.info/pipermail/mailscanner/2007-April/072504.html >> >> ) that some phishing mail are not blocked (I am also using >> the signatures of sanesecurity). If I do a clamscan on the full >> original mail with headers, clamscan find the virus (I can provide a >> sample if needed). Seems the problem is that MailScanner extracts the >> content of the mail (body + attachment) and scans it, but some >> phishing mail are only detected if the full headers are present (in >> the clamav DB in the extended signature format, option 4 is for mail >> files, look at signatures.pdf in clamav source, and are detected only >> if full mail with headers is scanned). >> MailScanner should be modified so that all the original mail (with >> headers and without extracting attachment) should be passed to >> clamscan/clamd, so all virus can be catched. > > To try the problem send a mail with the following text: > 2.83:9999/webscrr/ind > on a MailScanner with clamav mail server. > The mail does not get filtered. > > However if you do a clamscan on the received mail, you get: > test.eml: Email.Phishing.Pay-20 FOUND > If you scan a text file containing the magic string above, clamscan doesn't find anything wrong. It *only* spots it if the file has email headers in it as well. This is a bit disappointing on the part of ClamAV. But it is a very effective defence against false alarms. MailScanner extracts all the parts of the message and scans them as files. As a result this phishing detector in ClamAV won't be triggered. I can't see any effective good solution to this one. It does not appear to affect anything except this phishing trap (and possible a few other phishing traps), so I'm not overly concerned about it. There has been no evidence whatsoever that anything more important is let through, and MailScanner has its own phishing detectors which should be triggered anyway. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGQiCsEfZZRxQVtlQRAsrCAKDG/2Nv4D6sRQ7b3KmSaoYv+nNZWgCg/iLX /ZYGBSqmtwJsb8DM2wzwgzA= =rvWL -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ajos1 at onion.demon.co.uk Wed May 9 21:06:37 2007 From: ajos1 at onion.demon.co.uk (ajos1@onion.demon.co.uk) Date: Wed May 9 21:06:51 2007 Subject: No VirusScan on Local Messages... Message-ID: - Matt, You are my hero... works like a dream... (Quite embarassing... as it is all explained in the MailScanner.conf at the point you said to check). -----Original Message----- From: MailScanner discussion Subj: Re: No VirusScan on Local Messages... Date: Tue, 08 May 2007 17:09:52 -0400 Search for "Scan Messages =" in your MailScanner.conf And put: Scan Messages = %rules-dir%/scan.messages.rules And in the %rules-dir% create scan.messages.rules with the following: From: 127.0.0.1 no FromOrTo: default yes Save, restart MailScanner. -Matt == ===================================================================== = = "It is obvious the Treasurer is rolling in money," said Wayne = Swan, treasury spokesman for the opposition Labor Party. "It has = been raining gold bars thanks to the mining boom." = = Need help dealing with Parking Tickets, Bailiffs, Capita or NTL... = Call... +44 8457 90 90 90 http://www.samaritans.org/ = ===================================================================== From ajos1 at onion.demon.co.uk Wed May 9 21:19:08 2007 From: ajos1 at onion.demon.co.uk (ajos1@onion.demon.co.uk) Date: Wed May 9 21:19:28 2007 Subject: OT: Installing Mail-ClamAV-0.20 fails... Message-ID: - Anyone have ideas on this one... I have googled the errors... and see alot of mentions of this error and that the original author needs to fix them... but no solutions! It does the same for Mail-ClamAV-0.13 . Thanks in advance-o. My "Inline" version is 0.44 . Perl is: Perl: 5.008008 (5.8.8) Installing Perl Module - Mail-ClamAV-0.20 ------------------------------------------ CPAN: File::HomeDir loaded ok (v0.64) CPAN: Storable loaded ok (v2.16) Going to read /root/.cpan/Metadata Database was generated on Tue, 08 May 2007 05:10:52 GMT Running install for module 'Mail::ClamAV' Running make for S/SA/SABECK/Mail-ClamAV-0.20.tar.gz CPAN: Digest::SHA loaded ok (v5.44) CPAN: Compress::Zlib loaded ok (v2.004) Checksum for /root/.cpan/sources/authors/id/S/SA/SABECK/Mail-ClamAV-0.20.tar.gz ok Mail-ClamAV-0.20/ Mail-ClamAV-0.20/t/ Mail-ClamAV-0.20/t/eicarcom2.zip Mail-ClamAV-0.20/t/Mail-ClamAV.t Mail-ClamAV-0.20/t/virus.eml Mail-ClamAV-0.20/Inline/ Mail-ClamAV-0.20/Inline/MakeMaker.pm Mail-ClamAV-0.20/META.yml Mail-ClamAV-0.20/config.pl Mail-ClamAV-0.20/Changes Mail-ClamAV-0.20/MANIFEST Mail-ClamAV-0.20/ClamAV.pm Mail-ClamAV-0.20/INSTALL Mail-ClamAV-0.20/Makefile.PL Mail-ClamAV-0.20/README CPAN: File::Temp loaded ok (v0.18) CPAN.pm: Going to build S/SA/SABECK/Mail-ClamAV-0.20.tar.gz Checking if your kit is complete... Looks good Writing Makefile for Mail::ClamAV CPAN: YAML loaded ok (v0.62) cp ClamAV.pm blib/lib/Mail/ClamAV.pm /usr/bin/perl -Mblib -MInline=NOISY,_INSTALL_ -MMail::ClamAV -e1 0.20 blib/arch Starting Build Prepocess Stage Finished Build Prepocess Stage Starting Build Parse Stage Finished Build Parse Stage Starting Build Glue 1 Stage Finished Build Glue 1 Stage Starting Build Glue 2 Stage Finished Build Glue 2 Stage Starting Build Glue 3 Stage Finished Build Glue 3 Stage Starting Build Compile Stage Starting "perl Makefile.PL" Stage Writing Makefile for Mail::ClamAV Finished "perl Makefile.PL" Stage Starting "make" Stage make[1]: Entering directory `/root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6/_Inline/build/Mail/ClamAV' /usr/bin/perl /usr/lib/perl5/5.8.8/ExtUtils/xsubpp -typemap /usr/lib/perl5/5.8.8/ExtUtils/typemap ClamAV.xs > ClamAV.xsc && mv ClamAV.xsc ClamAV.c gcc -c -I/root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6 -I/usr/local/include -D_REENTRANT -D_GNU_SOURCE -fno-strict-aliasing -pipe -Wdeclaration-after-statement -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i386 -mtune=generic -fasynchronous-unwind-tables -DVERSION=\"0.20\" -DXS_VERSION=\"0.20\" -fPIC "-I/usr/lib/perl5/5.8.8/i386-linux-thread-multi/CORE" ClamAV.c ClamAV.xs: In function 'clamav_perl_new': ClamAV.xs:53: warning: implicit declaration of function 'cl_loaddbdir' ClamAV.xs:56: warning: implicit declaration of function 'cl_loaddb' ClamAV.xs: In function 'clamav_perl__scanfd': ClamAV.xs:202: warning: unused variable 'items' ClamAV.xs:197: warning: unused variable 'len' ClamAV.xs: In function 'clamav_perl__scanfile': ClamAV.xs:239: warning: unused variable 'items' ClamAV.xs:233: warning: unused variable 'len' ClamAV.xs: In function 'clamav_perl_constant': ClamAV.xs:350: error: 'CL_SCAN_ALGORITHMIC' undeclared (first use in this function) ClamAV.xs:350: error: (Each undeclared identifier is reported only once ClamAV.xs:350: error: for each function it appears in.) make[1]: *** [ClamAV.o] Error 1 make[1]: Leaving directory `/root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6/_Inline/build/Mail/ClamAV' A problem was encountered while attempting to compile and install your Inline C code. The command that failed was: make The build directory was: /root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6/_Inline/build/Mail/ClamAV To debug the problem, cd to the build directory, and inspect the output files. at /root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6/blib/lib/Mail/ClamAV.pm line 178 BEGIN failed--compilation aborted at /root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6/blib/lib/Mail/ClamAV.pm line 542. Compilation failed in require. BEGIN failed--compilation aborted. make: *** [ClamAV.inl] Error 25 SABECK/Mail-ClamAV-0.20.tar.gz /usr/bin/make -- NOT OK Running make test Can't test without successful make Running make install Make had returned bad status, install seems impossible == ===================================================================== = = "It is obvious the Treasurer is rolling in money," said Wayne = Swan, treasury spokesman for the opposition Labor Party. "It has = been raining gold bars thanks to the mining boom." = = Need help dealing with Parking Tickets, Bailiffs, Capita or NTL... = Call... +44 8457 90 90 90 http://www.samaritans.org/ = ===================================================================== From gmourani at prival.ca Wed May 9 21:23:30 2007 From: gmourani at prival.ca (Gerhard Mourani) Date: Wed May 9 21:24:09 2007 Subject: Issue with Blackberry Message-ID: <3123E1B72B666243917E340F3C8FD4A1069710@privaldc2003.prival.local> I found that the message shows up ok on the computer. It is when it shows on the blackberry that it is a problem. Some one has some idea why this happen on Blackberry? -----Original Message----- From: Gerhard Mourani Sent: Wednesday, May 09, 2007 2:28 PM To: Gerhard Mourani; 'MailScanner discussion' Subject: RE: Issue with Blackberry Ok, here an emails being sent from a users blackberry. Return-Path: X-Original-To: todd.savage@elitegroupinc.ca Delivered-To: todd.savage@elitegroupinc.ca Received: from smtp04.bis.na.blackberry.com (smtp04.bis.na.blackberry.com [216.9.248.51]) by mail.eliteclassics.com (Postfix) with ESMTP id 04231C549; Wed, 9 May 2007 14:02:10 -0400 (EDT) Message-ID: <344973756-1178733913-cardhu_blackberry.rim.net-1567301641-@bxe017-cell02.bisx.prod.on.blackberry> Reply-To: katie.papoutsis@elitegroupinc.ca Sensitivity: Normal Importance: Normal To: "Todd Savage" Subject: Fw: From: "=?UTF-8?B?S2F0aWUgUGFwb3V0c2lz?=" Date: Wed, 9 May 2007 18:05:39 +0000 Content-type: text/plain MIME-Version: 1.0 X-EliteGroupInc-MailScanner: Found to be clean X-EliteGroupInc-MailScanner-From: katie.papoutsis@elitegroupinc.ca X-Spam-Status: No -----Original Message----- From: Gerhard Mourani Sent: Wednesday, May 09, 2007 9:27 AM To: 'MailScanner discussion' Subject: RE: Issue with Blackberry Here what users sent to me. Also this is what I've in the -> /etc/postfix/header_checks file /^Received: (.*?) by eliteclassics.com(.*?)/ REJECT /^Received:/ HOLD Now the headers: A problem was found in an Email message you sent. This Email scanner intercepted it and stopped the entire message reaching its destination. The problem was reported to be: Disallowed breakage found in header name - potential virus Please contact your IT support personnel with any queries regarding this policy. Your message was sent with the following envelope: MAIL FROM: carla.redman@elitegroupinc.ca RCPT TO: joshua.levin@myexchangehosting.net ... and with the following headers: --- MAILFROM: carla.redman@elitegroupinc.ca Delivered-To: jwlevinp-joshua.levin@jwlevinpartners.com Received: (qmail 55802 invoked from network); 4 May 2007 18:37:42 -0000 Received: from unknown (HELO mail.eliteclassics.com) (149.99.191.243) by host355.ipowerweb.com with SMTP; 4 May 2007 18:37:42 -0000 Received: from EXECDanny (office.eliteclassics.com [149.99.191.242]) by mail.eliteclassics.com (Postfix) with ESMTP id CEC964DEC for ; Fri, 4 May 2007 14:40:18 -0400 (EDT) Return-Receipt-To: "Carla Redman" Reply-To: From: "Carla Redman" To: "'Levin, Joshua'" References: <435DF58A933BA74397B42CDEB8145A860B8C4AE3@ex9.hostedexchange.local> Subject: RE: feb 07 flights .xls Date: Fri, 4 May 2007 14:45:04 -0400 Organization: Elite Group Message-ID: MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0003_01C78E5A.CD761FE0" X-Mailer: Microsoft Office Outlook 11 Thread-Index: AceCyu12JEluHxWIQ7ClFI22mBkHtgAghwiAAA0iz+AAAC8ZAAK8H9XgAAIRniA= In-Reply-To: <435DF58A933BA74397B42CDEB8145A860B8C4AE3@ex9.hostedexchange.local> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 Disposition-Notification-To: "Carla Redman" X-Elite Group, Inc.-MailScanner: Found to be clean X-Elite Group, Inc.-MailScanner-From: carla.redman@elitegroupinc.ca X-Spam-Status: No Thanks, -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- Sent: Wednesday, May 09, 2007 9:08 AM To: MailScanner discussion Subject: Re: Issue with Blackberry Would be useful to see the actual headers, especially the MIME section. On Wed, 9 May 2007 08:38:05 -0400, "Gerhard Mourani" wrote: > Hello, > > > > I'm using MailScanner + Postfix + SpamAssassin on Linux and having strange > issues with email coming from blackberry servers, here how the received > email look like: > > > > Subject: Re: Hand Mixer Trial-Produce Report > > > > \Ib?HTjy?Z.hm%yXxj?'p?'wJI+{E+.1I?U)?g?g*"(tjdj?6V??6 R w&FR FR&GbV > v F2fVC > ________________________________ > > 6wB 6VRB > > > > &W&o??G2 W&vVB 6RVVFVBf"7[1] FW7Fp??F0?? > ________________________________ > > V&V6? &GV7B > ________________________________ > > vW" > ________________________________ > > 6V6 > ________________________________ > > 2?F&V7B?S > ________________________________ > > SB > ________________________________ > > ##r > ________________________________ > > s3r[1]??&v > ________________________________ > > W76vR?g&?[1]$FfBVr" > ________________________________ > > FfBVt VIFVw&W26?FFSGVR > ________________________________ > > ________________________________ > > ________________________________ > > # > ________________________________ > > ________________________________ > > r > ________________________________ > > ##?F&fW&F" > ________________________________ > > fW&FF?VIFVw&W26&W&2&W&" > ________________________________ > > W&2 &W&VIFVw&W26?63&FFv"" > ________________________________ > > FFv$VIFVw&W26%6Tr" > ________________________________ > > 6Rt 6V626&V&V" > ________________________________ > > V&V6 6V626'6G&'W&F" > ________________________________ > > 6G&'W&FVIFVw&W26&VWB" > ________________________________ > > VWBGW&W6vTVIFVw&W26&VFV" > ________________________________ > > VFV6 VVIFVw&W266TVIFVw&W26&V'F" > ________________________________ > > zV'FVIFVw&W26$FR" > ________________________________ > > zFRWG64VIFVw&W 26&FfBGW&" > ________________________________ > > FfBGW&VIFVw&W26%F" > ________________________________ > > FTVIFVw&W26'o R" > ________________________________ > > oTVIFVw&W26&66r" > ________________________________ > > ?66tVIFVw&W26&'R" > ________________________________ > > 'TVIFVw&W26$66R" > ________________________________ > > 66VF v?v6%6&?R" > ________________________________ > > F?6$6" > ________________________________ > > ?6Fv?v6&VfVr" > ________________________________ > > VfVtF?6?7V&V7C > ________________________________ > > B > ________________________________ > > ?W"G& &GV6R&W'@??FV" > ________________________________ > > fW&FW&2V6R 6VRB?W" G& > > > > &GV7" &W'B7V7F &W7VB2fVB&W7B &Vv&G2FfBVpVIFR > ________________________________ > > w&W[1] > ________________________________ > > 2 > ________________________________ > > 6 > ________________________________ > > ff6P&S > ________________________________ > > b3 > ________________________________ > > ________________________________ > > cs#cV?VIFW2?6 > ________________________________ > > c26? > ________________________________ > > FVIFW2?6 > ________________________________ > > c26R#FfBVtVIFVw&W26 > ________________________________ > > FFfBVtVIFVw&W26vV'6FS wwrVIFVw&W26 > ________________________________ > > ?GG > ________________________________ > > wwrVIFVw&W26%F2Vf76?R6F26fFVFf&FFVFVBof" FR W6Rb FR W'6VB&fR > ________________________________ > > b R&RB FRFVFVB &V6VBb F2Vf76?R" FRVVR"vVB &W76&Rf"FVIfW&rB > F FRFVFVB &V6VB R&RW&V'FfVB FBF76V?F"6 |*[1]b F2Vf76?\*[1]2 > 7G&7Fo > > > > &&FVB > ________________________________ > > b RfR &V6VfVB F2Vf76?RW'&" V6R &WGW& F W2C > ________________________________ > > sR6RGR > ________________________________ > > g&W&R > ________________________________ > > G&R > ________________________________ > > G&VVV&V2*[1] > ________________________________ > > 6F > ________________________________ > > 4" > ________________________________ > > 5,*[1]'fC > ________________________________ > > SB? > ________________________________ > > rS#s " F FR 6VFW"w2VFG&W72F6FVB&fR > > > > Gerhard, > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From mkettler at evi-inc.com Wed May 9 21:29:51 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Wed May 9 21:30:05 2007 Subject: OT: Installing Mail-ClamAV-0.20 fails... In-Reply-To: References: Message-ID: <46422F3F.4010204@evi-inc.com> ajos1@onion.demon.co.uk wrote: > - > > Anyone have ideas on this one... I have googled the errors... and see alot of mentions of this error and that the original author needs to fix them... but no solutions! > > It does the same for Mail-ClamAV-0.13 . > > Thanks in advance-o. Any chance you installed clamav from a distribution package, instead of source? Did you install the -devel package? Based on the messages you got, it looks like the header files for the clamav libraries (ie: clamav.h) are missing or empty. From doc at maddoc.net Wed May 9 21:31:56 2007 From: doc at maddoc.net (Doc Schneider) Date: Wed May 9 21:32:04 2007 Subject: OT: Installing Mail-ClamAV-0.20 fails... In-Reply-To: References: Message-ID: <46422FBC.5010902@maddoc.net> ajos1@onion.demon.co.uk wrote: > - > > Anyone have ideas on this one... I have googled the errors... and see alot of mentions of this error and that the original author needs to fix them... but no solutions! > > It does the same for Mail-ClamAV-0.13 . > > Thanks in advance-o. > > My "Inline" version is 0.44 . > Perl is: Perl: 5.008008 (5.8.8) > > Installing Perl Module - Mail-ClamAV-0.20 > ------------------------------------------ > > CPAN: File::HomeDir loaded ok (v0.64) > CPAN: Storable loaded ok (v2.16) > Going to read /root/.cpan/Metadata > Database was generated on Tue, 08 May 2007 05:10:52 GMT > Running install for module 'Mail::ClamAV' > Running make for S/SA/SABECK/Mail-ClamAV-0.20.tar.gz > CPAN: Digest::SHA loaded ok (v5.44) > CPAN: Compress::Zlib loaded ok (v2.004) > Checksum for /root/.cpan/sources/authors/id/S/SA/SABECK/Mail-ClamAV-0.20.tar.gz ok > Mail-ClamAV-0.20/ > Mail-ClamAV-0.20/t/ > Mail-ClamAV-0.20/t/eicarcom2.zip > Mail-ClamAV-0.20/t/Mail-ClamAV.t > Mail-ClamAV-0.20/t/virus.eml > Mail-ClamAV-0.20/Inline/ > Mail-ClamAV-0.20/Inline/MakeMaker.pm > Mail-ClamAV-0.20/META.yml > Mail-ClamAV-0.20/config.pl > Mail-ClamAV-0.20/Changes > Mail-ClamAV-0.20/MANIFEST > Mail-ClamAV-0.20/ClamAV.pm > Mail-ClamAV-0.20/INSTALL > Mail-ClamAV-0.20/Makefile.PL > Mail-ClamAV-0.20/README > CPAN: File::Temp loaded ok (v0.18) > > CPAN.pm: Going to build S/SA/SABECK/Mail-ClamAV-0.20.tar.gz > > Checking if your kit is complete... > Looks good > Writing Makefile for Mail::ClamAV > CPAN: YAML loaded ok (v0.62) > cp ClamAV.pm blib/lib/Mail/ClamAV.pm > /usr/bin/perl -Mblib -MInline=NOISY,_INSTALL_ -MMail::ClamAV -e1 0.20 blib/arch > Starting Build Prepocess Stage > Finished Build Prepocess Stage > > Starting Build Parse Stage > Finished Build Parse Stage > > Starting Build Glue 1 Stage > Finished Build Glue 1 Stage > > Starting Build Glue 2 Stage > Finished Build Glue 2 Stage > > Starting Build Glue 3 Stage > Finished Build Glue 3 Stage > > Starting Build Compile Stage > Starting "perl Makefile.PL" Stage > Writing Makefile for Mail::ClamAV > Finished "perl Makefile.PL" Stage > > Starting "make" Stage > make[1]: Entering directory `/root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6/_Inline/build/Mail/ClamAV' > /usr/bin/perl /usr/lib/perl5/5.8.8/ExtUtils/xsubpp -typemap /usr/lib/perl5/5.8.8/ExtUtils/typemap ClamAV.xs > ClamAV.xsc && mv ClamAV.xsc ClamAV.c > gcc -c -I/root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6 -I/usr/local/include -D_REENTRANT -D_GNU_SOURCE -fno-strict-aliasing -pipe -Wdeclaration-after-statement -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i386 -mtune=generic -fasynchronous-unwind-tables -DVERSION=\"0.20\" -DXS_VERSION=\"0.20\" -fPIC "-I/usr/lib/perl5/5.8.8/i386-linux-thread-multi/CORE" ClamAV.c > ClamAV.xs: In function 'clamav_perl_new': > ClamAV.xs:53: warning: implicit declaration of function 'cl_loaddbdir' > ClamAV.xs:56: warning: implicit declaration of function 'cl_loaddb' > ClamAV.xs: In function 'clamav_perl__scanfd': > ClamAV.xs:202: warning: unused variable 'items' > ClamAV.xs:197: warning: unused variable 'len' > ClamAV.xs: In function 'clamav_perl__scanfile': > ClamAV.xs:239: warning: unused variable 'items' > ClamAV.xs:233: warning: unused variable 'len' > ClamAV.xs: In function 'clamav_perl_constant': > ClamAV.xs:350: error: 'CL_SCAN_ALGORITHMIC' undeclared (first use in this function) > ClamAV.xs:350: error: (Each undeclared identifier is reported only once > ClamAV.xs:350: error: for each function it appears in.) > make[1]: *** [ClamAV.o] Error 1 > make[1]: Leaving directory `/root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6/_Inline/build/Mail/ClamAV' > > A problem was encountered while attempting to compile and install your Inline > C code. The command that failed was: > make > > The build directory was: > /root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6/_Inline/build/Mail/ClamAV > > To debug the problem, cd to the build directory, and inspect the output files. > > at /root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6/blib/lib/Mail/ClamAV.pm line 178 > BEGIN failed--compilation aborted at /root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6/blib/lib/Mail/ClamAV.pm line 542. > Compilation failed in require. > BEGIN failed--compilation aborted. > make: *** [ClamAV.inl] Error 25 > SABECK/Mail-ClamAV-0.20.tar.gz > /usr/bin/make -- NOT OK > Running make test > Can't test without successful make > Running make install > Make had returned bad status, install seems impossible > > == > ===================================================================== > = > = "It is obvious the Treasurer is rolling in money," said Wayne > = Swan, treasury spokesman for the opposition Labor Party. "It has > = been raining gold bars thanks to the mining boom." > = > = Need help dealing with Parking Tickets, Bailiffs, Capita or NTL... > = Call... +44 8457 90 90 90 http://www.samaritans.org/ > = > ===================================================================== After installing Clamav-0.90.2 make sure you check your /etc/ld.so.conf has the path to the new libraries. then run 'ldconfig' I ran into this one quite a bit. -- -Doc Lincoln, NE. http://www.genealogyforyou.com/ http://www.cairnproductions.com/ From ajos1 at onion.demon.co.uk Wed May 9 22:02:21 2007 From: ajos1 at onion.demon.co.uk (ajos1@onion.demon.co.uk) Date: Wed May 9 22:02:36 2007 Subject: OT: Installing Mail-ClamAV-0.20 fails... Message-ID: - Thanks mkettler and doc , you both made me check that my clamav was as upto date as possible... it looks like 90.RC3 had some issues fixed by 90.2 . I did have the source install of :- clamav-0.90rc3.tar.gz When I did :- find / -name clamav.h it came up with... /usr/local/include/clamav.h Installing Mail-ClamAV-0.20 fails... It was only when I did the correct install of :- clamav-0.90.2.tar.gz that the install of Mail-ClamAV-0.20 worked perfectly... I promise, if I ask another silly question... I will wear a set of these on my head... in public... http://www.cafepress.com/mailscanner2,mailscanner.4367945 Ta's a-lot-o. -----Original Message----- From: mailscanner@lists.mailscanner.info Subj: Re: OT: Installing Mail-ClamAV-0.20 fails... Date: Wed, 09 May 2007 16:29:51 -0400 ajos1@onion.demon.co.uk wrote: > - > > Anyone have ideas on this one... I have googled the errors... and see alot of mentions of this error and that the original author needs to fix them... but no solutions! > > It does the same for Mail-ClamAV-0.13 . > > Thanks in advance-o. Any chance you installed clamav from a distribution package, instead of source? Did you install the -devel package? Based on the messages you got, it looks like the header files for the clamav libraries (ie: clamav.h) are missing or empty. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! == ===================================================================== = = "It is obvious the Treasurer is rolling in money," said Wayne = Swan, treasury spokesman for the opposition Labor Party. "It has = been raining gold bars thanks to the mining boom." = = Need help dealing with Parking Tickets, Bailiffs, Capita or NTL... = Call... +44 8457 90 90 90 http://www.samaritans.org/ = ===================================================================== From res at ausics.net Wed May 9 23:45:16 2007 From: res at ausics.net (Res) Date: Wed May 9 23:45:29 2007 Subject: MailScanner w/ Qmail / Plesk ( format error: file is too short ) In-Reply-To: References: Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Cameron, The qms stuff has never been tested with mailwatch, as the environments in which it was developed and is used in does not use mailwatch. On Wed, 9 May 2007, Cameron B. Prince wrote: > Once I run MailScanner, it reads the file in the queue but fails with the > same error: > > /usr/sbin/MailScanner > In Debugging mode, not forking... > Ignore errors about failing to find EOCD signature > format error: file is too short > at /usr/sbin/MailScanner line 832 > Stopping now as you are debugging me. > commit ineffective with AutoCommit enabled at > /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, > line 34. > Commmit ineffective while AutoCommit is on at > /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, > line 34. - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGQk7/sWhAmSIQh7MRAs8jAJ9y9hOkrLbtw0aGE91iBCdIqFuzQQCgivqo v3JS/P86jzML5EmLO2vBE3c= =J/v3 -----END PGP SIGNATURE----- From cplists at princeservices.com Thu May 10 00:50:40 2007 From: cplists at princeservices.com (Cameron B. Prince) Date: Thu May 10 00:50:46 2007 Subject: MailScanner w/ Qmail / Plesk ( format error: file is too short ) In-Reply-To: Message-ID: Hi Res, I disabled MailWatch and tested again with the same results: [root@secure MailScanner]# /usr/sbin/MailScanner In Debugging mode, not forking... Ignore errors about failing to find EOCD signature format error: file is too short at /usr/sbin/MailScanner line 832 Stopping now as you are debugging me. It doesn't look like the problem is related to MailWatch. Thanks, Cameron On 5/9/07 5:45 PM, "Res" wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > Cameron, > The qms stuff has never been tested with mailwatch, as the > environments in which it was developed and is used in does > not use mailwatch. > > > On Wed, 9 May 2007, Cameron B. Prince wrote: > >> Once I run MailScanner, it reads the file in the queue but fails with the >> same error: >> >> /usr/sbin/MailScanner >> In Debugging mode, not forking... >> Ignore errors about failing to find EOCD signature >> format error: file is too short >> at /usr/sbin/MailScanner line 832 >> Stopping now as you are debugging me. >> commit ineffective with AutoCommit enabled at >> /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, >> line 34. >> Commmit ineffective while AutoCommit is on at >> /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, >> line 34. > > > - -- > Cheers > Res > > Vote for your favourite MTA at http://polls.ausics.net/v3.php > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.6 (GNU/Linux) > > iD8DBQFGQk7/sWhAmSIQh7MRAs8jAJ9y9hOkrLbtw0aGE91iBCdIqFuzQQCgivqo > v3JS/P86jzML5EmLO2vBE3c= > =J/v3 > -----END PGP SIGNATURE----- From res at ausics.net Thu May 10 01:05:59 2007 From: res at ausics.net (Res) Date: Thu May 10 01:06:10 2007 Subject: MailScanner w/ Qmail / Plesk ( format error: file is too short ) In-Reply-To: References: Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, What version of MailScanner are you using? Current I hope :) Is your MailScanner languages.conf file OK ? On Wed, 9 May 2007, Cameron B. Prince wrote: > Hi Res, > > I disabled MailWatch and tested again with the same results: > > [root@secure MailScanner]# /usr/sbin/MailScanner > In Debugging mode, not forking... > Ignore errors about failing to find EOCD signature > format error: file is too short > at /usr/sbin/MailScanner line 832 > Stopping now as you are debugging me. > > It doesn't look like the problem is related to MailWatch. > > Thanks, > Cameron > > > On 5/9/07 5:45 PM, "Res" wrote: > >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> >> Cameron, >> The qms stuff has never been tested with mailwatch, as the >> environments in which it was developed and is used in does >> not use mailwatch. >> >> >> On Wed, 9 May 2007, Cameron B. Prince wrote: >> >>> Once I run MailScanner, it reads the file in the queue but fails with the >>> same error: >>> >>> /usr/sbin/MailScanner >>> In Debugging mode, not forking... >>> Ignore errors about failing to find EOCD signature >>> format error: file is too short >>> at /usr/sbin/MailScanner line 832 >>> Stopping now as you are debugging me. >>> commit ineffective with AutoCommit enabled at >>> /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, >>> line 34. >>> Commmit ineffective while AutoCommit is on at >>> /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, >>> line 34. >> >> >> - -- >> Cheers >> Res >> >> Vote for your favourite MTA at http://polls.ausics.net/v3.php >> -----BEGIN PGP SIGNATURE----- >> Version: GnuPG v1.4.6 (GNU/Linux) >> >> iD8DBQFGQk7/sWhAmSIQh7MRAs8jAJ9y9hOkrLbtw0aGE91iBCdIqFuzQQCgivqo >> v3JS/P86jzML5EmLO2vBE3c= >> =J/v3 >> -----END PGP SIGNATURE----- > > > - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGQmHpsWhAmSIQh7MRAqlqAJ9SYJoleoHNaphQjAxIRRz+sI+wJgCcCNeR TGGsttpM+lLYglZRhyCOFj8= =coq7 -----END PGP SIGNATURE----- From cplists at princeservices.com Thu May 10 04:06:30 2007 From: cplists at princeservices.com (Cameron B. Prince) Date: Thu May 10 04:06:38 2007 Subject: MailScanner w/ Qmail / Plesk ( format error: file is too short ) In-Reply-To: Message-ID: Hi Res, Yes, it's current: Version number in MailScanner.conf (4.58.9) is correct. I haven't touched the languages.conf file but is there some way to make sure it's okay? I did some Googling and it seems the error, "format error: file is too short", comes from Archive::Zip. I am not sure how this fits in with things but maybe that will give someone a clue as to what the problem is. Thanks, Cameron On 5/9/07 7:05 PM, "Res" wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Hi, > > What version of MailScanner are you using? Current I hope :) > Is your MailScanner languages.conf file OK ? > > > > On Wed, 9 May 2007, Cameron B. Prince wrote: > >> Hi Res, >> >> I disabled MailWatch and tested again with the same results: >> >> [root@secure MailScanner]# /usr/sbin/MailScanner >> In Debugging mode, not forking... >> Ignore errors about failing to find EOCD signature >> format error: file is too short >> at /usr/sbin/MailScanner line 832 >> Stopping now as you are debugging me. >> >> It doesn't look like the problem is related to MailWatch. >> >> Thanks, >> Cameron >> >> >> On 5/9/07 5:45 PM, "Res" wrote: >> >>> -----BEGIN PGP SIGNED MESSAGE----- >>> Hash: SHA1 >>> >>> >>> Cameron, >>> The qms stuff has never been tested with mailwatch, as the >>> environments in which it was developed and is used in does >>> not use mailwatch. >>> >>> >>> On Wed, 9 May 2007, Cameron B. Prince wrote: >>> >>>> Once I run MailScanner, it reads the file in the queue but fails with the >>>> same error: >>>> >>>> /usr/sbin/MailScanner >>>> In Debugging mode, not forking... >>>> Ignore errors about failing to find EOCD signature >>>> format error: file is too short >>>> at /usr/sbin/MailScanner line 832 >>>> Stopping now as you are debugging me. >>>> commit ineffective with AutoCommit enabled at >>>> /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, >>>> line 34. >>>> Commmit ineffective while AutoCommit is on at >>>> /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, >>>> line 34. >>> >>> >>> - -- >>> Cheers >>> Res >>> >>> Vote for your favourite MTA at http://polls.ausics.net/v3.php >>> -----BEGIN PGP SIGNATURE----- >>> Version: GnuPG v1.4.6 (GNU/Linux) >>> >>> iD8DBQFGQk7/sWhAmSIQh7MRAs8jAJ9y9hOkrLbtw0aGE91iBCdIqFuzQQCgivqo >>> v3JS/P86jzML5EmLO2vBE3c= >>> =J/v3 >>> -----END PGP SIGNATURE----- >> >> >> > > - -- > > Cheers > Res > > Vote for your favourite MTA at http://polls.ausics.net/v3.php > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.6 (GNU/Linux) > > iD8DBQFGQmHpsWhAmSIQh7MRAqlqAJ9SYJoleoHNaphQjAxIRRz+sI+wJgCcCNeR > TGGsttpM+lLYglZRhyCOFj8= > =coq7 > -----END PGP SIGNATURE----- From res at ausics.net Thu May 10 04:25:28 2007 From: res at ausics.net (Res) Date: Thu May 10 04:25:41 2007 Subject: MailScanner w/ Qmail / Plesk ( format error: file is too short ) In-Reply-To: References: Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, Please disable spamassassin and retest On Wed, 9 May 2007, Cameron B. Prince wrote: > Hi Res, > > Yes, it's current: > > Version number in MailScanner.conf (4.58.9) is correct. > > I haven't touched the languages.conf file but is there some way to make sure > it's okay? > > I did some Googling and it seems the error, "format error: file is too > short", comes from Archive::Zip. I am not sure how this fits in with things > but maybe that will give someone a clue as to what the problem is. > > Thanks, > Cameron > > > On 5/9/07 7:05 PM, "Res" wrote: > >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> Hi, >> >> What version of MailScanner are you using? Current I hope :) >> Is your MailScanner languages.conf file OK ? >> >> >> >> On Wed, 9 May 2007, Cameron B. Prince wrote: >> >>> Hi Res, >>> >>> I disabled MailWatch and tested again with the same results: >>> >>> [root@secure MailScanner]# /usr/sbin/MailScanner >>> In Debugging mode, not forking... >>> Ignore errors about failing to find EOCD signature >>> format error: file is too short >>> at /usr/sbin/MailScanner line 832 >>> Stopping now as you are debugging me. >>> >>> It doesn't look like the problem is related to MailWatch. >>> >>> Thanks, >>> Cameron >>> >>> >>> On 5/9/07 5:45 PM, "Res" wrote: >>> >>>> -----BEGIN PGP SIGNED MESSAGE----- >>>> Hash: SHA1 >>>> >>>> >>>> Cameron, >>>> The qms stuff has never been tested with mailwatch, as the >>>> environments in which it was developed and is used in does >>>> not use mailwatch. >>>> >>>> >>>> On Wed, 9 May 2007, Cameron B. Prince wrote: >>>> >>>>> Once I run MailScanner, it reads the file in the queue but fails with the >>>>> same error: >>>>> >>>>> /usr/sbin/MailScanner >>>>> In Debugging mode, not forking... >>>>> Ignore errors about failing to find EOCD signature >>>>> format error: file is too short >>>>> at /usr/sbin/MailScanner line 832 >>>>> Stopping now as you are debugging me. >>>>> commit ineffective with AutoCommit enabled at >>>>> /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, >>>>> line 34. >>>>> Commmit ineffective while AutoCommit is on at >>>>> /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, >>>>> line 34. >>>> >>>> >>>> - -- >>>> Cheers >>>> Res >>>> >>>> Vote for your favourite MTA at http://polls.ausics.net/v3.php >>>> -----BEGIN PGP SIGNATURE----- >>>> Version: GnuPG v1.4.6 (GNU/Linux) >>>> >>>> iD8DBQFGQk7/sWhAmSIQh7MRAs8jAJ9y9hOkrLbtw0aGE91iBCdIqFuzQQCgivqo >>>> v3JS/P86jzML5EmLO2vBE3c= >>>> =J/v3 >>>> -----END PGP SIGNATURE----- >>> >>> >>> >> >> - -- >> >> Cheers >> Res >> >> Vote for your favourite MTA at http://polls.ausics.net/v3.php >> -----BEGIN PGP SIGNATURE----- >> Version: GnuPG v1.4.6 (GNU/Linux) >> >> iD8DBQFGQmHpsWhAmSIQh7MRAqlqAJ9SYJoleoHNaphQjAxIRRz+sI+wJgCcCNeR >> TGGsttpM+lLYglZRhyCOFj8= >> =coq7 >> -----END PGP SIGNATURE----- > > > - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGQpCrsWhAmSIQh7MRAnYYAKCcJe+cWGoFHWrfnVAOW4VMfDhG9gCeNC0J z9B5TZKHF9EEUR65Q1soguI= =erk9 -----END PGP SIGNATURE----- From cplists at princeservices.com Thu May 10 05:03:12 2007 From: cplists at princeservices.com (Cameron B. Prince) Date: Thu May 10 05:03:18 2007 Subject: MailScanner w/ Qmail / Plesk ( format error: file is too short ) In-Reply-To: Message-ID: Hi Res, I stepped through multiple tests first disabling Spam Checks, then Spam Assassin, and finally Virus Checks. Still get the same error with all those set to no. Here's a --lint test's output: # /usr/sbin/MailScanner --lint Read 764 hostnames from the phishing whitelist Checking version numbers... Version number in MailScanner.conf (4.58.9) is correct. MailScanner setting GID to (2520) MailScanner setting UID to (2520) Checking for SpamAssassin errors (if you use it)... lock.pl sees Config LockType = flock lock.pl sees have_module = 0 Using locktype = flock MailScanner.conf says "Virus Scanners = f-prot" Found these virus scanners installed: f-prot Is there a way to do an strace or something similar to get more verbose debugging? Thanks, Cameron On 5/9/07 10:25 PM, "Res" wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Hi, > > Please disable spamassassin and retest > > > On Wed, 9 May 2007, Cameron B. Prince wrote: > >> Hi Res, >> >> Yes, it's current: >> >> Version number in MailScanner.conf (4.58.9) is correct. >> >> I haven't touched the languages.conf file but is there some way to make sure >> it's okay? >> >> I did some Googling and it seems the error, "format error: file is too >> short", comes from Archive::Zip. I am not sure how this fits in with things >> but maybe that will give someone a clue as to what the problem is. >> >> Thanks, >> Cameron >> >> >> On 5/9/07 7:05 PM, "Res" wrote: >> >>> -----BEGIN PGP SIGNED MESSAGE----- >>> Hash: SHA1 >>> >>> Hi, >>> >>> What version of MailScanner are you using? Current I hope :) >>> Is your MailScanner languages.conf file OK ? >>> >>> >>> >>> On Wed, 9 May 2007, Cameron B. Prince wrote: >>> >>>> Hi Res, >>>> >>>> I disabled MailWatch and tested again with the same results: >>>> >>>> [root@secure MailScanner]# /usr/sbin/MailScanner >>>> In Debugging mode, not forking... >>>> Ignore errors about failing to find EOCD signature >>>> format error: file is too short >>>> at /usr/sbin/MailScanner line 832 >>>> Stopping now as you are debugging me. >>>> >>>> It doesn't look like the problem is related to MailWatch. >>>> >>>> Thanks, >>>> Cameron >>>> >>>> >>>> On 5/9/07 5:45 PM, "Res" wrote: >>>> >>>>> -----BEGIN PGP SIGNED MESSAGE----- >>>>> Hash: SHA1 >>>>> >>>>> >>>>> Cameron, >>>>> The qms stuff has never been tested with mailwatch, as the >>>>> environments in which it was developed and is used in does >>>>> not use mailwatch. >>>>> >>>>> >>>>> On Wed, 9 May 2007, Cameron B. Prince wrote: >>>>> >>>>>> Once I run MailScanner, it reads the file in the queue but fails with the >>>>>> same error: >>>>>> >>>>>> /usr/sbin/MailScanner >>>>>> In Debugging mode, not forking... >>>>>> Ignore errors about failing to find EOCD signature >>>>>> format error: file is too short >>>>>> at /usr/sbin/MailScanner line 832 >>>>>> Stopping now as you are debugging me. >>>>>> commit ineffective with AutoCommit enabled at >>>>>> /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, >>>>>> line 34. >>>>>> Commmit ineffective while AutoCommit is on at >>>>>> /usr/lib/MailScanner/MailScanner/CustomFunctions/MailWatch.pm line 93, >>>>>> line 34. >>>>> >>>>> >>>>> - -- >>>>> Cheers >>>>> Res >>>>> >>>>> Vote for your favourite MTA at http://polls.ausics.net/v3.php >>>>> -----BEGIN PGP SIGNATURE----- >>>>> Version: GnuPG v1.4.6 (GNU/Linux) >>>>> >>>>> iD8DBQFGQk7/sWhAmSIQh7MRAs8jAJ9y9hOkrLbtw0aGE91iBCdIqFuzQQCgivqo >>>>> v3JS/P86jzML5EmLO2vBE3c= >>>>> =J/v3 >>>>> -----END PGP SIGNATURE----- >>>> >>>> >>>> >>> >>> - -- >>> >>> Cheers >>> Res >>> >>> Vote for your favourite MTA at http://polls.ausics.net/v3.php >>> -----BEGIN PGP SIGNATURE----- >>> Version: GnuPG v1.4.6 (GNU/Linux) >>> >>> iD8DBQFGQmHpsWhAmSIQh7MRAqlqAJ9SYJoleoHNaphQjAxIRRz+sI+wJgCcCNeR >>> TGGsttpM+lLYglZRhyCOFj8= >>> =coq7 >>> -----END PGP SIGNATURE----- >> >> >> > > - -- > > Cheers > Res > > Vote for your favourite MTA at http://polls.ausics.net/v3.php > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.6 (GNU/Linux) > > iD8DBQFGQpCrsWhAmSIQh7MRAnYYAKCcJe+cWGoFHWrfnVAOW4VMfDhG9gCeNC0J > z9B5TZKHF9EEUR65Q1soguI= > =erk9 > -----END PGP SIGNATURE----- From res at ausics.net Thu May 10 05:40:24 2007 From: res at ausics.net (Res) Date: Thu May 10 05:40:36 2007 Subject: MailScanner w/ Qmail / Plesk ( format error: file is too short ) In-Reply-To: References: Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, On Wed, 9 May 2007, Cameron B. Prince wrote: > Version number in MailScanner.conf (4.58.9) is correct. > MailScanner setting GID to (2520) > MailScanner setting UID to (2520) This seems strange if you are using qmail. UID and GID should differ, UID is qmailq, GID is qmail Make sure qmail can write to your MS working dir > Is there a way to do an strace or something similar to get more verbose > debugging? - --lint --debug also try this, if you are certain it is to do with archive::zip (i'm not convinced myself) Whats the output of: perl -MArchive::Zip -le "print Archive::Zip->VERSION"; ....Should return 1.18 if lower, upgrade that package, it can't hurt. grep -i qmail MailScanner.conf and you should see: Run As User = qmailq Run As Group = qmail Incoming Queue Dir = /var/qmail/queue.in/mess Outgoing Queue Dir = /var/qmail/queue/mess MTA = qmail Sendmail = /var/qmail/bin/qmail-inject.mailscanner Sendmail2 = /var/qmail/bin/qmail-inject.mailscanner - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGQqI7sWhAmSIQh7MRAn7bAKClQArgk0BmZRsN+BvUJQmDYGCzkACfTpwZ 5NrqAUMlfPYogzWvx4gVh8E= =4S6f -----END PGP SIGNATURE----- From cplists at princeservices.com Thu May 10 06:22:41 2007 From: cplists at princeservices.com (Cameron B. Prince) Date: Thu May 10 06:22:46 2007 Subject: MailScanner w/ Qmail / Plesk ( format error: file is too short ) In-Reply-To: Message-ID: Hi Res, > > Version number in MailScanner.conf (4.58.9) is correct. > > MailScanner setting GID to (2520) > > MailScanner setting UID to (2520) > This seems strange if you are using qmail. UID and GID should differ, > UID is qmailq, GID is qmail I agree... This is strange, but as you can see from a grep of the config file, the user and group settings are correct: Run As User = qmailq Run As Group = qmail Incoming Queue Dir = /var/qmail/queue.in/mess Outgoing Queue Dir = /var/qmail/queue/mess MTA = Qmail Sendmail = /var/qmail/bin/qmail-inject.mailscanner Sendmail2 = /var/qmail/bin/qmail-inject.mailscanner I noticed the Qmail is lower case in your example... Mine was capitalized by the setup script. I've read documentation showing it both ways. I left it capitalized because that matches the MailScanner module name. I switched it tonight and it made no difference. > Make sure qmail can write to your MS working dir Here are the permissions: drwxr-xr-x 11 qmailq qmail 4096 May 8 22:22 queue drwxr-xr-x 6 qmailq qmail 4096 May 9 22:54 queue.in > > Is there a way to do an strace or something similar to get more verbose > > debugging? > - --lint --debug I tried a few variations of this and either got the same output or none. > also try this, if you are certain it is to do with archive::zip (i'm not > convinced myself) > Whats the output of: > perl -MArchive::Zip -le "print Archive::Zip->VERSION"; > ....Should return 1.18 if lower, upgrade that package, it can't hurt. I'm by no means convinced... I just saw the same error in a forum post related to Archive::Zip... I really don't know why that would be called in this case anyway as the test message has no attachment. Here's the output: # perl -MArchive::Zip -le "print Archive::Zip->VERSION"; 1.16 I went ahead and upgraded Archive::Zip and noticed that the make test failed because of missing perquisite File::Which and I thought I was on to something. I installed both modules and did the test again with the same results. The line that generates the error is calling a method called Explode: $batch->Explode(); I looked over the code in Message.pm and I'm wondering if it could be an issue with MIME::Parser. What do you think? Thanks, Cameron From res at ausics.net Thu May 10 06:37:52 2007 From: res at ausics.net (Res) Date: Thu May 10 06:38:03 2007 Subject: MailScanner w/ Qmail / Plesk ( format error: file is too short ) In-Reply-To: References: Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, On Thu, 10 May 2007, Cameron B. Prince wrote: > > I noticed the Qmail is lower case in your example... Mine was capitalized by Shouldn't matter >> Make sure qmail can write to your MS working dir > > Here are the permissions: > > drwxr-xr-x 11 qmailq qmail 4096 May 8 22:22 queue > drwxr-xr-x 6 qmailq qmail 4096 May 9 22:54 queue.in Actually I mean your MailScanner temp working dir, like /var/spool/MailScanner chown -R qmailq.qmail /var/spool/MailScanner the real qmail sources also set permissions diferent than what you have above, the queue dir is set 750 do you know what version of qmail plesk installs now days? as in what patches? I know it works on plesk from other comments I've had, but I'm unsure if those posters are members of this list, I suspectmaybe not? since none of them have commented. Check perms on... chown qmailq.qmail /var/qmail/bin/qmail-queue chown root.qmail /var/qmail/bin/qmail-inject.mailscanner chmod 4755 /var/qmail/bin/qmail-queue chmod 755 /var/qmail/bin/qmail-inject.mailscanner >> - --lint --debug > > I tried a few variations of this and either got the same output or none. You'll have to ask Jules on that one. > > The line that generates the error is calling a method called Explode: > > $batch->Explode(); > > I looked over the code in Message.pm and I'm wondering if it could be an > issue with MIME::Parser. What do you think? I have not looked at that code in a while, I can have alook this evening though. - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGQq+ysWhAmSIQh7MRAtMUAKCtG/6mmesYkn9IFfJwhns+WlKumgCePFAW 1D6xPxOCjdH56VhMmefWSM0= =JB8I -----END PGP SIGNATURE----- From steve.freegard at fsl.com Thu May 10 07:35:45 2007 From: steve.freegard at fsl.com (Steve Freegard) Date: Thu May 10 07:35:48 2007 Subject: Issue with Blackberry In-Reply-To: <3123E1B72B666243917E340F3C8FD4A1069703@privaldc2003.prival.local> References: <3123E1B72B666243917E340F3C8FD4A1069703@privaldc2003.prival.local> Message-ID: <4642BD41.9070205@fsl.com> Hi Gehard, I've seen the problem in the headers that you posted: > X-Elite Group, Inc.-MailScanner: Found to be clean > X-Elite Group, Inc.-MailScanner-From: carla.redman@elitegroupinc.ca ^^ & ^ On the MailScanner box that processed this message you have a bad %org-name% setting. Quoting MailScanner.conf: # Note: Some Symantec scanners complain (incorrectly) about "." # ***** characters appearing in the names of headers. # Some other mail servers complain about "_" characters # appearing in the names of headers as well. # So don't put "." or "_" in this setting. # # **** RULE: It must not contain any spaces! **** Your current %org-name% contains spaces and dots (I personally would also avoid commas). Change it to something like: %org-name% = Elite-Group-Inc And it should fix the problem. Kind regards, Steve. -- Steve Freegard Fort Systems Ltd. From jan-peter at koopmann.eu Thu May 10 07:56:14 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Thu May 10 07:56:21 2007 Subject: Clamav suggestions In-Reply-To: <46422078.6000508@ecs.soton.ac.uk> References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it><20070509105522.y9h0nbimg4kg0oks@luna.eco.unibs.it> <46422078.6000508@ecs.soton.ac.uk> Message-ID: On Wednesday, May 09, 2007 9:27 PM Julian Field wrote: > I can't see any effective good solution to this one. Except for convincing the clamav developers to put in another scan option. When called with this option they would not check for the existance of mail headers. I have no idea how delighted they would be if we proposed this though. Any volunteers? :-) Kind regards, JP From pedretti at eco.unibs.it Thu May 10 08:35:15 2007 From: pedretti at eco.unibs.it (Fabio Pedretti) Date: Thu May 10 08:33:29 2007 Subject: Clamav suggestions In-Reply-To: <46422078.6000508@ecs.soton.ac.uk> References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it> <20070509105522.y9h0nbimg4kg0oks@luna.eco.unibs.it> <46422078.6000508@ecs.soton.ac.uk> Message-ID: <20070510093515.sfb5azn34go8s0ww@luna.eco.unibs.it> Citando Julian Field : > > Fabio Pedretti wrote: >>> 2) I noticed (as well as others: >>> http://lists.mailscanner.info/pipermail/mailscanner/2007-April/072504.html >>> >>> ) that some phishing mail are not blocked (I am also using >>> the signatures of sanesecurity). If I do a clamscan on the full >>> original mail with headers, clamscan find the virus (I can provide a >>> sample if needed). Seems the problem is that MailScanner extracts the >>> content of the mail (body + attachment) and scans it, but some >>> phishing mail are only detected if the full headers are present (in >>> the clamav DB in the extended signature format, option 4 is for mail >>> files, look at signatures.pdf in clamav source, and are detected only >>> if full mail with headers is scanned). >>> MailScanner should be modified so that all the original mail (with >>> headers and without extracting attachment) should be passed to >>> clamscan/clamd, so all virus can be catched. >> >> To try the problem send a mail with the following text: >> 2.83:9999/webscrr/ind >> on a MailScanner with clamav mail server. >> The mail does not get filtered. >> >> However if you do a clamscan on the received mail, you get: >> test.eml: Email.Phishing.Pay-20 FOUND >> > If you scan a text file containing the magic string above, clamscan > doesn't find anything wrong. It *only* spots it if the file has email > headers in it as well. This is a bit disappointing on the part of > ClamAV. But it is a very effective defence against false alarms. > MailScanner extracts all the parts of the message and scans them as > files. As a result this phishing detector in ClamAV won't be triggered. > > I can't see any effective good solution to this one. It does not appear > to affect anything except this phishing trap (and possible a few other > phishing traps), so I'm not overly concerned about it. There has been no > evidence whatsoever that anything more important is let through, and > MailScanner has its own phishing detectors which should be triggered anyway. Why not change MailScanner to pass to clamav the full mail with headers? Latest clamav does a good job on scanning mail, and has also decoder for zip/rar2-3 etc. for decoding compressed attachment. From pedretti at eco.unibs.it Thu May 10 08:43:16 2007 From: pedretti at eco.unibs.it (Fabio Pedretti) Date: Thu May 10 08:41:29 2007 Subject: Clamav suggestions In-Reply-To: References: <20070504123613.hz8h28ltwkcko8o8@luna.eco.unibs.it><20070509105522.y9h0nbimg4kg0oks@luna.eco.unibs.it> <46422078.6000508@ecs.soton.ac.uk> Message-ID: <20070510094316.ft4nl33mucc88cww@luna.eco.unibs.it> Citando "Koopmann, Jan-Peter" : > On Wednesday, May 09, 2007 9:27 PM Julian Field wrote: > >> I can't see any effective good solution to this one. > > Except for convincing the clamav developers to put in another scan > option. When called with this option they would not check for the > existance of mail headers. I have no idea how delighted they would > be if we proposed this though. Any volunteers? :-) I don't know if this is a good solution. Clamav check for this strings only in mails, as check for macro viruses only in MS files, for unix viruses only on ELF files, etc... I think the problem is in how MailScanner call clamav, giving it all separated attachments and not the full mail. From uxbod at splatnix.net Thu May 10 09:24:13 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Thu May 10 09:24:20 2007 Subject: Clamav suggestions In-Reply-To: <20070510094316.ft4nl33mucc88cww@luna.eco.unibs.it> References: <20070510094316.ft4nl33mucc88cww@luna.eco.unibs.it> Message-ID: <75beaaf4febafe7fbcfebe749e3da29b@62.49.223.244> Why not just scan the whole file after all the individual scans, but only if it hasn't detected anything in the individual element ones ? On Thu, 10 May 2007 09:43:16 +0200, Fabio Pedretti wrote: > Citando "Koopmann, Jan-Peter" : > >> On Wednesday, May 09, 2007 9:27 PM Julian Field wrote: >> >>> I can't see any effective good solution to this one. >> >> Except for convincing the clamav developers to put in another scan >> option. When called with this option they would not check for the >> existance of mail headers. I have no idea how delighted they would >> be if we proposed this though. Any volunteers? :-) > > I don't know if this is a good solution. Clamav check for this strings > only in mails, as check for macro viruses only in MS files, for unix > viruses only on ELF files, etc... > I think the problem is in how MailScanner call clamav, giving it all > separated attachments and not the full mail. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Thu May 10 10:46:21 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 10 10:47:47 2007 Subject: OT: Installing Mail-ClamAV-0.20 fails... In-Reply-To: References: Message-ID: <4642E9ED.5070404@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Have you considered installing from my ClamAV+SA package? You can always stop it after it installs Mail::ClamAV if you want to. ajos1@onion.demon.co.uk wrote: > - > > Anyone have ideas on this one... I have googled the errors... and see alot of mentions of this error and that the original author needs to fix them... but no solutions! > > It does the same for Mail-ClamAV-0.13 . > > Thanks in advance-o. > > My "Inline" version is 0.44 . > Perl is: Perl: 5.008008 (5.8.8) > > Installing Perl Module - Mail-ClamAV-0.20 > ------------------------------------------ > > CPAN: File::HomeDir loaded ok (v0.64) > CPAN: Storable loaded ok (v2.16) > Going to read /root/.cpan/Metadata > Database was generated on Tue, 08 May 2007 05:10:52 GMT > Running install for module 'Mail::ClamAV' > Running make for S/SA/SABECK/Mail-ClamAV-0.20.tar.gz > CPAN: Digest::SHA loaded ok (v5.44) > CPAN: Compress::Zlib loaded ok (v2.004) > Checksum for /root/.cpan/sources/authors/id/S/SA/SABECK/Mail-ClamAV-0.20.tar.gz ok > Mail-ClamAV-0.20/ > Mail-ClamAV-0.20/t/ > Mail-ClamAV-0.20/t/eicarcom2.zip > Mail-ClamAV-0.20/t/Mail-ClamAV.t > Mail-ClamAV-0.20/t/virus.eml > Mail-ClamAV-0.20/Inline/ > Mail-ClamAV-0.20/Inline/MakeMaker.pm > Mail-ClamAV-0.20/META.yml > Mail-ClamAV-0.20/config.pl > Mail-ClamAV-0.20/Changes > Mail-ClamAV-0.20/MANIFEST > Mail-ClamAV-0.20/ClamAV.pm > Mail-ClamAV-0.20/INSTALL > Mail-ClamAV-0.20/Makefile.PL > Mail-ClamAV-0.20/README > CPAN: File::Temp loaded ok (v0.18) > > CPAN.pm: Going to build S/SA/SABECK/Mail-ClamAV-0.20.tar.gz > > Checking if your kit is complete... > Looks good > Writing Makefile for Mail::ClamAV > CPAN: YAML loaded ok (v0.62) > cp ClamAV.pm blib/lib/Mail/ClamAV.pm > /usr/bin/perl -Mblib -MInline=NOISY,_INSTALL_ -MMail::ClamAV -e1 0.20 blib/arch > Starting Build Prepocess Stage > Finished Build Prepocess Stage > > Starting Build Parse Stage > Finished Build Parse Stage > > Starting Build Glue 1 Stage > Finished Build Glue 1 Stage > > Starting Build Glue 2 Stage > Finished Build Glue 2 Stage > > Starting Build Glue 3 Stage > Finished Build Glue 3 Stage > > Starting Build Compile Stage > Starting "perl Makefile.PL" Stage > Writing Makefile for Mail::ClamAV > Finished "perl Makefile.PL" Stage > > Starting "make" Stage > make[1]: Entering directory `/root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6/_Inline/build/Mail/ClamAV' > /usr/bin/perl /usr/lib/perl5/5.8.8/ExtUtils/xsubpp -typemap /usr/lib/perl5/5.8.8/ExtUtils/typemap ClamAV.xs > ClamAV.xsc && mv ClamAV.xsc ClamAV.c > gcc -c -I/root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6 -I/usr/local/include -D_REENTRANT -D_GNU_SOURCE -fno-strict-aliasing -pipe -Wdeclaration-after-statement -I/usr/local/include -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64 -I/usr/include/gdbm -O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i386 -mtune=generic -fasynchronous-unwind-tables -DVERSION=\"0.20\" -DXS_VERSION=\"0.20\" -fPIC "-I/usr/lib/perl5/5.8.8/i386-linux-thread-multi/CORE" ClamAV.c > ClamAV.xs: In function 'clamav_perl_new': > ClamAV.xs:53: warning: implicit declaration of function 'cl_loaddbdir' > ClamAV.xs:56: warning: implicit declaration of function 'cl_loaddb' > ClamAV.xs: In function 'clamav_perl__scanfd': > ClamAV.xs:202: warning: unused variable 'items' > ClamAV.xs:197: warning: unused variable 'len' > ClamAV.xs: In function 'clamav_perl__scanfile': > ClamAV.xs:239: warning: unused variable 'items' > ClamAV.xs:233: warning: unused variable 'len' > ClamAV.xs: In function 'clamav_perl_constant': > ClamAV.xs:350: error: 'CL_SCAN_ALGORITHMIC' undeclared (first use in this function) > ClamAV.xs:350: error: (Each undeclared identifier is reported only once > ClamAV.xs:350: error: for each function it appears in.) > make[1]: *** [ClamAV.o] Error 1 > make[1]: Leaving directory `/root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6/_Inline/build/Mail/ClamAV' > > A problem was encountered while attempting to compile and install your Inline > C code. The command that failed was: > make > > The build directory was: > /root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6/_Inline/build/Mail/ClamAV > > To debug the problem, cd to the build directory, and inspect the output files. > > at /root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6/blib/lib/Mail/ClamAV.pm line 178 > BEGIN failed--compilation aborted at /root/.cpan/build/Mail-ClamAV-0.20-Cd7OP6/blib/lib/Mail/ClamAV.pm line 542. > Compilation failed in require. > BEGIN failed--compilation aborted. > make: *** [ClamAV.inl] Error 25 > SABECK/Mail-ClamAV-0.20.tar.gz > /usr/bin/make -- NOT OK > Running make test > Can't test without successful make > Running make install > Make had returned bad status, install seems impossible > > == > ===================================================================== > = > = "It is obvious the Treasurer is rolling in money," said Wayne > = Swan, treasury spokesman for the opposition Labor Party. "It has > = been raining gold bars thanks to the mining boom." > = > = Need help dealing with Parking Tickets, Bailiffs, Capita or NTL... > = Call... +44 8457 90 90 90 http://www.samaritans.org/ > = > ===================================================================== > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGQuoeEfZZRxQVtlQRAkWhAKD9ybuD2l5vgUYPFEzAQ2zjeirz5gCgqI8q UxYvqmVWLla2ZMoZmN3fqII= =1aqU -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Thu May 10 10:51:08 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 10 10:52:42 2007 Subject: Clamav suggestions In-Reply-To: <75beaaf4febafe7fbcfebe749e3da29b@62.49.223.244> References: <20070510094316.ft4nl33mucc88cww@luna.eco.unibs.it> <75beaaf4febafe7fbcfebe749e3da29b@62.49.223.244> Message-ID: <4642EB0C.8020304@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 That would slow it down a lot, as it would require another run of the command-line scanner(s). MailScanner always tries to deliver as much of the message as possible. So if you had 3 docs attached to an email message, 1 of which had a macro virus, scanning the whole message with ClamAV would result in none of the attachments getting through. Whereas MailScanner's philosophy is that the other 2 docs and the message body text should still get delivered as they are not infected. So I don't want to throw the whole message at ClamAV either. - --[ UxBoD ]-- wrote: > Why not just scan the whole file after all the individual scans, but only if it hasn't detected anything in the individual element ones ? > > On Thu, 10 May 2007 09:43:16 +0200, Fabio Pedretti wrote: > >> Citando "Koopmann, Jan-Peter" : >> >> >>> On Wednesday, May 09, 2007 9:27 PM Julian Field wrote: >>> >>> >>>> I can't see any effective good solution to this one. >>>> >>> Except for convincing the clamav developers to put in another scan >>> option. When called with this option they would not check for the >>> existance of mail headers. I have no idea how delighted they would >>> be if we proposed this though. Any volunteers? :-) >>> >> I don't know if this is a good solution. Clamav check for this strings >> only in mails, as check for macro viruses only in MS files, for unix >> viruses only on ELF files, etc... >> I think the problem is in how MailScanner call clamav, giving it all >> separated attachments and not the full mail. >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> -- >> This message has been scanned for viruses and dangerous content by >> MailScanner, and is >> believed to be clean. >> Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGQutIEfZZRxQVtlQRArzKAJ91LL+CA4vtESEYmlmQl94HwtslAwCg08jC jjcAgWal0akj1uoq014pszo= =bk0h -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From jan-peter at koopmann.eu Thu May 10 11:12:23 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Thu May 10 11:12:30 2007 Subject: feature request: compress attachments Message-ID: Hi, I just came across another product that offers automatic attachment compression on mails passing the proxy/gateway. Since many people tend to send their Powerpoint/Word/Excel files uncompressed due to lazyness this might actually be a good contribution. There are several solutions for this available at least for Exchange servers but it should be possible to implement this within MailScanner. So e.g. with a ruleset I could force all incoming mails with not compressed attachments to be zipped and save quite some storage in the Exchange databases. Kind regards, JP -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070510/b29a98fe/attachment.html From uxbod at splatnix.net Thu May 10 11:14:25 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Thu May 10 11:14:33 2007 Subject: Clamav suggestions In-Reply-To: <4642EB0C.8020304@ecs.soton.ac.uk> References: <4642EB0C.8020304@ecs.soton.ac.uk> Message-ID: <300007a508e8eb7fe8eab69218d48abc@62.49.223.244> Yeah that makes sense Jules. Taking a step back from this and looking at it again. Does this only happy with the SaneSecurity signatures ? Apologies, if I have missed a previous thread on this. On Thu, 10 May 2007 10:51:08 +0100, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > That would slow it down a lot, as it would require another run of the > command-line scanner(s). > > MailScanner always tries to deliver as much of the message as possible. > So if you had 3 docs attached to an email message, 1 of which had a > macro virus, scanning the whole message with ClamAV would result in none > of the attachments getting through. Whereas MailScanner's philosophy is > that the other 2 docs and the message body text should still get > delivered as they are not infected. So I don't want to throw the whole > message at ClamAV either. > > - --[ UxBoD ]-- wrote: >> Why not just scan the whole file after all the individual scans, but > only if it hasn't detected anything in the individual element ones ? >> >> On Thu, 10 May 2007 09:43:16 +0200, Fabio Pedretti > wrote: >> >>> Citando "Koopmann, Jan-Peter" : >>> >>> >>>> On Wednesday, May 09, 2007 9:27 PM Julian Field wrote: >>>> >>>> >>>>> I can't see any effective good solution to this one. >>>>> >>>> Except for convincing the clamav developers to put in another scan >>>> option. When called with this option they would not check for the >>>> existance of mail headers. I have no idea how delighted they would >>>> be if we proposed this though. Any volunteers? :-) >>>> >>> I don't know if this is a good solution. Clamav check for this strings >>> only in mails, as check for macro viruses only in MS files, for unix >>> viruses only on ELF files, etc... >>> I think the problem is in how MailScanner call clamav, giving it all >>> separated attachments and not the full mail. >>> >>> -- >>> MailScanner mailing list >>> mailscanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! >>> >>> -- >>> This message has been scanned for viruses and dangerous content by >>> MailScanner, and is >>> believed to be clean. >>> > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: UTF-8 > > wj8DBQFGQutIEfZZRxQVtlQRArzKAJ91LL+CA4vtESEYmlmQl94HwtslAwCg08jC > jjcAgWal0akj1uoq014pszo= > =bk0h > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From martinh at solidstatelogic.com Thu May 10 11:16:14 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Thu May 10 11:16:19 2007 Subject: feature request: compress attachments In-Reply-To: Message-ID: Would help here as well - for outgoing stuff as well. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Koopmann, Jan-Peter > Sent: 10 May 2007 11:12 > To: mailscanner@lists.mailscanner.info > Subject: feature request: compress attachments > > Hi, > > I just came across another product that offers automatic attachment > compression on mails passing the proxy/gateway. Since many people tend to > send their Powerpoint/Word/Excel files uncompressed due to lazyness this > might actually be a good contribution. There are several solutions for > this available at least for Exchange servers but it should be possible to > implement this within MailScanner. So e.g. with a ruleset I could force > all incoming mails with not compressed attachments to be zipped and save > quite some storage in the Exchange databases. > > > Kind regards, > JP ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From pedretti at eco.unibs.it Thu May 10 11:41:36 2007 From: pedretti at eco.unibs.it (Fabio Pedretti) Date: Thu May 10 11:39:49 2007 Subject: Clamav suggestions In-Reply-To: <300007a508e8eb7fe8eab69218d48abc@62.49.223.244> References: <4642EB0C.8020304@ecs.soton.ac.uk> <300007a508e8eb7fe8eab69218d48abc@62.49.223.244> Message-ID: <20070510124136.ht3byapm4kgso4cg@luna.eco.unibs.it> Citando "--[ UxBoD ]--" : > Yeah that makes sense Jules. > > Taking a step back from this and looking at it again. Does this > only happy with the SaneSecurity signatures ? No, in fact the string I have posted was taken from clamav signatures and not sanesecurity signatures. The problem is for all signatures that uses the "signature format #4" (the signature for checking mail), as specified in signatures.pdf in clamav source. From uxbod at splatnix.net Thu May 10 14:00:30 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Thu May 10 14:00:34 2007 Subject: Preferred Distribution Message-ID: Hi, I am having to setup a couple of new mailservers where I am working on contract at the moment, using Dell SC1435 rack mounts. The problem is that RedHat ES4 kernel is so old does not recognise the SAS RAID card. Now my question is should I get them to purchase RHES5, or go for either CentOS or Fedora ? Personally I would use Gentoo or Ubuntu, but they are really *not* happy in using either of them for a corporate system :( -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From holger at noefer.org Thu May 10 14:06:28 2007 From: holger at noefer.org (Holger =?iso-8859-1?b?TvZmZXI=?=) Date: Thu May 10 14:06:33 2007 Subject: feature request MailScanner with MySQL Message-ID: <20070510150628.dhu95j13x9k4cgcw@www.noefer.org> Hi, I think it is a nice feature to include MySQL in Mailscanner. What do you think about to get the /opt/MailScanner/etc/rules files from a database? For example postfix can get its mappings, like access, virtual maps and so on from a MySQL database and has a little cache. For MailScanner you can create a little cache so that MailScanner does not need to look into the database for each mail. The advantage is that it is more flexible und you can create a gui, web application or whatever to fill the MySQL database. And you don't need to restart MailScanner for every rule change. What do you think about it, is it possible? Does someone else need it? Best regards, Holger From oliver at linux-kernel.at Thu May 10 14:14:25 2007 From: oliver at linux-kernel.at (Oliver Falk) Date: Thu May 10 14:14:31 2007 Subject: Preferred Distribution In-Reply-To: References: Message-ID: <46431AB1.3040803@linux-kernel.at> On 05/10/2007 03:00 PM, --[ UxBoD ]-- wrote: > I am having to setup a couple of new mailservers where > I am working on contract at the moment, using Dell > SC1435 rack mounts. > The problem is that RedHat ES4 kernel is so old does > not recognise the SAS RAID card. > > Now my question is should I get them to purchase > RHES5, If you don't need support, there's no need for EL5. > or go for either CentOS or Fedora ? Both is fine. Fedora should recognize it AFAIK. > Personally I would use Gentoo or Ubuntu, but they > are really *not* happy in using either of them > for a corporate system :( Ubuntu is not really a server OS. Gentoo; I don't if you can manage a couple of servers with Gentoo - Software distribution, Updates, ... MS and Fedora are playing good together from my experience.... -of From daniel.maher at ubisoft.com Thu May 10 14:18:29 2007 From: daniel.maher at ubisoft.com (Daniel Maher) Date: Thu May 10 14:18:34 2007 Subject: Preferred Distribution In-Reply-To: Message-ID: <1E293D3FF63A3740B10AD5AAD88535D204E13733@UBIMAIL1.ubisoft.org> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- > Sent: May 10, 2007 9:01 AM > To: mailscanner@lists.mailscanner.info > Subject: Preferred Distribution > > Hi, > > I am having to setup a couple of new mailservers where I am working on > contract at the moment, using Dell SC1435 rack mounts. The problem is > that RedHat ES4 kernel is so old does not recognise the SAS RAID card. > > Now my question is should I get them to purchase RHES5, or go for either > CentOS or Fedora ? > > Personally I would use Gentoo or Ubuntu, but they are really *not* happy > in using either of them for a corporate system :( At my (reasonably large multi-national) company, we've started using CentOS for all of our new machines, and will likely continue to do so. We don't need RedHat's telephone support, nor do we care to use up2date, ergo the benefits of using RedHat over CentOS are almost non-existent. YMMV, of course - especially if you're at a smaller organisation where phone support might come in handy, or where you don't manage your own software repository. 0.02$ -- _ ?v? Daniel Maher /(_)\ Administrateur Syst?me Unix ^ ^ Unix System Administrator "The most incomprehensible thing about the world is that it is comprehensible." -- Albert Einstein. From pedretti at eco.unibs.it Thu May 10 14:23:13 2007 From: pedretti at eco.unibs.it (Fabio Pedretti) Date: Thu May 10 14:21:24 2007 Subject: Clamav suggestions In-Reply-To: <4642EB0C.8020304@ecs.soton.ac.uk> References: <20070510094316.ft4nl33mucc88cww@luna.eco.unibs.it> <75beaaf4febafe7fbcfebe749e3da29b@62.49.223.244> <4642EB0C.8020304@ecs.soton.ac.uk> Message-ID: <20070510152313.ul54et2kmoswcccg@luna.eco.unibs.it> > MailScanner always tries to deliver as much of the message as possible. > So if you had 3 docs attached to an email message, 1 of which had a > macro virus, scanning the whole message with ClamAV would result in none > of the attachments getting through. Whereas MailScanner's philosophy is > that the other 2 docs and the message body text should still get > delivered as they are not infected. So I don't want to throw the whole > message at ClamAV either. This make sense. However, in my experience: - most mail (>99%) with viruses are generated by spambots/spammers and should be deleted anyway; it's not usually desiderable to give the users the cleaned mail if the remaing is only spam; - if one user send some attachments with viruses it's better that he check and repairs immediately his system (and if he can't no more send mails he will do), rather than still provide mail with only the clean attachments; - I am using greylisting + MailScanner (with Spamassassin + Clamav + Sanesecurity sigs) and, after these, not many spam/phishing mail can reach the users; however, almost all of that mail would be detected by clamav (especially with sanesecurity sigs), if the scan would be done on the full mail. So it seems to me that the advantages to give clamav all mail with headers by default are bigger than to give it separated attachments. Or, at least, would be a valuable addition to provide a config option to do this. Fabio From pete at enitech.com.au Thu May 10 14:20:50 2007 From: pete at enitech.com.au (Pete Russell) Date: Thu May 10 14:21:26 2007 Subject: Preferred Distribution In-Reply-To: References: Message-ID: <46431C32.4030404@enitech.com.au> Fedora? They do not have support lifecycle suitable for corporate clients (espe ones using external linux skills), IMO. CentOS is the logical choice. Hassle free, you know mailscanner is going to work nicely on it - its RHAS... --[ UxBoD ]-- wrote: > Hi, > > I am having to setup a couple of new mailservers where I am working on contract at the moment, using Dell SC1435 rack mounts. The problem is that RedHat ES4 kernel is so old does not recognise the SAS RAID card. > > Now my question is should I get them to purchase RHES5, or go for either CentOS or Fedora ? > > Personally I would use Gentoo or Ubuntu, but they are really *not* happy in using either of them for a corporate system :( From derek at csolve.net Thu May 10 14:21:50 2007 From: derek at csolve.net (Derek Buttineau) Date: Thu May 10 14:22:29 2007 Subject: feature request MailScanner with MySQL In-Reply-To: <20070510150628.dhu95j13x9k4cgcw@www.noefer.org> References: <20070510150628.dhu95j13x9k4cgcw@www.noefer.org> Message-ID: <4C6461BB-270B-452C-8645-2BFC86634915@csolve.net> On 2007-May-10, at 9:06 AM, Holger N?fer wrote: > I think it is a nice feature to include MySQL in > Mailscanner. > > What do you think about to get the /opt/MailScanner/etc/rules files > from a database? > For example postfix can get its mappings, like access, virtual maps > and > so on from a MySQL database and has a little cache. > > For MailScanner you can create a little cache so that MailScanner > does not need to look into the database for each mail. > > The advantage is that it is more flexible und you can create a > gui, web application or whatever to fill the MySQL database. > And you don't need to restart MailScanner for every rule change. > > What do you think about it, is it possible? > Does someone else need it? You can extend MailScanner to include this functionality through the use of CustomFunctions. The function call can then be substituted for the rule file in MailScanner.conf. Personally, we used mysql calls with MailScanner in development years ago and while it worked it got fairly slow when dealing with large amounts of incoming e-mail. We currently use the CDB database package to provide rulesets to MailScanner, it's incredibly fast. Anyway, you can pretty much make MailScanner do whatever you want through CustomFunctions :) -- Regards, Derek Buttineau Internet Systems Developer Compu-SOLVE Internet Services Compu-SOLVE Technologies, Inc Phone: 705-725-1212 x255 E-Mail: derek@csolve.net From pedretti at eco.unibs.it Thu May 10 14:29:14 2007 From: pedretti at eco.unibs.it (Fabio Pedretti) Date: Thu May 10 14:27:25 2007 Subject: Preferred Distribution In-Reply-To: References: Message-ID: <20070510152914.g744m7cf28w88ggg@luna.eco.unibs.it> Citando "--[ UxBoD ]--" : > Hi, > > I am having to setup a couple of new mailservers where I am working > on contract at the moment, using Dell SC1435 rack mounts. The > problem is that RedHat ES4 kernel is so old does not recognise the > SAS RAID card. > > Now my question is should I get them to purchase RHES5, or go for > either CentOS or Fedora ? If I recall correct, if you have a RHES4 subscription, you can upgrade or downgrade to any other RHES version for free. I would not go with Fedora, it has short term support, and a lot of non bug fix updates, which sometimes break things. From uxbod at splatnix.net Thu May 10 14:27:57 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Thu May 10 14:28:24 2007 Subject: feature request MailScanner with MySQL In-Reply-To: <20070510150628.dhu95j13x9k4cgcw@www.noefer.org> References: <20070510150628.dhu95j13x9k4cgcw@www.noefer.org> Message-ID: <0350d60387e3004b6716b7b5231e51e2@62.49.223.244> I give my thumbs up for the feature :) On Thu, 10 May 2007 15:06:28 +0200, Holger N?fer wrote: > Hi, > > I think it is a nice feature to include MySQL in > Mailscanner. > > What do you think about to get the /opt/MailScanner/etc/rules files > from a database? > For example postfix can get its mappings, like access, virtual maps and > so on from a MySQL database and has a little cache. > > For MailScanner you can create a little cache so that MailScanner > does not need to look into the database for each mail. > > The advantage is that it is more flexible und you can create a > gui, web application or whatever to fill the MySQL database. > And you don't need to restart MailScanner for every rule change. > > What do you think about it, is it possible? > Does someone else need it? > > Best regards, > Holger > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From oliver at linux-kernel.at Thu May 10 14:34:49 2007 From: oliver at linux-kernel.at (Oliver Falk) Date: Thu May 10 14:34:54 2007 Subject: Preferred Distribution In-Reply-To: <1E293D3FF63A3740B10AD5AAD88535D204E13733@UBIMAIL1.ubisoft.org> References: <1E293D3FF63A3740B10AD5AAD88535D204E13733@UBIMAIL1.ubisoft.org> Message-ID: <46431F79.6050400@linux-kernel.at> On 05/10/2007 03:18 PM, Daniel Maher wrote: >> I am having to setup a couple of new mailservers where I am working on >> contract at the moment, using Dell SC1435 rack mounts. The problem is >> that RedHat ES4 kernel is so old does not recognise the SAS RAID card. >> >> Now my question is should I get them to purchase RHES5, or go for either >> CentOS or Fedora ? >> >> Personally I would use Gentoo or Ubuntu, but they are really *not* happy >> in using either of them for a corporate system :( > > At my (reasonably large multi-national) company, we've started using CentOS for all of our new machines, and will likely continue to do so. We don't need RedHat's telephone support, nor do we care to use up2date, ergo the benefits of using RedHat over CentOS are almost non-existent. And you don't have eg. Oracle running on Linux? :-) [ ... ] -of From jan-peter at koopmann.eu Thu May 10 14:40:13 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Thu May 10 14:40:25 2007 Subject: clamd problem Message-ID: Hi, on some machines I am getting this error message over and over again: May 10 15:35:44 proxy MailScanner[7529]: /var/spool/MailScanner/incoming/7529/.: lstat() failed. ERROR I am using clamd-wrapper. Permissions in MailScanner.conf are set as described and clamav user can acutally access the directories. Any bright ideas? Regards, JP -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070510/57ab3de0/attachment.html From Jason at SYO.Com Thu May 10 14:44:01 2007 From: Jason at SYO.Com (Jason Gottschalk) Date: Thu May 10 14:44:23 2007 Subject: Approve/Deny outgoing e-mail ? Message-ID: <1503721294.20070510094401@SYO.Com> I know mailscanner can scan outgoing mail (when the user uses the host as his smtp server). Is there any mechanism in mailscanner to hold an outgoing message until it is reviewed by an administrator who would approve/deny the message and then release it? -- Best regards, Jason Gottschalk mailto:Jason@SYO.Com SYO Computer Engineering Services, Inc. SYO - Servicing Your Organization 586-286-2557 From daniel.maher at ubisoft.com Thu May 10 14:45:44 2007 From: daniel.maher at ubisoft.com (Daniel Maher) Date: Thu May 10 14:45:47 2007 Subject: clamd problem In-Reply-To: Message-ID: <1E293D3FF63A3740B10AD5AAD88535D204E137B1@UBIMAIL1.ubisoft.org> Hello, I recently had exactly the same problem. I had to setgid the incoming directory, so that the sub-directories underneath (i.e. "7529/") were created with the correct group at run-time. -- _ ?v? Daniel Maher /(_)\ Administrateur Syst?me Unix ^ ^ Unix System Administrator "The most incomprehensible thing about the world is that it is comprehensible." -- Albert Einstein. ________________________________ From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Koopmann, Jan-Peter Sent: May 10, 2007 9:40 AM To: MailScanner discussion Subject: clamd problem Hi, on some machines I am getting this error message over and over again: May 10 15:35:44 proxy MailScanner[7529]: /var/spool/MailScanner/incoming/7529/.: lstat() failed. ERROR I am using clamd-wrapper. Permissions in MailScanner.conf are set as described and clamav user can acutally access the directories. Any bright ideas? Regards, JP -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070510/8b930f95/attachment.html From martinh at solidstatelogic.com Thu May 10 14:46:38 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Thu May 10 14:46:46 2007 Subject: clamd problem In-Reply-To: Message-ID: JP Yeah can the clamd user get to those directories - all the way down.....not just the bottom remember -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Koopmann, Jan-Peter > Sent: 10 May 2007 14:40 > To: MailScanner discussion > Subject: clamd problem > > Hi, > > on some machines I am getting this error message over and over again: > > May 10 15:35:44 proxy MailScanner[7529]: > /var/spool/MailScanner/incoming/7529/.: lstat() failed. ERROR > > I am using clamd-wrapper. Permissions in MailScanner.conf are set as > described and clamav user can acutally access the directories. Any bright > ideas? > > Regards, > JP ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From jan-peter at koopmann.eu Thu May 10 14:53:38 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Thu May 10 14:53:55 2007 Subject: clamd problem In-Reply-To: References: Message-ID: On Thursday, May 10, 2007 3:47 PM Martin.Hepworth wrote: > JP > Yeah can the clamd user get to those directories - all the way > down.....not just the bottom remember Yep it can. It even finds test viruses!!! Thats what is so confusing. On another machine with seemingly the same settings all is well. From jan-peter at koopmann.eu Thu May 10 14:54:33 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Thu May 10 14:54:49 2007 Subject: clamd problem In-Reply-To: <1E293D3FF63A3740B10AD5AAD88535D204E137B1@UBIMAIL1.ubisoft.org> References: <1E293D3FF63A3740B10AD5AAD88535D204E137B1@UBIMAIL1.ubisoft.org> Message-ID: Should the "Incoming Work Group" setting not take care of that? ________________________________ From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Daniel Maher Sent: Thursday, May 10, 2007 3:46 PM To: MailScanner discussion Subject: RE: clamd problem Hello, I recently had exactly the same problem. I had to setgid the incoming directory, so that the sub-directories underneath (i.e. "7529/") were created with the correct group at run-time. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070510/baa27708/attachment.html From jan-peter at koopmann.eu Thu May 10 14:56:49 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Thu May 10 14:57:03 2007 Subject: clamd problem In-Reply-To: References: Message-ID: On Thursday, May 10, 2007 3:47 PM Martin.Hepworth wrote: > JP > Yeah can the clamd user get to those directories - all the way > down.....not just the bottom remember Well in the maillog it finds the EICAR file but it is not reported in MailWatch... On my machine it is, on that second machine it is not. Very strange. From daniel.maher at ubisoft.com Thu May 10 15:10:21 2007 From: daniel.maher at ubisoft.com (Daniel Maher) Date: Thu May 10 15:10:25 2007 Subject: clamd problem In-Reply-To: Message-ID: <1E293D3FF63A3740B10AD5AAD88535D204E13818@UBIMAIL1.ubisoft.org> It should, but in my case, it did not. Using setgid solved the problem, no questions asked. :-) -- _ ?v? Daniel Maher /(_)\ Administrateur Syst?me Unix ^ ^ Unix System Administrator "The most incomprehensible thing about the world is that it is comprehensible." -- Albert Einstein. ________________________________ From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Koopmann, Jan-Peter Sent: May 10, 2007 9:55 AM To: MailScanner discussion Subject: RE: clamd problem Should the "Incoming Work Group" setting not take care of that? ________________________________ From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Daniel Maher Sent: Thursday, May 10, 2007 3:46 PM To: MailScanner discussion Subject: RE: clamd problem Hello, I recently had exactly the same problem. I had to setgid the incoming directory, so that the sub-directories underneath (i.e. "7529/") were created with the correct group at run-time. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070510/ad063f2b/attachment.html From dnsadmin at 1bigthink.com Thu May 10 15:58:48 2007 From: dnsadmin at 1bigthink.com (dnsadmin 1bigthink.com) Date: Thu May 10 15:59:14 2007 Subject: Preferred Distribution In-Reply-To: References: Message-ID: <200705101459.l4AEx2Qd024722@mxt.1bigthink.com> At 09:00 AM 5/10/2007, you wrote: >Hi, > >I am having to setup a couple of new mailservers where I am working >on contract at the moment, using Dell SC1435 rack mounts. The >problem is that RedHat ES4 kernel is so old does not recognise the >SAS RAID card. > >Now my question is should I get them to purchase RHES5, or go for >either CentOS or Fedora ? I am using CentOS 4.4 on Dell 1955 blades. Support for the SAS is there. I'd go CentOS. Fedora life-cycle is too short for me, and most likely for your current use/need. Cheers, Glenn From cplists at princeservices.com Thu May 10 16:59:27 2007 From: cplists at princeservices.com (Cameron B. Prince) Date: Thu May 10 16:59:35 2007 Subject: MailScanner w/ Qmail / Plesk ( format error: file is too short ) In-Reply-To: Message-ID: Hi Res, > Actually I mean your MailScanner temp working dir, like > /var/spool/MailScanner > > chown -R qmailq.qmail /var/spool/MailScanner I checked and reset this. > the real qmail sources also set permissions diferent than what you have > above, the queue dir is set 750 I went through both the queue and queue.in directories and reset the permissions. > do you know what version of qmail plesk installs now days? as in what > patches? I know it works on plesk from other comments I've had, but I'm > unsure if those posters are members of this list, I suspectmaybe not? > since none of them have commented. This is my first dealings with Qmail as I've historically only worked with sendmail. Can you tell me how I can find the information to answer your question? > Check perms on... > > chown qmailq.qmail /var/qmail/bin/qmail-queue > chown root.qmail /var/qmail/bin/qmail-inject.mailscanner > chmod 4755 /var/qmail/bin/qmail-queue > chmod 755 /var/qmail/bin/qmail-inject.mailscanner I checked and reset these... More tests result in the same error. I tried with an attachment also to make the message larger and it also produced the same error. > I have not looked at that code in a while, I can have alook this evening > though. Thank you, Cameron From mbneto at gmail.com Thu May 10 17:09:34 2007 From: mbneto at gmail.com (mbneto) Date: Thu May 10 17:09:37 2007 Subject: Build only (from rpm.tar.gz) Message-ID: <5cf776b80705100909t347d505co4c5776278daa559b@mail.gmail.com> Hi, I've noticed that when I perform a ./install.sh it generates a lot of rpm files and later installs. I could not find, however, the rpm for the mailscanner itself only the perl, tnef etc. Since I need to maintain a number of servers that does not have gcc and other libraries I need to generate the complete set of rpm and add to my yum repository. Any idea of how to do that (or to find the mailscanner.rpm generated)? tks. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070510/dab8cf94/attachment.html From jan-peter at koopmann.eu Thu May 10 17:28:28 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Thu May 10 17:28:46 2007 Subject: clamd problem In-Reply-To: <1E293D3FF63A3740B10AD5AAD88535D204E13818@UBIMAIL1.ubisoft.org> References: <1E293D3FF63A3740B10AD5AAD88535D204E13818@UBIMAIL1.ubisoft.org> Message-ID: Looks like a restart of clamd fixed the problem. One of those "do not ask" problems... -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070510/13dbd304/attachment.html From gmourani at prival.ca Thu May 10 19:23:59 2007 From: gmourani at prival.ca (Gerhard Mourani) Date: Thu May 10 19:24:27 2007 Subject: Issue with Blackberry In-Reply-To: <4642BD41.9070205@fsl.com> Message-ID: <3123E1B72B666243917E340F3C8FD4A1069754@privaldc2003.prival.local> Hi Steve, Thanks for your help, yes I've fixed this part into the config and also find other options responsible of this issue with Blackberry devices. Bellow is the options part causing the problems. Allow IFrame Tags = Allow Form Tags = Allow Script Tags = Allow WebBugs = All of the above should be set to yes for Blackberry to correctly display mails. Gerhard -----Original Message----- From: Steve Freegard [mailto:steve.freegard@fsl.com] Sent: Thursday, May 10, 2007 2:36 AM To: MailScanner discussion; Gerhard Mourani Subject: Re: Issue with Blackberry Hi Gehard, I've seen the problem in the headers that you posted: > X-Elite Group, Inc.-MailScanner: Found to be clean > X-Elite Group, Inc.-MailScanner-From: carla.redman@elitegroupinc.ca ^^ & ^ On the MailScanner box that processed this message you have a bad %org-name% setting. Quoting MailScanner.conf: # Note: Some Symantec scanners complain (incorrectly) about "." # ***** characters appearing in the names of headers. # Some other mail servers complain about "_" characters # appearing in the names of headers as well. # So don't put "." or "_" in this setting. # # **** RULE: It must not contain any spaces! **** Your current %org-name% contains spaces and dots (I personally would also avoid commas). Change it to something like: %org-name% = Elite-Group-Inc And it should fix the problem. Kind regards, Steve. -- Steve Freegard Fort Systems Ltd. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From damon at txmail.marinocrane.com Thu May 10 19:24:36 2007 From: damon at txmail.marinocrane.com (Damon Lambooy) Date: Thu May 10 19:25:34 2007 Subject: Preferred Distribution In-Reply-To: <1E293D3FF63A3740B10AD5AAD88535D204E13733@UBIMAIL1.ubisoft.org> References: <1E293D3FF63A3740B10AD5AAD88535D204E13733@UBIMAIL1.ubisoft.org> Message-ID: <46436364.40507@txmail.marinocrane.com> Daniel Maher wrote: >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- >> Sent: May 10, 2007 9:01 AM >> To: mailscanner@lists.mailscanner.info >> Subject: Preferred Distribution >> >> Hi, >> >> I am having to setup a couple of new mailservers where I am working on >> contract at the moment, using Dell SC1435 rack mounts. The problem is >> that RedHat ES4 kernel is so old does not recognise the SAS RAID card. >> >> Now my question is should I get them to purchase RHES5, or go for either >> CentOS or Fedora ? >> >> Personally I would use Gentoo or Ubuntu, but they are really *not* happy >> in using either of them for a corporate system :( >> > > At my (reasonably large multi-national) company, we've started using CentOS for all of our new machines, and will likely continue to do so. We don't need RedHat's telephone support, nor do we care to use up2date, ergo the benefits of using RedHat over CentOS are almost non-existent. > > YMMV, of course - especially if you're at a smaller organisation where phone support might come in handy, or where you don't manage your own software repository. > > 0.02$ > > > -- > _ > ?v? Daniel Maher > /(_)\ Administrateur Syst?me Unix > ^ ^ Unix System Administrator > > "The most incomprehensible thing about the world is that it is comprehensible." -- Albert Einstein. > I am tring to install Mailscanner 4.59.4-2 on Fedora 7 test 4 but getting strange error about rpms not being installed. [root@mailex MailScanner-4.59.4-2]# ./install.sh Good. You have the patch command. Good, you have /usr/src/redhat in place. Good, unpackaged files will not break the build process. Good, far-too-clever Perl requirements will be ignored. Good, you appear to only have 1 copy of Perl installed. I think you are running on RedHat Linux, Mandriva Linux or SuSE Linux. You must have the following RPM packages installed before you try and do anything else: binutils glibc-devel egcs make You are missing at least 1 of these. Please install them all (Read the manuals if you do not know how to do this). Then come back and run this install.sh script again. Can anyone point me in the right direction I have installed all but egcs which i can't find in a current rpm disto. has anyone else experienced any similar problems? or should I just wait until full version comes around? TIA Damon -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070510/cf03339e/attachment-0001.html From rpoe at plattesheriff.org Thu May 10 20:19:19 2007 From: rpoe at plattesheriff.org (Rob Poe) Date: Thu May 10 20:20:15 2007 Subject: Interesting need In-Reply-To: <463F5C10.7080307@ecs.soton.ac.uk> References: <463F0518.65ED.00A2.0@plattesheriff.org> <463F5C10.7080307@ecs.soton.ac.uk> Message-ID: <464329EA.65ED.00A2.0@plattesheriff.org> Perfect! Thanks, Jules. How are you feeling? Getting tired of hearing that? >>> Julian Field 5/7/2007 12:04 PM >>> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Dead easy. Put a ruleset on "Archive Mail =". For example, say "theboss@yourdomain.com" wants all his incoming external mail to go to himself and "assistant@yourdomain.com". In MailScanner.conf, set Archive Mail = %rules-dir%/archive.mail.rules Put the ruleset in /etc/MailScanner/rules/archive.mail.rules. In this file, put: FromOrTo: default To: theboss@yourdomain.com assistant@yourdomain.com Then just force a MailScanner configuration reload with service MailScanner reload Rob Poe wrote: > This might not be so much a MailScanner function ... but > > I have a Linux / Sendmail / MailScanner box set up in front of a corporate mail system. It's doing the domain as relay-domains and mailertable. One of their users wants all of his EXTERNAL incoming mail to go to both HIM and his assistant. > > I tried with the aliases and virtusertable ... didn't work (just forwarded on to the corp mail system as if nothing was in there). > > Is this something I can do with a MailScanner rule? > > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGP1zKEfZZRxQVtlQRAjv8AJ9aKslrMJC6Od0vG1XaNRmQw1JboACbBZ+Z qWfLcoajUFGC5li684N5+2Q= =cwWu -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu May 10 20:29:46 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 10 20:34:49 2007 Subject: Approve/Deny outgoing e-mail ? In-Reply-To: <1503721294.20070510094401@SYO.Com> References: <1503721294.20070510094401@SYO.Com> Message-ID: <464372AA.2090906@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 You could do this with a little ruleset and an external script that would show the admin each mail message and move it into the outgoing queue if it's 'approved'. Just use a ruleset that says that mail going to domains other than your own should go into /var/spool/mqueue.approval. Mail going to your domain goes straight into /var/spool/mqueue. The script would then show the messages in mqueue.approval to the admin, then if they are approved they are moved into mqueue (from where the MTA will then deliver them). Jason Gottschalk wrote: > I know mailscanner can scan outgoing mail (when the user uses the host > as his smtp server). Is there any mechanism in mailscanner to hold an > outgoing message until it is reviewed by an administrator who would > approve/deny the message and then release it? > > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGQ3OsEfZZRxQVtlQRAhWgAKDRMCFbCSWzncvbV1zsHnoxFN/cGQCdEyVp IUyhZgOVoITi/cvvX6l7zTw= =JBJd -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Thu May 10 20:33:17 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 10 20:34:51 2007 Subject: Build only (from rpm.tar.gz) In-Reply-To: <5cf776b80705100909t347d505co4c5776278daa559b@mail.gmail.com> References: <5cf776b80705100909t347d505co4c5776278daa559b@mail.gmail.com> Message-ID: <4643737D.1090500@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 It's there, you must be looking straight through it. MailScanner-4.59.4-2/mailscanner-4.59.4-2.noarch.rpm in the rpm.tar.gz file. mbneto wrote: > Hi, > > I've noticed that when I perform a ./install.sh it generates a lot of > rpm files and later installs. I could not find, however, the rpm for > the mailscanner itself only the perl, tnef etc. > > Since I need to maintain a number of servers that does not have gcc > and other libraries I need to generate the complete set of rpm and add > to my yum repository. > > Any idea of how to do that (or to find the mailscanner.rpm generated)? > > tks. > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGQ3OuEfZZRxQVtlQRAiQjAJ0ZYBqUBxToowiZxdk3MUZ/QR/7wwCgpcMu BWwU0ULq/aOZ3DDkLM6gIe0= =NfMx -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Thu May 10 20:39:44 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 10 20:43:50 2007 Subject: Preferred Distribution In-Reply-To: <46436364.40507@txmail.marinocrane.com> References: <1E293D3FF63A3740B10AD5AAD88535D204E13733@UBIMAIL1.ubisoft.org> <46436364.40507@txmail.marinocrane.com> Message-ID: <46437500.7080204@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Damon Lambooy wrote: > I am tring to install Mailscanner 4.59.4-2 on Fedora 7 test 4 but > getting strange error about rpms not being installed. > > [root@mailex MailScanner-4.59.4-2]# ./install.sh > > > Good. You have the patch command. > > Good, you have /usr/src/redhat in place. > > Good, unpackaged files will not break the build process. > Good, far-too-clever Perl requirements will be ignored. > > Good, you appear to only have 1 copy of Perl installed. > > I think you are running on RedHat Linux, Mandriva Linux or SuSE Linux. > You must have the following RPM packages installed before > you try and do anything else: > binutils glibc-devel egcs make > You are missing at least 1 of these. > Please install them all Do you have gcc installed? Fedora has probably just hit a problem caused by my being short-sighted in the install.sh script. if [ -f /etc/redhat-release ] && fgrep -q ' 6.' /etc/redhat-release ; then # RedHat used egcs in RedHat 6 and not gcc GCC=egcs fi So if it finds "6." in the redhat-release file then it won't look for gcc, it will look for egcs. What exactly does your /etc/redhat-release file say? If you can give me that I can work on the install.sh script and produce a new version for you that will work. I can probably just abandon the RedHat 6 test altogether now. Anyone still running it deserves all they get :-) Just delete those 4 lines. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGQ3XKEfZZRxQVtlQRAoaDAJ9YZ2xgHI0NdNhLB6qEXicWl7gXbwCgsYyZ 8IjfVu8sTTxVSZNM5WOTBdg= =GAu1 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Thu May 10 20:50:23 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 10 20:51:00 2007 Subject: Preferred Distribution In-Reply-To: <46437500.7080204@ecs.soton.ac.uk> References: <1E293D3FF63A3740B10AD5AAD88535D204E13733@UBIMAIL1.ubisoft.org> <46436364.40507@txmail.marinocrane.com> <46437500.7080204@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 5/10/2007 12:39 PM: > > > Damon Lambooy wrote: >> I am tring to install Mailscanner 4.59.4-2 on Fedora 7 test 4 but >> getting strange error about rpms not being installed. > >> [root@mailex MailScanner-4.59.4-2]# ./install.sh > > >> Good. You have the patch command. > >> Good, you have /usr/src/redhat in place. > >> Good, unpackaged files will not break the build process. >> Good, far-too-clever Perl requirements will be ignored. > >> Good, you appear to only have 1 copy of Perl installed. > >> I think you are running on RedHat Linux, Mandriva Linux or SuSE Linux. >> You must have the following RPM packages installed before >> you try and do anything else: >> binutils glibc-devel egcs make >> You are missing at least 1 of these. >> Please install them all > Do you have gcc installed? > Fedora has probably just hit a problem caused by my being short-sighted > in the install.sh script. > > if [ -f /etc/redhat-release ] && fgrep -q ' 6.' /etc/redhat-release ; then > # RedHat used egcs in RedHat 6 and not gcc > GCC=egcs > fi > > So if it finds "6." in the redhat-release file then it won't look for > gcc, it will look for egcs. What exactly does your /etc/redhat-release > file say? If you can give me that I can work on the install.sh script > and produce a new version for you that will work. I can probably just > abandon the RedHat 6 test altogether now. Anyone still running it > deserves all they get :-) > Just delete those 4 lines. > > > Jules > People should stop using RedHat 6. It has got to be almost 8 years old! -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From damon at txmail.marinocrane.com Thu May 10 21:01:42 2007 From: damon at txmail.marinocrane.com (Damon Lambooy) Date: Thu May 10 21:02:15 2007 Subject: Preferred Distribution In-Reply-To: References: <1E293D3FF63A3740B10AD5AAD88535D204E13733@UBIMAIL1.ubisoft.org> <46436364.40507@txmail.marinocrane.com> <46437500.7080204@ecs.soton.ac.uk> Message-ID: <46437A26.7040901@txmail.marinocrane.com> Scott Silva wrote: > Julian Field spake the following on 5/10/2007 12:39 PM: > >> Damon Lambooy wrote: >> >>> I am tring to install Mailscanner 4.59.4-2 on Fedora 7 test 4 but >>> getting strange error about rpms not being installed. >>> >>> [root@mailex MailScanner-4.59.4-2]# ./install.sh >>> >> >>> Good. You have the patch command. >>> >>> Good, you have /usr/src/redhat in place. >>> >>> Good, unpackaged files will not break the build process. >>> Good, far-too-clever Perl requirements will be ignored. >>> >>> Good, you appear to only have 1 copy of Perl installed. >>> >>> I think you are running on RedHat Linux, Mandriva Linux or SuSE Linux. >>> You must have the following RPM packages installed before >>> you try and do anything else: >>> binutils glibc-devel egcs make >>> You are missing at least 1 of these. >>> Please install them all >>> >> Do you have gcc installed? >> Fedora has probably just hit a problem caused by my being short-sighted >> in the install.sh script. >> >> if [ -f /etc/redhat-release ] && fgrep -q ' 6.' /etc/redhat-release ; then >> # RedHat used egcs in RedHat 6 and not gcc >> GCC=egcs >> fi >> >> So if it finds "6." in the redhat-release file then it won't look for >> gcc, it will look for egcs. What exactly does your /etc/redhat-release >> file say? If you can give me that I can work on the install.sh script >> and produce a new version for you that will work. I can probably just >> abandon the RedHat 6 test altogether now. Anyone still running it >> deserves all they get :-) >> Just delete those 4 lines. >> >> >> Jules >> >> > People should stop using RedHat 6. It has got to be almost 8 years old! > > Yip, Thanks Jules. That did it. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070510/c9fe1746/attachment.html From damon at txmail.marinocrane.com Thu May 10 21:18:31 2007 From: damon at txmail.marinocrane.com (Damon Lambooy) Date: Thu May 10 21:19:08 2007 Subject: Preferred Distribution In-Reply-To: <46437A26.7040901@txmail.marinocrane.com> References: <1E293D3FF63A3740B10AD5AAD88535D204E13733@UBIMAIL1.ubisoft.org> <46436364.40507@txmail.marinocrane.com> <46437500.7080204@ecs.soton.ac.uk> <46437A26.7040901@txmail.marinocrane.com> Message-ID: <46437E17.5030309@txmail.marinocrane.com> Damon Lambooy wrote: > Scott Silva wrote: >> Julian Field spake the following on 5/10/2007 12:39 PM: >> >>> Damon Lambooy wrote: >>> >>>> I am tring to install Mailscanner 4.59.4-2 on Fedora 7 test 4 but >>>> getting strange error about rpms not being installed. >>>> >>>> [root@mailex MailScanner-4.59.4-2]# ./install.sh >>>> >>> >>>> Good. You have the patch command. >>>> >>>> Good, you have /usr/src/redhat in place. >>>> >>>> Good, unpackaged files will not break the build process. >>>> Good, far-too-clever Perl requirements will be ignored. >>>> >>>> Good, you appear to only have 1 copy of Perl installed. >>>> >>>> I think you are running on RedHat Linux, Mandriva Linux or SuSE Linux. >>>> You must have the following RPM packages installed before >>>> you try and do anything else: >>>> binutils glibc-devel egcs make >>>> You are missing at least 1 of these. >>>> Please install them all >>>> >>> Do you have gcc installed? >>> Fedora has probably just hit a problem caused by my being short-sighted >>> in the install.sh script. >>> >>> if [ -f /etc/redhat-release ] && fgrep -q ' 6.' /etc/redhat-release ; then >>> # RedHat used egcs in RedHat 6 and not gcc >>> GCC=egcs >>> fi >>> >>> So if it finds "6." in the redhat-release file then it won't look for >>> gcc, it will look for egcs. What exactly does your /etc/redhat-release >>> file say? If you can give me that I can work on the install.sh script >>> and produce a new version for you that will work. I can probably just >>> abandon the RedHat 6 test altogether now. Anyone still running it >>> deserves all they get :-) >>> Just delete those 4 lines. >>> >>> >>> Jules >>> >>> >> People should stop using RedHat 6. It has got to be almost 8 years old! >> >> > Yip, Thanks Jules. That did it. In /etc/redhat-release file says " Fedora release 6.93 (Rawhide)" and yes commenting out those lines worked for me. Thanks again. Damon -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070510/12862f31/attachment.html From mkettler at evi-inc.com Thu May 10 21:21:12 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Thu May 10 21:21:26 2007 Subject: Preferred Distribution In-Reply-To: References: <1E293D3FF63A3740B10AD5AAD88535D204E13733@UBIMAIL1.ubisoft.org> <46436364.40507@txmail.marinocrane.com> <46437500.7080204@ecs.soton.ac.uk> Message-ID: <46437EB8.4050004@evi-inc.com> Scott Silva wrote: > People should stop using RedHat 6. It has got to be almost 8 years old! Yeah, clearly they should be on 6.3 by now :) Quite frankly, I'd be surprised if modern MailScanner would even run on RedHat 6.x.. Those releases used perl 5.005. It might run, but a lot of add-ons won't. I know the mailscanner RPM claims it only needs >= 5.005, but I know SpamAssassin 3.0.0 and higher require perl 5.6 or higher. As of 3.46 HTML::Parser requires perl 5.6 or higher. From res at ausics.net Thu May 10 21:37:03 2007 From: res at ausics.net (Res) Date: Thu May 10 21:37:15 2007 Subject: Preferred Distribution In-Reply-To: References: Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Thu, 10 May 2007, --[ UxBoD ]-- wrote: > Hi, > > I am having to setup a couple of new mailservers where I am working on contract at the moment, using Dell SC1435 rack mounts. The problem is that RedHat ES4 kernel is so old does not recognise the SAS RAID card. > > Now my question is should I get them to purchase RHES5, or go for either CentOS or Fedora ? Thisa is so far off topic its a joke...but....on servers, Slackware. Packages are identical or close as identical to the real source releases. Easy to upgrade between distros with slapt-get (so much so you can skip many in-the-middle releases). Stable, doesnt put out a release every 3 months, but keeps current. Support, is several years (around 5+, which is the same for RHES) Never found a bit of hardware that it wont work with yet. 2 CD install of everything, not 5. If you want GUI... go use winblow$... But slackware does come with KDE if you are one of those types that just must have a GUI. - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGQ4JxsWhAmSIQh7MRAjSFAJ4rcvJD/tAwe2ve17i9zoyI9bMprQCfe5f/ KSImnFAVEyMkZxyvlb3VpPo= =DqoU -----END PGP SIGNATURE----- From res at ausics.net Thu May 10 21:45:25 2007 From: res at ausics.net (Res) Date: Thu May 10 21:45:35 2007 Subject: MailScanner w/ Qmail / Plesk ( format error: file is too short ) In-Reply-To: References: Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, Since Qmail is unsupported in MailScanner and Julian hates people discussing it more than he does those talikng about postmix I'll contact you off-list, this way you can send me a copy of your mailscanner.conf and so on, PLEASE NOTE the email you get will be from a sourceforge address as you can not reply directly to this one. On Thu, 10 May 2007, Cameron B. Prince wrote: > Hi Res, > >> Actually I mean your MailScanner temp working dir, like >> /var/spool/MailScanner >> >> chown -R qmailq.qmail /var/spool/MailScanner > > I checked and reset this. > >> the real qmail sources also set permissions diferent than what you have >> above, the queue dir is set 750 > > I went through both the queue and queue.in directories and reset the > permissions. > >> do you know what version of qmail plesk installs now days? as in what >> patches? I know it works on plesk from other comments I've had, but I'm >> unsure if those posters are members of this list, I suspectmaybe not? >> since none of them have commented. > > This is my first dealings with Qmail as I've historically only worked with > sendmail. Can you tell me how I can find the information to answer your > question? > >> Check perms on... >> >> chown qmailq.qmail /var/qmail/bin/qmail-queue >> chown root.qmail /var/qmail/bin/qmail-inject.mailscanner >> chmod 4755 /var/qmail/bin/qmail-queue >> chmod 755 /var/qmail/bin/qmail-inject.mailscanner > > I checked and reset these... More tests result in the same error. I tried > with an attachment also to make the message larger and it also produced the > same error. > >> I have not looked at that code in a while, I can have alook this evening >> though. > > Thank you, > > Cameron > > > - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGQ4RosWhAmSIQh7MRAiCAAKCrCIAG+5U4T8sW3/D5q6+vHBx0twCfUKA6 ZM/BFRkL2cD3BR1f9msXQHY= =Rxd1 -----END PGP SIGNATURE----- From alex at nkpanama.com Thu May 10 21:59:51 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Thu May 10 22:00:35 2007 Subject: Issue with Blackberry In-Reply-To: <3123E1B72B666243917E340F3C8FD4A1069754@privaldc2003.prival.local> References: <3123E1B72B666243917E340F3C8FD4A1069754@privaldc2003.prival.local> Message-ID: <464387C7.8020208@nkpanama.com> Gerhard Mourani wrote: > Hi Steve, > Allow IFrame Tags = > Allow Form Tags = > Allow Script Tags = > Allow WebBugs = > > All of the above should be set to yes for Blackberry to correctly > display mails. > Why? From hvdkooij at vanderkooij.org Thu May 10 22:15:10 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Thu May 10 22:15:40 2007 Subject: Preferred Distribution In-Reply-To: <46431AB1.3040803@linux-kernel.at> References: <46431AB1.3040803@linux-kernel.at> Message-ID: On Thu, 10 May 2007, Oliver Falk wrote: > On 05/10/2007 03:00 PM, --[ UxBoD ]-- wrote: >> I am having to setup a couple of new mailservers where >> I am working on contract at the moment, using Dell >> SC1435 rack mounts. >> The problem is that RedHat ES4 kernel is so old does >> not recognise the SAS RAID card. >> >> Now my question is should I get them to purchase >> RHES5, > > If you don't need support, there's no need for EL5. > >> or go for either CentOS or Fedora ? > > Both is fine. Fedora should recognize it AFAIK. I do not recommend Fedora in anything even resembling a production environment. I hate to install a system which will be out of security updates in about a year. If you just want the system go for Centos 5 and use RHEL 5 if they want to spend money on support. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From dave.list at pixelhammer.com Thu May 10 22:24:09 2007 From: dave.list at pixelhammer.com (DAve) Date: Thu May 10 22:25:14 2007 Subject: Issue with Blackberry In-Reply-To: <3123E1B72B666243917E340F3C8FD4A1069754@privaldc2003.prival.local> References: <3123E1B72B666243917E340F3C8FD4A1069754@privaldc2003.prival.local> Message-ID: <46438D79.8060107@pixelhammer.com> Gerhard Mourani wrote: > Hi Steve, > > Thanks for your help, yes I've fixed this part into the config and also > find other options responsible of this issue with Blackberry devices. > Bellow is the options part causing the problems. > > Allow IFrame Tags = > Allow Form Tags = > Allow Script Tags = > Allow WebBugs = > > All of the above should be set to yes for Blackberry to correctly > display mails. > > Gerhard Our Blackberry users report no problems, we do not allow webbugs. Allow WebBugs = disarm DAve -- Three years now I've asked Google why they don't have a logo change for Memorial Day. Why do they choose to do logos for other non-international holidays, but nothing for Veterans? Maybe they forgot who made that choice possible. From alex at nkpanama.com Thu May 10 22:31:11 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Thu May 10 22:31:54 2007 Subject: Issue with Blackberry In-Reply-To: <46438D79.8060107@pixelhammer.com> References: <3123E1B72B666243917E340F3C8FD4A1069754@privaldc2003.prival.local> <46438D79.8060107@pixelhammer.com> Message-ID: <46438F1F.3000904@nkpanama.com> DAve wrote: > Our Blackberry users report no problems, we do not allow webbugs. > Allow WebBugs = disarm In fact, our blackberry users appreciate when e-mails get html-stripped completely. From mbneto at gmail.com Thu May 10 22:34:56 2007 From: mbneto at gmail.com (mbneto) Date: Thu May 10 22:34:58 2007 Subject: Build only (from rpm.tar.gz) In-Reply-To: <4643737D.1090500@ecs.soton.ac.uk> References: <5cf776b80705100909t347d505co4c5776278daa559b@mail.gmail.com> <4643737D.1090500@ecs.soton.ac.uk> Message-ID: <5cf776b80705101434t570d9e51r9118faa4d853fdf3@mail.gmail.com> Thanks Julian, I was looking at /usr/src/redhat/RPMS/(i386|noarch) where the others rpms are generated. Probably there is a reason for this but as a suggestion consider putting the mailscanner.rpm there too. regards. On 5/10/07, Julian Field wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > It's there, you must be looking straight through it. > > MailScanner-4.59.4-2/mailscanner-4.59.4-2.noarch.rpm > in the rpm.tar.gz file. > > mbneto wrote: > > Hi, > > > > I've noticed that when I perform a ./install.sh it generates a lot of > > rpm files and later installs. I could not find, however, the rpm for > > the mailscanner itself only the perl, tnef etc. > > > > Since I need to maintain a number of servers that does not have gcc > > and other libraries I need to generate the complete set of rpm and add > > to my yum repository. > > > > Any idea of how to do that (or to find the mailscanner.rpm generated)? > > > > tks. > > > > > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: ISO-8859-1 > > wj8DBQFGQ3OuEfZZRxQVtlQRAiQjAJ0ZYBqUBxToowiZxdk3MUZ/QR/7wwCgpcMu > BWwU0ULq/aOZ3DDkLM6gIe0= > =NfMx > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070510/ca75d1c0/attachment.html From ka at pacific.net Thu May 10 23:03:22 2007 From: ka at pacific.net (Ken A) Date: Thu May 10 23:03:26 2007 Subject: Preferred Distribution In-Reply-To: References: <46431AB1.3040803@linux-kernel.at> Message-ID: <464396AA.5090005@pacific.net> Hugo van der Kooij wrote: > On Thu, 10 May 2007, Oliver Falk wrote: > >> On 05/10/2007 03:00 PM, --[ UxBoD ]-- wrote: >>> I am having to setup a couple of new mailservers where >>> I am working on contract at the moment, using Dell >>> SC1435 rack mounts. >>> The problem is that RedHat ES4 kernel is so old does >>> not recognise the SAS RAID card. >>> >>> Now my question is should I get them to purchase >>> RHES5, >> >> If you don't need support, there's no need for EL5. >> >>> or go for either CentOS or Fedora ? >> >> Both is fine. Fedora should recognize it AFAIK. > > I do not recommend Fedora in anything even resembling a production > environment. I hate to install a system which will be out of security > updates in about a year. > > If you just want the system go for Centos 5 and use RHEL 5 if they want > to spend money on support. > > Hugo. > FC works fine in production. Whether it's a good choice depends on what hardware/software support you want/need, what else the box is doing, how well you can lock it down, and of course who you have to please! Busy spam-stomping machines can have a short hardware life-cycle too. Next year's hardware will be faster. FC7 will have better virtualization support than Centos5 does. You might need that, you might not. It might be buggy. You might not want to deal with that, or you might think it's a challenge. Securing a bare bones MailScanner box doesn't require that your entire LAMP install and all binaries be up2date. Of course it's best to have a box completely patched, but if vulnerable items are not accessible, it's as good as patched, well almost... Some can't sleep with that. Some can. Your choice. -- Ken Anderson Pacific.Net From amaclach at yahoo.co.uk Thu May 10 23:36:50 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Thu May 10 23:36:52 2007 Subject: Preferred Distribution Message-ID: <668089.55548.qm@web26309.mail.ukl.yahoo.com> > People should stop using RedHat 6. It has got to be almost 8 years old! Doesn't stop people using NT4... That was 10 years old in November and just as flaky as ever except the hardware it's running on has now almost turned to dust. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From mkettler at evi-inc.com Fri May 11 00:39:06 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Fri May 11 00:39:19 2007 Subject: Preferred Distribution In-Reply-To: <668089.55548.qm@web26309.mail.ukl.yahoo.com> References: <668089.55548.qm@web26309.mail.ukl.yahoo.com> Message-ID: <4643AD1A.3020706@evi-inc.com> Andrew MacLachlan wrote: > Doesn't stop people using NT4... That was 10 years old in November and just as flaky as ever except the hardware it's running on has now almost turned to dust. Flaky is such a gentle way to put it.... :) From mikej at rogers.com Fri May 11 00:49:11 2007 From: mikej at rogers.com (Mike Jakubik) Date: Fri May 11 00:51:11 2007 Subject: Preferred Distribution In-Reply-To: References: Message-ID: <4643AF77.5040202@rogers.com> --[ UxBoD ]-- wrote: > Hi, > > I am having to setup a couple of new mailservers where I am working on contract at the moment, using Dell SC1435 rack mounts. The problem is that RedHat ES4 kernel is so old does not recognise the SAS RAID card. > > Now my question is should I get them to purchase RHES5, or go for either CentOS or Fedora ? > FreeBSD. From cplists at princeservices.com Fri May 11 06:12:44 2007 From: cplists at princeservices.com (Cameron B. Prince) Date: Fri May 11 06:12:53 2007 Subject: MailScanner w/ Qmail / Plesk ( format error: file is too short ) In-Reply-To: Message-ID: Hi Res, Just wanted to let you know that I did reply to your message off-list. Please let me know if my reply didn't make it to you. Thanks, Cameron On 5/10/07 3:45 PM, "Res" wrote: > Hi, > > Since Qmail is unsupported in MailScanner and Julian hates people > discussing it more than he does those talikng about postmix I'll contact > you off-list, this way you can send me a copy of your mailscanner.conf and > so on, PLEASE NOTE the email you get will be from a sourceforge address as > you can not reply directly to this one. > From res at ausics.net Fri May 11 06:39:42 2007 From: res at ausics.net (Res) Date: Fri May 11 06:39:52 2007 Subject: MailScanner w/ Qmail / Plesk ( format error: file is too short ) In-Reply-To: References: Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Fri, 11 May 2007, Cameron B. Prince wrote: > Hi Res, > > Just wanted to let you know that I did reply to your message off-list. > Please let me know if my reply didn't make it to you. Got it... Good thing about the sourceforge address is it bypasses RBL's, my rather anal access lists, and spamassassin, it needs to cause of the devel work I do, SA was forever high scoring a lot of the diffs :) - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGRAGgsWhAmSIQh7MRAsLEAJ9vj9lJEJirw+2t8bpqiXnPt6lnfQCcCsV5 VtPdJd/X3ttw6UXa5E2bhO8= =NZSY -----END PGP SIGNATURE----- From yadu at netmagicsolutions.com Fri May 11 07:34:25 2007 From: yadu at netmagicsolutions.com (Yadavendra Awasthi) Date: Fri May 11 07:34:36 2007 Subject: SMTP_AUTH and sender restriction based on local domain using Mailscanner Message-ID: <062c01c79396$6b6929a0$1c01010a@netdom.loc> Hi List, I have configured outgoing SMTP server with SMTP_AUTH on postfix. Is it possible to have user based restriction in Mailscanner such that limited authenticated users are allowed to relay mail outside and all authenticated users are allowed to send mails to local domain. Regards. Yadavendra Awasthi. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070511/30b5c794/attachment.html From tgc at statsbiblioteket.dk Fri May 11 08:09:43 2007 From: tgc at statsbiblioteket.dk (Tom G. Christensen) Date: Fri May 11 08:09:45 2007 Subject: Preferred Distribution In-Reply-To: References: Message-ID: <464416B7.6010008@statsbiblioteket.dk> --[ UxBoD ]-- wrote: > Hi, > > I am having to setup a couple of new mailservers where I am working > on contract at the moment, using Dell SC1435 rack mounts. The > problem is that RedHat ES4 kernel is so old does not recognise the > SAS RAID card. > Use the latest RHEL4 update (U5) instead of the first release. > Now my question is should I get them to purchase RHES5, or go for > either CentOS or Fedora ? > With a valid server subscription you can use any version of RHEL you like. They can all be downloaded from RHN. > Personally I would use Gentoo or Ubuntu, but they are really *not* > happy in using either of them for a corporate system :( > Smart people. -tgc From uxbod at splatnix.net Fri May 11 08:58:15 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Fri May 11 08:58:19 2007 Subject: Preferred Distribution In-Reply-To: <46437E17.5030309@txmail.marinocrane.com> References: <46437E17.5030309@txmail.marinocrane.com> Message-ID: I am going to explore the CentOS route. Mainly due to the fact that the service will be email on the server, and not a application server like Oracle. I do appreciate that we would get support with RH, but with such a strong community behind most of the distributions we would be getting that anyway ;) Thanks all for your input, and yes I was joking when I said Gentoo or Ubuntu. Unfortunately neither are really ready for enterprise use yet for different reasons. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From list-mailscanner at linguaphone.com Fri May 11 09:16:09 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Fri May 11 09:16:17 2007 Subject: Preferred Distribution In-Reply-To: <46437EB8.4050004@evi-inc.com> References: <1E293D3FF63A3740B10AD5AAD88535D204E13733@UBIMAIL1.ubisoft.org> <46436364.40507@txmail.marinocrane.com> <46437500.7080204@ecs.soton.ac.uk> <46437EB8.4050004@evi-inc.com> Message-ID: <1178871369.6218.4.camel@gblades-suse.linguaphone-intranet.co.uk> On Thu, 2007-05-10 at 21:21, Matt Kettler wrote: > Scott Silva wrote: > > People should stop using RedHat 6. It has got to be almost 8 years old! > > Yeah, clearly they should be on 6.3 by now :) > > Quite frankly, I'd be surprised if modern MailScanner would even run on RedHat > 6.x.. Those releases used perl 5.005. It might run, but a lot of add-ons won't. > > I know the mailscanner RPM claims it only needs >= 5.005, but I know > SpamAssassin 3.0.0 and higher require perl 5.6 or higher. > > As of 3.46 HTML::Parser requires perl 5.6 or higher. I am still using Redhat 9 on my home server. I am running Spamassassin 3.18 fine with Pyzor, Razor, FuzzyOCR etc... I upgraded Perl to 5.8 and then reinstalled all the modules. I think one program failed to run afterwards but I just edited the per to make it point to the old perl. I had problems getting a couple of modules to install so I think SPF checks are currently not operational but thats it. From evanderleun at hal9000.nl Fri May 11 09:42:06 2007 From: evanderleun at hal9000.nl (Erik van der Leun) Date: Fri May 11 09:42:15 2007 Subject: Preferred Distribution In-Reply-To: References: Message-ID: <46442C5E.5010003@hal9000.nl> --[ UxBoD ]-- wrote: > Hi, > > I am having to setup a couple of new mailservers where I am working on contract at the moment, using Dell SC1435 rack mounts. The problem is that RedHat ES4 kernel is so old does not recognise the SAS RAID card. > > Now my question is should I get them to purchase RHES5, or go for either CentOS or Fedora ? > > Personally I would use Gentoo or Ubuntu, but they are really *not* happy in using either of them for a corporate system :( > I'm quite happy with my choice for Gentoo Linux really... I use the MailScanner tarball and handle the rest gentoo-wise. I haven't seen much gentoo users on this mailinglist yet though :-) -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070511/ea703ed2/attachment.html From amaclach at yahoo.co.uk Fri May 11 09:44:41 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Fri May 11 09:44:44 2007 Subject: Preferred Distribution Message-ID: <267957.74168.qm@web26313.mail.ukl.yahoo.com> I've got MailScanner working with postfix 2.4 and SA 3.2.0 on a virtualised Babbage Analytical Engine (I was having trouble getting parts for the original hardware)... ----- Original Message ---- From: Gareth To: MailScanner discussion Sent: Friday, 11 May, 2007 9:16:09 AM Subject: Re: Preferred Distribution On Thu, 2007-05-10 at 21:21, Matt Kettler wrote: > Scott Silva wrote: > > People should stop using RedHat 6. It has got to be almost 8 years old! > > Yeah, clearly they should be on 6.3 by now :) > > Quite frankly, I'd be surprised if modern MailScanner would even run on RedHat > 6.x.. Those releases used perl 5.005. It might run, but a lot of add-ons won't. > > I know the mailscanner RPM claims it only needs >= 5.005, but I know > SpamAssassin 3.0.0 and higher require perl 5.6 or higher. > > As of 3.46 HTML::Parser requires perl 5.6 or higher. I am still using Redhat 9 on my home server. I am running Spamassassin 3.18 fine with Pyzor, Razor, FuzzyOCR etc... I upgraded Perl to 5.8 and then reinstalled all the modules. I think one program failed to run afterwards but I just edited the per to make it point to the old perl. I had problems getting a couple of modules to install so I think SPF checks are currently not operational but thats it. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From glenn.steen at gmail.com Fri May 11 09:46:29 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri May 11 09:46:32 2007 Subject: Issue with Blackberry In-Reply-To: <46438F1F.3000904@nkpanama.com> References: <3123E1B72B666243917E340F3C8FD4A1069754@privaldc2003.prival.local> <46438D79.8060107@pixelhammer.com> <46438F1F.3000904@nkpanama.com> Message-ID: <223f97700705110146k2397cd41n1f6d5d1f66fff994@mail.gmail.com> On 10/05/07, Alex Neuman van der Hans wrote: > DAve wrote: > > Our Blackberry users report no problems, we do not allow webbugs. > > Allow WebBugs = disarm > In fact, our blackberry users appreciate when e-mails get html-stripped > completely. Yes.... I suspect Gerhad should perhaps look long and hard at his blackberry server, since that is the one responsible for formatting... We've seen some discrepancies with mail that is locally generated (hence never passes through MailScanner) that kind of looks like what he describes. Or perhaps it might be the simple fact that MS "edits" messages with forms and such, resulting in some kind of EOL or character set problems, which might confuse the blackberry server (if he indeed has one and is running Ent ed.). Cheers (well, that was yesterday... Testing Single Malts (all Ila)...:-) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From prandal at herefordshire.gov.uk Fri May 11 09:48:01 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Fri May 11 09:48:10 2007 Subject: Preferred Distribution In-Reply-To: <46431C32.4030404@enitech.com.au> References: <46431C32.4030404@enitech.com.au> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBAB2507E@HC-MBX02.herefordshire.gov.uk> I'd use CentOS 5 , not 4, if you're planning to use FuzzyOcr. netpbm is way too old on CentOS /RHEL 4, and you have to mess about with FuzzyOcr's scansets to get it to work properly. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Pete Russell > Sent: 10 May 2007 14:21 > To: MailScanner discussion > Subject: Re: Preferred Distribution > > Fedora? They do not have support lifecycle suitable for corporate > clients (espe ones using external linux skills), IMO. > > CentOS is the logical choice. Hassle free, you know > mailscanner is going > to work nicely on it - its RHAS... > > > > --[ UxBoD ]-- wrote: > > Hi, > > > > I am having to setup a couple of new mailservers where I am > working on contract at the moment, using Dell SC1435 rack > mounts. The problem is that RedHat ES4 kernel is so old does > not recognise the SAS RAID card. > > > > Now my question is should I get them to purchase RHES5, or > go for either CentOS or Fedora ? > > > > Personally I would use Gentoo or Ubuntu, but they are > really *not* happy in using either of them for a corporate system :( > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From prandal at herefordshire.gov.uk Fri May 11 09:54:13 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Fri May 11 09:54:20 2007 Subject: Preferred Distribution In-Reply-To: <1E293D3FF63A3740B10AD5AAD88535D204E13733@UBIMAIL1.ubisoft.org> References: <1E293D3FF63A3740B10AD5AAD88535D204E13733@UBIMAIL1.ubisoft.org> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBAB25080@HC-MBX02.herefordshire.gov.uk> You can use yum to update CentOS in an analogous manner to RHEL's old up2date. The rpmforge yum repository has re2c, needed for sa-compile with SA 3.2.0. CentOS 5 with protectbase plugin for yum plus the rpmforge repository and Jules' handy installers should mean not having to go to CPAN for anything (though there may be some FuzzOCR dependencies still needing the manual use of CPAN - I've yet to check). Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Daniel Maher > Sent: 10 May 2007 14:18 > To: MailScanner discussion > Subject: RE: Preferred Distribution > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- > > Sent: May 10, 2007 9:01 AM > > To: mailscanner@lists.mailscanner.info > > Subject: Preferred Distribution > > > > Hi, > > > > I am having to setup a couple of new mailservers where I am > working on > > contract at the moment, using Dell SC1435 rack mounts. The > problem is > > that RedHat ES4 kernel is so old does not recognise the SAS > RAID card. > > > > Now my question is should I get them to purchase RHES5, or > go for either > > CentOS or Fedora ? > > > > Personally I would use Gentoo or Ubuntu, but they are > really *not* happy > > in using either of them for a corporate system :( > > At my (reasonably large multi-national) company, we've > started using CentOS for all of our new machines, and will > likely continue to do so. We don't need RedHat's telephone > support, nor do we care to use up2date, ergo the benefits of > using RedHat over CentOS are almost non-existent. > > YMMV, of course - especially if you're at a smaller > organisation where phone support might come in handy, or > where you don't manage your own software repository. > > 0.02$ > > > -- > _ > ?v? Daniel Maher > /(_)\ Administrateur Syst?me Unix > ^ ^ Unix System Administrator > > "The most incomprehensible thing about the world is that it > is comprehensible." -- Albert Einstein. > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From john at tradoc.fr Fri May 11 10:01:13 2007 From: john at tradoc.fr (John Wilcock) Date: Fri May 11 10:01:23 2007 Subject: Preferred Distribution In-Reply-To: <46442C5E.5010003@hal9000.nl> References: <46442C5E.5010003@hal9000.nl> Message-ID: <464430D9.8090706@tradoc.fr> Erik van der Leun wrote: > I'm quite happy with my choice for > Gentoo Linux really... > > I use the MailScanner tarball and handle the rest gentoo-wise. > > I haven't seen much gentoo users on this mailinglist yet though :-) I've recently switched from Redhat to Gentoo at the suggestion of my favourite hosting company - I leased a test server for a month and never looked back. The build-everything-from-source philosophy appeals to me... On my production server I'm currently using the slightly-outdated version of MailScanner (4.57.6.1) in the sunrise overlay, and I'm intending to experiment with generating an updated ebuild soon on a spare server. John. -- -- Over 3000 webcams from ski resorts around the world - www.snoweye.com -- Translate your technical documents and web pages - www.tradoc.fr From uxbod at splatnix.net Fri May 11 10:14:40 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Fri May 11 10:14:43 2007 Subject: Preferred Distribution In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBAB2507E@HC-MBX02.herefordshire.gov.uk> References: <7EF0EE5CB3B263488C8C18823239BEBAB2507E@HC-MBX02.herefordshire.gov.uk> Message-ID: <1e0f1a74ad87496db2babcfbd1b8271e@62.49.223.244> To be honest, even on a RHES4 server I recently built, I did not rely on any of the installed packages, and built the whole system including perl etc directly from source. This meant I knew exactly what perl modules and software were in use. Plus, was able to stream line a lot of the packages ie. perl and PHP. On Fri, 11 May 2007 09:48:01 +0100, "Randal, Phil" wrote: > I'd use CentOS 5 , not 4, if you're planning to use FuzzyOcr. > > netpbm is way too old on CentOS /RHEL 4, and you have to mess about with > FuzzyOcr's scansets to get it to work properly. > > Cheers, > > Phil > > -- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf >> Of Pete Russell >> Sent: 10 May 2007 14:21 >> To: MailScanner discussion >> Subject: Re: Preferred Distribution >> >> Fedora? They do not have support lifecycle suitable for corporate >> clients (espe ones using external linux skills), IMO. >> >> CentOS is the logical choice. Hassle free, you know >> mailscanner is going >> to work nicely on it - its RHAS... >> >> >> >> --[ UxBoD ]-- wrote: >> > Hi, >> > >> > I am having to setup a couple of new mailservers where I am >> working on contract at the moment, using Dell SC1435 rack >> mounts. The problem is that RedHat ES4 kernel is so old does >> not recognise the SAS RAID card. >> > >> > Now my question is should I get them to purchase RHES5, or >> go for either CentOS or Fedora ? >> > >> > Personally I would use Gentoo or Ubuntu, but they are >> really *not* happy in using either of them for a corporate system :( >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Fri May 11 10:16:10 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Fri May 11 10:16:37 2007 Subject: Preferred Distribution In-Reply-To: <464430D9.8090706@tradoc.fr> References: <464430D9.8090706@tradoc.fr> Message-ID: <8656512431664886eb008e7f17b5eaed@62.49.223.244> My home workstation and server are all on Gentoo. I love meta-distributions as they are extremely light, especially for a server. Though as somebody else said on here, if you had 100s of servers to manage it could be quite difficult pushing the package changes out. On Fri, 11 May 2007 11:01:13 +0200, John Wilcock wrote: > Erik van der Leun wrote: >> I'm quite happy with my choice for >> Gentoo Linux really... >> >> I use the MailScanner tarball and handle the rest gentoo-wise. >> >> I haven't seen much gentoo users on this mailinglist yet though :-) > > I've recently switched from Redhat to Gentoo at the suggestion of my > favourite hosting company - I leased a test server for a month and never > looked back. The build-everything-from-source philosophy appeals to me... > > On my production server I'm currently using the slightly-outdated > version of MailScanner (4.57.6.1) in the sunrise overlay, and I'm > intending to experiment with generating an updated ebuild soon on a > spare server. > > John. > > -- > -- Over 3000 webcams from ski resorts around the world - www.snoweye.com > -- Translate your technical documents and web pages - www.tradoc.fr > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From jan-peter at koopmann.eu Fri May 11 11:27:38 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Fri May 11 11:27:50 2007 Subject: Preferred Distribution In-Reply-To: <4643AF77.5040202@rogers.com> References: <4643AF77.5040202@rogers.com> Message-ID: On Friday, May 11, 2007 1:49 AM Mike Jakubik wrote: > FreeBSD. I did not dare to throw that one in but naturally I second that opinion! Regards, JP From glenn.steen at gmail.com Fri May 11 12:14:11 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri May 11 12:14:14 2007 Subject: Build only (from rpm.tar.gz) In-Reply-To: <5cf776b80705101434t570d9e51r9118faa4d853fdf3@mail.gmail.com> References: <5cf776b80705100909t347d505co4c5776278daa559b@mail.gmail.com> <4643737D.1090500@ecs.soton.ac.uk> <5cf776b80705101434t570d9e51r9118faa4d853fdf3@mail.gmail.com> Message-ID: <223f97700705110414n180e74f6ia3dff7d172db06b5@mail.gmail.com> On 10/05/07, mbneto wrote: > Thanks Julian, > > I was looking at /usr/src/redhat/RPMS/(i386|noarch) where > the others rpms are generated. > > Probably there is a reason for this but as a suggestion consider putting the > mailscanner.rpm there too. > > regards. Keyword here is that the other rpms are _generated_ on your system (the RPMs are rebuilt). This is why they are in the /usr/src/RPM tree. Since the MailScanner RPM isn't rebuilt, it doesn't end up in that place, and it shouldn't... So there really is nothing to do here, for Jules. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From ugob at lubik.ca Fri May 11 12:14:49 2007 From: ugob at lubik.ca (Ugo Bellavance) Date: Fri May 11 12:14:33 2007 Subject: MCP Message-ID: Hi, I'm thinking about implementing MCP on my servers, but I have a few questions: 1- I know it runs a second copy of SpamAssassin... but what kind of load does it add to the system? 2- Is there still an issue regarding no-spam-scanning and MCP like in http://permalink.gmane.org/gmane.mail.virus.mailscanner/48773 3- Is the bug related to sa-update fixed (see http://thread.gmane.org/gmane.mail.virus.mailscanner/46722)? Regards, Ugo From gmourani at prival.ca Fri May 11 15:02:19 2007 From: gmourani at prival.ca (Gerhard Mourani) Date: Fri May 11 15:02:43 2007 Subject: Issue with Blackberry In-Reply-To: <223f97700705110146k2397cd41n1f6d5d1f66fff994@mail.gmail.com> Message-ID: <3123E1B72B666243917E340F3C8FD4A106977D@privaldc2003.prival.local> I don't have any control on this blackberry server and I don't think my client use their own blackberry server but just receive from around the word through blackberry network. Also I know that they updated all blackberry devices to the latest one available from the company and without saying 'yes' to the option as posted before, then lot users call and complain about problem not being able to read their email on Blackberry. This doesn't happen on Outlook for example when they receive from Blackberry network and again just on the Blackberry device itself. Gerhard, -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Glenn Steen Sent: Friday, May 11, 2007 4:46 AM To: MailScanner discussion Subject: Re: Issue with Blackberry On 10/05/07, Alex Neuman van der Hans wrote: > DAve wrote: > > Our Blackberry users report no problems, we do not allow webbugs. > > Allow WebBugs = disarm > In fact, our blackberry users appreciate when e-mails get html-stripped > completely. Yes.... I suspect Gerhad should perhaps look long and hard at his blackberry server, since that is the one responsible for formatting... We've seen some discrepancies with mail that is locally generated (hence never passes through MailScanner) that kind of looks like what he describes. Or perhaps it might be the simple fact that MS "edits" messages with forms and such, resulting in some kind of EOL or character set problems, which might confuse the blackberry server (if he indeed has one and is running Ent ed.). Cheers (well, that was yesterday... Testing Single Malts (all Ila)...:-) -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From claude.gagne at multitech.qc.ca Fri May 11 15:24:02 2007 From: claude.gagne at multitech.qc.ca (=?ISO-8859-1?Q?Claude_Gagn=E9?=) Date: Fri May 11 15:22:34 2007 Subject: init.d script Message-ID: <46447C82.90006@multitech.qc.ca> Hi, I use the tarball installation of the lastest MailScanner on Ubuntu Server but I can't find the /etc/init.d script that everybody seems to have. I have searched on the wiki and MS web site but I can't find it. Any can tell me where can I get it ? Thanks. Claude From mkercher at nfsmith.com Fri May 11 15:33:15 2007 From: mkercher at nfsmith.com (Mike Kercher) Date: Fri May 11 15:37:08 2007 Subject: SMTP_AUTH and sender restriction based on local domain usingMailscanner References: <062c01c79396$6b6929a0$1c01010a@netdom.loc> Message-ID: <6DEF8ABC1767C045B91F42066D36358E920C@HOUPEX01.nfsmith.info> I wouldn't think so since MailScanner doesn't touch the SMTP transactions. -Mike ________________________________ From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Yadavendra Awasthi Sent: Friday, May 11, 2007 1:34 AM To: mailscanner@lists.mailscanner.info Subject: SMTP_AUTH and sender restriction based on local domain usingMailscanner Hi List, I have configured outgoing SMTP server with SMTP_AUTH on postfix. Is it possible to have user based restriction in Mailscanner such that limited authenticated users are allowed to relay mail outside and all authenticated users are allowed to send mails to local domain. Regards. Yadavendra Awasthi. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070511/24e38dd1/attachment.html From res at ausics.net Fri May 11 15:46:56 2007 From: res at ausics.net (Res) Date: Fri May 11 15:47:06 2007 Subject: init.d script In-Reply-To: <46447C82.90006@multitech.qc.ca> References: <46447C82.90006@multitech.qc.ca> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 This is for RPM versions, tarball install everything under /opt We don't really need it :) On Fri, 11 May 2007, Claude Gagn? wrote: > Hi, > > I use the tarball installation of the lastest MailScanner on Ubuntu Server > but I can't find the /etc/init.d script that everybody seems to have. I have > searched on the wiki and MS web site but I can't find it. > > Any can tell me where can I get it ? > > Thanks. > > Claude > - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGRIHjsWhAmSIQh7MRAgsYAJ9y88a7iWSzKTcG2uRVl1m9Fx3VZwCcC3/E 7jLaKHO0eGTLI1UYI9w40d4= =DvZt -----END PGP SIGNATURE----- From claude.gagne at multitech.qc.ca Fri May 11 16:33:17 2007 From: claude.gagne at multitech.qc.ca (=?ISO-8859-1?Q?Claude_Gagn=E9?=) Date: Fri May 11 16:31:49 2007 Subject: init.d script In-Reply-To: References: <46447C82.90006@multitech.qc.ca> Message-ID: <46448CBD.4040609@multitech.qc.ca> Res a ?crit : > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > This is for RPM versions, tarball install everything under /opt > > We don't really need it :) > > On Fri, 11 May 2007, Claude Gagn? wrote: > >> Hi, >> >> I use the tarball installation of the lastest MailScanner on Ubuntu >> Server but I can't find the /etc/init.d script that everybody seems >> to have. I have searched on the wiki and MS web site but I can't find >> it. >> >> Any can tell me where can I get it ? >> >> Thanks. >> >> Claude >> > > - -- > Cheers > Res > > Vote for your favourite MTA at http://polls.ausics.net/v3.php > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.6 (GNU/Linux) > > iD8DBQFGRIHjsWhAmSIQh7MRAgsYAJ9y88a7iWSzKTcG2uRVl1m9Fx3VZwCcC3/E > 7jLaKHO0eGTLI1UYI9w40d4= > =DvZt > -----END PGP SIGNATURE----- It can be usefull to reload configuration without killing all MailScanner process and restart. Or is it other ways to do it ? Thanks for your help :) Claude From ka at pacific.net Fri May 11 16:34:54 2007 From: ka at pacific.net (Ken A) Date: Fri May 11 16:34:58 2007 Subject: Preferred Distribution In-Reply-To: <267957.74168.qm@web26313.mail.ukl.yahoo.com> References: <267957.74168.qm@web26313.mail.ukl.yahoo.com> Message-ID: <46448D1E.3010702@pacific.net> Andrew MacLachlan wrote: > I've got MailScanner working with postfix 2.4 and SA 3.2.0 on a virtualised Babbage Analytical Engine (I was having trouble getting parts for the original hardware)... too lazy to turn the crank, huh? figures you are a postfix user! ;-) Ken > > ----- Original Message ---- > From: Gareth > To: MailScanner discussion > Sent: Friday, 11 May, 2007 9:16:09 AM > Subject: Re: Preferred Distribution > > On Thu, 2007-05-10 at 21:21, Matt Kettler wrote: >> Scott Silva wrote: >>> People should stop using RedHat 6. It has got to be almost 8 years old! >> Yeah, clearly they should be on 6.3 by now :) >> >> Quite frankly, I'd be surprised if modern MailScanner would even run on RedHat >> 6.x.. Those releases used perl 5.005. It might run, but a lot of add-ons won't. >> >> I know the mailscanner RPM claims it only needs >= 5.005, but I know >> SpamAssassin 3.0.0 and higher require perl 5.6 or higher. >> >> As of 3.46 HTML::Parser requires perl 5.6 or higher. > > I am still using Redhat 9 on my home server. I am running Spamassassin > 3.18 fine with Pyzor, Razor, FuzzyOCR etc... > > I upgraded Perl to 5.8 and then reinstalled all the modules. > I think one program failed to run afterwards but I just edited the per > to make it point to the old perl. > I had problems getting a couple of modules to install so I think SPF > checks are currently not operational but thats it. > -- Ken Anderson Pacific.Net From gmourani at prival.ca Fri May 11 16:36:59 2007 From: gmourani at prival.ca (Gerhard Mourani) Date: Fri May 11 16:37:45 2007 Subject: init.d script In-Reply-To: <46448CBD.4040609@multitech.qc.ca> Message-ID: <3123E1B72B666243917E340F3C8FD4A1069786@privaldc2003.prival.local> Claude, That's the one I use, it's not perfect but a good starting point. #!/bin/bash # # Modified for OpenNA Linux by Gerhard Mourani # This shell script takes care of starting and stopping MailScanner. # # chkconfig: 345 80 30 # description: MailScanner is an open-source E-Mail Gateway Virus Scanner. # processname: MailScanner # config: /etc/MailScanner/MailScanner.conf # pidfile: /var/run/MailScanner.pid # Source function library. . /etc/init.d/functions # Source networking configuration. . /etc/sysconfig/network # Check that networking is up. [ ${NETWORKING} = "no" ] && exit 0 [ -f /usr/sbin/check_MailScanner ] || exit 0 RETVAL=0 prog="mailscanner" start() { echo -n "Starting $prog: " /usr/sbin/check_MailScanner >/dev/null RETVAL=$? [ $RETVAL -eq 0 ] && touch /var/lock/subsys/MailScanner [ $RETVAL -eq 0 ] && rm -f /var/lock/subsys/MailScanner.off echo return $RETVAL } stop() { echo -n "Shutting down $prog: " killproc MailScanner -15 RETVAL=$? [ $RETVAL -eq 0 ] && rm -f /var/lock/subsys/MailScanner [ $RETVAL -eq 0 ] && touch /var/lock/subsys/MailScanner.off rm -f /var/run/MailScanner.pid echo return $RETVAL } restart() { stop start } reload() { pid=`pidofproc MailScanner` if [ -z "$pid" ] ; then failure else /bin/kill -HUP -- -$pid success fi echo } # See how we were called. case "$1" in start) start ;; stop) stop ;; restart) restart ;; reload) reload ;; *) echo $"Usage: $0 {start|stop|restart|reload}" exit 1 esac exit $RETVAL Gerhard, -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Claude Gagn? Sent: Friday, May 11, 2007 11:33 AM To: MailScanner discussion Subject: Re: init.d script Res a ?crit : > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > This is for RPM versions, tarball install everything under /opt > > We don't really need it :) > > On Fri, 11 May 2007, Claude Gagn? wrote: > >> Hi, >> >> I use the tarball installation of the lastest MailScanner on Ubuntu >> Server but I can't find the /etc/init.d script that everybody seems >> to have. I have searched on the wiki and MS web site but I can't find >> it. >> >> Any can tell me where can I get it ? >> >> Thanks. >> >> Claude >> > > - -- > Cheers > Res > > Vote for your favourite MTA at http://polls.ausics.net/v3.php > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.6 (GNU/Linux) > > iD8DBQFGRIHjsWhAmSIQh7MRAgsYAJ9y88a7iWSzKTcG2uRVl1m9Fx3VZwCcC3/E > 7jLaKHO0eGTLI1UYI9w40d4= > =DvZt > -----END PGP SIGNATURE----- It can be usefull to reload configuration without killing all MailScanner process and restart. Or is it other ways to do it ? Thanks for your help :) Claude -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From Jason at SYO.Com Fri May 11 17:22:21 2007 From: Jason at SYO.Com (Jason Gottschalk) Date: Fri May 11 17:22:41 2007 Subject: Approve/Deny outgoing e-mail ? In-Reply-To: <464372AA.2090906@ecs.soton.ac.uk> References: <1503721294.20070510094401@SYO.Com> <464372AA.2090906@ecs.soton.ac.uk> Message-ID: <948967026.20070511122221@SYO.Com> Hello Julian, Is /var/spool/mqueue.approval a file or directory? If it is a file, will mailscanner create it if it is not there? just by my having created a rulset? and where would I define the ruleset? Please pardon my questions, but I typically just edit the archive.rules file and I only just get by doing that! Thursday, May 10, 2007, 3:29:46 PM, you wrote: Julian> -----BEGIN PGP SIGNED MESSAGE----- Julian> Hash: SHA1 Julian> You could do this with a little ruleset and an external script that Julian> would show the admin each mail message and move it into the outgoing Julian> queue if it's 'approved'. Julian> Just use a ruleset that says that mail going to domains other than your Julian> own should go into /var/spool/mqueue.approval. Mail going to your domain Julian> goes straight into /var/spool/mqueue. Julian> The script would then show the messages in mqueue.approval to the admin, Julian> then if they are approved they are moved into mqueue (from where the MTA Julian> will then deliver them). Julian> Jason Gottschalk wrote: >> I know mailscanner can scan outgoing mail (when the user uses the host >> as his smtp server). Is there any mechanism in mailscanner to hold an >> outgoing message until it is reviewed by an administrator who would >> approve/deny the message and then release it? >> >> >> >> Julian> Jules Julian> - -- Julian> Julian Field MEng CITP Julian> www.MailScanner.info Julian> Buy the MailScanner book at www.MailScanner.info/store Julian> MailScanner customisation, or any advanced system administration help? Julian> Contact me at Jules@Jules.FM Julian> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 Julian> For all your IT requirements visit www.transtec.co.uk Julian> -----BEGIN PGP SIGNATURE----- Julian> Version: PGP Desktop 9.6.1 (Build 1012) Julian> Charset: ISO-8859-1 Julian> wj8DBQFGQ3OsEfZZRxQVtlQRAhWgAKDRMCFbCSWzncvbV1zsHnoxFN/cGQCdEyVp Julian> IUyhZgOVoITi/cvvX6l7zTw= Julian> =JBJd Julian> -----END PGP SIGNATURE----- Julian> -- Julian> This message has been scanned for viruses and Julian> dangerous content by MailScanner, and is Julian> believed to be clean. Julian> For all your IT requirements visit www.transtec.co.uk -- Best regards, Jason Gottschalk mailto:Jason@SYO.Com SYO Computer Engineering Services, Inc. 586-286-2557 From seanos at seanos.net Fri May 11 17:31:21 2007 From: seanos at seanos.net (=?utf-8?B?U2XDoW4gTyBTdWxsaXZhbg==?=) Date: Fri May 11 17:31:31 2007 Subject: MailWatch - new release Message-ID: <41236.160.6.1.47.1178901081.squirrel@webmail.seanos.net> Since I know a lot here use Mailwatch, new release out. 1.04 released today. Looks like bug/security fixes mainly. Regards, Sean From res at ausics.net Fri May 11 18:31:31 2007 From: res at ausics.net (Res) Date: Fri May 11 18:31:41 2007 Subject: init.d script In-Reply-To: <46448CBD.4040609@multitech.qc.ca> References: <46447C82.90006@multitech.qc.ca> <46448CBD.4040609@multitech.qc.ca> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Fri, 11 May 2007, Claude Gagn? wrote: > It can be usefull to reload configuration without killing all MailScanner > process and restart. Or is it other ways to do it ? killall -HUP MailScanner if you can edit your startup for your MTA add this is a reload segment or similar. - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGRKh1sWhAmSIQh7MRAseBAKCmP15DLYxIKHz5Cn4FjlcIXu9MzwCgie7N saFSd0KR0MTSkJmJ5R7SXnE= =SkYj -----END PGP SIGNATURE----- From ugob at lubik.ca Fri May 11 20:18:50 2007 From: ugob at lubik.ca (Ugo Bellavance) Date: Fri May 11 20:19:15 2007 Subject: MCP (test...) Message-ID: Hi, I sent a post earlier regarding MCP. I can see it in the archive, but not in gmane... il there a problem between gmane and the list servers? ugo From MailScanner at ecs.soton.ac.uk Fri May 11 20:40:00 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri May 11 20:43:37 2007 Subject: Approve/Deny outgoing e-mail ? In-Reply-To: <948967026.20070511122221@SYO.Com> References: <1503721294.20070510094401@SYO.Com> <464372AA.2090906@ecs.soton.ac.uk> <948967026.20070511122221@SYO.Com> Message-ID: <4644C690.6020907@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Jason Gottschalk wrote: > Hello Julian, > > Is /var/spool/mqueue.approval a file or directory? > In my example, it would be a directory. > If it is a file, will mailscanner create it if it is not there? just > by my having created a rulset? and where would I define the ruleset? > You will need to create it, or else MailScanner will whine about it. > Please pardon my questions, but I typically just edit the > archive.rules file and I only just get by doing that! > > > > Thursday, May 10, 2007, 3:29:46 PM, you wrote: > Julian> -----BEGIN PGP SIGNED MESSAGE----- > Julian> Hash: SHA1 > > Julian> You could do this with a little ruleset and an external script that > Julian> would show the admin each mail message and move it into the outgoing > Julian> queue if it's 'approved'. > Julian> Just use a ruleset that says that mail going to domains other than your > Julian> own should go into /var/spool/mqueue.approval. Mail going to your domain > Julian> goes straight into /var/spool/mqueue. > > Julian> The script would then show the messages in mqueue.approval to the admin, > Julian> then if they are approved they are moved into mqueue (from where the MTA > Julian> will then deliver them). > > Julian> Jason Gottschalk wrote: > >>> I know mailscanner can scan outgoing mail (when the user uses the host >>> as his smtp server). Is there any mechanism in mailscanner to hold an >>> outgoing message until it is reviewed by an administrator who would >>> approve/deny the message and then release it? >>> >>> >>> >>> >>> > > Julian> Jules > > Julian> - -- > Julian> Julian Field MEng CITP > Julian> www.MailScanner.info > Julian> Buy the MailScanner book at www.MailScanner.info/store > > Julian> MailScanner customisation, or any advanced system administration help? > Julian> Contact me at Jules@Jules.FM > > Julian> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > Julian> For all your IT requirements visit www.transtec.co.uk > > > > Julian> -----BEGIN PGP SIGNATURE----- > Julian> Version: PGP Desktop 9.6.1 (Build 1012) > Julian> Charset: ISO-8859-1 > > Julian> wj8DBQFGQ3OsEfZZRxQVtlQRAhWgAKDRMCFbCSWzncvbV1zsHnoxFN/cGQCdEyVp > Julian> IUyhZgOVoITi/cvvX6l7zTw= > Julian> =JBJd > Julian> -----END PGP SIGNATURE----- > > Julian> -- > Julian> This message has been scanned for viruses and > Julian> dangerous content by MailScanner, and is > Julian> believed to be clean. > Julian> For all your IT requirements visit www.transtec.co.uk > > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGRMdCEfZZRxQVtlQRAjE5AKCJoqGzmFpXj9gKMLLjDrHgaZMXMACeMGHE S7YY21Y2JTeSvY5I///f6Qg= =kkgS -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Fri May 11 20:44:35 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri May 11 20:48:42 2007 Subject: SMTP_AUTH and sender restriction based on local domain using Mailscanner In-Reply-To: <062c01c79396$6b6929a0$1c01010a@netdom.loc> References: <062c01c79396$6b6929a0$1c01010a@netdom.loc> Message-ID: <4644C7A3.1080909@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 That's the job of your MTA, it's not a MailScanner problem at all. Yadavendra Awasthi wrote: > Hi List, > > I have configured outgoing SMTP server with SMTP_AUTH on postfix. Is > it possible to have user based restriction in Mailscanner such that > limited authenticated users are allowed to relay mail outside and all > authenticated users are allowed to send mails to local domain. > > Regards. > Yadavendra Awasthi. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGRMhwEfZZRxQVtlQRApJ9AKDroqw8pu8FyfMtJQ1Jw4+pppE2XgCfV6Vc DSrLcq5n1GZ8inCwgmIdCOA= =CFAD -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Fri May 11 20:43:06 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri May 11 20:48:59 2007 Subject: Build only (from rpm.tar.gz) In-Reply-To: <5cf776b80705101434t570d9e51r9118faa4d853fdf3@mail.gmail.com> References: <5cf776b80705100909t347d505co4c5776278daa559b@mail.gmail.com> <4643737D.1090500@ecs.soton.ac.uk> <5cf776b80705101434t570d9e51r9118faa4d853fdf3@mail.gmail.com> Message-ID: <4644C74A.2050007@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 The other RPMs get put there as they are rebuilt by the install.sh. The MailScanner script doesn't get rebuilt from src.rpm, just installed, so there's no reason to put it there, it belongs just in the main tarball. It's not me that puts the other RPMs in /usr/src/redhat...., it is rpmbuild that puts them there. I personally wish it wouldn't, as the path varies between different distros. mbneto wrote: > Thanks Julian, > > I was looking at /usr/src/redhat/RPMS/(i386|noarch) where the others > rpms are generated. > > Probably there is a reason for this but as a suggestion consider > putting the mailscanner.rpm there too. > > regards. > > On 5/10/07, *Julian Field* > wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > It's there, you must be looking straight through it. > > MailScanner-4.59.4-2/mailscanner-4.59.4-2.noarch.rpm > in the rpm.tar.gz file. > > mbneto wrote: > > Hi, > > > > I've noticed that when I perform a ./install.sh it generates a > lot of > > rpm files and later installs. I could not find, however, the > rpm for > > the mailscanner itself only the perl, tnef etc. > > > > Since I need to maintain a number of servers that does not have gcc > > and other libraries I need to generate the complete set of rpm > and add > > to my yum repository. > > > > Any idea of how to do that (or to find the mailscanner.rpm > generated)? > > > > tks. > > > > > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: ISO-8859-1 > > wj8DBQFGQ3OuEfZZRxQVtlQRAiQjAJ0ZYBqUBxToowiZxdk3MUZ/QR/7wwCgpcMu > BWwU0ULq/aOZ3DDkLM6gIe0= > =NfMx > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGRMhuEfZZRxQVtlQRAoHlAKCnoYluAkno9/r2XnqTF74yQqmVQQCgj9h0 ldx3/hRT9tRhRG9ZF1XY42I= =Ky+/ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Fri May 11 20:49:05 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri May 11 20:51:54 2007 Subject: MCP In-Reply-To: References: Message-ID: <4644C8B1.5030000@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Ugo Bellavance wrote: > Hi, > > I'm thinking about implementing MCP on my servers, but I have a > few questions: > > 1- I know it runs a second copy of SpamAssassin... but what kind of > load does it add to the system? If Matt Hampton is reading this list at the moment, please can you send me your patches to reduce the SpamAssassin load caused by MCP? Matt cracked it for me, quite a long time ago, I just never got the patches off him for it. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGRMk4EfZZRxQVtlQRAuJ4AJ0T6CPq+WY9OWZze1MjvQym9mZbCgCeP7NY XoPtk3aGl166NHUC0Uu/DbE= =U62W -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From jnalley at fgp.com Fri May 11 21:29:21 2007 From: jnalley at fgp.com (Jonathan Nalley) Date: Fri May 11 21:29:44 2007 Subject: postfix dropping SMTP connection when receiving mail Message-ID: <4644D221.3050403@fgp.com> Hi, I'm running MailScanner 4.58.9-1 using postfix 2.3.3 on Centos 5. I've set our M$ Exchange Server 2007 to use our MailScanner/Postfix box as a "smart host" such that all outbound mail would be sent through the MailScanner/postfix box. The problem is that when the Exchange box is trying to pass along an e-mail to postfix, the connection and SMTP session gets dropped or something really bizarre is going on. Below is a snippet of /var/log/maillog (with postfix's debug_peer_level=1000). For the purposes of these pasted log files. 192.168.0.207 is the exchange box and 192.168.0.208 is the Postfix box. May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_hostname: exchange.myinternaldomain.com ~? 192.168.0.0/24 May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_hostaddr: 192.168.0.207 ~? 192.168.0.0/24 May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 220 mailscanner.myinternaldomain.com ESMTP Postfix May 11 09:40:23 mailscanner postfix/smtpd[18829]: watchdog_pat: 0x99266a0 May 11 09:40:23 mailscanner postfix/smtpd[18829]: vstream_fflush_some: fd 9 flush 83 May 11 09:40:23 mailscanner postfix/smtpd[18829]: vstream_buf_get_ready: fd 9 got 29 May 11 09:40:23 mailscanner postfix/smtpd[18829]: < exchange.myinternaldomain.com[192.168.0.207]: EHLO exchange.myinternaldomain.com May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-mailscanner.myinternaldomain.com May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-PIPELINING May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-SIZE 10240000 May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-VRFY May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-ETRN May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-AUTH LOGIN PLAIN May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_list_match: exchange.myinternaldomain.com: no match May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_list_match: 192.168.0.207: no match May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-AUTH=LOGIN PLAIN May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-ENHANCEDSTATUSCODES May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-8BITMIME May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250 DSN May 11 09:40:23 mailscanner postfix/smtpd[18829]: watchdog_pat: 0x99266a0 May 11 09:40:23 mailscanner postfix/smtpd[18829]: vstream_fflush_some: fd 9 flush 178 May 11 09:40:23 mailscanner postfix/smtpd[18829]: smtp_get: EOF May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_hostname: exchange.myinternaldomain.com ~? 192.168.0.0/24 May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_hostaddr: 192.168.0.207 ~? 192.168.0.0/24 May 11 09:40:23 mailscanner postfix/smtpd[18829]: lost connection after EHLO from exchange.myinternaldomain.com[192.168.0.207] May 11 09:40:23 mailscanner postfix/smtpd[18829]: disconnect from exchange.myinternaldomain.com[192.168.0.207] When enabling verbose session logging on the M$ Exchange box, below is the relevant SMTP session snippet: 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,0,,192.168.0.208:25,*,,attempting to connect 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,1,192.168.0.207:11256,192.168.0.208:25,+,, 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,2,192.168.0.207:11256,192.168.0.208:25,<,220 postfixbox.myinternaldomain.com ESMTP Postfix, 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,3,192.168.0.207:11256,192.168.0.208:25,>,EHLO exchange.myinternaldomain.com, 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,4,192.168.0.207:11256,192.168.0.208:25,<, 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,5,192.168.0.207:11256,192.168.0.208:25,-,,Local The second-to-last line actually has 65 spaces and then the closing comma but i couldn't get my mailer to display that in a desirable fashion. I know it's tempting to say or to think that the problem might be with the M$ Exchange box, but i can tell Exchange to use other Postfix/MailScanner installations (admittedly running MailScanner version 4.46.2-2 and postfix version 2.1.5) as the smart host and everything works smoothly. I've seen other posts in the mailing list with people having "smtp_get: EOF" in their logs and other similar entries but many were related to TLS, SSL, SASL and authentication and all that stuff but i'm not trying to do any of that here. Any thoughts, wisdom, insights, fixes, and solutions greatly appreciated. Thanks In Advance. Below is postconf -n: alias_database = hash:/etc/aliases alias_maps = hash:/etc/aliases broken_sasl_auth_clients = yes command_directory = /usr/sbin config_directory = /etc/postfix daemon_directory = /usr/libexec/postfix debug_peer_level = 1000 debug_peer_list = 192.168.0.207 header_checks = regexp:/etc/postfix/header_checks html_directory = no inet_interfaces = all mail_owner = postfix mailq_path = /usr/bin/mailq.postfix manpage_directory = /usr/share/man mydestination = localhost.$mydomain, localhost, $mydomain mydomain = myinternaldomain.com myhostname = mailscanner.myinternaldomain.com mynetworks = 192.168.0.0/24, 127.0.0.0/8 myorigin = $mydomain newaliases_path = /usr/bin/newaliases.postfix queue_directory = /var/spool/postfix readme_directory = /usr/share/doc/postfix-2.3.3/README_FILES relay_domains = $mydestination sample_directory = /usr/share/doc/postfix-2.3.3/samples sendmail_path = /usr/sbin/sendmail.postfix setgid_group = postdrop smtpd_banner = $myhostname ESMTP $mail_name smtpd_recipient_restrictions = permit_mynetworks permit_sasl_authenticated reject_unauth_destination smtpd_sasl_auth_enable = yes smtpd_sasl_path = smtpd transport_maps = hash:/etc/postfix/transport unknown_local_recipient_reject_code = 550 From res at ausics.net Fri May 11 23:55:45 2007 From: res at ausics.net (Res) Date: Fri May 11 23:55:55 2007 Subject: MCP (test...) In-Reply-To: References: Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Fri, 11 May 2007, Ugo Bellavance wrote: > Hi, > > I sent a post earlier regarding MCP. I can see it in the archive, > but not in gmane... il there a problem between gmane and the list servers? gmane is hopeless, mail is being delivered hours and hours later, SA 3-6 hour date in past scores are hitting anything that comes from them, we run a new mail-nntp gateways and use SA with that gw, we had to edit those scores here a week ago so it wouldnt interfere with it, but in past 2 days, posts from them to sourceforge lists are also now hitting this problem. gmane should be dumped, use the real list. - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGRPRzsWhAmSIQh7MRAh2LAJ4kH77BTnXNoJhEGiCHEuwSFdg9xQCfbH6b p2faSMBmR7RVs43gGtZlOD8= =AeD7 -----END PGP SIGNATURE----- From raywjohnson at gmail.com Sat May 12 02:55:40 2007 From: raywjohnson at gmail.com (RayJ) Date: Sat May 12 03:00:07 2007 Subject: SMPID vs. INPID References: <002101c78f49$651fdcc0$5a01a8c0@AldenLap> Message-ID: Alden Levy engineno9inc.com> writes: > > I had a problem a long time ago on my old server that never got solved; > unfortunately, it's reared it's ugly head on the new server (I had to copy > over a file from the old server), and I'd like to put it to bed for good. > > Basically, when I start MS, all works well, but when I check status, I get > an error > # service MailScanner status > Checking MailScanner daemons: > MailScanner: [ OK ] > incoming sendmail: [ FAIL ] > outgoing sendmail: [ OK ] > > However, it works fine as it is. In order to get rid of the fail, though, > I've been updating sendmail.in.pid with the proper pid, and everything > works. > --SNIP-- > Any help would be greatly appreciated. > > For the record, I am running MS 4.68.9-1 and SA 3.18 on CentOS 4.4. > > Thanks, > Alden > Hi Alden, Found this while looking for an answer to the same problem: This is what fix it! service MailScanner stop service sendmail stop <-- Important! Make sure no PIDs remain: ls -al /var/run MailScanner.pid sendmail.out.pid sendmail.pid <-- This one seemed to be the problem! sm-client.pid Not sure these had any effect, but tried anyway! chkconfig --del mailscanner chkconfig --del sendmail chkconfig --add sendmail chkconfig --add mailscanner service MailScanner start Hope that helps! --RayJ From hvdkooij at vanderkooij.org Sat May 12 09:00:32 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sat May 12 09:01:06 2007 Subject: SMPID vs. INPID In-Reply-To: References: <002101c78f49$651fdcc0$5a01a8c0@AldenLap> Message-ID: On Sat, 12 May 2007, RayJ wrote: > This is what fix it! > service MailScanner stop > service sendmail stop <-- Important! These are actions on the running services. If you do nothing they will start up again as configured after a reboot or even a change of init level. > Not sure these had any effect, but tried anyway! > chkconfig --del mailscanner > chkconfig --del sendmail > chkconfig --add sendmail > chkconfig --add mailscanner These do the other thing. They have an impact on wether or not services are started at certain runlevels. So, If one is to add MailScanner to Centos environment with sendmail support and sendmail is active (default Centos MTA) you would need to do: 1. Install MailScanner (and subsidaries) ((And make sure you configure it right but do not activae it now!)) 2. Stop sendmail `service sendmail stop` 3. Prevent sendmail from starting again `chkconfig sendmail off` 4. Activate MailScanner `service mailScanner start` 5. Make sure MailScanner starts at boot time `chkconfig MailScanner on` At your discretion you can replace sendmail with postfix if that happens to be the active MTA of your choice. For more details on runlevels, and the use of the service and chkconfig tools please consult the manual in a document repository near you. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From dhawal at netmagicsolutions.com Sat May 12 09:23:35 2007 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Sat May 12 09:23:51 2007 Subject: MCP (test...) In-Reply-To: References: Message-ID: <46457987.80705@netmagicsolutions.com> Ugo Bellavance wrote: > Hi, > > I sent a post earlier regarding MCP. I can see it in the archive, > but not in gmane... il there a problem between gmane and the list servers? i can see it in gmane.. see "Message-ID: " From smlists at shaw.ca Sat May 12 16:05:34 2007 From: smlists at shaw.ca (Steve Mason) Date: Sat May 12 16:05:42 2007 Subject: Preferred Distribution In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBAB2507E@HC-MBX02.herefordshire.gov.uk> Message-ID: <000e01c794a6$fdefed70$2924010a@SMC840> -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Randal, Phil Sent: Friday, May 11, 2007 2:48 AM To: MailScanner discussion Subject: RE: Preferred Distribution I'd use CentOS 5 , not 4, if you're planning to use FuzzyOcr. netpbm is way too old on CentOS /RHEL 4, and you have to mess about with FuzzyOcr's scansets to get it to work properly. -------------------- Yes, I just gave up trying to solve some dependencies with FuzzyOcr on Centos 4.4 and upgraded to Centos 5. FuzzyOcr dropped in with (almost)no problems. My head feels much better now that I stopped banging it... From root at doctor.nl2k.ab.ca Sat May 12 19:40:39 2007 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Sat May 12 19:45:21 2007 Subject: Message-ID Message-ID: <20070512184038.GC19693@doctor.nl2k.ab.ca> IS there a way of using Message-ID is identify Spam or Ham? -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From hvdkooij at vanderkooij.org Sat May 12 19:58:56 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sat May 12 19:59:37 2007 Subject: Message-ID In-Reply-To: <20070512184038.GC19693@doctor.nl2k.ab.ca> References: <20070512184038.GC19693@doctor.nl2k.ab.ca> Message-ID: On Sat, 12 May 2007, Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem wrote: > IS there a way of using Message-ID is identify Spam or Ham? The Message-ID is to uniquely identify that message. Think of it like as a social security number. Do you want to declare a person a cheat becuase you do not like his/her social security number? You can give some point to messages that do not set their own Message-ID. That is allready part of spamassassin for ages. Or are you trying to ask something completely differently? Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From root at doctor.nl2k.ab.ca Sat May 12 21:59:35 2007 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Sat May 12 22:04:22 2007 Subject: {Spam?} Re: Message-ID In-Reply-To: References: <20070512184038.GC19693@doctor.nl2k.ab.ca> Message-ID: <20070512205935.GA16507@doctor.nl2k.ab.ca> On Sat, May 12, 2007 at 08:58:56PM +0200, Hugo van der Kooij wrote: > On Sat, 12 May 2007, Dave Shariff Yadallee - System Administrator a.k.a. > The Root of the Problem wrote: > > >IS there a way of using Message-ID is identify Spam or Ham? > > The Message-ID is to uniquely identify that message. Think of it like as a > social security number. Do you want to declare a person a cheat becuase > you do not like his/her social security number? > > You can give some point to messages that do not set their own Message-ID. > That is allready part of spamassassin for ages. > > Or are you trying to ask something completely differently? > Nope on the correct track. What is then needed is to cross reference the message-id with the mail logs, trace back the offending IP and make the spam disappear. NOw I should open a black hole! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From amaclach at yahoo.co.uk Sat May 12 22:55:59 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Sat May 12 22:56:01 2007 Subject: {Spam?} Re: Message-ID Message-ID: <651459.19860.qm@web26310.mail.ukl.yahoo.com> I believe that policyd will do just that for you. ----- Original Message ---- From: Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem To: MailScanner discussion Sent: Saturday, 12 May, 2007 9:59:35 PM Subject: Re: {Spam?} Re: Message-ID On Sat, May 12, 2007 at 08:58:56PM +0200, Hugo van der Kooij wrote: > On Sat, 12 May 2007, Dave Shariff Yadallee - System Administrator a.k.a. > The Root of the Problem wrote: > > >IS there a way of using Message-ID is identify Spam or Ham? > > The Message-ID is to uniquely identify that message. Think of it like as a > social security number. Do you want to declare a person a cheat becuase > you do not like his/her social security number? > > You can give some point to messages that do not set their own Message-ID. > That is allready part of spamassassin for ages. > > Or are you trying to ask something completely differently? > Nope on the correct track. What is then needed is to cross reference the message-id with the mail logs, trace back the offending IP and make the spam disappear. NOw I should open a black hole! -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From glenn.steen at gmail.com Mon May 14 10:28:28 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Mon May 14 10:28:32 2007 Subject: postfix dropping SMTP connection when receiving mail In-Reply-To: <4644D221.3050403@fgp.com> References: <4644D221.3050403@fgp.com> Message-ID: <223f97700705140228l7beefb0dp1640a23cd99478f5@mail.gmail.com> On 11/05/07, Jonathan Nalley wrote: > Hi, I'm running MailScanner 4.58.9-1 using postfix 2.3.3 on Centos 5. > > I've set our M$ Exchange Server 2007 to use our MailScanner/Postfix box as a "smart host" such that all outbound mail would be sent through the MailScanner/postfix box. The problem is that when the Exchange box is trying to pass along an e-mail to postfix, the connection and SMTP session gets dropped or something really bizarre is going on. > > Below is a snippet of /var/log/maillog (with postfix's debug_peer_level=1000). For the purposes of these pasted log files. 192.168.0.207 is the exchange box and 192.168.0.208 is the Postfix box. > > May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_hostname: exchange.myinternaldomain.com ~? 192.168.0.0/24 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_hostaddr: 192.168.0.207 ~? 192.168.0.0/24 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 220 mailscanner.myinternaldomain.com ESMTP Postfix > May 11 09:40:23 mailscanner postfix/smtpd[18829]: watchdog_pat: 0x99266a0 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: vstream_fflush_some: fd 9 flush 83 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: vstream_buf_get_ready: fd 9 got 29 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: < exchange.myinternaldomain.com[192.168.0.207]: EHLO exchange.myinternaldomain.com > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-mailscanner.myinternaldomain.com > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-PIPELINING > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-SIZE 10240000 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-VRFY > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-ETRN > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-AUTH LOGIN PLAIN > May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_list_match: exchange.myinternaldomain.com: no match > May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_list_match: 192.168.0.207: no match > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-AUTH=LOGIN PLAIN > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-ENHANCEDSTATUSCODES > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-8BITMIME > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250 DSN > May 11 09:40:23 mailscanner postfix/smtpd[18829]: watchdog_pat: 0x99266a0 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: vstream_fflush_some: fd 9 flush 178 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: smtp_get: EOF > May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_hostname: exchange.myinternaldomain.com ~? 192.168.0.0/24 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_hostaddr: 192.168.0.207 ~? 192.168.0.0/24 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: lost connection after EHLO from exchange.myinternaldomain.com[192.168.0.207] > May 11 09:40:23 mailscanner postfix/smtpd[18829]: disconnect from exchange.myinternaldomain.com[192.168.0.207] > > > When enabling verbose session logging on the M$ Exchange box, below is the relevant SMTP session snippet: > > 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,0,,192.168.0.208:25,*,,attempting to connect > 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,1,192.168.0.207:11256,192.168.0.208:25,+,, > 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,2,192.168.0.207:11256,192.168.0.208:25,<,220 postfixbox.myinternaldomain.com ESMTP Postfix, > 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,3,192.168.0.207:11256,192.168.0.208:25,>,EHLO exchange.myinternaldomain.com, > 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,4,192.168.0.207:11256,192.168.0.208:25,<, > 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,5,192.168.0.207:11256,192.168.0.208:25,-,,Local > > The second-to-last line actually has 65 spaces and then the closing comma but i couldn't get my mailer to display that in a desirable fashion. > > I know it's tempting to say or to think that the problem might be with the M$ Exchange box, but i can tell Exchange to use other Postfix/MailScanner installations (admittedly running MailScanner version 4.46.2-2 and postfix version 2.1.5) as the smart host and everything works smoothly. > > I've seen other posts in the mailing list with people having "smtp_get: EOF" in their logs and other similar entries but many were related to TLS, SSL, SASL and authentication and all that stuff but i'm not trying to do any of that here. Any thoughts, wisdom, insights, fixes, and solutions greatly appreciated. Thanks In Advance. > > > Below is postconf -n: > > alias_database = hash:/etc/aliases > alias_maps = hash:/etc/aliases > broken_sasl_auth_clients = yes > command_directory = /usr/sbin > config_directory = /etc/postfix > daemon_directory = /usr/libexec/postfix > debug_peer_level = 1000 > debug_peer_list = 192.168.0.207 > header_checks = regexp:/etc/postfix/header_checks > html_directory = no > inet_interfaces = all > mail_owner = postfix > mailq_path = /usr/bin/mailq.postfix > manpage_directory = /usr/share/man > mydestination = localhost.$mydomain, localhost, $mydomain > mydomain = myinternaldomain.com > myhostname = mailscanner.myinternaldomain.com > mynetworks = 192.168.0.0/24, 127.0.0.0/8 > myorigin = $mydomain > newaliases_path = /usr/bin/newaliases.postfix > queue_directory = /var/spool/postfix > readme_directory = /usr/share/doc/postfix-2.3.3/README_FILES > relay_domains = $mydestination > sample_directory = /usr/share/doc/postfix-2.3.3/samples > sendmail_path = /usr/sbin/sendmail.postfix > setgid_group = postdrop > smtpd_banner = $myhostname ESMTP $mail_name > smtpd_recipient_restrictions = permit_mynetworks permit_sasl_authenticated reject_unauth_destination > smtpd_sasl_auth_enable = yes > smtpd_sasl_path = smtpd > transport_maps = hash:/etc/postfix/transport > unknown_local_recipient_reject_code = 550 > Not really an MailScanner problem this... If you telnet to it and "play MTA", does it work then? If you remove the SASL thing from recipient_restrictions, still the same? -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From matt at coders.co.uk Mon May 14 11:32:11 2007 From: matt at coders.co.uk (Matt Hampton) Date: Mon May 14 11:29:47 2007 Subject: Does anyone catch this.... Message-ID: <46483AAB.7040800@coders.co.uk> http://www.coders.co.uk/slipped.through.txt It has sailed through both a SA3.1.8 and SA3.2.0 (3.2.0-pre2-r512851) running on recent versions of MailScanner cheers Matt From martinh at solidstatelogic.com Mon May 14 11:36:53 2007 From: martinh at solidstatelogic.com (martinh@solidstatelogic.com) Date: Mon May 14 11:37:21 2007 Subject: Does anyone catch this.... In-Reply-To: <46483AAB.7040800@coders.co.uk> Message-ID: <1a4d33aefaed9045b83b9d05da8898f6@solidstatelogic.com> Matt Content analysis details: (5.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.6 REPLY_TO_EMPTY Reply-To: is empty 0.1 FORGED_RCVD_HELO Received: contains a forged HELO 0.6 J_CHICKENPOX_82 BODY: {8}Letter - punctuation - {2}Letter 0.0 HTML_MESSAGE BODY: HTML included in message 0.0 BAYES_50 BODY: Bayesian spam probability is 40 to 60% [score: 0.4951] 0.0 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 4.0 DCC_CHECK Listed in DCC (http://rhyolite.com/anti-spam/dcc/) -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: Matt Hampton [mailto:matt@coders.co.uk] > Sent: 14 May 2007 11:32 > To: mailscanner@lists.mailscanner.info; users@spamassassin.apache.org > Subject: Does anyone catch this.... > > http://www.coders.co.uk/slipped.through.txt > > It has sailed through both a SA3.1.8 and SA3.2.0 (3.2.0-pre2-r512851) > running on recent versions of MailScanner > > cheers > > Matt > ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From list-mailscanner at linguaphone.com Mon May 14 11:40:16 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon May 14 11:40:24 2007 Subject: Does anyone catch this.... In-Reply-To: <46483AAB.7040800@coders.co.uk> References: <46483AAB.7040800@coders.co.uk> Message-ID: <1179139216.12949.8.camel@gblades-suse.linguaphone-intranet.co.uk> On Mon, 2007-05-14 at 11:32, Matt Hampton wrote: > http://www.coders.co.uk/slipped.through.txt > > It has sailed through both a SA3.1.8 and SA3.2.0 (3.2.0-pre2-r512851) > running on recent versions of MailScanner > > cheers > > Matt It would have made it past our spam filter aswell. It looks like a phishing email so it might have been stopped by clamav's phishing signatures. From edward.prendergast at netring.co.uk Mon May 14 11:41:37 2007 From: edward.prendergast at netring.co.uk (Edward Prendergast) Date: Mon May 14 11:41:48 2007 Subject: Does anyone catch this.... In-Reply-To: <46483AAB.7040800@coders.co.uk> Message-ID: <200705141041.l4EAfkEP027689@safir.blacknight.ie> -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Matt Hampton Sent: 14 May 2007 11:32 To: mailscanner@lists.mailscanner.info; users@spamassassin.apache.org Subject: Does anyone catch this.... http://www.coders.co.uk/slipped.through.txt It has sailed through both a SA3.1.8 and SA3.2.0 (3.2.0-pre2-r512851) running on recent versions of MailScanner cheers Matt --------------------------- Hi Matt, It would've slipped through for me too: pts rule name description ---- ---------------------- -------------------------------------------------- 1.0 BAYES_60 BODY: Bayesian spam probability is 60 to 80% [score: 0.6832] 0.0 HTML_MESSAGE BODY: HTML included in message 1.5 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 2.2 DCC_CHECK Listed in DCC (http://rhyolite.com/anti-spam/dcc/) ************ The information in this email is confidential and may be legally privileged. It is intended solely for the addressee. Access to this email by anyone else is unauthorised. If you are not the intended recipient, any action taken or omitted to be taken in reliance on it, any form of reproduction, dissemination, copying, disclosure, modification, distribution and/or publication of this E-mail message is strictly prohibited and may be unlawful. If you have received this E-mail message in error, please notify us immediately. Please also destroy and delete the message from your computer. ************ From rcooper at dwford.com Mon May 14 13:11:54 2007 From: rcooper at dwford.com (Rick Cooper) Date: Mon May 14 13:13:26 2007 Subject: Does anyone catch this.... In-Reply-To: <1179139216.12949.8.camel@gblades-suse.linguaphone-intranet.co.uk> References: <46483AAB.7040800@coders.co.uk> <1179139216.12949.8.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <04d401c79621$10172d30$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Gareth > Sent: Monday, May 14, 2007 6:40 AM > To: MailScanner discussion > Subject: Re: Does anyone catch this.... > > On Mon, 2007-05-14 at 11:32, Matt Hampton wrote: > > http://www.coders.co.uk/slipped.through.txt > > > > It has sailed through both a SA3.1.8 and SA3.2.0 > (3.2.0-pre2-r512851) > > running on recent versions of MailScanner > > > > cheers > > > > Matt > > It would have made it past our spam filter aswell. It looks like a > phishing email so it might have been stopped by clamav's phishing > signatures. > Clam says : Html.Phishing.Bank.Sanesecurity.06030604 FOUND so it wouldn't make it past exim (or to spamd). Of course you would have to be using the SaneSecurity phishing signatures. Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From mogens at fumlersoft.dk Mon May 14 14:59:48 2007 From: mogens at fumlersoft.dk (Mogens Melander) Date: Mon May 14 14:59:38 2007 Subject: Does anyone catch this.... In-Reply-To: <1179139216.12949.8.camel@gblades-suse.linguaphone-intranet.co.uk> References: <46483AAB.7040800@coders.co.uk> <1179139216.12949.8.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <3908.90.184.17.152.1179151188.squirrel@mail.fumlersoft.dk> On Mon, May 14, 2007 12:40, Gareth wrote: > On Mon, 2007-05-14 at 11:32, Matt Hampton wrote: >> http://www.coders.co.uk/slipped.through.txt >> >> It has sailed through both a SA3.1.8 and SA3.2.0 (3.2.0-pre2-r512851) >> running on recent versions of MailScanner >> >> cheers >> >> Matt > > It would have made it past our spam filter aswell. It looks like a > phishing email so it might have been stopped by clamav's phishing > signatures. Well, both original OpenProtect and MS-SA-ClamAV upgraded OpenProtect catch that one: MailScanner ./blabla/msg-20986-1.txt: HTML.Phishing.Bank-1077 FOUND -- Later Mogens Melander +45 40 85 71 38 +66 870 133 224 -- This message has been scanned for viruses and dangerous content by OpenProtect(http://www.openprotect.com), and is believed to be clean. From m.anderlini at database.it Mon May 14 15:06:35 2007 From: m.anderlini at database.it (Marcello Anderlini) Date: Mon May 14 15:11:43 2007 Subject: Mqueue.in growing In-Reply-To: <04d401c79621$10172d30$0301a8c0@SAHOMELT> References: <46483AAB.7040800@coders.co.uk><1179139216.12949.8.camel@gblades-suse.linguaphone-intranet.co.uk> <04d401c79621$10172d30$0301a8c0@SAHOMELT> Message-ID: <00d401c79631$156716f0$3f01a8c0@dbdomain.database.it> Hello to all, some time ago I've already post this question, It seemed I've solved the problem but this morning it compare again. I'm using centos 4.4 with kernel 2.6.9-42.0.10.Elsmp, mailscanner 4.58.9.1, spamassassin 3.2.0.1.el4.rf. Razor, pyzor, dcc and fuzzy_ocr. Without changing anything on my configuration, suddendly this morning the mqueue.in start to grow until 4000 msg. I've tried to remove mailscanner rbl check e and I've set skip_rbl_checks 1 in spam.assassin.pref.conf but without success. I've check in /root/.spamassassin folder and I found some lock file so I set Rebuild Bayes Every = 86400. When I try spamassassin -D -lint -p /etc/MailScanner/spam.assassin.prefs.con I get : ========= [26122] warn: The -l option has been deprecated and is no longer supported, ignoring. [26122] dbg: logger: adding facilities: all [26122] dbg: logger: logging level is DBG [26122] dbg: generic: SpamAssassin version 3.2.0 [26122] dbg: config: score set 0 chosen. [26122] dbg: util: running in taint mode? yes [26122] dbg: util: taint mode: deleting unsafe environment variables, resetting PATH [26122] dbg: util: PATH included '/usr/kerberos/sbin', keeping [26122] dbg: util: PATH included '/usr/kerberos/bin', keeping [26122] dbg: util: PATH included '/usr/local/sbin', keeping [26122] dbg: util: PATH included '/usr/local/bin', keeping [26122] dbg: util: PATH included '/sbin', keeping [26122] dbg: util: PATH included '/bin', keeping [26122] dbg: util: PATH included '/usr/sbin', keeping [26122] dbg: util: PATH included '/usr/bin', keeping [26122] dbg: util: PATH included '/usr/X11R6/bin', keeping [26122] dbg: util: PATH included '/root/bin', which doesn't exist, dropping [26122] dbg: util: final PATH set to: /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b in:/usr/sbin:/usr/bin:/usr/X11R6/bin [26122] dbg: dns: no ipv6 [26122] dbg: dns: is Net::DNS::Resolver available? yes [26122] dbg: dns: Net::DNS version: 0.48 ========= And it seemed to stop, what can be ? Could you help me ? Thanks a lot -- Messaggio verificato dal servizio antivirus di Database Informatica From m.anderlini at database.it Mon May 14 15:12:00 2007 From: m.anderlini at database.it (Marcello Anderlini) Date: Mon May 14 15:15:05 2007 Subject: R: Mqueue.in growing References: <46483AAB.7040800@coders.co.uk><1179139216.12949.8.camel@gblades-suse.linguaphone-intranet.co.uk> <04d401c79621$10172d30$0301a8c0@SAHOMELT> Message-ID: <00d501c79631$d7117d40$3f01a8c0@dbdomain.database.it> Sorry, I made a mistake writing spamassassin -D -lint -p /etc/MailScanner/spam.assassin.prefs.conf, if I write spamassassin -D --lint -p /etc/MailScanner/spam.assassin.prefs.conf, it continues but I still can NOT understand why it's so slow. Please help me :-( Best regards -----Messaggio originale----- Da: Marcello Anderlini [mailto:m.anderlini@database.it] Inviato: luned? 14 maggio 2007 16.07 A: 'MailScanner discussion' Oggetto: Mqueue.in growing Hello to all, some time ago I've already post this question, It seemed I've solved the problem but this morning it compare again. I'm using centos 4.4 with kernel 2.6.9-42.0.10.Elsmp, mailscanner 4.58.9.1, spamassassin 3.2.0.1.el4.rf. Razor, pyzor, dcc and fuzzy_ocr. Without changing anything on my configuration, suddendly this morning the mqueue.in start to grow until 4000 msg. I've tried to remove mailscanner rbl check e and I've set skip_rbl_checks 1 in spam.assassin.pref.conf but without success. I've check in /root/.spamassassin folder and I found some lock file so I set Rebuild Bayes Every = 86400. When I try spamassassin -D -lint -p /etc/MailScanner/spam.assassin.prefs.conf I get : ========= [26122] warn: The -l option has been deprecated and is no longer supported, ignoring. [26122] dbg: logger: adding facilities: all [26122] dbg: logger: logging level is DBG [26122] dbg: generic: SpamAssassin version 3.2.0 [26122] dbg: config: score set 0 chosen. [26122] dbg: util: running in taint mode? yes [26122] dbg: util: taint mode: deleting unsafe environment variables, resetting PATH [26122] dbg: util: PATH included '/usr/kerberos/sbin', keeping [26122] dbg: util: PATH included '/usr/kerberos/bin', keeping [26122] dbg: util: PATH included '/usr/local/sbin', keeping [26122] dbg: util: PATH included '/usr/local/bin', keeping [26122] dbg: util: PATH included '/sbin', keeping [26122] dbg: util: PATH included '/bin', keeping [26122] dbg: util: PATH included '/usr/sbin', keeping [26122] dbg: util: PATH included '/usr/bin', keeping [26122] dbg: util: PATH included '/usr/X11R6/bin', keeping [26122] dbg: util: PATH included '/root/bin', which doesn't exist, dropping [26122] dbg: util: final PATH set to: /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b in:/usr/sbin:/usr/bin:/usr/X11R6/bin [26122] dbg: dns: no ipv6 [26122] dbg: dns: is Net::DNS::Resolver available? yes [26122] dbg: dns: Net::DNS version: 0.48 ========= And it seemed to stop, what can be ? Could you help me ? Thanks a lot -- Messaggio verificato dal servizio antivirus di Database Informatica From mkercher at nfsmith.com Mon May 14 15:11:58 2007 From: mkercher at nfsmith.com (Mike Kercher) Date: Mon May 14 15:15:52 2007 Subject: Mqueue.in growing References: <46483AAB.7040800@coders.co.uk><1179139216.12949.8.camel@gblades-suse.linguaphone-intranet.co.uk><04d401c79621$10172d30$0301a8c0@SAHOMELT> <00d401c79631$156716f0$3f01a8c0@dbdomain.database.it> Message-ID: <6DEF8ABC1767C045B91F42066D36358E9224@HOUPEX01.nfsmith.info> Marcello Anderlini <> wrote on Monday, May 14, 2007 9:07 AM: : Hello to all, some time ago I've already post this question, It : seemed I've solved the problem but this morning it compare again. : : I'm using centos 4.4 with kernel 2.6.9-42.0.10.Elsmp, mailscanner : 4.58.9.1, spamassassin 3.2.0.1.el4.rf. : Razor, pyzor, dcc and fuzzy_ocr. : : Without changing anything on my configuration, suddendly this morning : the mqueue.in start to grow until 4000 msg. I've tried to remove : mailscanner rbl check e and I've set skip_rbl_checks 1 in : spam.assassin.pref.conf but without success. : : I've check in /root/.spamassassin folder and I found some lock file : so I set Rebuild Bayes Every = 86400. : : When I try spamassassin -D -lint -p : /etc/MailScanner/spam.assassin.prefs.con : I get : : ========= : [26122] warn: The -l option has been deprecated and is no longer : supported, ignoring. [26122] dbg: logger: adding facilities: all : [26122] dbg: logger: logging level is DBG [26122] dbg: generic: : SpamAssassin version 3.2.0 [26122] dbg: config: score set 0 chosen. : [26122] dbg: util: running in taint mode? yes [26122] dbg: util: : taint mode: deleting unsafe environment variables, resetting PATH : [26122] dbg: util: PATH included '/usr/kerberos/sbin', keeping : [26122] dbg: util: PATH included '/usr/kerberos/bin', keeping [26122] : dbg: util: PATH included '/usr/local/sbin', keeping [26122] dbg: : util: PATH included '/usr/local/bin', keeping [26122] dbg: util: PATH : included '/sbin', keeping [26122] dbg: util: PATH included '/bin', : keeping [26122] dbg: util: PATH included '/usr/sbin', keeping [26122] : dbg: util: PATH included '/usr/bin', keeping [26122] dbg: util: PATH : included '/usr/X11R6/bin', keeping [26122] dbg: util: PATH included : '/root/bin', which doesn't exist, dropping [26122] dbg: util: final : PATH set to: : /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbi n:/b : in:/usr/sbin:/usr/bin:/usr/X11R6/bin : [26122] dbg: dns: no ipv6 : [26122] dbg: dns: is Net::DNS::Resolver available? yes [26122] dbg: : dns: Net::DNS version: 0.48 ========= : : And it seemed to stop, what can be ? Could you help me ? : : Thanks a lot : : : -- : Messaggio verificato dal servizio antivirus di Database Informatica Try spamassassin -D --lint (you missed a dash) -Mike From mkercher at nfsmith.com Mon May 14 15:15:27 2007 From: mkercher at nfsmith.com (Mike Kercher) Date: Mon May 14 15:19:20 2007 Subject: Mqueue.in growing References: <46483AAB.7040800@coders.co.uk><1179139216.12949.8.camel@gblades-suse.linguaphone-intranet.co.uk><04d401c79621$10172d30$0301a8c0@SAHOMELT> <00d501c79631$d7117d40$3f01a8c0@dbdomain.database.it> Message-ID: <6DEF8ABC1767C045B91F42066D36358E9225@HOUPEX01.nfsmith.info> Marcello Anderlini <> wrote on Monday, May 14, 2007 9:12 AM: : Sorry, I made a mistake writing spamassassin -D -lint -p : /etc/MailScanner/spam.assassin.prefs.conf, if I write spamassassin -D : --lint -p /etc/MailScanner/spam.assassin.prefs.conf, it continues but : I still can NOT understand why it's so slow. : : Please help me :-( : : Best regards : : -----Messaggio originale----- : Da: Marcello Anderlini [mailto:m.anderlini@database.it] : Inviato: luned? 14 maggio 2007 16.07 : A: 'MailScanner discussion' : Oggetto: Mqueue.in growing : : Hello to all, some time ago I've already post this question, It : seemed I've solved the problem but this morning it compare again. : : I'm using centos 4.4 with kernel 2.6.9-42.0.10.Elsmp, mailscanner : 4.58.9.1, spamassassin 3.2.0.1.el4.rf. : Razor, pyzor, dcc and fuzzy_ocr. : : Without changing anything on my configuration, suddendly this morning : the mqueue.in start to grow until 4000 msg. I've tried to remove : mailscanner rbl check e and I've set skip_rbl_checks 1 in : spam.assassin.pref.conf but without success. : : I've check in /root/.spamassassin folder and I found some lock file : so I set Rebuild Bayes Every = 86400. : : When I try spamassassin -D -lint -p : /etc/MailScanner/spam.assassin.prefs.conf I get : : ========= : [26122] warn: The -l option has been deprecated and is no longer : supported, ignoring. [26122] dbg: logger: adding facilities: all : [26122] dbg: logger: logging level is DBG [26122] dbg: generic: : SpamAssassin version 3.2.0 [26122] dbg: : config: score set 0 chosen. : [26122] dbg: util: running in taint mode? yes [26122] dbg: util: : taint mode: : deleting unsafe environment variables, resetting PATH [26122] dbg: : util: : PATH included '/usr/kerberos/sbin', keeping [26122] dbg: util: PATH : included '/usr/kerberos/bin', keeping [26122] dbg: util: PATH : included '/usr/local/sbin', keeping [26122] dbg: util: PATH included : '/usr/local/bin', keeping [26122] dbg: util: PATH included '/sbin', : keeping [26122] dbg: util: PATH included '/bin', keeping [26122] dbg: : util: PATH included '/usr/sbin', keeping [26122] dbg: util: PATH : included '/usr/bin', keeping [26122] dbg: util: PATH included : '/usr/X11R6/bin', keeping [26122] dbg: util: PATH included : '/root/bin', which doesn't exist, dropping [26122] : dbg: util: final PATH set to: : /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b : in:/usr/sbin:/usr/bin:/usr/X11R6/bin : [26122] dbg: dns: no ipv6 : [26122] dbg: dns: is Net::DNS::Resolver available? yes [26122] dbg: : dns: : Net::DNS version: 0.48 ========= : : And it seemed to stop, what can be ? Could you help me ? : : Thanks a lot : : : -- When I run it, I get: [3262] dbg: dns: no ipv6 [3262] dbg: dns: is Net::DNS::Resolver available? yes [3262] dbg: dns: Net::DNS version: 0.59 You might try updating your Net::DNS and see if that helps. -Mike From martinh at solidstatelogic.com Mon May 14 15:24:38 2007 From: martinh at solidstatelogic.com (martinh@solidstatelogic.com) Date: Mon May 14 15:24:42 2007 Subject: Mqueue.in growing In-Reply-To: <00d401c79631$156716f0$3f01a8c0@dbdomain.database.it> Message-ID: <615771af0d8da44c85f5994a3e31da5c@solidstatelogic.com> Marcello What version of perl. There's an issue with SA 3.2.0 and perl < 5.8.8, and a workaround.... -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Marcello Anderlini > Sent: 14 May 2007 15:07 > To: MailScanner discussion > Subject: Mqueue.in growing > > Hello to all, some time ago I've already post this question, It seemed > I've > solved the problem but this morning it compare again. > > I'm using centos 4.4 with kernel 2.6.9-42.0.10.Elsmp, mailscanner > 4.58.9.1, > spamassassin 3.2.0.1.el4.rf. > Razor, pyzor, dcc and fuzzy_ocr. > > Without changing anything on my configuration, suddendly this morning the > mqueue.in start to grow until 4000 msg. I've tried to remove mailscanner > rbl > check e and I've set skip_rbl_checks 1 in spam.assassin.pref.conf but > without success. > > I've check in /root/.spamassassin folder and I found some lock file so I > set > Rebuild Bayes Every = 86400. > > When I try spamassassin -D -lint -p > /etc/MailScanner/spam.assassin.prefs.con > I get : > ========= > [26122] warn: The -l option has been deprecated and is no longer > supported, > ignoring. > [26122] dbg: logger: adding facilities: all > [26122] dbg: logger: logging level is DBG > [26122] dbg: generic: SpamAssassin version 3.2.0 > [26122] dbg: config: score set 0 chosen. > [26122] dbg: util: running in taint mode? yes > [26122] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH > [26122] dbg: util: PATH included '/usr/kerberos/sbin', keeping > [26122] dbg: util: PATH included '/usr/kerberos/bin', keeping > [26122] dbg: util: PATH included '/usr/local/sbin', keeping > [26122] dbg: util: PATH included '/usr/local/bin', keeping > [26122] dbg: util: PATH included '/sbin', keeping > [26122] dbg: util: PATH included '/bin', keeping > [26122] dbg: util: PATH included '/usr/sbin', keeping > [26122] dbg: util: PATH included '/usr/bin', keeping > [26122] dbg: util: PATH included '/usr/X11R6/bin', keeping > [26122] dbg: util: PATH included '/root/bin', which doesn't exist, > dropping > [26122] dbg: util: final PATH set to: > /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbi n: > /b > in:/usr/sbin:/usr/bin:/usr/X11R6/bin > [26122] dbg: dns: no ipv6 > [26122] dbg: dns: is Net::DNS::Resolver available? yes > [26122] dbg: dns: Net::DNS version: 0.48 > ========= > > And it seemed to stop, what can be ? Could you help me ? > > Thanks a lot > > > -- > Messaggio verificato dal servizio antivirus di Database Informatica > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From mkercher at nfsmith.com Mon May 14 15:25:11 2007 From: mkercher at nfsmith.com (Mike Kercher) Date: Mon May 14 15:29:05 2007 Subject: Mqueue.in growing References: <615771af0d8da44c85f5994a3e31da5c@solidstatelogic.com> Message-ID: <6DEF8ABC1767C045B91F42066D36358E9227@HOUPEX01.nfsmith.info> martinh@solidstatelogic.com <> wrote on Monday, May 14, 2007 9:25 AM: : Marcello : : What version of perl. There's an issue with SA 3.2.0 and perl < : 5.8.8, and a workaround.... : : -- This is perl, v5.8.5 built for i386-linux-thread-multi This is on CentOS 4.4 as well. -Mike From mkercher at nfsmith.com Mon May 14 15:26:13 2007 From: mkercher at nfsmith.com (Mike Kercher) Date: Mon May 14 15:30:07 2007 Subject: Mqueue.in growing References: <615771af0d8da44c85f5994a3e31da5c@solidstatelogic.com> Message-ID: <6DEF8ABC1767C045B91F42066D36358E9228@HOUPEX01.nfsmith.info> martinh@solidstatelogic.com <> wrote on Monday, May 14, 2007 9:25 AM: : Marcello : : What version of perl. There's an issue with SA 3.2.0 and perl < : 5.8.8, and a workaround.... : : -- Oops...disregard. Back to the coffee pot! -Mike From martinh at solidstatelogic.com Mon May 14 15:34:28 2007 From: martinh at solidstatelogic.com (martinh@solidstatelogic.com) Date: Mon May 14 15:34:34 2007 Subject: Mqueue.in growing In-Reply-To: <6DEF8ABC1767C045B91F42066D36358E9227@HOUPEX01.nfsmith.info> Message-ID: Mike There's a fair chance you've got hit by the use bytes bug in SA 3.2.0. Find the Message.pm in the perl path for sa 3.2.0 Just below "use warnings;" add a newline... use bytes; this should sort the problem as long as your not using the normalize_charset functionality in SA. If you are you're stuffed and will have to go back to 3.1.8. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Mike Kercher > Sent: 14 May 2007 15:25 > To: MailScanner discussion > Subject: RE: Mqueue.in growing > > martinh@solidstatelogic.com <> wrote on Monday, May 14, 2007 9:25 AM: > > : Marcello > : > : What version of perl. There's an issue with SA 3.2.0 and perl < > : 5.8.8, and a workaround.... > : > : -- > > This is perl, v5.8.5 built for i386-linux-thread-multi > > This is on CentOS 4.4 as well. > > -Mike > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From m.anderlini at database.it Mon May 14 15:39:38 2007 From: m.anderlini at database.it (Marcello Anderlini) Date: Mon May 14 15:51:00 2007 Subject: R: Mqueue.in growing In-Reply-To: <615771af0d8da44c85f5994a3e31da5c@solidstatelogic.com> References: <00d401c79631$156716f0$3f01a8c0@dbdomain.database.it> <615771af0d8da44c85f5994a3e31da5c@solidstatelogic.com> Message-ID: <00d601c79635$b2e8e8f0$3f01a8c0@dbdomain.database.it> I'm using perl 5.8.5.36.RHEL4 What's the workaround ? bye -----Messaggio originale----- Da: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di martinh@solidstatelogic.com Inviato: luned? 14 maggio 2007 16.25 A: MailScanner discussion Oggetto: RE: Mqueue.in growing Marcello What version of perl. There's an issue with SA 3.2.0 and perl < 5.8.8, and a workaround.... -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Marcello Anderlini > Sent: 14 May 2007 15:07 > To: MailScanner discussion > Subject: Mqueue.in growing > > Hello to all, some time ago I've already post this question, It seemed > I've solved the problem but this morning it compare again. > > I'm using centos 4.4 with kernel 2.6.9-42.0.10.Elsmp, mailscanner > 4.58.9.1, spamassassin 3.2.0.1.el4.rf. > Razor, pyzor, dcc and fuzzy_ocr. > > Without changing anything on my configuration, suddendly this morning the > mqueue.in start to grow until 4000 msg. I've tried to remove mailscanner > rbl > check e and I've set skip_rbl_checks 1 in spam.assassin.pref.conf but > without success. > > I've check in /root/.spamassassin folder and I found some lock file so I > set > Rebuild Bayes Every = 86400. > > When I try spamassassin -D -lint -p > /etc/MailScanner/spam.assassin.prefs.con > I get : > ========= > [26122] warn: The -l option has been deprecated and is no longer > supported, ignoring. > [26122] dbg: logger: adding facilities: all [26122] dbg: logger: > logging level is DBG [26122] dbg: generic: SpamAssassin version 3.2.0 > [26122] dbg: config: score set 0 chosen. > [26122] dbg: util: running in taint mode? yes [26122] dbg: util: taint > mode: deleting unsafe environment variables, resetting PATH [26122] > dbg: util: PATH included '/usr/kerberos/sbin', keeping [26122] dbg: > util: PATH included '/usr/kerberos/bin', keeping [26122] dbg: util: > PATH included '/usr/local/sbin', keeping [26122] dbg: util: PATH > included '/usr/local/bin', keeping [26122] dbg: util: PATH included > '/sbin', keeping [26122] dbg: util: PATH included '/bin', keeping > [26122] dbg: util: PATH included '/usr/sbin', keeping [26122] dbg: > util: PATH included '/usr/bin', keeping [26122] dbg: util: PATH > included '/usr/X11R6/bin', keeping [26122] dbg: util: PATH included > '/root/bin', which doesn't exist, dropping [26122] dbg: util: final > PATH set to: > /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbi n: > /b > in:/usr/sbin:/usr/bin:/usr/X11R6/bin > [26122] dbg: dns: no ipv6 > [26122] dbg: dns: is Net::DNS::Resolver available? yes [26122] dbg: > dns: Net::DNS version: 0.48 ========= > > And it seemed to stop, what can be ? Could you help me ? > > Thanks a lot > > > -- > Messaggio verificato dal servizio antivirus di Database Informatica > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- Messaggio verificato dal servizio antivirus di Database Informatica -- Messaggio verificato dal servizio antivirus di Database Informatica From m.anderlini at database.it Mon May 14 15:47:02 2007 From: m.anderlini at database.it (Marcello Anderlini) Date: Mon May 14 15:52:39 2007 Subject: R: Mqueue.in growing In-Reply-To: <6DEF8ABC1767C045B91F42066D36358E9228@HOUPEX01.nfsmith.info> References: <615771af0d8da44c85f5994a3e31da5c@solidstatelogic.com> <6DEF8ABC1767C045B91F42066D36358E9228@HOUPEX01.nfsmith.info> Message-ID: <00d701c79636$bb9b5c70$3f01a8c0@dbdomain.database.it> Sorry, I do not understand (My english it's very low). I've also commented this line in /etc/mail/spamassassin/v310.pre to disable Pyzor and Razor but nothing the queue is still growing... # Pyzor - perform Pyzor message checks. # #loadplugin Mail::SpamAssassin::Plugin::Pyzor # Razor2 - perform Razor2 message checks. # #loadplugin Mail::SpamAssassin::Plugin::Razor2 -----Messaggio originale----- Da: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di Mike Kercher Inviato: luned? 14 maggio 2007 16.26 A: MailScanner discussion Oggetto: RE: Mqueue.in growing martinh@solidstatelogic.com <> wrote on Monday, May 14, 2007 9:25 AM: : Marcello : : What version of perl. There's an issue with SA 3.2.0 and perl < : 5.8.8, and a workaround.... : : -- Oops...disregard. Back to the coffee pot! -Mike -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- Messaggio verificato dal servizio antivirus di Database Informatica -- Messaggio verificato dal servizio antivirus di Database Informatica From m.anderlini at database.it Mon May 14 15:50:15 2007 From: m.anderlini at database.it (Marcello Anderlini) Date: Mon May 14 15:53:22 2007 Subject: R: Mqueue.in growing In-Reply-To: References: <6DEF8ABC1767C045B91F42066D36358E9227@HOUPEX01.nfsmith.info> Message-ID: <00d801c79637$2ed42050$3f01a8c0@dbdomain.database.it> Sorry again, but this suggestion is for me or just for Mike Kercher ? -----Messaggio originale----- Da: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di martinh@solidstatelogic.com Inviato: luned? 14 maggio 2007 16.34 A: MailScanner discussion Oggetto: RE: Mqueue.in growing Mike There's a fair chance you've got hit by the use bytes bug in SA 3.2.0. Find the Message.pm in the perl path for sa 3.2.0 Just below "use warnings;" add a newline... use bytes; this should sort the problem as long as your not using the normalize_charset functionality in SA. If you are you're stuffed and will have to go back to 3.1.8. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Mike Kercher > Sent: 14 May 2007 15:25 > To: MailScanner discussion > Subject: RE: Mqueue.in growing > > martinh@solidstatelogic.com <> wrote on Monday, May 14, 2007 9:25 AM: > > : Marcello > : > : What version of perl. There's an issue with SA 3.2.0 and perl < > : 5.8.8, and a workaround.... > : > : -- > > This is perl, v5.8.5 built for i386-linux-thread-multi > > This is on CentOS 4.4 as well. > > -Mike > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- Messaggio verificato dal servizio antivirus di Database Informatica -- Messaggio verificato dal servizio antivirus di Database Informatica From martinh at solidstatelogic.com Mon May 14 15:56:39 2007 From: martinh at solidstatelogic.com (martinh@solidstatelogic.com) Date: Mon May 14 15:56:44 2007 Subject: Mqueue.in growing In-Reply-To: <00d801c79637$2ed42050$3f01a8c0@dbdomain.database.it> Message-ID: <6e47fac3597ec8419c3cb6dfe92b3a0a@solidstatelogic.com> Marcello You - you need to Message.pm for spamassassin 3.2.0 and edit as below (don't worry about you're English skills - much better than any other language I use). -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Marcello Anderlini > Sent: 14 May 2007 15:50 > To: MailScanner discussion > Subject: R: Mqueue.in growing > > Sorry again, but this suggestion is for me or just for Mike Kercher ? > > -----Messaggio originale----- > Da: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di > martinh@solidstatelogic.com > Inviato: luned? 14 maggio 2007 16.34 > A: MailScanner discussion > Oggetto: RE: Mqueue.in growing > > Mike > > There's a fair chance you've got hit by the use bytes bug in SA 3.2.0. > > Find the Message.pm in the perl path for sa 3.2.0 > > Just below "use warnings;" add a newline... > > use bytes; > > this should sort the problem as long as your not using the > normalize_charset > functionality in SA. If you are you're stuffed and will have to go back to > 3.1.8. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Mike Kercher > > Sent: 14 May 2007 15:25 > > To: MailScanner discussion > > Subject: RE: Mqueue.in growing > > > > martinh@solidstatelogic.com <> wrote on Monday, May 14, 2007 9:25 AM: > > > > : Marcello > > : > > : What version of perl. There's an issue with SA 3.2.0 and perl < > > : 5.8.8, and a workaround.... > > : > > : -- > > > > This is perl, v5.8.5 built for i386-linux-thread-multi > > > > This is on CentOS 4.4 as well. > > > > -Mike > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error you > must take no action based on them, nor must you copy or show them to > anyone. > Please advise the sender by replying to this e-mail immediately and then > delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of the > author and unless specifically stated to the contrary, are not necessarily > those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that > you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments > are free from known viruses but in keeping with good computing practice, > you > should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United > Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > Messaggio verificato dal servizio antivirus di Database Informatica > > > -- > Messaggio verificato dal servizio antivirus di Database Informatica > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From m.anderlini at database.it Mon May 14 16:00:16 2007 From: m.anderlini at database.it (Marcello Anderlini) Date: Mon May 14 16:00:22 2007 Subject: R: Mqueue.in growing In-Reply-To: <6e47fac3597ec8419c3cb6dfe92b3a0a@solidstatelogic.com> References: <00d801c79637$2ed42050$3f01a8c0@dbdomain.database.it> <6e47fac3597ec8419c3cb6dfe92b3a0a@solidstatelogic.com> Message-ID: <00e901c79638$952f52b0$3f01a8c0@dbdomain.database.it> Thanks for all, but where I can found Message.pm ? And also why it was working well until this morning ? bye -----Messaggio originale----- Da: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di martinh@solidstatelogic.com Inviato: luned? 14 maggio 2007 16.57 A: MailScanner discussion Oggetto: RE: Mqueue.in growing Marcello You - you need to Message.pm for spamassassin 3.2.0 and edit as below (don't worry about you're English skills - much better than any other language I use). -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Marcello Anderlini > Sent: 14 May 2007 15:50 > To: MailScanner discussion > Subject: R: Mqueue.in growing > > Sorry again, but this suggestion is for me or just for Mike Kercher ? > > -----Messaggio originale----- > Da: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di > martinh@solidstatelogic.com > Inviato: luned? 14 maggio 2007 16.34 > A: MailScanner discussion > Oggetto: RE: Mqueue.in growing > > Mike > > There's a fair chance you've got hit by the use bytes bug in SA 3.2.0. > > Find the Message.pm in the perl path for sa 3.2.0 > > Just below "use warnings;" add a newline... > > use bytes; > > this should sort the problem as long as your not using the > normalize_charset functionality in SA. If you are you're stuffed and > will have to go back to > 3.1.8. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Mike Kercher > > Sent: 14 May 2007 15:25 > > To: MailScanner discussion > > Subject: RE: Mqueue.in growing > > > > martinh@solidstatelogic.com <> wrote on Monday, May 14, 2007 9:25 AM: > > > > : Marcello > > : > > : What version of perl. There's an issue with SA 3.2.0 and perl < > > : 5.8.8, and a workaround.... > > : > > : -- > > > > This is perl, v5.8.5 built for i386-linux-thread-multi > > > > This is on CentOS 4.4 as well. > > > > -Mike > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error you > must take no action based on them, nor must you copy or show them to > anyone. > Please advise the sender by replying to this e-mail immediately and then > delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of the > author and unless specifically stated to the contrary, are not necessarily > those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, > you > should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United > Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > Messaggio verificato dal servizio antivirus di Database Informatica > > > -- > Messaggio verificato dal servizio antivirus di Database Informatica > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- Messaggio verificato dal servizio antivirus di Database Informatica -- Messaggio verificato dal servizio antivirus di Database Informatica From martinh at solidstatelogic.com Mon May 14 16:06:51 2007 From: martinh at solidstatelogic.com (martinh@solidstatelogic.com) Date: Mon May 14 16:06:56 2007 Subject: Mqueue.in growing In-Reply-To: <00e901c79638$952f52b0$3f01a8c0@dbdomain.database.it> Message-ID: <3822a92168130a42b2532496de4ea715@solidstatelogic.com> "locate Message.pm" will help..... Mine's at..... /usr/local/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Message.pm The problem is that it's error logging and this slows the whole thing down. When did you upgrade to 3.2.0? It could be the system was just coping before and now it's just got that little bit too busy and can't sope. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Marcello Anderlini > Sent: 14 May 2007 16:00 > To: MailScanner discussion > Subject: R: Mqueue.in growing > > Thanks for all, but where I can found Message.pm ? And also why it was > working well until this morning ? > > bye > > -----Messaggio originale----- > Da: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di > martinh@solidstatelogic.com > Inviato: luned? 14 maggio 2007 16.57 > A: MailScanner discussion > Oggetto: RE: Mqueue.in growing > > Marcello > > You - you need to Message.pm for spamassassin 3.2.0 and edit as below > > (don't worry about you're English skills - much better than any other > language I use). > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Marcello Anderlini > > Sent: 14 May 2007 15:50 > > To: MailScanner discussion > > Subject: R: Mqueue.in growing > > > > Sorry again, but this suggestion is for me or just for Mike Kercher ? > > > > -----Messaggio originale----- > > Da: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di > > martinh@solidstatelogic.com > > Inviato: luned? 14 maggio 2007 16.34 > > A: MailScanner discussion > > Oggetto: RE: Mqueue.in growing > > > > Mike > > > > There's a fair chance you've got hit by the use bytes bug in SA 3.2.0. > > > > Find the Message.pm in the perl path for sa 3.2.0 > > > > Just below "use warnings;" add a newline... > > > > use bytes; > > > > this should sort the problem as long as your not using the > > normalize_charset functionality in SA. If you are you're stuffed and > > will have to go > back to > > 3.1.8. > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- > > > bounces@lists.mailscanner.info] On Behalf Of Mike Kercher > > > Sent: 14 May 2007 15:25 > > > To: MailScanner discussion > > > Subject: RE: Mqueue.in growing > > > > > > martinh@solidstatelogic.com <> wrote on Monday, May 14, 2007 9:25 > AM: > > > > > > : Marcello > > > : > > > : What version of perl. There's an issue with SA 3.2.0 and perl < > > > : 5.8.8, and a workaround.... > > > : > > > : -- > > > > > > This is perl, v5.8.5 built for i386-linux-thread-multi > > > > > > This is on CentOS 4.4 as well. > > > > > > -Mike > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are intended for the > > addressee only and may be confidential. If they come to you in error > you > > must take no action based on them, nor must you copy or show them to > > anyone. > > Please advise the sender by replying to this e-mail immediately and > then > > delete the original from your computer. > > > > Opinion : Any opinions expressed in this e-mail are entirely those of > the > > author and unless specifically stated to the contrary, are not > necessarily > > those of the author's employer. > > > > Security Warning : Internet e-mail is not necessarily a secure > > communications medium and can be subject to data corruption. We advise > > that you consider this fact when e-mailing us. > > > > Viruses : We have taken steps to ensure that this e-mail and any > > attachments are free from known viruses but in keeping with good > > computing > practice, > > you > > should ensure that they are virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic > > Registered as a limited company in England and Wales (Company > No:5362730) > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United > > Kingdom > > ********************************************************************** > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > -- > > Messaggio verificato dal servizio antivirus di Database Informatica > > > > > > -- > > Messaggio verificato dal servizio antivirus di Database Informatica > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error you > must take no action based on them, nor must you copy or show them to > anyone. > Please advise the sender by replying to this e-mail immediately and then > delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of the > author and unless specifically stated to the contrary, are not necessarily > those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that > you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments > are free from known viruses but in keeping with good computing practice, > you > should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United > Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > Messaggio verificato dal servizio antivirus di Database Informatica > > > -- > Messaggio verificato dal servizio antivirus di Database Informatica > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From m.anderlini at database.it Mon May 14 16:14:19 2007 From: m.anderlini at database.it (Marcello Anderlini) Date: Mon May 14 16:14:37 2007 Subject: R: Mqueue.in growing In-Reply-To: <3822a92168130a42b2532496de4ea715@solidstatelogic.com> References: <00e901c79638$952f52b0$3f01a8c0@dbdomain.database.it> <3822a92168130a42b2532496de4ea715@solidstatelogic.com> Message-ID: <00ea01c7963a$8b9b9f90$3f01a8c0@dbdomain.database.it> I've upgraded to SA 3.2 on 03 May 2007. I really can't believe that it take so much time because meantime I've restarted mailscanner many times... Meantime I've cleaned the queue and disabled Pyzor and Razor and it seem it's going better.... -----Messaggio originale----- Da: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di martinh@solidstatelogic.com Inviato: luned? 14 maggio 2007 17.07 A: MailScanner discussion Oggetto: RE: Mqueue.in growing "locate Message.pm" will help..... Mine's at..... /usr/local/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Message.pm The problem is that it's error logging and this slows the whole thing down. When did you upgrade to 3.2.0? It could be the system was just coping before and now it's just got that little bit too busy and can't sope. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Marcello Anderlini > Sent: 14 May 2007 16:00 > To: MailScanner discussion > Subject: R: Mqueue.in growing > > Thanks for all, but where I can found Message.pm ? And also why it was > working well until this morning ? > > bye > > -----Messaggio originale----- > Da: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di > martinh@solidstatelogic.com > Inviato: luned? 14 maggio 2007 16.57 > A: MailScanner discussion > Oggetto: RE: Mqueue.in growing > > Marcello > > You - you need to Message.pm for spamassassin 3.2.0 and edit as below > > (don't worry about you're English skills - much better than any other > language I use). > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Marcello Anderlini > > Sent: 14 May 2007 15:50 > > To: MailScanner discussion > > Subject: R: Mqueue.in growing > > > > Sorry again, but this suggestion is for me or just for Mike Kercher ? > > > > -----Messaggio originale----- > > Da: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di > > martinh@solidstatelogic.com > > Inviato: luned? 14 maggio 2007 16.34 > > A: MailScanner discussion > > Oggetto: RE: Mqueue.in growing > > > > Mike > > > > There's a fair chance you've got hit by the use bytes bug in SA 3.2.0. > > > > Find the Message.pm in the perl path for sa 3.2.0 > > > > Just below "use warnings;" add a newline... > > > > use bytes; > > > > this should sort the problem as long as your not using the > > normalize_charset functionality in SA. If you are you're stuffed and > > will have to go > back to > > 3.1.8. > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- > > > bounces@lists.mailscanner.info] On Behalf Of Mike Kercher > > > Sent: 14 May 2007 15:25 > > > To: MailScanner discussion > > > Subject: RE: Mqueue.in growing > > > > > > martinh@solidstatelogic.com <> wrote on Monday, May 14, 2007 9:25 > AM: > > > > > > : Marcello > > > : > > > : What version of perl. There's an issue with SA 3.2.0 and perl < > > > : 5.8.8, and a workaround.... > > > : > > > : -- > > > > > > This is perl, v5.8.5 built for i386-linux-thread-multi > > > > > > This is on CentOS 4.4 as well. > > > > > > -Mike > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are intended for the > > addressee only and may be confidential. If they come to you in error > you > > must take no action based on them, nor must you copy or show them to > > anyone. > > Please advise the sender by replying to this e-mail immediately and > then > > delete the original from your computer. > > > > Opinion : Any opinions expressed in this e-mail are entirely those of > the > > author and unless specifically stated to the contrary, are not > necessarily > > those of the author's employer. > > > > Security Warning : Internet e-mail is not necessarily a secure > > communications medium and can be subject to data corruption. We advise > > that you consider this fact when e-mailing us. > > > > Viruses : We have taken steps to ensure that this e-mail and any > > attachments are free from known viruses but in keeping with good > > computing > practice, > > you > > should ensure that they are virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic Registered as a limited > > company in England and Wales (Company > No:5362730) > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United > > Kingdom > > ********************************************************************** > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > -- > > Messaggio verificato dal servizio antivirus di Database Informatica > > > > > > -- > > Messaggio verificato dal servizio antivirus di Database Informatica > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error you > must take no action based on them, nor must you copy or show them to > anyone. > Please advise the sender by replying to this e-mail immediately and then > delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of the > author and unless specifically stated to the contrary, are not necessarily > those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, > you > should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United > Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > Messaggio verificato dal servizio antivirus di Database Informatica > > > -- > Messaggio verificato dal servizio antivirus di Database Informatica > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- Messaggio verificato dal servizio antivirus di Database Informatica -- Messaggio verificato dal servizio antivirus di Database Informatica From mogens at fumlersoft.dk Mon May 14 16:23:27 2007 From: mogens at fumlersoft.dk (Mogens Melander) Date: Mon May 14 16:23:41 2007 Subject: Mqueue.in growing In-Reply-To: <6DEF8ABC1767C045B91F42066D36358E9225@HOUPEX01.nfsmith.info> References: <46483AAB.7040800@coders.co.uk><1179139216.12949.8.camel@gblades-suse.linguaphone-intranet.co.uk><04d401c79621$10172d30$0301a8c0@SAHOMELT> <00d501c79631$d7117d40$3f01a8c0@dbdomain.database.it> <6DEF8ABC1767C045B91F42066D36358E9225@HOUPEX01.nfsmith.info> Message-ID: <4035.90.184.17.152.1179156207.squirrel@mail.fumlersoft.dk> On Mon, May 14, 2007 16:15, Mike Kercher wrote: > Marcello Anderlini <> wrote on Monday, May 14, 2007 9:12 AM: > > : Sorry, I made a mistake writing spamassassin -D -lint -p > : /etc/MailScanner/spam.assassin.prefs.conf, if I write spamassassin -D > : --lint -p /etc/MailScanner/spam.assassin.prefs.conf, it continues but > : I still can NOT understand why it's so slow. > : -- > > When I run it, I get: > > [3262] dbg: dns: no ipv6 > [3262] dbg: dns: is Net::DNS::Resolver available? yes > [3262] dbg: dns: Net::DNS version: 0.59 > > You might try updating your Net::DNS and see if that helps. 0.59 is the latest on CPAN ... -- Later Mogens Melander +45 40 85 71 38 +66 870 133 224 -- This message has been scanned for viruses and dangerous content by OpenProtect(http://www.openprotect.com), and is believed to be clean. From mogens at fumlersoft.dk Mon May 14 17:08:48 2007 From: mogens at fumlersoft.dk (Mogens Melander) Date: Mon May 14 17:08:56 2007 Subject: R: Mqueue.in growing In-Reply-To: <00e901c79638$952f52b0$3f01a8c0@dbdomain.database.it> References: <00d801c79637$2ed42050$3f01a8c0@dbdomain.database.it> <6e47fac3597ec8419c3cb6dfe92b3a0a@solidstatelogic.com> <00e901c79638$952f52b0$3f01a8c0@dbdomain.database.it> Message-ID: <4121.90.184.17.152.1179158928.squirrel@mail.fumlersoft.dk> On Mon, May 14, 2007 17:00, Marcello Anderlini wrote: > Thanks for all, but where I can found Message.pm Mine was lurking in: /usr/lib/perl5/site_perl/5.8.4/Mail/SpamAssassin/Message.pm but a "locate Message.pm | grep SpamAssassin" should give you a hint. > ? And also why it was working well until this morning ? ?^) > > bye > -- Later Mogens Melander +45 40 85 71 38 +66 870 133 224 -- This message has been scanned for viruses and dangerous content by OpenProtect(http://www.openprotect.com), and is believed to be clean. From MailScanner at ecs.soton.ac.uk Mon May 14 17:11:54 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 14 17:12:51 2007 Subject: Mqueue.in growing In-Reply-To: References: Message-ID: <46488A4A.8070409@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Martin, How much of a speed difference does this fix make? martinh@solidstatelogic.com wrote: > Mike > > There's a fair chance you've got hit by the use bytes bug in SA 3.2.0. > > Find the Message.pm in the perl path for sa 3.2.0 > > Just below "use warnings;" add a newline... > > use bytes; > > this should sort the problem as long as your not using the > normalize_charset functionality in SA. If you are you're stuffed and > will have to go back to 3.1.8. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Mike Kercher >> Sent: 14 May 2007 15:25 >> To: MailScanner discussion >> Subject: RE: Mqueue.in growing >> >> martinh@solidstatelogic.com <> wrote on Monday, May 14, 2007 9:25 AM: >> >> : Marcello >> : >> : What version of perl. There's an issue with SA 3.2.0 and perl < >> : 5.8.8, and a workaround.... >> : >> : -- >> >> This is perl, v5.8.5 built for i386-linux-thread-multi >> >> This is on CentOS 4.4 as well. >> >> -Mike >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGSIpOEfZZRxQVtlQRAgmWAKCeyPjmVsedL/V3pUPyGWX9+BKuRwCgwnoz Q9qcpDpUT6xpn2SwxU+0MTg= =zNii -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From mikael at syska.dk Mon May 14 17:13:54 2007 From: mikael at syska.dk (Mikael Syska) Date: Mon May 14 17:14:43 2007 Subject: Mqueue.in growing In-Reply-To: <00d401c79631$156716f0$3f01a8c0@dbdomain.database.it> References: <46483AAB.7040800@coders.co.uk><1179139216.12949.8.camel@gblades-suse.linguaphone-intranet.co.uk> <04d401c79621$10172d30$0301a8c0@SAHOMELT> <00d401c79631$156716f0$3f01a8c0@dbdomain.database.it> Message-ID: <46488AC2.5080701@syska.dk> Please dont start a message with replying to an old subject ... It brakes the tree structure in Thunderbird and also the online mail archive ... Now all the messges is in the same tree as "Re: Does anyone catch this...." // ouT Marcello Anderlini wrote: > Hello to all, some time ago I've already post this question, It seemed I've > solved the problem but this morning it compare again. > > I'm using centos 4.4 with kernel 2.6.9-42.0.10.Elsmp, mailscanner 4.58.9.1, > spamassassin 3.2.0.1.el4.rf. > Razor, pyzor, dcc and fuzzy_ocr. > > Without changing anything on my configuration, suddendly this morning the > mqueue.in start to grow until 4000 msg. I've tried to remove mailscanner rbl > check e and I've set skip_rbl_checks 1 in spam.assassin.pref.conf but > without success. > > I've check in /root/.spamassassin folder and I found some lock file so I set > Rebuild Bayes Every = 86400. > > When I try spamassassin -D -lint -p /etc/MailScanner/spam.assassin.prefs.con > I get : > ========= > [26122] warn: The -l option has been deprecated and is no longer supported, > ignoring. > [26122] dbg: logger: adding facilities: all > [26122] dbg: logger: logging level is DBG > [26122] dbg: generic: SpamAssassin version 3.2.0 > [26122] dbg: config: score set 0 chosen. > [26122] dbg: util: running in taint mode? yes > [26122] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH > [26122] dbg: util: PATH included '/usr/kerberos/sbin', keeping > [26122] dbg: util: PATH included '/usr/kerberos/bin', keeping > [26122] dbg: util: PATH included '/usr/local/sbin', keeping > [26122] dbg: util: PATH included '/usr/local/bin', keeping > [26122] dbg: util: PATH included '/sbin', keeping > [26122] dbg: util: PATH included '/bin', keeping > [26122] dbg: util: PATH included '/usr/sbin', keeping > [26122] dbg: util: PATH included '/usr/bin', keeping > [26122] dbg: util: PATH included '/usr/X11R6/bin', keeping > [26122] dbg: util: PATH included '/root/bin', which doesn't exist, dropping > [26122] dbg: util: final PATH set to: > /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b > in:/usr/sbin:/usr/bin:/usr/X11R6/bin > [26122] dbg: dns: no ipv6 > [26122] dbg: dns: is Net::DNS::Resolver available? yes > [26122] dbg: dns: Net::DNS version: 0.48 > ========= > > And it seemed to stop, what can be ? Could you help me ? > > Thanks a lot > > > From prandal at herefordshire.gov.uk Mon May 14 16:52:29 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Mon May 14 17:17:42 2007 Subject: Mqueue.in growing In-Reply-To: <00e901c79638$952f52b0$3f01a8c0@dbdomain.database.it> References: <00d801c79637$2ed42050$3f01a8c0@dbdomain.database.it><6e47fac3597ec8419c3cb6dfe92b3a0a@solidstatelogic.com> <00e901c79638$952f52b0$3f01a8c0@dbdomain.database.it> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBAB25310@HC-MBX02.herefordshire.gov.uk> MailScanner seems slower here today too (using SA 3.1.8). I suspect that one of the RBLs has gone slow or is timing out. I haven't had a chance to debug it. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Marcello Anderlini > Sent: 14 May 2007 16:00 > To: 'MailScanner discussion' > Subject: R: Mqueue.in growing > > Thanks for all, but where I can found Message.pm ? And also > why it was > working well until this morning ? > > bye > > -----Messaggio originale----- > Da: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di > martinh@solidstatelogic.com > Inviato: luned? 14 maggio 2007 16.57 > A: MailScanner discussion > Oggetto: RE: Mqueue.in growing > > Marcello > > You - you need to Message.pm for spamassassin 3.2.0 and edit as below > > (don't worry about you're English skills - much better than any other > language I use). > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Marcello Anderlini > > Sent: 14 May 2007 15:50 > > To: MailScanner discussion > > Subject: R: Mqueue.in growing > > > > Sorry again, but this suggestion is for me or just for Mike > Kercher ? > > > > -----Messaggio originale----- > > Da: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di > > martinh@solidstatelogic.com > > Inviato: luned? 14 maggio 2007 16.34 > > A: MailScanner discussion > > Oggetto: RE: Mqueue.in growing > > > > Mike > > > > There's a fair chance you've got hit by the use bytes bug > in SA 3.2.0. > > > > Find the Message.pm in the perl path for sa 3.2.0 > > > > Just below "use warnings;" add a newline... > > > > use bytes; > > > > this should sort the problem as long as your not using the > > normalize_charset functionality in SA. If you are you're > stuffed and > > will have to go > back to > > 3.1.8. > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- > > > bounces@lists.mailscanner.info] On Behalf Of Mike Kercher > > > Sent: 14 May 2007 15:25 > > > To: MailScanner discussion > > > Subject: RE: Mqueue.in growing > > > > > > martinh@solidstatelogic.com <> wrote on Monday, May 14, 2007 9:25 > AM: > > > > > > : Marcello > > > : > > > : What version of perl. There's an issue with SA 3.2.0 and perl < > > > : 5.8.8, and a workaround.... > > > : > > > : -- > > > > > > This is perl, v5.8.5 built for i386-linux-thread-multi > > > > > > This is on CentOS 4.4 as well. > > > > > > -Mike > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are > intended for the > > addressee only and may be confidential. If they come to you in error > you > > must take no action based on them, nor must you copy or > show them to > > anyone. > > Please advise the sender by replying to this e-mail immediately and > then > > delete the original from your computer. > > > > Opinion : Any opinions expressed in this e-mail are > entirely those of > the > > author and unless specifically stated to the contrary, are not > necessarily > > those of the author's employer. > > > > Security Warning : Internet e-mail is not necessarily a secure > > communications medium and can be subject to data > corruption. We advise > > that you consider this fact when e-mailing us. > > > > Viruses : We have taken steps to ensure that this e-mail and any > > attachments are free from known viruses but in keeping with good > > computing > practice, > > you > > should ensure that they are virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic > > Registered as a limited company in England and Wales (Company > No:5362730) > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United > > Kingdom > > > ********************************************************************** > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > -- > > Messaggio verificato dal servizio antivirus di Database Informatica > > > > > > -- > > Messaggio verificato dal servizio antivirus di Database Informatica > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you > in error you > must take no action based on them, nor must you copy or show > them to anyone. > Please advise the sender by replying to this e-mail > immediately and then > delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely > those of the > author and unless specifically stated to the contrary, are > not necessarily > those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. > We advise that > you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and > any attachments > are free from known viruses but in keeping with good > computing practice, you > should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales (Company > No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 > 1RU, United > Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > Messaggio verificato dal servizio antivirus di Database Informatica > > > -- > Messaggio verificato dal servizio antivirus di Database Informatica > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From martinh at solidstatelogic.com Mon May 14 17:18:30 2007 From: martinh at solidstatelogic.com (martinh@solidstatelogic.com) Date: Mon May 14 17:18:35 2007 Subject: Mqueue.in growing In-Reply-To: <46488A4A.8070409@ecs.soton.ac.uk> Message-ID: <2fd0e0b8d5042144bb688dcac3b73725@solidstatelogic.com> Jules We'll the problem is that SA spews errors (lots of them) and chokes syslog with them. Hence the whole thing slows downs to a crawl. People have reported this as 'SA very slow' and this seems to be the workaround. It only effects people running perl < 5.8.8 AND the SARE rulsets. Apparently both the SARE and SA folks are working on a fix. So we should see a 3.2.1 and new SARE rules at some stage. The 'workaround' stops all the errors and therefore restores performance levels, but can have an impact if you are using lots of different languages and normalising these charsets into the base language. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Julian Field > Sent: 14 May 2007 17:12 > To: MailScanner discussion > Subject: Re: Mqueue.in growing > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Martin, > > How much of a speed difference does this fix make? > > martinh@solidstatelogic.com wrote: > > Mike > > > > There's a fair chance you've got hit by the use bytes bug in SA 3.2.0. > > > > Find the Message.pm in the perl path for sa 3.2.0 > > > > Just below "use warnings;" add a newline... > > > > use bytes; > > > > this should sort the problem as long as your not using the > > normalize_charset functionality in SA. If you are you're stuffed and > > will have to go back to 3.1.8. > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > > > >> -----Original Message----- > >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > >> bounces@lists.mailscanner.info] On Behalf Of Mike Kercher > >> Sent: 14 May 2007 15:25 > >> To: MailScanner discussion > >> Subject: RE: Mqueue.in growing > >> > >> martinh@solidstatelogic.com <> wrote on Monday, May 14, 2007 9:25 AM: > >> > >> : Marcello > >> : > >> : What version of perl. There's an issue with SA 3.2.0 and perl < > >> : 5.8.8, and a workaround.... > >> : > >> : -- > >> > >> This is perl, v5.8.5 built for i386-linux-thread-multi > >> > >> This is on CentOS 4.4 as well. > >> > >> -Mike > >> -- > >> MailScanner mailing list > >> mailscanner@lists.mailscanner.info > >> http://lists.mailscanner.info/mailman/listinfo/mailscanner > >> > >> Before posting, read http://wiki.mailscanner.info/posting > >> > >> Support MailScanner development - buy the book off the website! > >> > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are intended for the > > addressee only and may be confidential. If they come to you in error > > you must take no action based on them, nor must you copy or show them > > to anyone. Please advise the sender by replying to this e-mail > > immediately and then delete the original from your computer. > > > > Opinion : Any opinions expressed in this e-mail are entirely those of > > the author and unless specifically stated to the contrary, are not > > necessarily those of the author's employer. > > > > Security Warning : Internet e-mail is not necessarily a secure > > communications medium and can be subject to data corruption. We advise > > that you consider this fact when e-mailing us. > > > > Viruses : We have taken steps to ensure that this e-mail and any > > attachments are free from known viruses but in keeping with good > > computing practice, you should ensure that they are virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic > > Registered as a limited company in England and Wales > > (Company No:5362730) > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > United Kingdom > > ********************************************************************** > > > > > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: ISO-8859-1 > > wj8DBQFGSIpOEfZZRxQVtlQRAgmWAKCeyPjmVsedL/V3pUPyGWX9+BKuRwCgwnoz > Q9qcpDpUT6xpn2SwxU+0MTg= > =zNii > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From m.anderlini at database.it Mon May 14 17:14:08 2007 From: m.anderlini at database.it (Marcello Anderlini) Date: Mon May 14 17:18:38 2007 Subject: R: Mqueue.in growing In-Reply-To: <00ea01c7963a$8b9b9f90$3f01a8c0@dbdomain.database.it> References: <00e901c79638$952f52b0$3f01a8c0@dbdomain.database.it><3822a92168130a42b2532496de4ea715@solidstatelogic.com> <00ea01c7963a$8b9b9f90$3f01a8c0@dbdomain.database.it> Message-ID: <00f901c79642$e685ba00$3f01a8c0@dbdomain.database.it> I've made the correction on Message.pm suggested and reset to use Pyzor and razor. For about 1/2 our it seemed worked well but now it's growing again. SA took about 320 secs. To process 23 msg, about 13 secs for msg. I think the problems it's regarding one of this plugin but I can not understand which is. Does someone else has timeout problem whith Pyzor or Razor ? How can I improve their perfomance ? Thanks again -----Messaggio originale----- Da: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di Marcello Anderlini Inviato: luned? 14 maggio 2007 17.14 A: 'MailScanner discussion' Oggetto: R: Mqueue.in growing I've upgraded to SA 3.2 on 03 May 2007. I really can't believe that it take so much time because meantime I've restarted mailscanner many times... Meantime I've cleaned the queue and disabled Pyzor and Razor and it seem it's going better.... -----Messaggio originale----- Da: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di martinh@solidstatelogic.com Inviato: luned? 14 maggio 2007 17.07 A: MailScanner discussion Oggetto: RE: Mqueue.in growing "locate Message.pm" will help..... Mine's at..... /usr/local/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Message.pm The problem is that it's error logging and this slows the whole thing down. When did you upgrade to 3.2.0? It could be the system was just coping before and now it's just got that little bit too busy and can't sope. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Marcello Anderlini > Sent: 14 May 2007 16:00 > To: MailScanner discussion > Subject: R: Mqueue.in growing > > Thanks for all, but where I can found Message.pm ? And also why it was > working well until this morning ? > > bye > > -----Messaggio originale----- > Da: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di > martinh@solidstatelogic.com > Inviato: luned? 14 maggio 2007 16.57 > A: MailScanner discussion > Oggetto: RE: Mqueue.in growing > > Marcello > > You - you need to Message.pm for spamassassin 3.2.0 and edit as below > > (don't worry about you're English skills - much better than any other > language I use). > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Marcello Anderlini > > Sent: 14 May 2007 15:50 > > To: MailScanner discussion > > Subject: R: Mqueue.in growing > > > > Sorry again, but this suggestion is for me or just for Mike Kercher ? > > > > -----Messaggio originale----- > > Da: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di > > martinh@solidstatelogic.com > > Inviato: luned? 14 maggio 2007 16.34 > > A: MailScanner discussion > > Oggetto: RE: Mqueue.in growing > > > > Mike > > > > There's a fair chance you've got hit by the use bytes bug in SA 3.2.0. > > > > Find the Message.pm in the perl path for sa 3.2.0 > > > > Just below "use warnings;" add a newline... > > > > use bytes; > > > > this should sort the problem as long as your not using the > > normalize_charset functionality in SA. If you are you're stuffed and > > will have to go > back to > > 3.1.8. > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- > > > bounces@lists.mailscanner.info] On Behalf Of Mike Kercher > > > Sent: 14 May 2007 15:25 > > > To: MailScanner discussion > > > Subject: RE: Mqueue.in growing > > > > > > martinh@solidstatelogic.com <> wrote on Monday, May 14, 2007 9:25 > AM: > > > > > > : Marcello > > > : > > > : What version of perl. There's an issue with SA 3.2.0 and perl < > > > : 5.8.8, and a workaround.... > > > : > > > : -- > > > > > > This is perl, v5.8.5 built for i386-linux-thread-multi > > > > > > This is on CentOS 4.4 as well. > > > > > > -Mike > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are intended for the > > addressee only and may be confidential. If they come to you in error > you > > must take no action based on them, nor must you copy or show them to > > anyone. > > Please advise the sender by replying to this e-mail immediately and > then > > delete the original from your computer. > > > > Opinion : Any opinions expressed in this e-mail are entirely those of > the > > author and unless specifically stated to the contrary, are not > necessarily > > those of the author's employer. > > > > Security Warning : Internet e-mail is not necessarily a secure > > communications medium and can be subject to data corruption. We advise > > that you consider this fact when e-mailing us. > > > > Viruses : We have taken steps to ensure that this e-mail and any > > attachments are free from known viruses but in keeping with good > > computing > practice, > > you > > should ensure that they are virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic Registered as a limited > > company in England and Wales (Company > No:5362730) > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United > > Kingdom > > ********************************************************************** > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > -- > > Messaggio verificato dal servizio antivirus di Database Informatica > > > > > > -- > > Messaggio verificato dal servizio antivirus di Database Informatica > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error you > must take no action based on them, nor must you copy or show them to > anyone. > Please advise the sender by replying to this e-mail immediately and then > delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of the > author and unless specifically stated to the contrary, are not necessarily > those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, > you > should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United > Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > Messaggio verificato dal servizio antivirus di Database Informatica > > > -- > Messaggio verificato dal servizio antivirus di Database Informatica > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- Messaggio verificato dal servizio antivirus di Database Informatica -- Messaggio verificato dal servizio antivirus di Database Informatica -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- Messaggio verificato dal servizio antivirus di Database Informatica From martinh at solidstatelogic.com Mon May 14 17:22:36 2007 From: martinh at solidstatelogic.com (martinh@solidstatelogic.com) Date: Mon May 14 17:23:41 2007 Subject: Mqueue.in growing In-Reply-To: <00f901c79642$e685ba00$3f01a8c0@dbdomain.database.it> Message-ID: <6057201acfd169428f6ec9bbe29282b2@solidstatelogic.com> Marcello Could be your pyzor setup. I've got the following in my .pyzor/servers 82.94.255.100:24441 As the default pyzor is completely overloaded and whoever used to maintain pyzor doesn't seem to be doing anything. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Marcello Anderlini > Sent: 14 May 2007 17:14 > To: MailScanner discussion > Subject: R: Mqueue.in growing > > I've made the correction on Message.pm suggested and reset to use Pyzor > and > razor. > For about 1/2 our it seemed worked well but now it's growing again. > SA took about 320 secs. To process 23 msg, about 13 secs for msg. I think > the problems it's regarding one of this plugin but I can not understand > which is. Does someone else has timeout problem whith Pyzor or Razor ? How > can I improve their perfomance ? > > Thanks again > > -----Messaggio originale----- > Da: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di Marcello > Anderlini > Inviato: luned? 14 maggio 2007 17.14 > A: 'MailScanner discussion' > Oggetto: R: Mqueue.in growing > > I've upgraded to SA 3.2 on 03 May 2007. I really can't believe that it > take > so much time because meantime I've restarted mailscanner many times... > Meantime I've cleaned the queue and disabled Pyzor and Razor and it seem > it's going better.... > > -----Messaggio originale----- > Da: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di > martinh@solidstatelogic.com > Inviato: luned? 14 maggio 2007 17.07 > A: MailScanner discussion > Oggetto: RE: Mqueue.in growing > > "locate Message.pm" will help..... > > Mine's at..... > > /usr/local/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/Message.pm > > The problem is that it's error logging and this slows the whole thing > down. > When did you upgrade to 3.2.0? It could be the system was just coping > before > and now it's just got that little bit too busy and can't sope. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Marcello Anderlini > > Sent: 14 May 2007 16:00 > > To: MailScanner discussion > > Subject: R: Mqueue.in growing > > > > Thanks for all, but where I can found Message.pm ? And also why it > was > > working well until this morning ? > > > > bye > > > > -----Messaggio originale----- > > Da: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di > > martinh@solidstatelogic.com > > Inviato: luned? 14 maggio 2007 16.57 > > A: MailScanner discussion > > Oggetto: RE: Mqueue.in growing > > > > Marcello > > > > You - you need to Message.pm for spamassassin 3.2.0 and edit as below > > > > (don't worry about you're English skills - much better than any other > > language I use). > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- > > > bounces@lists.mailscanner.info] On Behalf Of Marcello Anderlini > > > Sent: 14 May 2007 15:50 > > > To: MailScanner discussion > > > Subject: R: Mqueue.in growing > > > > > > Sorry again, but this suggestion is for me or just for Mike Kercher > ? > > > > > > -----Messaggio originale----- > > > Da: mailscanner-bounces@lists.mailscanner.info > > > [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di > > > martinh@solidstatelogic.com > > > Inviato: luned? 14 maggio 2007 16.34 > > > A: MailScanner discussion > > > Oggetto: RE: Mqueue.in growing > > > > > > Mike > > > > > > There's a fair chance you've got hit by the use bytes bug in SA > 3.2.0. > > > > > > Find the Message.pm in the perl path for sa 3.2.0 > > > > > > Just below "use warnings;" add a newline... > > > > > > use bytes; > > > > > > this should sort the problem as long as your not using the > > > normalize_charset functionality in SA. If you are you're stuffed and > > > will have to go > > back to > > > 3.1.8. > > > > > > -- > > > Martin Hepworth > > > Snr Systems Administrator > > > Solid State Logic > > > Tel: +44 (0)1865 842300 > > > > > > > -----Original Message----- > > > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner- > > > > bounces@lists.mailscanner.info] On Behalf Of Mike Kercher > > > > Sent: 14 May 2007 15:25 > > > > To: MailScanner discussion > > > > Subject: RE: Mqueue.in growing > > > > > > > > martinh@solidstatelogic.com <> wrote on Monday, May 14, 2007 9:25 > > AM: > > > > > > > > : Marcello > > > > : > > > > : What version of perl. There's an issue with SA 3.2.0 and perl < > > > > : 5.8.8, and a workaround.... > > > > : > > > > : -- > > > > > > > > This is perl, v5.8.5 built for i386-linux-thread-multi > > > > > > > > This is on CentOS 4.4 as well. > > > > > > > > -Mike > > > > -- > > > > MailScanner mailing list > > > > mailscanner@lists.mailscanner.info > > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > > > > > > > ********************************************************************** > > > Confidentiality : This e-mail and any attachments are intended for > the > > > addressee only and may be confidential. If they come to you in error > > you > > > must take no action based on them, nor must you copy or show them to > > > anyone. > > > Please advise the sender by replying to this e-mail immediately and > > then > > > delete the original from your computer. > > > > > > Opinion : Any opinions expressed in this e-mail are entirely those > of > > the > > > author and unless specifically stated to the contrary, are not > > necessarily > > > those of the author's employer. > > > > > > Security Warning : Internet e-mail is not necessarily a secure > > > communications medium and can be subject to data corruption. We > advise > > > that you consider this fact when e-mailing us. > > > > > > Viruses : We have taken steps to ensure that this e-mail and any > > > attachments are free from known viruses but in keeping with good > > > computing > > practice, > > > you > > > should ensure that they are virus free. > > > > > > Red Lion 49 Ltd T/A Solid State Logic Registered as a limited > > > company in England and Wales (Company > > No:5362730) > > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > United > > > Kingdom > > > > ********************************************************************** > > > > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > > > > > -- > > > Messaggio verificato dal servizio antivirus di Database Informatica > > > > > > > > > -- > > > Messaggio verificato dal servizio antivirus di Database Informatica > > > > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are intended for the > > addressee only and may be confidential. If they come to you in error > you > > must take no action based on them, nor must you copy or show them to > > anyone. > > Please advise the sender by replying to this e-mail immediately and > then > > delete the original from your computer. > > > > Opinion : Any opinions expressed in this e-mail are entirely those of > the > > author and unless specifically stated to the contrary, are not > necessarily > > those of the author's employer. > > > > Security Warning : Internet e-mail is not necessarily a secure > > communications medium and can be subject to data corruption. We advise > > that you consider this fact when e-mailing us. > > > > Viruses : We have taken steps to ensure that this e-mail and any > > attachments are free from known viruses but in keeping with good > > computing > practice, > > you > > should ensure that they are virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic > > Registered as a limited company in England and Wales (Company > No:5362730) > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United > > Kingdom > > ********************************************************************** > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > -- > > Messaggio verificato dal servizio antivirus di Database Informatica > > > > > > -- > > Messaggio verificato dal servizio antivirus di Database Informatica > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error you > must take no action based on them, nor must you copy or show them to > anyone. > Please advise the sender by replying to this e-mail immediately and then > delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of the > author and unless specifically stated to the contrary, are not necessarily > those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that > you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments > are free from known viruses but in keeping with good computing practice, > you > should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United > Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > Messaggio verificato dal servizio antivirus di Database Informatica > > > -- > Messaggio verificato dal servizio antivirus di Database Informatica > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > -- > Messaggio verificato dal servizio antivirus di Database Informatica > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From Kevin_Miller at ci.juneau.ak.us Mon May 14 17:24:49 2007 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Mon May 14 17:24:36 2007 Subject: Mqueue.in growing In-Reply-To: <00f901c79642$e685ba00$3f01a8c0@dbdomain.database.it> References: <00e901c79638$952f52b0$3f01a8c0@dbdomain.database.it><3822a92168130a42b2532496de4ea715@solidstatelogic.com><00ea01c7963a$8b9b9f90$3f01a8c0@dbdomain.database.it> <00f901c79642$e685ba00$3f01a8c0@dbdomain.database.it> Message-ID: Marcello Anderlini wrote: > I've made the correction on Message.pm suggested and reset to use > Pyzor and razor. > For about 1/2 our it seemed worked well but now it's growing again. > SA took about 320 secs. To process 23 msg, about 13 secs for msg. I > think the problems it's regarding one of this plugin but I can not > understand which is. Does someone else has timeout problem whith > Pyzor or Razor ? How can I improve their perfomance ? > > Thanks again Marcello, Pyzor has a file called servers - mine's in /root/.pyzor - which tells pyzor what server to use. The default one is not reliable. Many of us have changed it to the following entry: 82.94.255.100:24441 You might try that. Pyzor has cron job that will reset the server to the old default. Make sure you disable that or tomorrow you'll be pointing to the old server again. Also make sure that the necessary ports are open on your firewall for both pyzor and razor. That could cause timeouts if they're not set right. Hope this helps... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From m.anderlini at database.it Mon May 14 18:04:54 2007 From: m.anderlini at database.it (Marcello Anderlini) Date: Mon May 14 18:04:59 2007 Subject: R: Mqueue.in growing In-Reply-To: References: <00e901c79638$952f52b0$3f01a8c0@dbdomain.database.it><3822a92168130a42b2532496de4ea715@solidstatelogic.com><00ea01c7963a$8b9b9f90$3f01a8c0@dbdomain.database.it><00f901c79642$e685ba00$3f01a8c0@dbdomain.database.it> Message-ID: <010301c79649$fe419b80$3f01a8c0@dbdomain.database.it> I'm not behind a firewall,if I try to telnet 82.94.255.100 24441 I get telnet: connect to address 82.94.255.100: Connection refused. Is it normal or I should get an answer of any kind ? Are there other pyzor servers ? thanks -----Messaggio originale----- Da: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di Kevin Miller Inviato: luned? 14 maggio 2007 18.25 A: MailScanner discussion Oggetto: RE: Mqueue.in growing Marcello Anderlini wrote: > I've made the correction on Message.pm suggested and reset to use > Pyzor and razor. > For about 1/2 our it seemed worked well but now it's growing again. > SA took about 320 secs. To process 23 msg, about 13 secs for msg. I > think the problems it's regarding one of this plugin but I can not > understand which is. Does someone else has timeout problem whith Pyzor > or Razor ? How can I improve their perfomance ? > > Thanks again Marcello, Pyzor has a file called servers - mine's in /root/.pyzor - which tells pyzor what server to use. The default one is not reliable. Many of us have changed it to the following entry: 82.94.255.100:24441 You might try that. Pyzor has cron job that will reset the server to the old default. Make sure you disable that or tomorrow you'll be pointing to the old server again. Also make sure that the necessary ports are open on your firewall for both pyzor and razor. That could cause timeouts if they're not set right. Hope this helps... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- Messaggio verificato dal servizio antivirus di Database Informatica -- Messaggio verificato dal servizio antivirus di Database Informatica From alex at nkpanama.com Mon May 14 18:25:52 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Mon May 14 18:26:45 2007 Subject: R: Mqueue.in growing In-Reply-To: <010301c79649$fe419b80$3f01a8c0@dbdomain.database.it> References: <00e901c79638$952f52b0$3f01a8c0@dbdomain.database.it><3822a92168130a42b2532496de4ea715@solidstatelogic.com><00ea01c7963a$8b9b9f90$3f01a8c0@dbdomain.database.it><00f901c79642$e685ba00$3f01a8c0@dbdomain.database.it> <010301c79649$fe419b80$3f01a8c0@dbdomain.database.it> Message-ID: <46489BA0.6020903@nkpanama.com> AFAIK it's UDP so telnet shouldn't work, I think... Marcello Anderlini wrote: > I'm not behind a firewall,if I try to telnet 82.94.255.100 24441 I get > telnet: connect to address 82.94.255.100: Connection refused. Is it normal > or I should get an answer of any kind ? Are there other pyzor servers ? > > thanks > > -----Messaggio originale----- > Da: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Per conto di Kevin > Miller > Inviato: luned? 14 maggio 2007 18.25 > A: MailScanner discussion > Oggetto: RE: Mqueue.in growing > > Marcello Anderlini wrote: > >> I've made the correction on Message.pm suggested and reset to use >> Pyzor and razor. >> For about 1/2 our it seemed worked well but now it's growing again. >> SA took about 320 secs. To process 23 msg, about 13 secs for msg. I >> think the problems it's regarding one of this plugin but I can not >> understand which is. Does someone else has timeout problem whith Pyzor >> or Razor ? How can I improve their perfomance ? >> >> Thanks again >> > > Marcello, > > Pyzor has a file called servers - mine's in /root/.pyzor - which tells pyzor > what server to use. The default one is not reliable. Many of us have > changed it to the following entry: > 82.94.255.100:24441 > > You might try that. Pyzor has cron job that will reset the server to the > old default. Make sure you disable that or tomorrow you'll be pointing to > the old server again. > > Also make sure that the necessary ports are open on your firewall for both > pyzor and razor. That could cause timeouts if they're not set right. > > Hope this helps... > > ...Kevin > From ssilva at sgvwater.com Mon May 14 18:31:08 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 14 18:31:29 2007 Subject: Does anyone catch this.... In-Reply-To: <46483AAB.7040800__11850.3815414899$1179138645$gmane$org@coders.co.uk> References: <46483AAB.7040800__11850.3815414899$1179138645$gmane$org@coders.co.uk> Message-ID: Matt Hampton spake the following on 5/14/2007 3:32 AM: > http://www.coders.co.uk/slipped.through.txt > > It has sailed through both a SA3.1.8 and SA3.2.0 (3.2.0-pre2-r512851) > running on recent versions of MailScanner > > cheers > > Matt > > [27458] dbg: learn: auto-learn? no: inside auto-learn thresholds, not considered ham or spam [27458] dbg: check: is spam? score=9.602 required=5 [27458] dbg: check: tests=BAYES_99,FORGED_RCVD_HELO,HTML_MESSAGE,MIME_HTML_ONLY,RAZOR2_CHECK,REPLY_TO_EMPTY [27458] dbg: check: subtests=__BOTNET_NOTRUST,__CT,__CTE,__CTYPE_HTML,__HAS_MSGID,__HAS_RCVD,__HAS_SUBJECT, __LOCAL_PP_B_UPD,__LOCAL_PP_NONPPURL,__MIME_HTML,__MIME_VERSION,__MSGID_OK_DIGITS,__NAKED_TO, __NONEMPTY_BODY,__RCVD_IN_NERDS,__SANE_MSGID,__SARE_BLACK_FG_COLOR,__SARE_BODY_BLNK_5_100, __SARE_FRAUD_MONEY,__SARE_HAS_BG_COLOR,__SARE_HAS_FG_COLOR,__SARE_HTML_HAS_A,__SARE_HTML_HAS_BR, __SARE_HTML_HAS_DIV,__SARE_HTML_HAS_FONT,__SARE_HTML_HAS_IMG,__SARE_HTML_HAS_P,__SARE_META_MURTY3, __SARE_URI_ANY,__SARE_WHITELIST_FLAG,__TAG_EXISTS_HTML,__TOCC_EXISTS -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From rpoe at plattesheriff.org Mon May 14 19:46:29 2007 From: rpoe at plattesheriff.org (Rob Poe) Date: Mon May 14 19:48:00 2007 Subject: Interesting need In-Reply-To: <223f97700705071442w106785bu1a9a50405476f9cb@mail.gmail.com> References: <463F0518.65ED.00A2.0@plattesheriff.org> <463F5C10.7080307@ecs.soton.ac.uk> <463F7783.7070608@nkpanama.com> <463F822E.2010108@ecs.soton.ac.uk> <223f97700705071442w106785bu1a9a50405476f9cb@mail.gmail.com> Message-ID: <4648683F.65ED.00A2.0@plattesheriff.org> >>> Archive mail "forwards" email? I thought it only "archived" it... >> RTFM my friend :-) >Yes I did, and I have a question...Wouldn't using Archive Mail >forwarding include all the spam etc? Yes, it does. This was brought to me by an admin assistant to a lawyer, who expects that all of his email gets delivered to both of them. I had a rule set up in their email system to do such a thing, but if he opens the email BEFORE the rule fires, it's no longer "unopened" and doesn't forward. Even though it's NOT supposed to work like that -- it does .. bug or feature. So using Jules' suggestion, I put it in and it works beautifully. The admin assistant complained she was now receiving more spam than she used to (duuuh!), and I explained why she was. She wanted "something done about it". I explained to her that her boss wanted as FEW spam controls as possible, as their clients don't admin their own email systems, and rely on brain-dead admins (or brain-dead shared mail systems) who can't configure mail software or domains to RFC specs - and thus get flagged as spam. Since he's involved in multi-billion dollar deals for his clients, I turned many of the big spam rules off for them - and they do get spam. It's the whole "can't have cake and eat it too" things.. From leiw324 at yahoo.com.hk Tue May 15 03:02:05 2007 From: leiw324 at yahoo.com.hk (Wilson Kwok) Date: Tue May 15 03:02:11 2007 Subject: How to upgrade MailScanner ? Message-ID: <586285.48912.qm@web54409.mail.yahoo.com> Anyone can tell me the upgrade step ? Thanks --------------------------------- ²{¦b§A¥i»´©öªý¾×©U§£¶l¥ó¡A¥ß§Y¨Ï¥ÎYahoo! Mail §A´N·|¬Û«H! -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070515/2d14a29b/attachment.html From res at ausics.net Tue May 15 03:36:49 2007 From: res at ausics.net (Res) Date: Tue May 15 03:36:57 2007 Subject: How to upgrade MailScanner ? In-Reply-To: <586285.48912.qm@web54409.mail.yahoo.com> References: <586285.48912.qm@web54409.mail.yahoo.com> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Tue, 15 May 2007, Wilson Kwok wrote: > Anyone can tell me the upgrade step ? > > Are you using RPM or source ? > Thanks > > > --------------------------------- > ²{¦b§A¥i»´©öªý¾×©U§£¶l¥ó¡A¥ß§Y¨Ï¥ÎYahoo! Mail §A´N·|¬Û«H! - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGSRzDsWhAmSIQh7MRAivUAJwJ8Y3/RVZDWlvpzXhfJ3GpjQ9YAgCfQ4gH YwZ5JYFOZCdmhCDSUWgEXv0= =YHeQ -----END PGP SIGNATURE----- From ugob at lubik.ca Tue May 15 04:16:11 2007 From: ugob at lubik.ca (Ugo Bellavance) Date: Tue May 15 04:16:30 2007 Subject: How to upgrade MailScanner ? In-Reply-To: <586285.48912.qm@web54409.mail.yahoo.com> References: <586285.48912.qm@web54409.mail.yahoo.com> Message-ID: Wilson Kwok wrote: > Anyone can tell me the upgrade step ? Please see the MAQ section of the MailScanner Wiki (http://wiki.mailscanner.info) Ugo From jim.barber at ddihealth.com Tue May 15 04:28:15 2007 From: jim.barber at ddihealth.com (Jim Barber) Date: Tue May 15 04:28:51 2007 Subject: Does anyone catch this.... In-Reply-To: <46483AAB.7040800@coders.co.uk> References: <46483AAB.7040800@coders.co.uk> Message-ID: <464928CF.30005@ddihealth.com> Matt Hampton wrote: > http://www.coders.co.uk/slipped.through.txt > > It has sailed through both a SA3.1.8 and SA3.2.0 (3.2.0-pre2-r512851) > running on recent versions of MailScanner Is the correct way to test this is as follows? spamassassin -p /etc/MailScanner/spam.assassin.prefs.conf -t < slipped.through.txt If so, then I get: Content analysis details: (1.1 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.6 REPLY_TO_EMPTY Reply-To: is empty 0.0 HTML_MESSAGE BODY: HTML included in message 0.0 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 0.5 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/) Using the Debian packaged install of Spamassassin 3.1.7 and mailscanner 4.58.9 ---------- Jim Barber DDI Health From jon.bates at summitmotors.com.au Tue May 15 07:38:39 2007 From: jon.bates at summitmotors.com.au (Jon Bates) Date: Tue May 15 07:38:51 2007 Subject: Quarantined Email Report to Recipient not working Message-ID: <200705150638.l4F6chpc000408@summitmotors.com.au> Hi, I was wondering if someone could help me quickly to figure out why a report is not being sent to the recipients of emails which exceed a size limit. I am setting the size limit with the "Maximum Message Size" option. Emails are being quarantined perfectly, and the sender.size.report.txt is being sent to the sender of the email perfectly as well. My issue is that -recipients- are not being notified that messages are being quarantined. I have the following set in my MailScanner.cf, and this report file does in fact exist: Stored Size Message Report = %report-dir%/stored.size.message.txt Unfortunately still no message is sent to the recipient. Can anyone offer any assistance? Cheers, Jon From uxbod at splatnix.net Tue May 15 09:19:39 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Tue May 15 09:19:44 2007 Subject: FPs and SA 3.2.0 Message-ID: <696e72b1c21ce7a6c8a34e2d1aded211@62.49.223.244> Hi, Not sure what is happening but I am seeing a lot of FPs at the moment where MailScanner is marking messages as "List in RBL" in MailWatch. How does this get triggered in MailScanner ? If I run the quarantined message through SA in debug mode it gets a score of 6.55, with the threshold set at 10 so it should not have been marked. Help! Thanks. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Tue May 15 09:37:19 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Tue May 15 09:37:23 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <696e72b1c21ce7a6c8a34e2d1aded211@62.49.223.244> References: <696e72b1c21ce7a6c8a34e2d1aded211@62.49.223.244> Message-ID: <1deab809ae576ec7b0786dd87eaa5003@62.49.223.244> I have a feeling that if one of the RBLs times out when a look is performed it is automatically being marked as SPAM. Julian could you provide some input please ? I have disabled all RBL checks for the time being and relying on Bayes and other rules while get to the bottom of this. On Tue, 15 May 2007 09:19:39 +0100, "--[ UxBoD ]--" wrote: > Hi, > > Not sure what is happening but I am seeing a lot of FPs at the moment > where MailScanner is marking messages as "List in RBL" in MailWatch. How > does this get triggered in MailScanner ? If I run the quarantined message > through SA in debug mode it gets a score of 6.55, with the threshold set at > 10 so it should not have been marked. > > Help! Thanks. > -- > --[ UxBoD ]-- > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From martinh at solidstatelogic.com Tue May 15 09:47:49 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Tue May 15 09:47:53 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <696e72b1c21ce7a6c8a34e2d1aded211@62.49.223.244> Message-ID: This in done inside mailscanner itself... Spam List = Is the setting you need to look for. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- > Sent: 15 May 2007 09:20 > To: mailscanner@lists.mailscanner.info > Subject: FPs and SA 3.2.0 > > Hi, > > Not sure what is happening but I am seeing a lot of FPs at the moment > where MailScanner is marking messages as "List in RBL" in MailWatch. How > does this get triggered in MailScanner ? If I run the quarantined message > through SA in debug mode it gets a score of 6.55, with the threshold set > at 10 so it should not have been marked. > > Help! Thanks. > -- > --[ UxBoD ]-- > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From uxbod at splatnix.net Tue May 15 10:00:26 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Tue May 15 10:01:24 2007 Subject: FPs and SA 3.2.0 In-Reply-To: References: Message-ID: Hi Martin, If I set Spam List = blank that all seems to work fine, as SA is then performing its own RBL lookup based on the ruleset. As soon as I set some RBLs in Spam List then all hell breaks out and I get a huge amount of FPs. Within the MailScanner code if a RBL lookup fails ie. timesout does it get marked as Spam ? Thanks, On Tue, 15 May 2007 09:47:49 +0100, "Martin.Hepworth" wrote: > This in done inside mailscanner itself... > > Spam List = > > Is the setting you need to look for. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- >> Sent: 15 May 2007 09:20 >> To: mailscanner@lists.mailscanner.info >> Subject: FPs and SA 3.2.0 >> >> Hi, >> >> Not sure what is happening but I am seeing a lot of FPs at the moment >> where MailScanner is marking messages as "List in RBL" in MailWatch. > How >> does this get triggered in MailScanner ? If I run the quarantined > message >> through SA in debug mode it gets a score of 6.55, with the threshold > set >> at 10 so it should not have been marked. >> >> Help! Thanks. >> -- >> --[ UxBoD ]-- >> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" >> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >> >> >> -- >> This message has been scanned for viruses and dangerous content by >> MailScanner, and is >> believed to be clean. >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Tue May 15 10:59:04 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Tue May 15 10:59:58 2007 Subject: FPs and SA 3.2.0 In-Reply-To: References: Message-ID: Hi Martin, Which RBLs are using for Spam List ? Thanks, On Tue, 15 May 2007 09:47:49 +0100, "Martin.Hepworth" wrote: > This in done inside mailscanner itself... > > Spam List = > > Is the setting you need to look for. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- >> Sent: 15 May 2007 09:20 >> To: mailscanner@lists.mailscanner.info >> Subject: FPs and SA 3.2.0 >> >> Hi, >> >> Not sure what is happening but I am seeing a lot of FPs at the moment >> where MailScanner is marking messages as "List in RBL" in MailWatch. > How >> does this get triggered in MailScanner ? If I run the quarantined > message >> through SA in debug mode it gets a score of 6.55, with the threshold > set >> at 10 so it should not have been marked. >> >> Help! Thanks. >> -- >> --[ UxBoD ]-- >> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" >> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >> >> >> -- >> This message has been scanned for viruses and dangerous content by >> MailScanner, and is >> believed to be clean. >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From martinh at solidstatelogic.com Tue May 15 11:06:03 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Tue May 15 11:06:00 2007 Subject: FPs and SA 3.2.0 In-Reply-To: Message-ID: <892b6d03f18d324d9a87cea1748a8d1b@solidstatelogic.com> I don't - I do all this from SA. I've been burnt by FP's on RBLS. It's better now you need X RBL's in MailScanner, but at the time some of the RBL's shutdown and marked ALL email as spam... -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- > Sent: 15 May 2007 10:59 > To: MailScanner discussion > Subject: RE: FPs and SA 3.2.0 > > Hi Martin, > > Which RBLs are using for Spam List ? > > Thanks, > > On Tue, 15 May 2007 09:47:49 +0100, "Martin.Hepworth" > wrote: > > This in done inside mailscanner itself... > > > > Spam List = > > > > Is the setting you need to look for. > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > >> -----Original Message----- > >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > >> bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- > >> Sent: 15 May 2007 09:20 > >> To: mailscanner@lists.mailscanner.info > >> Subject: FPs and SA 3.2.0 > >> > >> Hi, > >> > >> Not sure what is happening but I am seeing a lot of FPs at the moment > >> where MailScanner is marking messages as "List in RBL" in MailWatch. > > How > >> does this get triggered in MailScanner ? If I run the quarantined > > message > >> through SA in debug mode it gets a score of 6.55, with the threshold > > set > >> at 10 so it should not have been marked. > >> > >> Help! Thanks. > >> -- > >> --[ UxBoD ]-- > >> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > >> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > >> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > >> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > >> > >> > >> -- > >> This message has been scanned for viruses and dangerous content by > >> MailScanner, and is > >> believed to be clean. > >> > >> -- > >> MailScanner mailing list > >> mailscanner@lists.mailscanner.info > >> http://lists.mailscanner.info/mailman/listinfo/mailscanner > >> > >> Before posting, read http://wiki.mailscanner.info/posting > >> > >> Support MailScanner development - buy the book off the website! > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are intended for the > > addressee only and may be confidential. If they come to you in error > > you must take no action based on them, nor must you copy or show them > > to anyone. Please advise the sender by replying to this e-mail > > immediately and then delete the original from your computer. > > > > Opinion : Any opinions expressed in this e-mail are entirely those of > > the author and unless specifically stated to the contrary, are not > > necessarily those of the author's employer. > > > > Security Warning : Internet e-mail is not necessarily a secure > > communications medium and can be subject to data corruption. We advise > > that you consider this fact when e-mailing us. > > > > Viruses : We have taken steps to ensure that this e-mail and any > > attachments are free from known viruses but in keeping with good > > computing practice, you should ensure that they are virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic > > Registered as a limited company in England and Wales > > (Company No:5362730) > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > United Kingdom > > ********************************************************************** > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > -- > --[ UxBoD ]-- > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From uxbod at splatnix.net Tue May 15 11:20:58 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Tue May 15 11:21:34 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <892b6d03f18d324d9a87cea1748a8d1b@solidstatelogic.com> References: <892b6d03f18d324d9a87cea1748a8d1b@solidstatelogic.com> Message-ID: <0cb536e7779ae9007fe28ee4ba67f26e@62.49.223.244> Arggh, I bet that is what has been happening here then. I presume then it is just checking for the returned code, and not message then. On Tue, 15 May 2007 11:06:03 +0100, "Martin.Hepworth" wrote: > > I don't - I do all this from SA. I've been burnt by FP's on RBLS. > > It's better now you need X RBL's in MailScanner, but at the time some of > the RBL's shutdown and marked ALL email as spam... > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- >> Sent: 15 May 2007 10:59 >> To: MailScanner discussion >> Subject: RE: FPs and SA 3.2.0 >> >> Hi Martin, >> >> Which RBLs are using for Spam List ? >> >> Thanks, >> >> On Tue, 15 May 2007 09:47:49 +0100, "Martin.Hepworth" >> wrote: >> > This in done inside mailscanner itself... >> > >> > Spam List = >> > >> > Is the setting you need to look for. >> > >> > -- >> > Martin Hepworth >> > Snr Systems Administrator >> > Solid State Logic >> > Tel: +44 (0)1865 842300 >> > >> >> -----Original Message----- >> >> From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- >> >> bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- >> >> Sent: 15 May 2007 09:20 >> >> To: mailscanner@lists.mailscanner.info >> >> Subject: FPs and SA 3.2.0 >> >> >> >> Hi, >> >> >> >> Not sure what is happening but I am seeing a lot of FPs at the > moment >> >> where MailScanner is marking messages as "List in RBL" in > MailWatch. >> > How >> >> does this get triggered in MailScanner ? If I run the quarantined >> > message >> >> through SA in debug mode it gets a score of 6.55, with the > threshold >> > set >> >> at 10 so it should not have been marked. >> >> >> >> Help! Thanks. >> >> -- >> >> --[ UxBoD ]-- >> >> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg > --import" >> >> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >> >> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >> >> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >> >> >> >> >> >> -- >> >> This message has been scanned for viruses and dangerous content by >> >> MailScanner, and is >> >> believed to be clean. >> >> >> >> -- >> >> MailScanner mailing list >> >> mailscanner@lists.mailscanner.info >> >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> >> >> Support MailScanner development - buy the book off the website! >> > >> > >> > >> > >> > > ********************************************************************** >> > Confidentiality : This e-mail and any attachments are intended for > the >> > addressee only and may be confidential. If they come to you in error >> > you must take no action based on them, nor must you copy or show > them >> > to anyone. Please advise the sender by replying to this e-mail >> > immediately and then delete the original from your computer. >> > >> > Opinion : Any opinions expressed in this e-mail are entirely those > of >> > the author and unless specifically stated to the contrary, are not >> > necessarily those of the author's employer. >> > >> > Security Warning : Internet e-mail is not necessarily a secure >> > communications medium and can be subject to data corruption. We > advise >> > that you consider this fact when e-mailing us. >> > >> > Viruses : We have taken steps to ensure that this e-mail and any >> > attachments are free from known viruses but in keeping with good >> > computing practice, you should ensure that they are virus free. >> > >> > Red Lion 49 Ltd T/A Solid State Logic >> > Registered as a limited company in England and Wales >> > (Company No:5362730) >> > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, >> > United Kingdom >> > > ********************************************************************** >> > >> > -- >> > MailScanner mailing list >> > mailscanner@lists.mailscanner.info >> > http://lists.mailscanner.info/mailman/listinfo/mailscanner >> > >> > Before posting, read http://wiki.mailscanner.info/posting >> > >> > Support MailScanner development - buy the book off the website! >> > >> > >> -- >> --[ UxBoD ]-- >> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" >> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >> >> >> -- >> This message has been scanned for viruses and dangerous content by >> MailScanner, and is >> believed to be clean. >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Tue May 15 11:24:49 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 15 11:25:44 2007 Subject: FPs and SA 3.2.0 In-Reply-To: References: Message-ID: <46498A71.7000401@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - --[ UxBoD ]-- wrote: > Hi Martin, > > If I set Spam List = blank that all seems to work fine, as SA is then performing its own RBL lookup based on the ruleset. As soon as I set some RBLs in Spam List then all hell breaks out and I get a huge amount of FPs. Within the MailScanner code if a RBL lookup fails ie. timesout does it get marked as Spam ? > No. I have had this situation arise myself, and it certainly didn't mark messages as spam. When you say it marks it as spam, does the name of the dead RBL get added to the list of RBLs it thinks it found the message in? > Thanks, > > On Tue, 15 May 2007 09:47:49 +0100, "Martin.Hepworth" wrote: > >> This in done inside mailscanner itself... >> >> Spam List = >> >> Is the setting you need to look for. >> >> -- >> Martin Hepworth >> Snr Systems Administrator >> Solid State Logic >> Tel: +44 (0)1865 842300 >> >> >>> -----Original Message----- >>> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >>> bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- >>> Sent: 15 May 2007 09:20 >>> To: mailscanner@lists.mailscanner.info >>> Subject: FPs and SA 3.2.0 >>> >>> Hi, >>> >>> Not sure what is happening but I am seeing a lot of FPs at the moment >>> where MailScanner is marking messages as "List in RBL" in MailWatch. >>> >> How >> >>> does this get triggered in MailScanner ? If I run the quarantined >>> >> message >> >>> through SA in debug mode it gets a score of 6.55, with the threshold >>> >> set >> >>> at 10 so it should not have been marked. >>> >>> Help! Thanks. >>> -- >>> --[ UxBoD ]-- >>> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" >>> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >>> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >>> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >>> >>> >>> -- >>> This message has been scanned for viruses and dangerous content by >>> MailScanner, and is >>> believed to be clean. >>> >>> -- >>> MailScanner mailing list >>> mailscanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! >>> >> >> >> ********************************************************************** >> Confidentiality : This e-mail and any attachments are intended for the >> addressee only and may be confidential. If they come to you in error >> you must take no action based on them, nor must you copy or show them >> to anyone. Please advise the sender by replying to this e-mail >> immediately and then delete the original from your computer. >> >> Opinion : Any opinions expressed in this e-mail are entirely those of >> the author and unless specifically stated to the contrary, are not >> necessarily those of the author's employer. >> >> Security Warning : Internet e-mail is not necessarily a secure >> communications medium and can be subject to data corruption. We advise >> that you consider this fact when e-mailing us. >> >> Viruses : We have taken steps to ensure that this e-mail and any >> attachments are free from known viruses but in keeping with good >> computing practice, you should ensure that they are virus free. >> >> Red Lion 49 Ltd T/A Solid State Logic >> Registered as a limited company in England and Wales >> (Company No:5362730) >> Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, >> United Kingdom >> ********************************************************************** >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> >> Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGSYp4EfZZRxQVtlQRAm70AJ9802SRyjweE96wppONVuSeEvbIVACg6t9q h4pHNF8jdGhOSgREPvlxA1A= =tEL0 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From res at ausics.net Tue May 15 11:35:37 2007 From: res at ausics.net (Res) Date: Tue May 15 11:35:45 2007 Subject: OT: MTA poll results Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Posting this here cause a couple of you have said you voted. I've been asked to end this poll this weekend as it's been running for a month, and basically, the end results are: Sendmail [503 users, 47.86%] Qmail [309 users, 29.40%] Exim [57 users, 5.42%] Postfix [64 users, 6.09%] Exchange [66 users, 6.28%] Groupware (other) [31 users, 2.95%] Unix (other) [13 users, 1.24%] Windows (other) [8 users, 0.76%] Total 1051 Users voted - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGSYz8sWhAmSIQh7MRAo2oAKCySN//C0afIPESzIvELjS7/3yK6gCfa2hr IRc6DNjr+WsjEb1TyXlAO5A= =ASew -----END PGP SIGNATURE----- From uxbod at splatnix.net Tue May 15 11:37:43 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Tue May 15 11:38:47 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <46498A71.7000401@ecs.soton.ac.uk> References: <46498A71.7000401@ecs.soton.ac.uk> Message-ID: Nope. No list at all. It just reports in MailWatch as "Listed in RBL". On Tue, 15 May 2007 11:24:49 +0100, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > - --[ UxBoD ]-- wrote: >> Hi Martin, >> >> If I set Spam List = blank that all seems to work fine, as SA is then > performing its own RBL lookup based on the ruleset. As soon as I set some > RBLs in Spam List then all hell breaks out and I get a huge amount of FPs. > Within the MailScanner code if a RBL lookup fails ie. timesout does it get > marked as Spam ? >> > No. I have had this situation arise myself, and it certainly didn't mark > messages as spam. > When you say it marks it as spam, does the name of the dead RBL get > added to the list of RBLs it thinks it found the message in? >> Thanks, >> >> On Tue, 15 May 2007 09:47:49 +0100, "Martin.Hepworth" > wrote: >> >>> This in done inside mailscanner itself... >>> >>> Spam List = >>> >>> Is the setting you need to look for. >>> >>> -- >>> Martin Hepworth >>> Snr Systems Administrator >>> Solid State Logic >>> Tel: +44 (0)1865 842300 >>> >>> >>>> -----Original Message----- >>>> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >>>> bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- >>>> Sent: 15 May 2007 09:20 >>>> To: mailscanner@lists.mailscanner.info >>>> Subject: FPs and SA 3.2.0 >>>> >>>> Hi, >>>> >>>> Not sure what is happening but I am seeing a lot of FPs at the moment >>>> where MailScanner is marking messages as "List in RBL" in MailWatch. >>>> >>> How >>> >>>> does this get triggered in MailScanner ? If I run the quarantined >>>> >>> message >>> >>>> through SA in debug mode it gets a score of 6.55, with the threshold >>>> >>> set >>> >>>> at 10 so it should not have been marked. >>>> >>>> Help! Thanks. >>>> -- >>>> --[ UxBoD ]-- >>>> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" >>>> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >>>> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >>>> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >>>> >>>> >>>> -- >>>> This message has been scanned for viruses and dangerous content by >>>> MailScanner, and is >>>> believed to be clean. >>>> >>>> -- >>>> MailScanner mailing list >>>> mailscanner@lists.mailscanner.info >>>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>>> >>>> Before posting, read http://wiki.mailscanner.info/posting >>>> >>>> Support MailScanner development - buy the book off the website! >>>> >>> >>> >>> ********************************************************************** >>> Confidentiality : This e-mail and any attachments are intended for the >>> addressee only and may be confidential. If they come to you in error >>> you must take no action based on them, nor must you copy or show them >>> to anyone. Please advise the sender by replying to this e-mail >>> immediately and then delete the original from your computer. >>> >>> Opinion : Any opinions expressed in this e-mail are entirely those of >>> the author and unless specifically stated to the contrary, are not >>> necessarily those of the author's employer. >>> >>> Security Warning : Internet e-mail is not necessarily a secure >>> communications medium and can be subject to data corruption. We advise >>> that you consider this fact when e-mailing us. >>> >>> Viruses : We have taken steps to ensure that this e-mail and any >>> attachments are free from known viruses but in keeping with good >>> computing practice, you should ensure that they are virus free. >>> >>> Red Lion 49 Ltd T/A Solid State Logic >>> Registered as a limited company in England and Wales >>> (Company No:5362730) >>> Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, >>> United Kingdom >>> ********************************************************************** >>> >>> -- >>> MailScanner mailing list >>> mailscanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! >>> >>> >>> > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: UTF-8 > > wj8DBQFGSYp4EfZZRxQVtlQRAm70AJ9802SRyjweE96wppONVuSeEvbIVACg6t9q > h4pHNF8jdGhOSgREPvlxA1A= > =tEL0 > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From wilson.galafassi at gmail.com Tue May 15 11:52:27 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Tue May 15 11:52:37 2007 Subject: RES: duplicated SQL logging In-Reply-To: <1177401731.29785.3.camel@gblades-suse.linguaphone-intranet.co.uk> References: <001e01c7862e$2278ace0$676a06a0$@com.br> <1177401731.29785.3.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: I have only one Always Looked Up Last = &MailWatchLogging and mailwatch still displaying duplicated messages. -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Gareth Enviada em: ter?a-feira, 24 de abril de 2007 05:02 Para: MailScanner discussion Assunto: Re: duplicated SQL logging On Tue, 2007-04-24 at 06:05, Wilson A. Galafassi Jr. wrote: > Hello. > My messages are logged to SQL duplicate: see the log above: > > Apr 24 02:04:02 netserver postfix/pickup[13168]: 9F7FD16FCAF: uid=0 > from= > Apr 24 02:04:02 netserver postfix/cleanup[13190]: 9F7FD16FCAF: hold: header > Received: by netserver.ftpman (Postfix, from userid 0)??id 9F7FD16FCAF; Tue, > 24 Apr 2007 02:04:02 -0300 (BRT) from local; from= > to= > Apr 24 02:04:02 netserver postfix/cleanup[13190]: 9F7FD16FCAF: > message-id=<20070424050402.9F7FD16FCAF@netserver.ftpmanagerbr> > Apr 24 02:04:07 netserver MailScanner[13183]: New Batch: Scanning 1 > messages, 540 bytes > Apr 24 02:04:07 netserver MailScanner[13183]: Logging message > 9F7FD16FCAF.25F36 to SQL > Apr 24 02:04:07 netserver MailScanner[13183]: Virus and Content Scanning: > Starting > Apr 24 02:04:07 netserver MailScanner[13183]: Logging message > 9F7FD16FCAF.25F36 to SQL > Apr 24 02:04:07 netserver MailScanner[13179]: 9F7FD16FCAF.25F36: Logged to > MailWatch SQL > Apr 24 02:04:07 netserver MailScanner[13179]: 9F7FD16FCAF.25F36: Logged to > MailWatch SQL > Apr 24 02:04:07 netserver MailScanner[13183]: Requeue: 9F7FD16FCAF.25F36 to > 5592316FCAE > Apr 24 02:04:07 netserver postfix/qmgr[13169]: 5592316FCAE: > from=, size=711, nrcpt=1 (queue active) > Apr 24 02:04:07 netserver MailScanner[13183]: Uninfected: Delivered 1 > messages > What do you get if you run this command :- [root@mailscanner ~]# cat /etc/MailScanner/MailScanner.conf | grep MailWatch Always Looked Up Last = &MailWatchLogging My guess is that you are somehow calling it twice. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From glenn.steen at gmail.com Tue May 15 11:52:49 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue May 15 11:52:53 2007 Subject: Interesting need In-Reply-To: <4648683F.65ED.00A2.0@plattesheriff.org> References: <463F0518.65ED.00A2.0@plattesheriff.org> <463F5C10.7080307@ecs.soton.ac.uk> <463F7783.7070608@nkpanama.com> <463F822E.2010108@ecs.soton.ac.uk> <223f97700705071442w106785bu1a9a50405476f9cb@mail.gmail.com> <4648683F.65ED.00A2.0@plattesheriff.org> Message-ID: <223f97700705150352y53e7b148i47485f73b0c7f2a9@mail.gmail.com> On 14/05/07, Rob Poe wrote: > >>> Archive mail "forwards" email? I thought it only "archived" it... > > >> RTFM my friend :-) > > >Yes I did, and I have a question...Wouldn't using Archive Mail > >forwarding include all the spam etc? > > Yes, it does. The question was more of a rhetorical nature...:-) > This was brought to me by an admin assistant to a lawyer, who expects that all of his email gets delivered to both of them. I had a rule set up in their email system to do such a thing, but if he opens the email BEFORE the rule fires, it's no longer "unopened" and doesn't forward. Even though it's NOT supposed to work like that -- it does .. bug or feature. > > So using Jules' suggestion, I put it in and it works beautifully. The admin assistant complained she was now receiving more spam than she used to (duuuh!), and I explained why she was. She wanted "something done about it". I explained to her that her boss wanted as FEW spam controls as possible, as their clients don't admin their own email systems, and rely on brain-dead admins (or brain-dead shared mail systems) who can't configure mail software or domains to RFC specs - and thus get flagged as spam. Since he's involved in multi-billion dollar deals for his clients, I turned many of the big spam rules off for them - and they do get spam. It's the whole "can't have cake and eat it too" things.. > Ok, so ... Did they elect to go for a solution with more control(s) and a forward-in-a-ruleset on Non Spam Actions? Or did they decide to b...h about it?:-P Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From wilson.galafassi at gmail.com Tue May 15 12:08:11 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Tue May 15 12:08:21 2007 Subject: duplicated SQL logging Message-ID: I have only one Always Looked Up Last = &MailWatchLogging and mailwatch still displaying duplicated messages. -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Gareth Enviada em: ter?a-feira, 24 de abril de 2007 05:02 Para: MailScanner discussion Assunto: Re: duplicated SQL logging On Tue, 2007-04-24 at 06:05, Wilson A. Galafassi Jr. wrote: > Hello. > My messages are logged to SQL duplicate: see the log above: > > Apr 24 02:04:02 netserver postfix/pickup[13168]: 9F7FD16FCAF: uid=0 > from= > Apr 24 02:04:02 netserver postfix/cleanup[13190]: 9F7FD16FCAF: hold: header > Received: by netserver.ftpman (Postfix, from userid 0)??id 9F7FD16FCAF; Tue, > 24 Apr 2007 02:04:02 -0300 (BRT) from local; from= > to= > Apr 24 02:04:02 netserver postfix/cleanup[13190]: 9F7FD16FCAF: > message-id=<20070424050402.9F7FD16FCAF@netserver.ftpmanagerbr> > Apr 24 02:04:07 netserver MailScanner[13183]: New Batch: Scanning 1 > messages, 540 bytes > Apr 24 02:04:07 netserver MailScanner[13183]: Logging message > 9F7FD16FCAF.25F36 to SQL > Apr 24 02:04:07 netserver MailScanner[13183]: Virus and Content Scanning: > Starting > Apr 24 02:04:07 netserver MailScanner[13183]: Logging message > 9F7FD16FCAF.25F36 to SQL > Apr 24 02:04:07 netserver MailScanner[13179]: 9F7FD16FCAF.25F36: Logged to > MailWatch SQL > Apr 24 02:04:07 netserver MailScanner[13179]: 9F7FD16FCAF.25F36: Logged to > MailWatch SQL > Apr 24 02:04:07 netserver MailScanner[13183]: Requeue: 9F7FD16FCAF.25F36 to > 5592316FCAE > Apr 24 02:04:07 netserver postfix/qmgr[13169]: 5592316FCAE: > from=, size=711, nrcpt=1 (queue active) > Apr 24 02:04:07 netserver MailScanner[13183]: Uninfected: Delivered 1 > messages > What do you get if you run this command :- [root@mailscanner ~]# cat /etc/MailScanner/MailScanner.conf | grep MailWatch Always Looked Up Last = &MailWatchLogging My guess is that you are somehow calling it twice. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From wilson.galafassi at gmail.com Tue May 15 12:20:51 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Tue May 15 12:21:01 2007 Subject: duplicated mailwatch loggin only from non-spam messages Message-ID: Hello. My mailscanner is loggin duplicated messages only when the messages isn?t spam. Any have this problem? Thanks Wilson -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070515/5e72b4a5/attachment.html From martinh at solidstatelogic.com Tue May 15 12:30:24 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Tue May 15 12:30:43 2007 Subject: duplicated mailwatch loggin only from non-spam messages In-Reply-To: Message-ID: <575a741960f19042a8ad9b348eb24184@solidstatelogic.com> Wilson What's the actions on "Non Spam Actions" in MailScanner.conf. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Wilson A. Galafassi Jr. > Sent: 15 May 2007 12:21 > To: 'MailScanner discussion' > Subject: duplicated mailwatch loggin only from non-spam messages > > Hello. > > > > My mailscanner is loggin duplicated messages only when the messages isn?t > spam. Any have this problem? > > Thanks > > Wilson > > > > > > ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From glenn.steen at gmail.com Tue May 15 12:33:26 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue May 15 12:33:28 2007 Subject: duplicated mailwatch loggin only from non-spam messages In-Reply-To: References: Message-ID: <223f97700705150433n49925910x4a8f9c3ec03ac2b4@mail.gmail.com> On 15/05/07, Wilson A. Galafassi Jr. wrote: > > > > > Hello. > > > > My mailscanner is loggin duplicated messages only when the messages isn?t > spam. Any have this problem? > > Thanks > > Wilson > Wilson, This question probably more rightly belongs in the MailWatch list than here... However... What exactly do you mean when you say duplicate messages? Two entries in the maillog table for every (non-spam) message? So that if you look at the details for a message, it looks ... doubled? And if you do a "select count(*) from maillog where id='';" you get a count of 2, not 1? If so, could you describe your system(s) a bit, OS, versions of everything (MS, MW etc)? Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Tue May 15 12:39:52 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue May 15 12:39:55 2007 Subject: duplicated mailwatch loggin only from non-spam messages In-Reply-To: <223f97700705150433n49925910x4a8f9c3ec03ac2b4@mail.gmail.com> References: <223f97700705150433n49925910x4a8f9c3ec03ac2b4@mail.gmail.com> Message-ID: <223f97700705150439q3696471fs37bf71a40d75c220@mail.gmail.com> On 15/05/07, Glenn Steen wrote: > On 15/05/07, Wilson A. Galafassi Jr. wrote: > > > > > > > > > > Hello. > > > > > > > > My mailscanner is loggin duplicated messages only when the messages isn?t > > spam. Any have this problem? > > > > Thanks > > > > Wilson > > > Wilson, > > This question probably more rightly belongs in the MailWatch list than > here... However... > What exactly do you mean when you say duplicate messages? Two entries > in the maillog table for every (non-spam) message? So that if you look > at the details for a message, it looks ... doubled? And if you do a > "select count(*) from maillog where id=' ID>';" you get a count of 2, not 1? > If so, could you describe your system(s) a bit, OS, versions of > everything (MS, MW etc)? > > Cheers Just saw another message from you where you seem to be running Postfix... And where you indeed have multiple logging events... You _are_ using the HOLD method, and not the deprecated dual-PF-and-defer method, to "interface" with MailScanner, right? Other than that.... If you only have one call to MailWatchLogging, and use the HOLD method, you likely need look long and hard at your MailWatch.pm file. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From wilson.galafassi at gmail.com Tue May 15 12:54:35 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Tue May 15 12:54:46 2007 Subject: RES: duplicated mailwatch loggin only from non-spam messages In-Reply-To: <223f97700705150433n49925910x4a8f9c3ec03ac2b4@mail.gmail.com> References: <223f97700705150433n49925910x4a8f9c3ec03ac2b4@mail.gmail.com> Message-ID: This problem is in other Server. I?m running centos with exim (Cpanel) May 15 08:44:20 netserver MailScanner[28417]: New Batch: Scanning 1 messages, 2524 bytes May 15 08:44:20 netserver MailScanner[28417]: Spam Checks: Found 1 spam messages May 15 08:44:21 netserver MailScanner[28417]: Virus and Content Scanning: Starting May 15 08:44:21 netserver MailScanner[28417]: Logging message 1HnvRy-0007OS-PG to SQL May 15 08:44:21 netserver MailScanner[28257]: 1HnvRy-0007OS-PG: Logged to MailWatch SQL May 15 08:44:39 netserver MailScanner[28417]: New Batch: Scanning 1 messages, 11182 bytes May 15 08:44:41 netserver MailScanner[28417]: Virus and Content Scanning: Starting May 15 08:44:41 netserver MailScanner[28417]: Uninfected: Delivered 1 messages May 15 08:44:41 netserver MailScanner[28417]: Logging message 1HnvSI-0007Oq-D0 to SQL May 15 08:44:41 netserver MailScanner[28257]: 1HnvSI-0007Oq-D0: Logged to MailWatch SQL May 15 08:44:41 netserver spamc[28471]: connect to spamd on 127.0.0.1 failed, retrying (#1 of 3): Connection refused May 15 08:44:42 netserver spamc[28471]: connect to spamd on 127.0.0.1 failed, retrying (#2 of 3): Connection refused May 15 08:44:43 netserver spamc[28471]: connect to spamd on 127.0.0.1 failed, retrying (#3 of 3): Connection refused May 15 08:44:44 netserver spamc[28471]: connection attempt to spamd aborted after 3 retries May 15 08:44:46 netserver MailScanner[28414]: New Batch: Scanning 1 messages, 11497 bytes May 15 08:44:46 netserver MailScanner[28414]: SpamAssassin cache hit for message 1HnvSL-0007PB-Ko May 15 08:44:46 netserver MailScanner[28414]: Virus and Content Scanning: Starting May 15 08:44:47 netserver MailScanner[28414]: Uninfected: Delivered 1 messages May 15 08:44:47 netserver MailScanner[28414]: Logging message 1HnvSL-0007PB-Ko to SQL May 15 08:44:47 netserver MailScanner[28257]: 1HnvSL-0007PB-Ko: Logged to MailWatch SQL Mailscanner generate 2 message 1HnvRy-0007OS-PG and 1HnvSL-0007PB-Ko for the same message. -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Glenn Steen Enviada em: ter?a-feira, 15 de maio de 2007 08:33 Para: MailScanner discussion Assunto: Re: duplicated mailwatch loggin only from non-spam messages On 15/05/07, Wilson A. Galafassi Jr. wrote: > > > > > Hello. > > > > My mailscanner is loggin duplicated messages only when the messages isn?t > spam. Any have this problem? > > Thanks > > Wilson > Wilson, This question probably more rightly belongs in the MailWatch list than here... However... What exactly do you mean when you say duplicate messages? Two entries in the maillog table for every (non-spam) message? So that if you look at the details for a message, it looks ... doubled? And if you do a "select count(*) from maillog where id='';" you get a count of 2, not 1? If so, could you describe your system(s) a bit, OS, versions of everything (MS, MW etc)? Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From glenn.steen at gmail.com Tue May 15 13:38:38 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue May 15 13:38:46 2007 Subject: duplicated mailwatch loggin only from non-spam messages In-Reply-To: References: <223f97700705150433n49925910x4a8f9c3ec03ac2b4@mail.gmail.com> Message-ID: <223f97700705150538t74663089x9c8a118b8c28f059@mail.gmail.com> On 15/05/07, Wilson A. Galafassi Jr. wrote: > This problem is in other Server. I?m running centos with exim (Cpanel) > > May 15 08:44:20 netserver MailScanner[28417]: New Batch: Scanning 1 > messages, 2524 bytes > May 15 08:44:20 netserver MailScanner[28417]: Spam Checks: Found 1 spam > messages > May 15 08:44:21 netserver MailScanner[28417]: Virus and Content Scanning: > Starting > May 15 08:44:21 netserver MailScanner[28417]: Logging message > 1HnvRy-0007OS-PG to SQL > May 15 08:44:21 netserver MailScanner[28257]: 1HnvRy-0007OS-PG: Logged to > MailWatch SQL > May 15 08:44:39 netserver MailScanner[28417]: New Batch: Scanning 1 > messages, 11182 bytes > May 15 08:44:41 netserver MailScanner[28417]: Virus and Content Scanning: > Starting > May 15 08:44:41 netserver MailScanner[28417]: Uninfected: Delivered 1 > messages > May 15 08:44:41 netserver MailScanner[28417]: Logging message > 1HnvSI-0007Oq-D0 to SQL > May 15 08:44:41 netserver MailScanner[28257]: 1HnvSI-0007Oq-D0: Logged to > MailWatch SQL > May 15 08:44:41 netserver spamc[28471]: connect to spamd on 127.0.0.1 > failed, retrying (#1 of 3): Connection refused > May 15 08:44:42 netserver spamc[28471]: connect to spamd on 127.0.0.1 > failed, retrying (#2 of 3): Connection refused > May 15 08:44:43 netserver spamc[28471]: connect to spamd on 127.0.0.1 > failed, retrying (#3 of 3): Connection refused No spamd running, or a firewall rule missing? You should perhaps fix that. > May 15 08:44:44 netserver spamc[28471]: connection attempt to spamd aborted > after 3 retries > May 15 08:44:46 netserver MailScanner[28414]: New Batch: Scanning 1 > messages, 11497 bytes > May 15 08:44:46 netserver MailScanner[28414]: SpamAssassin cache hit for > message 1HnvSL-0007PB-Ko > May 15 08:44:46 netserver MailScanner[28414]: Virus and Content Scanning: > Starting > May 15 08:44:47 netserver MailScanner[28414]: Uninfected: Delivered 1 > messages > May 15 08:44:47 netserver MailScanner[28414]: Logging message > 1HnvSL-0007PB-Ko to SQL > May 15 08:44:47 netserver MailScanner[28257]: 1HnvSL-0007PB-Ko: Logged to > MailWatch SQL > > Mailscanner generate 2 message 1HnvRy-0007OS-PG and 1HnvSL-0007PB-Ko for the > same message. Same Message-ID? Check your exim logs... likely comes from one bad sender sending it twice... Happens occasionally;-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From wilson.galafassi at gmail.com Tue May 15 13:52:51 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Tue May 15 13:53:03 2007 Subject: RES: duplicated mailwatch loggin only from non-spam messages In-Reply-To: <223f97700705150538t74663089x9c8a118b8c28f059@mail.gmail.com> References: <223f97700705150433n49925910x4a8f9c3ec03ac2b4@mail.gmail.com> <223f97700705150538t74663089x9c8a118b8c28f059@mail.gmail.com> Message-ID: Here is my exim log: 2007-05-15 09:50:00 1HnwTY-0001T0-AZ <= wilson.galafassi@gmail.com H=(wx-out-0506.google.com) [66.249.82.233] P=esmtp S=4577 id=!&!AAAAAAAAAAAYAAAAAAAAACCX86jW8GpMuxxs8io8EHLCgAAAEAAAAJxHavjKBv1LoOvHfk Pc5ZUBAAAAAA==@galafassi.com.br T="teste" 2007-05-15 09:50:09 cwd=/var/spool/MailScanner/incoming/28253 5 args: /usr/sbin/exim -C /etc/exim_outgoing.conf -Mc 1HnwTY-0001T0-AZ 2007-05-15 09:50:09 cwd=/tmp 2 args: /usr/sbin/sendmail -bS 2007-05-15 09:50:12 1HnwTh-0001Yo-Ni <= wilson.galafassi@gmail.com U=celta P=local-bsmtp S=5282 id=!&!AAAAAAAAAAAYAAAAAAAAACCX86jW8GpMuxxs8io8EHLCgAAAEAAAAJxHavjKBv1LoOvHfk Pc5ZUBAAAAAA==@galafassi.com.br T="teste" 2007-05-15 09:50:12 1HnwTY-0001T0-AZ => derek R=virtual_sa_user T=virtual_sa_userdelivery 2007-05-15 09:50:12 1HnwTY-0001T0-AZ Completed 2007-05-15 09:50:14 cwd=/var/spool/MailScanner/incoming/28414 5 args: /usr/sbin/exim -C /etc/exim_outgoing.conf -Mc 1HnwTh-0001Yo-Ni 2007-05-15 09:50:14 1HnwTh-0001Yo-Ni => derek R=virtual_user T=virtual_userdelivery 2007-05-15 09:50:14 1HnwTh-0001Yo-Ni Completed Exim is duplicating emails? -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Glenn Steen Enviada em: ter?a-feira, 15 de maio de 2007 09:39 Para: MailScanner discussion Assunto: Re: duplicated mailwatch loggin only from non-spam messages On 15/05/07, Wilson A. Galafassi Jr. wrote: > This problem is in other Server. I?m running centos with exim (Cpanel) > > May 15 08:44:20 netserver MailScanner[28417]: New Batch: Scanning 1 > messages, 2524 bytes > May 15 08:44:20 netserver MailScanner[28417]: Spam Checks: Found 1 spam > messages > May 15 08:44:21 netserver MailScanner[28417]: Virus and Content Scanning: > Starting > May 15 08:44:21 netserver MailScanner[28417]: Logging message > 1HnvRy-0007OS-PG to SQL > May 15 08:44:21 netserver MailScanner[28257]: 1HnvRy-0007OS-PG: Logged to > MailWatch SQL > May 15 08:44:39 netserver MailScanner[28417]: New Batch: Scanning 1 > messages, 11182 bytes > May 15 08:44:41 netserver MailScanner[28417]: Virus and Content Scanning: > Starting > May 15 08:44:41 netserver MailScanner[28417]: Uninfected: Delivered 1 > messages > May 15 08:44:41 netserver MailScanner[28417]: Logging message > 1HnvSI-0007Oq-D0 to SQL > May 15 08:44:41 netserver MailScanner[28257]: 1HnvSI-0007Oq-D0: Logged to > MailWatch SQL > May 15 08:44:41 netserver spamc[28471]: connect to spamd on 127.0.0.1 > failed, retrying (#1 of 3): Connection refused > May 15 08:44:42 netserver spamc[28471]: connect to spamd on 127.0.0.1 > failed, retrying (#2 of 3): Connection refused > May 15 08:44:43 netserver spamc[28471]: connect to spamd on 127.0.0.1 > failed, retrying (#3 of 3): Connection refused No spamd running, or a firewall rule missing? You should perhaps fix that. > May 15 08:44:44 netserver spamc[28471]: connection attempt to spamd aborted > after 3 retries > May 15 08:44:46 netserver MailScanner[28414]: New Batch: Scanning 1 > messages, 11497 bytes > May 15 08:44:46 netserver MailScanner[28414]: SpamAssassin cache hit for > message 1HnvSL-0007PB-Ko > May 15 08:44:46 netserver MailScanner[28414]: Virus and Content Scanning: > Starting > May 15 08:44:47 netserver MailScanner[28414]: Uninfected: Delivered 1 > messages > May 15 08:44:47 netserver MailScanner[28414]: Logging message > 1HnvSL-0007PB-Ko to SQL > May 15 08:44:47 netserver MailScanner[28257]: 1HnvSL-0007PB-Ko: Logged to > MailWatch SQL > > Mailscanner generate 2 message 1HnvRy-0007OS-PG and 1HnvSL-0007PB-Ko for the > same message. Same Message-ID? Check your exim logs... likely comes from one bad sender sending it twice... Happens occasionally;-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Tue May 15 13:57:30 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 15 14:01:14 2007 Subject: FPs and SA 3.2.0 In-Reply-To: References: <46498A71.7000401@ecs.soton.ac.uk> Message-ID: <4649AE3A.3030405@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 That's interesting. It may be a continuation of the perl bug I suffered from there before. Can you try something for me please? Look at the bottom of /usr/lib/MailScanner/MailScanner/RBLs.pm and you will find this: # JKF 3/10/2005 my $temp = @HitList; $temp = $temp + 0; return ($temp, join(', ', @HitList)); } Please add a line to change it to this: # JKF 3/10/2005 my $temp = @HitList; $temp = $temp + 0; $temp = 0 unless $HitList[0] =~ /a-z/i; return ($temp, join(', ', @HitList)); } Let's see if that helps. According to the book, the 2 middle lines shouldn't be needed at all. - --[ UxBoD ]-- wrote: > Nope. No list at all. It just reports in MailWatch as "Listed in RBL". > > On Tue, 15 May 2007 11:24:49 +0100, Julian Field wrote: > >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> >> >> - --[ UxBoD ]-- wrote: >> >>> Hi Martin, >>> >>> If I set Spam List = blank that all seems to work fine, as SA is then >>> >> performing its own RBL lookup based on the ruleset. As soon as I set some >> RBLs in Spam List then all hell breaks out and I get a huge amount of FPs. >> Within the MailScanner code if a RBL lookup fails ie. timesout does it get >> marked as Spam ? >> >>> >>> >> No. I have had this situation arise myself, and it certainly didn't mark >> messages as spam. >> When you say it marks it as spam, does the name of the dead RBL get >> added to the list of RBLs it thinks it found the message in? >> >>> Thanks, >>> >>> On Tue, 15 May 2007 09:47:49 +0100, "Martin.Hepworth" >>> >> wrote: >> >>> >>> >>>> This in done inside mailscanner itself... >>>> >>>> Spam List = >>>> >>>> Is the setting you need to look for. >>>> >>>> -- >>>> Martin Hepworth >>>> Snr Systems Administrator >>>> Solid State Logic >>>> Tel: +44 (0)1865 842300 >>>> >>>> >>>> >>>>> -----Original Message----- >>>>> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >>>>> bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- >>>>> Sent: 15 May 2007 09:20 >>>>> To: mailscanner@lists.mailscanner.info >>>>> Subject: FPs and SA 3.2.0 >>>>> >>>>> Hi, >>>>> >>>>> Not sure what is happening but I am seeing a lot of FPs at the moment >>>>> where MailScanner is marking messages as "List in RBL" in MailWatch. >>>>> >>>>> >>>> How >>>> >>>> >>>>> does this get triggered in MailScanner ? If I run the quarantined >>>>> >>>>> >>>> message >>>> >>>> >>>>> through SA in debug mode it gets a score of 6.55, with the threshold >>>>> >>>>> >>>> set >>>> >>>> >>>>> at 10 so it should not have been marked. >>>>> >>>>> Help! Thanks. >>>>> -- >>>>> --[ UxBoD ]-- >>>>> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" >>>>> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >>>>> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >>>>> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >>>>> >>>>> >>>>> -- >>>>> This message has been scanned for viruses and dangerous content by >>>>> MailScanner, and is >>>>> believed to be clean. >>>>> >>>>> -- >>>>> MailScanner mailing list >>>>> mailscanner@lists.mailscanner.info >>>>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>>>> >>>>> Before posting, read http://wiki.mailscanner.info/posting >>>>> >>>>> Support MailScanner development - buy the book off the website! >>>>> >>>>> >>>> ********************************************************************** >>>> Confidentiality : This e-mail and any attachments are intended for the >>>> addressee only and may be confidential. If they come to you in error >>>> you must take no action based on them, nor must you copy or show them >>>> to anyone. Please advise the sender by replying to this e-mail >>>> immediately and then delete the original from your computer. >>>> >>>> Opinion : Any opinions expressed in this e-mail are entirely those of >>>> the author and unless specifically stated to the contrary, are not >>>> necessarily those of the author's employer. >>>> >>>> Security Warning : Internet e-mail is not necessarily a secure >>>> communications medium and can be subject to data corruption. We advise >>>> that you consider this fact when e-mailing us. >>>> >>>> Viruses : We have taken steps to ensure that this e-mail and any >>>> attachments are free from known viruses but in keeping with good >>>> computing practice, you should ensure that they are virus free. >>>> >>>> Red Lion 49 Ltd T/A Solid State Logic >>>> Registered as a limited company in England and Wales >>>> (Company No:5362730) >>>> Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, >>>> United Kingdom >>>> ********************************************************************** >>>> >>>> -- >>>> MailScanner mailing list >>>> mailscanner@lists.mailscanner.info >>>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>>> >>>> Before posting, read http://wiki.mailscanner.info/posting >>>> >>>> Support MailScanner development - buy the book off the website! >>>> >>>> >>>> >>>> >> Jules >> >> - -- >> Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> MailScanner customisation, or any advanced system administration help? >> Contact me at Jules@Jules.FM >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> For all your IT requirements visit www.transtec.co.uk >> >> >> >> -----BEGIN PGP SIGNATURE----- >> Version: PGP Desktop 9.6.1 (Build 1012) >> Charset: UTF-8 >> >> wj8DBQFGSYp4EfZZRxQVtlQRAm70AJ9802SRyjweE96wppONVuSeEvbIVACg6t9q >> h4pHNF8jdGhOSgREPvlxA1A= >> =tEL0 >> -----END PGP SIGNATURE----- >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> For all your IT requirements visit www.transtec.co.uk >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> >> Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGSa6jEfZZRxQVtlQRAoS5AJ9x5jPciSoHKsGhcJmJoIzPvwHzaQCgsH3w gvCpF3QvoZiCXBTBR15U4DU= =r+vp -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From martinh at solidstatelogic.com Tue May 15 14:03:02 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Tue May 15 14:03:10 2007 Subject: duplicated mailwatch loggin only from non-spam messages In-Reply-To: Message-ID: <8f28bccd5e9f314ea505ddc5a386f68c@solidstatelogic.com> Wilson Might be worthwhile putting the outgoing exim logs onto a different file, then you can see what each instance is up to in a clearer manner. Something like this in etc/exim_outgoing.conf. log_file_path = /var/log/exim/log/%slog -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Wilson A. Galafassi Jr. > Sent: 15 May 2007 13:53 > To: MailScanner discussion > Subject: RES: duplicated mailwatch loggin only from non-spam messages > > Here is my exim log: > > > 2007-05-15 09:50:00 1HnwTY-0001T0-AZ <= wilson.galafassi@gmail.com > H=(wx-out-0506.google.com) [66.249.82.233] P=esmtp S=4577 > id=!&!AAAAAAAAAAAYAAAAAAAAACCX86jW8GpMuxxs8io8EHLCgAAAEAAAAJxHavjKBv1LoO vH > fk > Pc5ZUBAAAAAA==@galafassi.com.br T="teste" > 2007-05-15 09:50:09 cwd=/var/spool/MailScanner/incoming/28253 5 args: > /usr/sbin/exim -C /etc/exim_outgoing.conf -Mc 1HnwTY-0001T0-AZ > 2007-05-15 09:50:09 cwd=/tmp 2 args: /usr/sbin/sendmail -bS > 2007-05-15 09:50:12 1HnwTh-0001Yo-Ni <= wilson.galafassi@gmail.com U=celta > P=local-bsmtp S=5282 > id=!&!AAAAAAAAAAAYAAAAAAAAACCX86jW8GpMuxxs8io8EHLCgAAAEAAAAJxHavjKBv1LoO vH > fk > Pc5ZUBAAAAAA==@galafassi.com.br T="teste" > 2007-05-15 09:50:12 1HnwTY-0001T0-AZ => derek > R=virtual_sa_user T=virtual_sa_userdelivery > 2007-05-15 09:50:12 1HnwTY-0001T0-AZ Completed > 2007-05-15 09:50:14 cwd=/var/spool/MailScanner/incoming/28414 5 args: > /usr/sbin/exim -C /etc/exim_outgoing.conf -Mc 1HnwTh-0001Yo-Ni > 2007-05-15 09:50:14 1HnwTh-0001Yo-Ni => derek > R=virtual_user T=virtual_userdelivery > 2007-05-15 09:50:14 1HnwTh-0001Yo-Ni Completed > > Exim is duplicating emails? > > > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Glenn Steen > Enviada em: ter?a-feira, 15 de maio de 2007 09:39 > Para: MailScanner discussion > Assunto: Re: duplicated mailwatch loggin only from non-spam messages > > On 15/05/07, Wilson A. Galafassi Jr. wrote: > > This problem is in other Server. I?m running centos with exim (Cpanel) > > > > May 15 08:44:20 netserver MailScanner[28417]: New Batch: Scanning 1 > > messages, 2524 bytes > > May 15 08:44:20 netserver MailScanner[28417]: Spam Checks: Found 1 spam > > messages > > May 15 08:44:21 netserver MailScanner[28417]: Virus and Content > Scanning: > > Starting > > May 15 08:44:21 netserver MailScanner[28417]: Logging message > > 1HnvRy-0007OS-PG to SQL > > May 15 08:44:21 netserver MailScanner[28257]: 1HnvRy-0007OS-PG: Logged > to > > MailWatch SQL > > May 15 08:44:39 netserver MailScanner[28417]: New Batch: Scanning 1 > > messages, 11182 bytes > > May 15 08:44:41 netserver MailScanner[28417]: Virus and Content > Scanning: > > Starting > > May 15 08:44:41 netserver MailScanner[28417]: Uninfected: Delivered 1 > > messages > > May 15 08:44:41 netserver MailScanner[28417]: Logging message > > 1HnvSI-0007Oq-D0 to SQL > > May 15 08:44:41 netserver MailScanner[28257]: 1HnvSI-0007Oq-D0: Logged > to > > MailWatch SQL > > May 15 08:44:41 netserver spamc[28471]: connect to spamd on 127.0.0.1 > > failed, retrying (#1 of 3): Connection refused > > May 15 08:44:42 netserver spamc[28471]: connect to spamd on 127.0.0.1 > > failed, retrying (#2 of 3): Connection refused > > May 15 08:44:43 netserver spamc[28471]: connect to spamd on 127.0.0.1 > > failed, retrying (#3 of 3): Connection refused > > No spamd running, or a firewall rule missing? You should perhaps fix that. > > > May 15 08:44:44 netserver spamc[28471]: connection attempt to spamd > aborted > > after 3 retries > > May 15 08:44:46 netserver MailScanner[28414]: New Batch: Scanning 1 > > messages, 11497 bytes > > May 15 08:44:46 netserver MailScanner[28414]: SpamAssassin cache hit for > > message 1HnvSL-0007PB-Ko > > May 15 08:44:46 netserver MailScanner[28414]: Virus and Content > Scanning: > > Starting > > May 15 08:44:47 netserver MailScanner[28414]: Uninfected: Delivered 1 > > messages > > May 15 08:44:47 netserver MailScanner[28414]: Logging message > > 1HnvSL-0007PB-Ko to SQL > > May 15 08:44:47 netserver MailScanner[28257]: 1HnvSL-0007PB-Ko: Logged > to > > MailWatch SQL > > > > Mailscanner generate 2 message 1HnvRy-0007OS-PG and 1HnvSL-0007PB-Ko for > the > > same message. > > Same Message-ID? Check your exim logs... likely comes from one bad > sender sending it twice... Happens occasionally;-) > > Cheers > -- > -- Glenn > email: glenn < dot > steen < at > gmail < dot > com > work: glenn < dot > steen < at > ap1 < dot > se > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From norbert.schmidt at interactivedata.com Tue May 15 14:08:32 2007 From: norbert.schmidt at interactivedata.com (Norbert Schmidt) Date: Tue May 15 14:13:00 2007 Subject: Report: Denial of Service attack in message! Message-ID: Hi, I am seeing quite a few "Report: Denial of Service attack in message!" in the logfiles. The mails are quarantined since I selected to quarantine silent viruses. May 15 13:52:52 localhost MailScanner[30916]: Virus and Content Scanning: Starting May 15 13:53:23 localhost MailScanner[30916]: Commercial scanner clamav timed out! May 15 13:53:23 localhost MailScanner[30916]: clamav: Failed to complete, timed out May 15 13:53:23 localhost MailScanner[30916]: Virus Scanning: Denial Of Service attack detected! May 15 13:53:54 localhost MailScanner[30916]: Commercial scanner clamav timed out! May 15 13:53:54 localhost MailScanner[30916]: clamav: Failed to complete, timed out May 15 13:53:54 localhost MailScanner[30916]: Virus Scanning: Denial Of Service attack is in message 096EAC42EE.ABDA7 May 15 13:54:56 localhost MailScanner[30916]: Infected message 096EAC42EE.ABDA7 came from xxx.11.206.74 May 15 13:54:56 localhost MailScanner[30916]: HTML Img tag found in message B34D6C441C.201C8 from cakrystyemi@iriomote.com May 15 13:54:56 localhost MailScanner[30916]: tag found in message 69E50C42EF.E6402 from May 15 13:54:56 localhost MailScanner[30916]: Virus Scanning completed at 479 bytes per second May 15 13:54:56 localhost MailScanner[30916]: Saved entire message to /var/spool/MailScanner/quarantine/20070515/096EAC42EE.ABDA7 May 15 13:54:56 localhost MailScanner[30916]: Viruses marked as silent: Denial of Service attack in message! May 15 13:54:5 The mails are legitimate and it doesn't look like there is anything fishy about them. The server is not experiencing a very heavy load the problem comes up a few minutes after the server is started. I've got a second machine running an older version of Mailscanner ( 4.55.10-3), which is also experiencing clamav time outs, but not marking those mails as Viruses. Is there any option I can set to still deliver these mails? OS: Debian Sarge Mailscanner Version is 4.57.6-1 Clamav Version is: 0.90.2-1+b1 Regards Norbert -- Norbert Schmidt | IT / Systems Interactive Data Managed Solutions AG ---------------------------------------------------------------------- -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3972 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070515/c59537cc/smime.bin From amaclach at yahoo.co.uk Tue May 15 14:37:34 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Tue May 15 14:37:36 2007 Subject: Report: Denial of Service attack in message! Message-ID: <20070515133734.63654.qmail@web26306.mail.ukl.yahoo.com> Are there nested archives in those messages? ----- Original Message ---- From: Norbert Schmidt To: mailscanner@lists.mailscanner.info Sent: Tuesday, 15 May, 2007 2:08:32 PM Subject: Report: Denial of Service attack in message! Hi, I am seeing quite a few "Report: Denial of Service attack in message!" in the logfiles. The mails are quarantined since I selected to quarantine silent viruses. May 15 13:52:52 localhost MailScanner[30916]: Virus and Content Scanning: Starting May 15 13:53:23 localhost MailScanner[30916]: Commercial scanner clamav timed out! May 15 13:53:23 localhost MailScanner[30916]: clamav: Failed to complete, timed out May 15 13:53:23 localhost MailScanner[30916]: Virus Scanning: Denial Of Service attack detected! May 15 13:53:54 localhost MailScanner[30916]: Commercial scanner clamav timed out! May 15 13:53:54 localhost MailScanner[30916]: clamav: Failed to complete, timed out May 15 13:53:54 localhost MailScanner[30916]: Virus Scanning: Denial Of Service attack is in message 096EAC42EE.ABDA7 May 15 13:54:56 localhost MailScanner[30916]: Infected message 096EAC42EE.ABDA7 came from xxx.11.206.74 May 15 13:54:56 localhost MailScanner[30916]: HTML Img tag found in message B34D6C441C.201C8 from cakrystyemi@iriomote.com May 15 13:54:56 localhost MailScanner[30916]: tag found in message 69E50C42EF.E6402 from May 15 13:54:56 localhost MailScanner[30916]: Virus Scanning completed at 479 bytes per second May 15 13:54:56 localhost MailScanner[30916]: Saved entire message to /var/spool/MailScanner/quarantine/20070515/096EAC42EE.ABDA7 May 15 13:54:56 localhost MailScanner[30916]: Viruses marked as silent: Denial of Service attack in message! May 15 13:54:5 The mails are legitimate and it doesn't look like there is anything fishy about them. The server is not experiencing a very heavy load the problem comes up a few minutes after the server is started. I've got a second machine running an older version of Mailscanner ( 4.55.10-3), which is also experiencing clamav time outs, but not marking those mails as Viruses. Is there any option I can set to still deliver these mails? OS: Debian Sarge Mailscanner Version is 4.57.6-1 Clamav Version is: 0.90.2-1+b1 Regards Norbert -- Norbert Schmidt | IT / Systems Interactive Data Managed Solutions AG ---------------------------------------------------------------------- -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From mkettler at evi-inc.com Tue May 15 15:03:49 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Tue May 15 15:04:13 2007 Subject: Preferred Distribution In-Reply-To: <1178871369.6218.4.camel@gblades-suse.linguaphone-intranet.co.uk> References: <1E293D3FF63A3740B10AD5AAD88535D204E13733@UBIMAIL1.ubisoft.org> <46436364.40507@txmail.marinocrane.com> <46437500.7080204@ecs.soton.ac.uk> <46437EB8.4050004@evi-inc.com> <1178871369.6218.4.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <4649BDC5.5090602@evi-inc.com> Gareth wrote: > On Thu, 2007-05-10 at 21:21, Matt Kettler wrote: >> Scott Silva wrote: >>> People should stop using RedHat 6. It has got to be almost 8 years old! >> Yeah, clearly they should be on 6.3 by now :) >> >> Quite frankly, I'd be surprised if modern MailScanner would even run on RedHat >> 6.x.. Those releases used perl 5.005. It might run, but a lot of add-ons won't. >> >> I know the mailscanner RPM claims it only needs >= 5.005, but I know >> SpamAssassin 3.0.0 and higher require perl 5.6 or higher. >> >> As of 3.46 HTML::Parser requires perl 5.6 or higher. > > I am still using Redhat 9 on my home server. I am running Spamassassin > 3.18 fine with Pyzor, Razor, FuzzyOCR etc... > > I upgraded Perl to 5.8 and then reinstalled all the modules. > I think one program failed to run afterwards but I just edited the per > to make it point to the old perl. > I had problems getting a couple of modules to install so I think SPF > checks are currently not operational but thats it. > Redhat 9 should be fine.. There's some limitations, ie: some of the newer sendmail features aren't supported, but nothing horrible. Redhat 6 on the other hand is a lot older, and would be quite troublesome to run MailScanner on. From MailScanner at ecs.soton.ac.uk Tue May 15 15:12:02 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 15 15:12:42 2007 Subject: Report: Denial of Service attack in message! In-Reply-To: References: Message-ID: <4649BFB2.3080402@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 This could happen if for some reason clamscan is asking for user input. This should not happen in normal situations, obviously. Have you changed the "Virus Scanner Timeout" setting from the default (300 seconds == 5 minutes)? Run the command MailScanner --changed | grep 'timeout' and tell me what it says. It should be left at the default value of 300 seconds. The new 0.90 clamscan is very slow to start up and could easily take 30 seconds to scan a large batch of messages. From your log entries below, I think you have changed the timeout :-( Do you have the clamavmodule Mail::ClamAV perl module installed? "MailScanner -version" will tell you. And "MailScanner -lint" will tell you if it thinks you have the support for the clamavmodule scanner all installed. If you do have it all installed okay (and you need Mail::ClamAV version 0.20 for ClamAV 0.90 !) then try using the "clamavmodule" instead of the "clamav" virus scanner. Then see if this helps solve the problem. Jules. Norbert Schmidt wrote: > Hi, > > I am seeing quite a few "Report: Denial of Service attack in message!" in > the logfiles. > > The mails are quarantined since I selected to quarantine silent viruses. > > > May 15 13:52:52 localhost MailScanner[30916]: Virus and Content Scanning: > Starting > May 15 13:53:23 localhost MailScanner[30916]: Commercial scanner clamav > timed out! > May 15 13:53:23 localhost MailScanner[30916]: clamav: Failed to complete, > timed out > May 15 13:53:23 localhost MailScanner[30916]: Virus Scanning: Denial Of > Service attack detected! > May 15 13:53:54 localhost MailScanner[30916]: Commercial scanner clamav > timed out! > May 15 13:53:54 localhost MailScanner[30916]: clamav: Failed to complete, > timed out > May 15 13:53:54 localhost MailScanner[30916]: Virus Scanning: Denial Of > Service attack is in message 096EAC42EE.ABDA7 > May 15 13:54:56 localhost MailScanner[30916]: Infected message > 096EAC42EE.ABDA7 came from xxx.11.206.74 > May 15 13:54:56 localhost MailScanner[30916]: HTML Img tag found in > message B34D6C441C.201C8 from cakrystyemi@iriomote.com > May 15 13:54:56 localhost MailScanner[30916]: tag found in message > 69E50C42EF.E6402 from > May 15 13:54:56 localhost MailScanner[30916]: Virus Scanning completed at > 479 bytes per second > May 15 13:54:56 localhost MailScanner[30916]: Saved entire message to > /var/spool/MailScanner/quarantine/20070515/096EAC42EE.ABDA7 > May 15 13:54:56 localhost MailScanner[30916]: Viruses marked as silent: > Denial of Service attack in message! > May 15 13:54:5 > > > The mails are legitimate and it doesn't look like there is anything fishy > about them. > > > The server is not experiencing a very heavy load the problem comes up a > few minutes after the server is started. > I've got a second machine running an older version of Mailscanner ( > 4.55.10-3), which is also experiencing clamav time outs, but not marking > those mails as Viruses. > Is there any option I can set to still deliver these mails? > > OS: Debian Sarge > Mailscanner Version is 4.57.6-1 > Clamav Version is: 0.90.2-1+b1 > > Regards > > Norbert > -- > > Norbert Schmidt | IT / Systems > Interactive Data Managed Solutions AG > ---------------------------------------------------------------------- > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGSb+3EfZZRxQVtlQRAnIEAKDzuXABcui5a2N+YkBc0ZQsE5+UTwCgsipo pqyzzSth8d7xqWLhleLWjoc= =5/X3 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From steinkel at pa.net Tue May 15 15:36:04 2007 From: steinkel at pa.net (Leland J. Steinke) Date: Tue May 15 15:37:13 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <4649AE3A.3030405@ecs.soton.ac.uk> References: <46498A71.7000401@ecs.soton.ac.uk> <4649AE3A.3030405@ecs.soton.ac.uk> Message-ID: <4649C554.3060300@pa.net> Julian Field wrote: > > # JKF 3/10/2005 > my $temp = @HitList; > $temp = $temp + 0; > $temp = 0 unless $HitList[0] =~ /a-z/i; > return ($temp, join(', ', @HitList)); > } > > Let's see if that helps. According to the book, the 2 middle lines > shouldn't be needed at all. Why not "my $temp = scalar(@HitList);"? Leland From MailScanner at ecs.soton.ac.uk Tue May 15 15:58:31 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 15 15:59:27 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <4649C554.3060300@pa.net> References: <46498A71.7000401@ecs.soton.ac.uk> <4649AE3A.3030405@ecs.soton.ac.uk> <4649C554.3060300@pa.net> Message-ID: <4649CA97.5050802@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Leland J. Steinke wrote: > Julian Field wrote: >> >> # JKF 3/10/2005 >> my $temp = @HitList; >> $temp = $temp + 0; >> $temp = 0 unless $HitList[0] =~ /a-z/i; >> return ($temp, join(', ', @HitList)); >> } >> >> Let's see if that helps. According to the book, the 2 middle lines >> shouldn't be needed at all. > > Why not "my $temp = scalar(@HitList);"? That should be the exact equivalent of "$temp = @HitList" as $temp is a scalar anyway. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGScqmEfZZRxQVtlQRAk0fAKDkHKSy1XfSr7NmFl7exuiR5RJmGgCcC79L BZI+vdG3BNijd2m6HIXK/zA= =311a -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From mrm at medicine.wisc.edu Tue May 15 18:20:38 2007 From: mrm at medicine.wisc.edu (Michael Masse) Date: Tue May 15 18:21:12 2007 Subject: Detecting forwarded spam Message-ID: <4649A54A.7FBE.00FC.3@medicine.wisc.edu> Is there a way for MailScanner to detect if a forwarded message has already been detected as spam by another system, therefore not needing to run it's own spam check? We have a large number of users who used to use a separate email provider and they now just have that email forwarded to their account here. Their old system detects spam and creates a header entry like: X-Spam-Report: IsSpam=yes Right now our system just ignores that, so I was wondering if I can get our Mailscanner to take this into account and not bother with spamassassin checks if it sees this in the header? I'm sure I could make a spamassassin rule to assign points if it saw this, but the whole point is to not have to get spamassassin involved. Is this possible, or should I just stick with a spamassassin rule? Mike From ugob at lubik.ca Tue May 15 18:28:24 2007 From: ugob at lubik.ca (Ugo Bellavance) Date: Tue May 15 18:28:40 2007 Subject: SA: change score for one rule for one destination domain Message-ID: Hi, After trying several times sending to the SA list, I have to post here: I read the rules howtos, and I have done a few SA custom rules myself, but I can't figure out this one... Is it possible to disable Botnet (or any other rule) for one destination domain? Is is enough to create a rule saying that 'for this "To: domain", set score to 0.0? Regards, Ugo From ssilva at sgvwater.com Tue May 15 18:41:27 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 15 18:41:51 2007 Subject: Detecting forwarded spam In-Reply-To: <4649A54A.7FBE.00FC.3@medicine.wisc.edu> References: <4649A54A.7FBE.00FC.3@medicine.wisc.edu> Message-ID: Michael Masse spake the following on 5/15/2007 10:20 AM: > Is there a way for MailScanner to detect if a forwarded message has already been detected as spam by another system, therefore not needing to run it's own spam check? > > We have a large number of users who used to use a separate email provider and they now just have that email forwarded to their account here. Their old system detects spam and creates a header entry like: > X-Spam-Report: IsSpam=yes > > Right now our system just ignores that, so I was wondering if I can get our Mailscanner to take this into account and not bother with spamassassin checks if it sees this in the header? I'm sure I could make a spamassassin rule to assign points if it saw this, but the whole point is to not have to get spamassassin involved. > > Is this possible, or should I just stick with a spamassassin rule? > > Mike > > You could write a custom function to do this, and maybe you could get Julian to write it for you for some $$$ (money, deniro, cash, mammon, greenbacks, script, coinage, euros, pounds sterling, etc...). -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Tue May 15 18:42:24 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 15 18:45:11 2007 Subject: SA: change score for one rule for one destination domain In-Reply-To: References: Message-ID: Ugo Bellavance spake the following on 5/15/2007 10:28 AM: > Hi, > > After trying several times sending to the SA list, I have to post here: > > I read the rules howtos, and I have done a few SA custom rules myself, > but I can't figure out this one... > > Is it possible to disable Botnet (or any other rule) for one destination > domain? Is is enough to create a rule saying that 'for this "To: > domain", set score to 0.0? > > Regards, > > Ugo > Can you just whitelist that domain in spamassassins whitelist? -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From prandal at herefordshire.gov.uk Tue May 15 18:50:12 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Tue May 15 18:50:23 2007 Subject: Detecting forwarded spam In-Reply-To: <4649A54A.7FBE.00FC.3@medicine.wisc.edu> References: <4649A54A.7FBE.00FC.3@medicine.wisc.edu> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBAB25440@HC-MBX02.herefordshire.gov.uk> Great idea. Not! I'll just send you 100,000 spams with an "X-Spam-Report: IsSpam=yes" header. Just what you wanted? Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Michael Masse > Sent: 15 May 2007 18:21 > To: Subject: Detecting forwarded spam > > Is there a way for MailScanner to detect if a forwarded > message has already been detected as spam by another system, > therefore not needing to run it's own spam check? > > We have a large number of users who used to use a separate > email provider and they now just have that email forwarded to > their account here. Their old system detects spam and > creates a header entry like: > X-Spam-Report: IsSpam=yes > > Right now our system just ignores that, so I was wondering if > I can get our Mailscanner to take this into account and not > bother with spamassassin checks if it sees this in the > header? I'm sure I could make a spamassassin rule to > assign points if it saw this, but the whole point is to not > have to get spamassassin involved. > > Is this possible, or should I just stick with a spamassassin rule? > > Mike > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From mrm at medicine.wisc.edu Tue May 15 19:22:55 2007 From: mrm at medicine.wisc.edu (Michael Masse) Date: Tue May 15 19:23:52 2007 Subject: Detecting forwarded spam In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBAB25440@HC-MBX02.herefordshire.gov.uk> References: <4649A54A.7FBE.00FC.3@medicine.wisc.edu> <7EF0EE5CB3B263488C8C18823239BEBAB25440@HC-MBX02.herefordshire.gov.uk> Message-ID: <4649B3E3.7FBE.00FC.3@medicine.wisc.edu> >>> On 5/15/2007 at 12:50 PM, in message > Great idea. > > Not! > > I'll just send you 100,000 spams with an "X-Spam-Report: IsSpam=yes" > header. > > Just what you wanted? > > Cheers, > Why would I care? If MailScanner could pick them out, then I wouldn't waste any time with spamassassin on them and they could just get sent to /dev/null. So yes, it is just what I wanted. Mike From list-mailscanner at linguaphone.com Tue May 15 19:43:57 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Tue May 15 19:44:09 2007 Subject: Detecting forwarded spam In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBAB25440@HC-MBX02.herefordshire.gov.uk> Message-ID: > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Randal, > Phil > Sent: 15 May 2007 18:50 > To: MailScanner discussion > Subject: RE: Detecting forwarded spam > > > Great idea. > > Not! > > I'll just send you 100,000 spams with an "X-Spam-Report: IsSpam=yes" > header. > > Just what you wanted? > > Cheers, > > Phil It would only be a problem if IsSpam=no was used to bypass spamassassin and deliver anyway. Doing what the author asked would only allow people to abuse the system by having all abusive email automatically classed as spam which is not an issue. From Denis.Beauchemin at USherbrooke.ca Tue May 15 19:59:47 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Tue May 15 20:00:09 2007 Subject: Detecting forwarded spam In-Reply-To: <4649B3E3.7FBE.00FC.3@medicine.wisc.edu> References: <4649A54A.7FBE.00FC.3@medicine.wisc.edu> <7EF0EE5CB3B263488C8C18823239BEBAB25440@HC-MBX02.herefordshire.gov.uk> <4649B3E3.7FBE.00FC.3@medicine.wisc.edu> Message-ID: <464A0323.8030609@USherbrooke.ca> Michael Masse a ?crit : >>>> On 5/15/2007 at 12:50 PM, in message >>>> >> Great idea. >> >> Not! >> >> I'll just send you 100,000 spams with an "X-Spam-Report: IsSpam=yes" >> header. >> >> Just what you wanted? >> >> Cheers, >> >> > > Why would I care? If MailScanner could pick them out, then I wouldn't waste any time with spamassassin on them and they could just get sent to /dev/null. > > So yes, it is just what I wanted. > > Mike > > > Do you delete all spam MS catches? If so then I guess you could do the same with spam identified by others, but otherwise how would you know the score of the spam you received? Even if you could find it, would you trust it? It could be abused. I delete all spam which score 20 or more. This is quite conservative but I nonetheless delete close to 90% of all spam MS finds. That leaves 10% to my users' scrutiny. If I elected to trust other sites about spam detection I can't think of a way I could still delete all that spam without going overboard and deleting borderline spam that happen to be ham... I would definitely not use such a feature! Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3595 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070515/d3106875/smime.bin From uxbod at splatnix.net Tue May 15 20:07:20 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Tue May 15 20:07:24 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <4649CA97.5050802@ecs.soton.ac.uk> References: <4649CA97.5050802@ecs.soton.ac.uk> Message-ID: Hi Jules, I will try out the change tomorrow. Also noticed that it is doing the same on my home server, so it is not a isolated issue. Both servers are x86_64 by the way. Cheers, On Tue, 15 May 2007 15:58:31 +0100, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Leland J. Steinke wrote: >> Julian Field wrote: >>> >>> # JKF 3/10/2005 >>> my $temp = @HitList; >>> $temp = $temp + 0; >>> $temp = 0 unless $HitList[0] =~ /a-z/i; >>> return ($temp, join(', ', @HitList)); >>> } >>> >>> Let's see if that helps. According to the book, the 2 middle lines >>> shouldn't be needed at all. >> >> Why not "my $temp = scalar(@HitList);"? > That should be the exact equivalent of "$temp = @HitList" as $temp is a > scalar anyway. > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: UTF-8 > > wj8DBQFGScqmEfZZRxQVtlQRAk0fAKDkHKSy1XfSr7NmFl7exuiR5RJmGgCcC79L > BZI+vdG3BNijd2m6HIXK/zA= > =311a > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ugob at lubik.ca Tue May 15 20:40:44 2007 From: ugob at lubik.ca (Ugo Bellavance) Date: Tue May 15 20:40:56 2007 Subject: SA: change score for one rule for one destination domain In-Reply-To: References: Message-ID: Scott Silva wrote: > Ugo Bellavance spake the following on 5/15/2007 10:28 AM: >> Hi, >> >> After trying several times sending to the SA list, I have to post here: >> >> I read the rules howtos, and I have done a few SA custom rules myself, >> but I can't figure out this one... >> >> Is it possible to disable Botnet (or any other rule) for one destination >> domain? Is is enough to create a rule saying that 'for this "To: >> domain", set score to 0.0? >> >> Regards, >> >> Ugo >> > Can you just whitelist that domain in spamassassins whitelist? > > No, many source domains have this problem... We'd like to disable botnet for one destination domain. Thanks, Ugo From mkettler at evi-inc.com Tue May 15 21:29:15 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Tue May 15 21:29:27 2007 Subject: Detecting forwarded spam In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBAB25440@HC-MBX02.herefordshire.gov.uk> References: <4649A54A.7FBE.00FC.3@medicine.wisc.edu> <7EF0EE5CB3B263488C8C18823239BEBAB25440@HC-MBX02.herefordshire.gov.uk> Message-ID: <464A181B.5070202@evi-inc.com> Randal, Phil wrote: > Great idea. > > Not! > > I'll just send you 100,000 spams with an "X-Spam-Report: IsSpam=yes" > header. > > Just what you wanted? If someone wants to self-declare that all their mail is spam, why should we stop them? Why should we not honor that and automatically treat them as spam without further evaluation? Do I really need to rescan the message and independently conclude that it is, in fact, spam? It's one thing to not trust one that says IsSpam=no, because spammers have a motivation to fake that to bypass your filters. However, who has any motivation to falsely declare that a message is spam? Anyone who isn't a moron or twit? At that point you may as well argue that GTUBE should be eliminated from SpamAssassin because anyone can insert the GTUBE string into their message and force your SA to categorize it as spam... So what? I can send you emails with GTUBE in it as well. The end result is the same, it ends up being categorized as spam. From daniel.maher at ubisoft.com Tue May 15 21:34:33 2007 From: daniel.maher at ubisoft.com (Daniel Maher) Date: Tue May 15 21:34:37 2007 Subject: mailscanner error, but doesn't appear to affect delivery? Message-ID: <1E293D3FF63A3740B10AD5AAD88535D204ED7EE0@UBIMAIL1.ubisoft.org> Hi all, I recently built a brand-new incoming mail server, using Postfix 2.4.x, SpamAssassin 3.2.x, and the newest MailScanner and MailWatch packages. It works properly, in that it receives, scans, tags, and delivers mail; however, every mail that it parses produces the following error in the mail log: May 15 20:26:41 localhost MailScanner[3225]: /var/spool/MailScanner/incoming/3225/./23322FA4E.22E9F.header: Unable to open file or directory ERROR Of course, the path (which exists, and is readable by MailScanner) and filename are different for each mail, but the message is the same. Again, as I mentioned above, the mail is properly scanned and delivered, so the error doesn't appear to be affecting behaviour at all. That said, it is worrisome that an error is being produced at all - especially if it's "not really" an error. Any ideas? -- _ ?v? Daniel Maher /(_)\ Administrateur Syst?me Unix ^ ^ Unix System Administrator "The most incomprehensible thing about the world is that it is comprehensible." -- Albert Einstein. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070515/7fc1522e/attachment.html From jnalley at fgp.com Tue May 15 21:32:45 2007 From: jnalley at fgp.com (Jonathan Nalley) Date: Tue May 15 21:35:06 2007 Subject: postfix dropping SMTP connection when receiving mail - RESOLVED In-Reply-To: <4644D221.3050403@fgp.com> References: <4644D221.3050403@fgp.com> Message-ID: <464A18ED.2060102@fgp.com> just as an update, after running wireshark on both machines involved, i found that there were several TCP checksum's that were not correct and other such errors at that level. Wireshark had a blurb in there about the problem possibly being caused by TCP Offloading and so as a workaround, i disabled TCP Offloading on my M$ exchange box and all is well again. On Friday, May 11, 2007 16:29:21 , Jonathan Nalley wrote: > Hi, I'm running MailScanner 4.58.9-1 using postfix 2.3.3 on Centos 5. > > I've set our M$ Exchange Server 2007 to use our MailScanner/Postfix box as a "smart host" such that all outbound mail would be sent through the MailScanner/postfix box. The problem is that when the Exchange box is trying to pass along an e-mail to postfix, the connection and SMTP session gets dropped or something really bizarre is going on. > > Below is a snippet of /var/log/maillog (with postfix's debug_peer_level=1000). For the purposes of these pasted log files. 192.168.0.207 is the exchange box and 192.168.0.208 is the Postfix box. > > May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_hostname: exchange.myinternaldomain.com ~? 192.168.0.0/24 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_hostaddr: 192.168.0.207 ~? 192.168.0.0/24 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 220 mailscanner.myinternaldomain.com ESMTP Postfix > May 11 09:40:23 mailscanner postfix/smtpd[18829]: watchdog_pat: 0x99266a0 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: vstream_fflush_some: fd 9 flush 83 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: vstream_buf_get_ready: fd 9 got 29 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: < exchange.myinternaldomain.com[192.168.0.207]: EHLO exchange.myinternaldomain.com > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-mailscanner.myinternaldomain.com > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-PIPELINING > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-SIZE 10240000 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-VRFY > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-ETRN > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-AUTH LOGIN PLAIN > May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_list_match: exchange.myinternaldomain.com: no match > May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_list_match: 192.168.0.207: no match > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-AUTH=LOGIN PLAIN > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-ENHANCEDSTATUSCODES > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250-8BITMIME > May 11 09:40:23 mailscanner postfix/smtpd[18829]: > exchange.myinternaldomain.com[192.168.0.207]: 250 DSN > May 11 09:40:23 mailscanner postfix/smtpd[18829]: watchdog_pat: 0x99266a0 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: vstream_fflush_some: fd 9 flush 178 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: smtp_get: EOF > May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_hostname: exchange.myinternaldomain.com ~? 192.168.0.0/24 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: match_hostaddr: 192.168.0.207 ~? 192.168.0.0/24 > May 11 09:40:23 mailscanner postfix/smtpd[18829]: lost connection after EHLO from exchange.myinternaldomain.com[192.168.0.207] > May 11 09:40:23 mailscanner postfix/smtpd[18829]: disconnect from exchange.myinternaldomain.com[192.168.0.207] > > > When enabling verbose session logging on the M$ Exchange box, below is the relevant SMTP session snippet: > > 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,0,,192.168.0.208:25,*,,attempting to connect > 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,1,192.168.0.207:11256,192.168.0.208:25,+,, > 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,2,192.168.0.207:11256,192.168.0.208:25,<,220 postfixbox.myinternaldomain.com ESMTP Postfix, > 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,3,192.168.0.207:11256,192.168.0.208:25,>,EHLO exchange.myinternaldomain.com, > 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,4,192.168.0.207:11256,192.168.0.208:25,<, > 2007-05-11T18:06:53.714Z,PostFixSendConnector,08C9612DB0BAB77B,5,192.168.0.207:11256,192.168.0.208:25,-,,Local > > The second-to-last line actually has 65 spaces and then the closing comma but i couldn't get my mailer to display that in a desirable fashion. > > I know it's tempting to say or to think that the problem might be with the M$ Exchange box, but i can tell Exchange to use other Postfix/MailScanner installations (admittedly running MailScanner version 4.46.2-2 and postfix version 2.1.5) as the smart host and everything works smoothly. > > I've seen other posts in the mailing list with people having "smtp_get: EOF" in their logs and other similar entries but many were related to TLS, SSL, SASL and authentication and all that stuff but i'm not trying to do any of that here. Any thoughts, wisdom, insights, fixes, and solutions greatly appreciated. Thanks In Advance. > > > Below is postconf -n: > > alias_database = hash:/etc/aliases > alias_maps = hash:/etc/aliases > broken_sasl_auth_clients = yes > command_directory = /usr/sbin > config_directory = /etc/postfix > daemon_directory = /usr/libexec/postfix > debug_peer_level = 1000 > debug_peer_list = 192.168.0.207 > header_checks = regexp:/etc/postfix/header_checks > html_directory = no > inet_interfaces = all > mail_owner = postfix > mailq_path = /usr/bin/mailq.postfix > manpage_directory = /usr/share/man > mydestination = localhost.$mydomain, localhost, $mydomain > mydomain = myinternaldomain.com > myhostname = mailscanner.myinternaldomain.com > mynetworks = 192.168.0.0/24, 127.0.0.0/8 > myorigin = $mydomain > newaliases_path = /usr/bin/newaliases.postfix > queue_directory = /var/spool/postfix > readme_directory = /usr/share/doc/postfix-2.3.3/README_FILES > relay_domains = $mydestination > sample_directory = /usr/share/doc/postfix-2.3.3/samples > sendmail_path = /usr/sbin/sendmail.postfix > setgid_group = postdrop > smtpd_banner = $myhostname ESMTP $mail_name > smtpd_recipient_restrictions = permit_mynetworks permit_sasl_authenticated reject_unauth_destination > smtpd_sasl_auth_enable = yes > smtpd_sasl_path = smtpd > transport_maps = hash:/etc/postfix/transport > unknown_local_recipient_reject_code = 550 > > From dominian at slackadelic.com Tue May 15 21:44:41 2007 From: dominian at slackadelic.com (Matt Hayes) Date: Tue May 15 21:44:52 2007 Subject: mailscanner error, but doesn't appear to affect delivery? In-Reply-To: <1E293D3FF63A3740B10AD5AAD88535D204ED7EE0@UBIMAIL1.ubisoft.org> References: <1E293D3FF63A3740B10AD5AAD88535D204ED7EE0@UBIMAIL1.ubisoft.org> Message-ID: <464A1BB9.4010501@slackadelic.com> Daniel Maher wrote: > Hi all, > > > > I recently built a brand-new incoming mail server, using Postfix 2.4.x, > SpamAssassin 3.2.x, and the newest MailScanner and MailWatch packages. > It works properly, in that it receives, scans, tags, and delivers mail; > however, every mail that it parses produces the following error in the > mail log: > > > > May 15 20:26:41 localhost MailScanner[3225]: > /var/spool/MailScanner/incoming/3225/./23322FA4E.22E9F.header: Unable to > open file or directory ERROR > > > > Of course, the path (which exists, and is readable by MailScanner) and > filename are different for each mail, but the message is the same. > Again, as I mentioned above, the mail is properly scanned and > delivered, so the error doesn?t appear to be affecting behaviour at all. > That said, it is worrisome that an error is being produced at all ? > especially if it?s ?not really? an error. > > > > Any ideas? > Its looking to use /dev/shm. I had the same issue. Once I setup fstab to load /dev/shm and mounted it.. the error went away. For some odd reason, with the newest release of MailScanner.. it actually wants spamassassin to use /dev/shm.. which actually helps speed up scan times. However, in previous versions, I found the same "if /dev/shm exists use it" for SA and it wasn't being used... but suddenly it does hehe. Invoking MailScanner in debug mode would've helped you to figure this out :) -Matt From daniel.maher at ubisoft.com Tue May 15 22:02:34 2007 From: daniel.maher at ubisoft.com (Daniel Maher) Date: Tue May 15 22:02:39 2007 Subject: mailscanner error, but doesn't appear to affect delivery? In-Reply-To: <464A1BB9.4010501@slackadelic.com> Message-ID: <1E293D3FF63A3740B10AD5AAD88535D204ED7F61@UBIMAIL1.ubisoft.org> > Its looking to use /dev/shm. > > I had the same issue. Once I setup fstab to load /dev/shm and mounted > it.. the error went away. > > For some odd reason, with the newest release of MailScanner.. it > actually wants spamassassin to use /dev/shm.. which actually helps speed > up scan times. > > However, in previous versions, I found the same "if /dev/shm exists use > it" for SA and it wasn't being used... but suddenly it does hehe. > > Invoking MailScanner in debug mode would've helped you to figure this out > :) If it's looking to use /dev/shm, it's welcome to do so: # grep shm /etc/fstab none /dev/shm tmpfs defaults 0 0 That said, I restarted mailscanner a few times - just for fun - and now the error has disappeared. I'm happy that the error is gone, but not as pleased about the fact that waving a dead chicken around seemed to solve it. Any further insight would be most welcome. -- _ ?v? Daniel Maher /(_)\ Administrateur Syst?me Unix ^ ^ Unix System Administrator "The most incomprehensible thing about the world is that it is comprehensible." -- Albert Einstein. From ssilva at sgvwater.com Tue May 15 22:37:47 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 15 22:38:17 2007 Subject: mailscanner error, but doesn't appear to affect delivery? In-Reply-To: <1E293D3FF63A3740B10AD5AAD88535D204ED7F61@UBIMAIL1.ubisoft.org> References: <464A1BB9.4010501@slackadelic.com> <1E293D3FF63A3740B10AD5AAD88535D204ED7F61@UBIMAIL1.ubisoft.org> Message-ID: Daniel Maher spake the following on 5/15/2007 2:02 PM: >> Its looking to use /dev/shm. >> >> I had the same issue. Once I setup fstab to load /dev/shm and mounted >> it.. the error went away. >> >> For some odd reason, with the newest release of MailScanner.. it >> actually wants spamassassin to use /dev/shm.. which actually helps speed >> up scan times. >> >> However, in previous versions, I found the same "if /dev/shm exists use >> it" for SA and it wasn't being used... but suddenly it does hehe. >> >> Invoking MailScanner in debug mode would've helped you to figure this out >> :) > > If it's looking to use /dev/shm, it's welcome to do so: > > # grep shm /etc/fstab > none /dev/shm tmpfs defaults 0 0 > > That said, I restarted mailscanner a few times - just for fun - and now the error has disappeared. I'm happy that the error is gone, but not as pleased about the fact that waving a dead chicken around seemed to solve it. > > Any further insight would be most welcome. Waving the dead chicken is the current acceptable practice these days. Especially since the PETA people stopped us from waving LIVE chickens! ;-P Sacrificing old DAT tapes has also worked for some, as has chanting lines from Monty Python or The Hitchhikers Guide... If the error is gone, and doesn't come back, you fixed it.. Pat yourself on the back and go on to the hundreds of other problems that have probably come in to your inbox since you were working on this one. If it does come back, then you probably need to dig deeper. I know this doesn't seem to be the best way to deal with it, but it works, and it will let you have a few minutes of free time once in a while. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From glenn.steen at gmail.com Wed May 16 08:57:21 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed May 16 08:57:23 2007 Subject: SA: change score for one rule for one destination domain In-Reply-To: References: Message-ID: <223f97700705160057n4104ea5dm4686d72855d1b6d9@mail.gmail.com> On 15/05/07, Ugo Bellavance wrote: > Scott Silva wrote: > > Ugo Bellavance spake the following on 5/15/2007 10:28 AM: > >> Hi, > >> > >> After trying several times sending to the SA list, I have to post here: > >> > >> I read the rules howtos, and I have done a few SA custom rules myself, > >> but I can't figure out this one... > >> > >> Is it possible to disable Botnet (or any other rule) for one destination > >> domain? Is is enough to create a rule saying that 'for this "To: > >> domain", set score to 0.0? > >> > >> Regards, > >> > >> Ugo > >> > > Can you just whitelist that domain in spamassassins whitelist? > > > > > > No, many source domains have this problem... We'd like to disable botnet > for one destination domain. > > Thanks, > > Ugo > If you ask John, maybe he'll add support for it (if there isn't already support for it... ISTR there were some knobs like that... Don't use the plugin though, so don't really know:). I'm sure you'll find his email easily enough (heck, why not just search the archives for John Rudd:-):-). Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Wed May 16 09:07:54 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed May 16 09:07:57 2007 Subject: postfix dropping SMTP connection when receiving mail - RESOLVED In-Reply-To: <464A18ED.2060102@fgp.com> References: <4644D221.3050403@fgp.com> <464A18ED.2060102@fgp.com> Message-ID: <223f97700705160107r14cc9776w7bfbdadeda8e131@mail.gmail.com> On 15/05/07, Jonathan Nalley wrote: > just as an update, after running wireshark on both machines involved, i found that there were several TCP checksum's that were not correct and other such errors at that level. Wireshark had a blurb in there about the problem possibly being caused by TCP Offloading and so as a workaround, i disabled TCP Offloading on my M$ exchange box and all is well again. > So... All MTA, and the workable solution in exchange... Thanks for sharing Jonathan. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From martinh at solidstatelogic.com Wed May 16 09:36:18 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 16 09:36:26 2007 Subject: Detecting forwarded spam In-Reply-To: <4649A54A.7FBE.00FC.3@medicine.wisc.edu> Message-ID: <638c6232e17f17489ffb8b869c7a9475@solidstatelogic.com> Daniel We had a similar situation a few years back (3?). The X-MailScanner headers could be used as trust mechanism - ie it's got the "X-MailScanner: Found to be clean", so we'll trust that and allow the email through. Now the virus writers found out about this and inserted this header into the emails they send out, in order to circumvent MailScanner doing checks on the email. Jules had to rush a new release quickly where the %org-name% was inserted into the headers to try and make this a little unique, so there was some chance of the header being actually inserted by MS. Can't see anything in the changelog, but it was around version 4.22 from memory *IF* you trust this you may hold yourself open to false positives, ie just because someone else's system says its spam doesn't mean yours will. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Michael Masse > Sent: 15 May 2007 18:21 > To: Subject: Detecting forwarded spam > > Is there a way for MailScanner to detect if a forwarded message has > already been detected as spam by another system, therefore not needing to > run it's own spam check? > > We have a large number of users who used to use a separate email provider > and they now just have that email forwarded to their account here. > Their old system detects spam and creates a header entry like: > X-Spam-Report: IsSpam=yes > > Right now our system just ignores that, so I was wondering if I can get > our Mailscanner to take this into account and not bother with spamassassin > checks if it sees this in the header? I'm sure I could make a > spamassassin rule to assign points if it saw this, but the whole point is > to not have to get spamassassin involved. > > Is this possible, or should I just stick with a spamassassin rule? > > Mike > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From uxbod at splatnix.net Wed May 16 09:40:56 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Wed May 16 09:41:00 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <4649CA97.5050802@ecs.soton.ac.uk> References: <4649CA97.5050802@ecs.soton.ac.uk> Message-ID: <966f599d85a64d0aca29aa16c0991f8b@62.49.223.244> Hi Jules, Made the change this morning and no FPs so far. Will keep an eye on it throughout the day. Regards, On Tue, 15 May 2007 15:58:31 +0100, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Leland J. Steinke wrote: >> Julian Field wrote: >>> >>> # JKF 3/10/2005 >>> my $temp = @HitList; >>> $temp = $temp + 0; >>> $temp = 0 unless $HitList[0] =~ /a-z/i; >>> return ($temp, join(', ', @HitList)); >>> } >>> >>> Let's see if that helps. According to the book, the 2 middle lines >>> shouldn't be needed at all. >> >> Why not "my $temp = scalar(@HitList);"? > That should be the exact equivalent of "$temp = @HitList" as $temp is a > scalar anyway. > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: UTF-8 > > wj8DBQFGScqmEfZZRxQVtlQRAk0fAKDkHKSy1XfSr7NmFl7exuiR5RJmGgCcC79L > BZI+vdG3BNijd2m6HIXK/zA= > =311a > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From norbert.schmidt at interactivedata.com Wed May 16 09:46:40 2007 From: norbert.schmidt at interactivedata.com (Norbert Schmidt) Date: Wed May 16 09:50:56 2007 Subject: Report: Denial of Service attack in message! In-Reply-To: <200705151744.l4FHiaX4012853@safir.blacknight.ie> Message-ID: Hi Jules, the Value for "Virus Scanner Timeout" was still on the old standard (I belive) 30 seconds. I haven't changed that, but I've changed the version of clamav due to regular updates. This must have let to the problem. I've now raised the timeout to 300 seconds and all is quiet now. I think there is a big problem with the classification as "Denial of service attack" when the virusscanner times out because all messages in that batch are marked as "containing a virus" and thus are thrown away. This can lead to loss of a lot of legitimate mail that happened to be in the same batch with a mail containing a "Denial of service attack". I guess an option, to control this behaviour would be usefull. I do not have the Mail::ClamAV module installed but will do so now. This leads me to a question... Is it better to upgrade MailScanner or is it better to install the new version each time? We've been using MailScanner for the last 3 years now. I didn't go thru every version, but always skipped a few as it is always quite some hassel to go thru all options and set them up appropriate. Is there a way to set the seldom changed options like Company name, webpage etc. So after an update these things stay the same... Thanks for your help Norbert ----- Message from Julian Field on Tue, 15 May 2007 15:12:02 +0100 ----- To: MailScanner discussion Subject: Re: Report: Denial of Service attack in message! -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 This could happen if for some reason clamscan is asking for user input. This should not happen in normal situations, obviously. Have you changed the "Virus Scanner Timeout" setting from the default (300 seconds == 5 minutes)? Run the command MailScanner --changed | grep 'timeout' and tell me what it says. It should be left at the default value of 300 seconds. The new 0.90 clamscan is very slow to start up and could easily take 30 seconds to scan a large batch of messages. From your log entries below, I think you have changed the timeout :-( Do you have the clamavmodule Mail::ClamAV perl module installed? "MailScanner -version" will tell you. And "MailScanner -lint" will tell you if it thinks you have the support for the clamavmodule scanner all installed. If you do have it all installed okay (and you need Mail::ClamAV version 0.20 for ClamAV 0.90 !) then try using the "clamavmodule" instead of the "clamav" virus scanner. Then see if this helps solve the problem. Jules. Norbert Schmidt wrote: > Hi, > > I am seeing quite a few "Report: Denial of Service attack in message!" in > the logfiles. > > The mails are quarantined since I selected to quarantine silent viruses. > > > May 15 13:52:52 localhost MailScanner[30916]: Virus and Content Scanning: > Starting > May 15 13:53:23 localhost MailScanner[30916]: Commercial scanner clamav > timed out! > May 15 13:53:23 localhost MailScanner[30916]: clamav: Failed to complete, > timed out > May 15 13:53:23 localhost MailScanner[30916]: Virus Scanning: Denial Of > Service attack detected! > May 15 13:53:54 localhost MailScanner[30916]: Commercial scanner clamav > timed out! > May 15 13:53:54 localhost MailScanner[30916]: clamav: Failed to complete, > timed out > May 15 13:53:54 localhost MailScanner[30916]: Virus Scanning: Denial Of > Service attack is in message 096EAC42EE.ABDA7 > May 15 13:54:56 localhost MailScanner[30916]: Infected message > 096EAC42EE.ABDA7 came from xxx.11.206.74 > May 15 13:54:56 localhost MailScanner[30916]: HTML Img tag found in > message B34D6C441C.201C8 from cakrystyemi@iriomote.com > May 15 13:54:56 localhost MailScanner[30916]: tag found in message > 69E50C42EF.E6402 from > May 15 13:54:56 localhost MailScanner[30916]: Virus Scanning completed at > 479 bytes per second > May 15 13:54:56 localhost MailScanner[30916]: Saved entire message to > /var/spool/MailScanner/quarantine/20070515/096EAC42EE.ABDA7 > May 15 13:54:56 localhost MailScanner[30916]: Viruses marked as silent: > Denial of Service attack in message! > May 15 13:54:5 > > > The mails are legitimate and it doesn't look like there is anything fishy > about them. > > > The server is not experiencing a very heavy load the problem comes up a > few minutes after the server is started. > I've got a second machine running an older version of Mailscanner ( > 4.55.10-3), which is also experiencing clamav time outs, but not marking > those mails as Viruses. > Is there any option I can set to still deliver these mails? > > OS: Debian Sarge > Mailscanner Version is 4.57.6-1 > Clamav Version is: 0.90.2-1+b1 > > Regards > > Norbert -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3972 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070516/b04d7fc7/smime.bin From uxbod at splatnix.net Wed May 16 10:26:51 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Wed May 16 10:26:56 2007 Subject: MS & Lotus Notes Message-ID: <5b630a3c79229c7209ba7a19debf9b1b@62.49.223.244> Hi, We have received some helpdesk calls from users who have been experiencing no delivery messages with the following text :- DELIVERY FAILURE: Error transferring to XXXXXXXXXX/XXX/XXX mail.box; Cannotstore document - database has too many unique field names. Please set the'Allow more fields in database' option or ask your administrator to compact the database. Has anybody else seen these ? This is happening when we send emails to a couple of our suppliers. I am wondering whether they have a automated jobs which parses the email and stores the embedded data. Any ideas ? -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From martinh at solidstatelogic.com Wed May 16 10:35:04 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 16 10:35:04 2007 Subject: MS & Lotus Notes In-Reply-To: <5b630a3c79229c7209ba7a19debf9b1b@62.49.223.244> Message-ID: Hi This isn't a problem with the %org-name% containing illegal characters is it?? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- > Sent: 16 May 2007 10:27 > To: mailscanner@lists.mailscanner.info > Subject: MS & Lotus Notes > > Hi, > > We have received some helpdesk calls from users who have been experiencing > no delivery messages with the following text :- > > DELIVERY FAILURE: Error transferring to XXXXXXXXXX/XXX/XXX mail.box; > Cannotstore document - database has too many unique field names. Please > set the'Allow more fields in database' option or ask your administrator to > compact the database. > > Has anybody else seen these ? This is happening when we send emails to a > couple of our suppliers. I am wondering whether they have a automated > jobs which parses the email and stores the embedded data. > > Any ideas ? > -- > --[ UxBoD ]-- > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From uxbod at splatnix.net Wed May 16 10:36:14 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Wed May 16 10:36:20 2007 Subject: MS & Lotus Notes In-Reply-To: <5b630a3c79229c7209ba7a19debf9b1b@62.49.223.244> References: <5b630a3c79229c7209ba7a19debf9b1b@62.49.223.244> Message-ID: Is it possible to disable all MS headers from being inserted into outbound email ? On Wed, 16 May 2007 10:26:51 +0100, "--[ UxBoD ]--" wrote: > Hi, > > We have received some helpdesk calls from users who have been experiencing > no delivery messages with the following text :- > > DELIVERY FAILURE: Error transferring to XXXXXXXXXX/XXX/XXX mail.box; > Cannotstore document - database has too many unique field names. Please set > the'Allow more fields in database' option or ask your administrator to > compact the database. > > Has anybody else seen these ? This is happening when we send emails to a > couple of our suppliers. I am wondering whether they have a automated jobs > which parses the email and stores the embedded data. > > Any ideas ? > -- > --[ UxBoD ]-- > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From fabien.garziano at caliseo.com Wed May 16 10:39:17 2007 From: fabien.garziano at caliseo.com (Fabien GARZIANO) Date: Wed May 16 10:41:21 2007 Subject: Bayes disk space usage fast increase Message-ID: Hi, I'm stuck on an issue with my MailScanner mail gateway, actually with the bayesian database. I don't use any database so my bayesian files are on my /var FS. Since 2 days, disk space usage is fastly increasing and I'll soon be short of disk space. As far as I can see in logs, I don't find any explanation about this. I've looked in the FAQ on the website, and I don't see any thing like this. I've checked http://wiki.apache.org/spamassassin/BayesFaq?highlight=%28bayes%29 I've also tried to look in the mail archive but without success. My baysian files are in the default dir => /var/spool/MailScanner/spamassassin [root@califw3 spamassassin]# pwd /var/spool/MailScanner/spamassassin [root@califw3 spamassassin]# du -h 731M . [root@califw3 MailScanner]# spamassassin -D --lint debug: SpamAssassin version 3.0.5 [...] debug: bayes: 19794 tie-ing to DB file R/O /root/.spamassassin/bayes_toks debug: bayes: 19794 tie-ing to DB file R/O /root/.spamassassin/bayes_seen debug: bayes: found bayes db version 3 debug: bayes: Not available for scanning, only 0 spam(s) in Bayes DB < 200 debug: bayes: 19794 untie-ing debug: bayes: 19794 untie-ing db_toks debug: bayes: 19794 untie-ing db_seen Now, that's weird, cause I received some spam this morning, and bayes scored them. For information : [root@califw3 MailScanner]# MailScanner -v Running on Linux califw3.caliseo.fr 2.6.16-1.2108_FC4 #1 Thu May 4 23:52:01 EDT 2006 i686 i686 i386 GNU/Linux This is Fedora Core release 4 (Stentz) This is Perl version 5.008006 (5.8.6) This is MailScanner version 4.53.8 Is this behaviour usual ? I've been runnig this gateway for 1 year now, and that's the first time I got something like this. Anyone met this behaviour already ? Is there a way to limit bayes space usage ? Thanks ! From pete at enitech.com.au Wed May 16 10:42:44 2007 From: pete at enitech.com.au (Pete Russell) Date: Wed May 16 10:42:54 2007 Subject: MS & Lotus Notes In-Reply-To: References: Message-ID: <464AD214.2050107@enitech.com.au> Have you tested whether this occurs for certain users or all users and whether there is anything in mail.box ? Have you tried some of the basics like a updall, compact or fixup ? www.notes.net > go to the user forums > search for unique field names - i had a few issues with this, but on the NAB, at the start of the year, but i totally forget how i resolved it other than using notes.net :) Martin.Hepworth wrote: > Hi > > This isn't a problem with the %org-name% containing illegal characters > is it?? > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- >> Sent: 16 May 2007 10:27 >> To: mailscanner@lists.mailscanner.info >> Subject: MS & Lotus Notes >> >> Hi, >> >> We have received some helpdesk calls from users who have been > experiencing >> no delivery messages with the following text :- >> >> DELIVERY FAILURE: Error transferring to XXXXXXXXXX/XXX/XXX mail.box; >> Cannotstore document - database has too many unique field names. > Please >> set the'Allow more fields in database' option or ask your > administrator to >> compact the database. >> >> Has anybody else seen these ? This is happening when we send emails to > a >> couple of our suppliers. I am wondering whether they have a automated >> jobs which parses the email and stores the embedded data. >> >> Any ideas ? >> -- >> --[ UxBoD ]-- >> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" >> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >> >> >> -- >> This message has been scanned for viruses and dangerous content by >> MailScanner, and is >> believed to be clean. >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > From list-mailscanner at linguaphone.com Wed May 16 10:46:47 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed May 16 10:46:53 2007 Subject: Bayes disk space usage fast increase In-Reply-To: References: Message-ID: <1179308807.18358.18.camel@gblades-suse.linguaphone-intranet.co.uk> On Wed, 2007-05-16 at 10:39, Fabien GARZIANO wrote: > Hi, > > I'm stuck on an issue with my MailScanner mail gateway, actually with > the bayesian database. I don't use any database so my bayesian files are > on my /var FS. Since 2 days, disk space usage is fastly increasing and > I'll soon be short of disk space. As far as I can see in logs, I don't > find any explanation about this. I've looked in the FAQ on the website, > and I don't see any thing like this. Can you do a directory listing on the offending bayes files so we can see how big each one of them is. From febrianto at sioenasia.com Wed May 16 10:51:57 2007 From: febrianto at sioenasia.com (Budi Febrianto) Date: Wed May 16 10:47:03 2007 Subject: MS & Lotus Notes In-Reply-To: <5b630a3c79229c7209ba7a19debf9b1b@62.49.223.244> Message-ID: mailscanner-bounces@lists.mailscanner.info wrote on 05-16-2007 04:26:51 PM: > Hi, > > We have received some helpdesk calls from users who have been > experiencing no delivery messages with the following text :- > > DELIVERY FAILURE: Error transferring to XXXXXXXXXX/XXX/XXX mail.box; > Cannotstore document - database has too many unique field names. > Please set the'Allow more fields in database' option or ask your > administrator to compact the database. > > Has anybody else seen these ? This is happening when we send emails > to a couple of our suppliers. I am wondering whether they have a > automated jobs which parses the email and stores the embedded data. > > Any ideas ? > -- > --[ UxBoD ]-- > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > I'm using lotus notes and mailscanner. Is you or your customer that using lotus notes? In standard lotus notes, there is limitation on how many fields that in one database can have, and simply enable 'allow more fields in database' will help. I think mailscanner add too much headers in outgoing emails. From ajs at vifilfell.is Wed May 16 10:41:32 2007 From: ajs at vifilfell.is (ajs@vifilfell.is) Date: Wed May 16 10:47:19 2007 Subject: MS & Lotus Notes In-Reply-To: Message-ID: if I remember right, you have to check the "Allow more fields in database" option, in the advanced options tab, for the mail template and then "refresh design" for all the lotus users. asgeir. "--[ UxBoD ]--" Sent by: mailscanner-bounces@lists.mailscanner.info 16.05.2007 09:36 Please respond to MailScanner discussion To MailScanner discussion cc Subject Re: MS & Lotus Notes Is it possible to disable all MS headers from being inserted into outbound email ? On Wed, 16 May 2007 10:26:51 +0100, "--[ UxBoD ]--" wrote: > Hi, > > We have received some helpdesk calls from users who have been experiencing > no delivery messages with the following text :- > > DELIVERY FAILURE: Error transferring to XXXXXXXXXX/XXX/XXX mail.box; > Cannotstore document - database has too many unique field names. Please set > the'Allow more fields in database' option or ask your administrator to > compact the database. > > Has anybody else seen these ? This is happening when we send emails to a > couple of our suppliers. I am wondering whether they have a automated jobs > which parses the email and stores the embedded data. > > Any ideas ? > -- > --[ UxBoD ]-- > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From uxbod at splatnix.net Wed May 16 10:48:05 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Wed May 16 10:48:10 2007 Subject: MS & Lotus Notes In-Reply-To: References: Message-ID: <3740fc59ebcb52cfc5f6ab7394365211@62.49.223.244> Nope. That is set to a single word all lower case, and no funny characters. On Wed, 16 May 2007 10:35:04 +0100, "Martin.Hepworth" wrote: > Hi > > This isn't a problem with the %org-name% containing illegal characters > is it?? > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- >> Sent: 16 May 2007 10:27 >> To: mailscanner@lists.mailscanner.info >> Subject: MS & Lotus Notes >> >> Hi, >> >> We have received some helpdesk calls from users who have been > experiencing >> no delivery messages with the following text :- >> >> DELIVERY FAILURE: Error transferring to XXXXXXXXXX/XXX/XXX mail.box; >> Cannotstore document - database has too many unique field names. > Please >> set the'Allow more fields in database' option or ask your > administrator to >> compact the database. >> >> Has anybody else seen these ? This is happening when we send emails to > a >> couple of our suppliers. I am wondering whether they have a automated >> jobs which parses the email and stores the embedded data. >> >> Any ideas ? >> -- >> --[ UxBoD ]-- >> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" >> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >> >> >> -- >> This message has been scanned for viruses and dangerous content by >> MailScanner, and is >> believed to be clean. >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From martinh at solidstatelogic.com Wed May 16 10:47:58 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 16 10:48:13 2007 Subject: Bayes disk space usage fast increase In-Reply-To: Message-ID: <6bab851eae7bee43b9ae31db215a078e@solidstatelogic.com> Fabien Where's the file space use in /var? it is in the bayes area? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Fabien GARZIANO > Sent: 16 May 2007 10:39 > To: MailScanner discussion > Subject: Bayes disk space usage fast increase > > Hi, > > I'm stuck on an issue with my MailScanner mail gateway, actually with > the bayesian database. I don't use any database so my bayesian files are > on my /var FS. Since 2 days, disk space usage is fastly increasing and > I'll soon be short of disk space. As far as I can see in logs, I don't > find any explanation about this. I've looked in the FAQ on the website, > and I don't see any thing like this. > I've checked > http://wiki.apache.org/spamassassin/BayesFaq?highlight=%28bayes%29 > I've also tried to look in the mail archive but without success. > > My baysian files are in the default dir => > /var/spool/MailScanner/spamassassin > > [root@califw3 spamassassin]# pwd > /var/spool/MailScanner/spamassassin > [root@califw3 spamassassin]# du -h > 731M . > > [root@califw3 MailScanner]# spamassassin -D --lint > debug: SpamAssassin version 3.0.5 > [...] > debug: bayes: 19794 tie-ing to DB file R/O > /root/.spamassassin/bayes_toks > debug: bayes: 19794 tie-ing to DB file R/O > /root/.spamassassin/bayes_seen > debug: bayes: found bayes db version 3 > debug: bayes: Not available for scanning, only 0 spam(s) in Bayes DB < > 200 > debug: bayes: 19794 untie-ing > debug: bayes: 19794 untie-ing db_toks > debug: bayes: 19794 untie-ing db_seen > > Now, that's weird, cause I received some spam this morning, and bayes > scored them. > > For information : > [root@califw3 MailScanner]# MailScanner -v > Running on > Linux califw3.caliseo.fr 2.6.16-1.2108_FC4 #1 Thu May 4 23:52:01 EDT > 2006 i686 i686 i386 GNU/Linux > This is Fedora Core release 4 (Stentz) > This is Perl version 5.008006 (5.8.6) > This is MailScanner version 4.53.8 > > Is this behaviour usual ? I've been runnig this gateway for 1 year now, > and that's the first time I got something like this. Anyone met this > behaviour already ? > Is there a way to limit bayes space usage ? > > Thanks ! > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From uxbod at splatnix.net Wed May 16 10:50:17 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Wed May 16 10:50:21 2007 Subject: MS & Lotus Notes In-Reply-To: References: Message-ID: <1c270abf3654e0e354fb1ee4d48d1971@62.49.223.244> It is a couple of suppliers we email too. Is it possible to disable all headers in MailScanner ? On Wed, 16 May 2007 16:51:57 +0700, Budi Febrianto wrote: > mailscanner-bounces@lists.mailscanner.info wrote on 05-16-2007 04:26:51 PM: > >> Hi, >> >> We have received some helpdesk calls from users who have been >> experiencing no delivery messages with the following text :- >> >> DELIVERY FAILURE: Error transferring to XXXXXXXXXX/XXX/XXX mail.box; >> Cannotstore document - database has too many unique field names. >> Please set the'Allow more fields in database' option or ask your >> administrator to compact the database. >> >> Has anybody else seen these ? This is happening when we send emails >> to a couple of our suppliers. I am wondering whether they have a >> automated jobs which parses the email and stores the embedded data. >> >> Any ideas ? >> -- >> --[ UxBoD ]-- >> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" >> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >> > > I'm using lotus notes and mailscanner. > Is you or your customer that using lotus notes? > In standard lotus notes, there is limitation on how many fields that in > one > database can have, and simply enable 'allow more fields in database' will > help. > I think mailscanner add too much headers in outgoing emails. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From martinh at solidstatelogic.com Wed May 16 10:58:24 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 16 10:58:30 2007 Subject: MS & Lotus Notes In-Reply-To: Message-ID: If that's the case a lot of email lists will break this default setting as then. I surprised it's just you who's having issues. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Budi Febrianto > Sent: 16 May 2007 10:52 > To: MailScanner discussion > Subject: Re: MS & Lotus Notes > > mailscanner-bounces@lists.mailscanner.info wrote on 05-16-2007 04:26:51 > PM: > > > Hi, > > > > We have received some helpdesk calls from users who have been > > experiencing no delivery messages with the following text :- > > > > DELIVERY FAILURE: Error transferring to XXXXXXXXXX/XXX/XXX mail.box; > > Cannotstore document - database has too many unique field names. > > Please set the'Allow more fields in database' option or ask your > > administrator to compact the database. > > > > Has anybody else seen these ? This is happening when we send emails > > to a couple of our suppliers. I am wondering whether they have a > > automated jobs which parses the email and stores the embedded data. > > > > Any ideas ? > > -- > > --[ UxBoD ]-- > > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > > > > I'm using lotus notes and mailscanner. > Is you or your customer that using lotus notes? > In standard lotus notes, there is limitation on how many fields that in > one > database can have, and simply enable 'allow more fields in database' will > help. > I think mailscanner add too much headers in outgoing emails. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From uxbod at splatnix.net Wed May 16 11:11:53 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Wed May 16 11:12:58 2007 Subject: MS & Lotus Notes In-Reply-To: References: Message-ID: Based on that I would say it is the supplier who is having issues, as they potentially have not configured their Notes servers correctly with that option. The problem is that I have installed this solution and emails out bouncing to our biggest customers and suppliers. Hmmm, I suppose I could switch off all outbound scanning for those domains. Is this possible with MailScanner, or will I need to modify Postfix so that it does not HOLD them for those domains ? Thanks, On Wed, 16 May 2007 10:58:24 +0100, "Martin.Hepworth" wrote: > If that's the case a lot of email lists will break this default setting > as then. I surprised it's just you who's having issues. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Budi Febrianto >> Sent: 16 May 2007 10:52 >> To: MailScanner discussion >> Subject: Re: MS & Lotus Notes >> >> mailscanner-bounces@lists.mailscanner.info wrote on 05-16-2007 > 04:26:51 >> PM: >> >> > Hi, >> > >> > We have received some helpdesk calls from users who have been >> > experiencing no delivery messages with the following text :- >> > >> > DELIVERY FAILURE: Error transferring to XXXXXXXXXX/XXX/XXX mail.box; >> > Cannotstore document - database has too many unique field names. >> > Please set the'Allow more fields in database' option or ask your >> > administrator to compact the database. >> > >> > Has anybody else seen these ? This is happening when we send emails >> > to a couple of our suppliers. I am wondering whether they have a >> > automated jobs which parses the email and stores the embedded data. >> > >> > Any ideas ? >> > -- >> > --[ UxBoD ]-- >> > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg > --import" >> > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >> > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >> > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >> > >> >> I'm using lotus notes and mailscanner. >> Is you or your customer that using lotus notes? >> In standard lotus notes, there is limitation on how many fields that > in >> one >> database can have, and simply enable 'allow more fields in database' > will >> help. >> I think mailscanner add too much headers in outgoing emails. >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From martinh at solidstatelogic.com Wed May 16 11:18:37 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 16 11:18:43 2007 Subject: MS & Lotus Notes In-Reply-To: Message-ID: <70fd045c73cf914284f93d8dec109052@solidstatelogic.com> Yeah you can do this - but it'll still add in some headers. I'd bounce the problem at the third party - the email you are sending complies to all rfc's so they should be able to accept it. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- > Sent: 16 May 2007 11:12 > To: MailScanner discussion > Subject: RE: MS & Lotus Notes > > Based on that I would say it is the supplier who is having issues, as they > potentially have not configured their Notes servers correctly with that > option. > > The problem is that I have installed this solution and emails out bouncing > to our biggest customers and suppliers. > > Hmmm, I suppose I could switch off all outbound scanning for those > domains. Is this possible with MailScanner, or will I need to modify > Postfix so that it does not HOLD them for those domains ? > > Thanks, > > On Wed, 16 May 2007 10:58:24 +0100, "Martin.Hepworth" > wrote: > > If that's the case a lot of email lists will break this default setting > > as then. I surprised it's just you who's having issues. > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > >> -----Original Message----- > >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > >> bounces@lists.mailscanner.info] On Behalf Of Budi Febrianto > >> Sent: 16 May 2007 10:52 > >> To: MailScanner discussion > >> Subject: Re: MS & Lotus Notes > >> > >> mailscanner-bounces@lists.mailscanner.info wrote on 05-16-2007 > > 04:26:51 > >> PM: > >> > >> > Hi, > >> > > >> > We have received some helpdesk calls from users who have been > >> > experiencing no delivery messages with the following text :- > >> > > >> > DELIVERY FAILURE: Error transferring to XXXXXXXXXX/XXX/XXX mail.box; > >> > Cannotstore document - database has too many unique field names. > >> > Please set the'Allow more fields in database' option or ask your > >> > administrator to compact the database. > >> > > >> > Has anybody else seen these ? This is happening when we send emails > >> > to a couple of our suppliers. I am wondering whether they have a > >> > automated jobs which parses the email and stores the embedded data. > >> > > >> > Any ideas ? > >> > -- > >> > --[ UxBoD ]-- > >> > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg > > --import" > >> > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > >> > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > >> > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > >> > > >> > >> I'm using lotus notes and mailscanner. > >> Is you or your customer that using lotus notes? > >> In standard lotus notes, there is limitation on how many fields that > > in > >> one > >> database can have, and simply enable 'allow more fields in database' > > will > >> help. > >> I think mailscanner add too much headers in outgoing emails. > >> > >> -- > >> MailScanner mailing list > >> mailscanner@lists.mailscanner.info > >> http://lists.mailscanner.info/mailman/listinfo/mailscanner > >> > >> Before posting, read http://wiki.mailscanner.info/posting > >> > >> Support MailScanner development - buy the book off the website! > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are intended for the > > addressee only and may be confidential. If they come to you in error > > you must take no action based on them, nor must you copy or show them > > to anyone. Please advise the sender by replying to this e-mail > > immediately and then delete the original from your computer. > > > > Opinion : Any opinions expressed in this e-mail are entirely those of > > the author and unless specifically stated to the contrary, are not > > necessarily those of the author's employer. > > > > Security Warning : Internet e-mail is not necessarily a secure > > communications medium and can be subject to data corruption. We advise > > that you consider this fact when e-mailing us. > > > > Viruses : We have taken steps to ensure that this e-mail and any > > attachments are free from known viruses but in keeping with good > > computing practice, you should ensure that they are virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic > > Registered as a limited company in England and Wales > > (Company No:5362730) > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > United Kingdom > > ********************************************************************** > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > -- > --[ UxBoD ]-- > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From glenn.steen at gmail.com Wed May 16 11:20:02 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed May 16 11:20:05 2007 Subject: Report: Denial of Service attack in message! In-Reply-To: References: <200705151744.l4FHiaX4012853@safir.blacknight.ie> Message-ID: <223f97700705160320mb365184ue3db81f74d3cef71@mail.gmail.com> On 16/05/07, Norbert Schmidt wrote: > Hi Jules, > > the Value for "Virus Scanner Timeout" was still on the old standard (I > belive) 30 seconds. I haven't changed that, but I've changed the version > of clamav due to regular updates. This must have let to the problem. I've > now raised the timeout to 300 seconds and all is quiet now. > > I think there is a big problem with the classification as "Denial of > service attack" when the virusscanner times out because all messages in > that batch are marked as "containing a virus" and thus are thrown away. > This can lead to loss of a lot of legitimate mail that happened to be in > the same batch with a mail containing a "Denial of service attack". I > guess an option, to control this behaviour would be usefull. > > I do not have the Mail::ClamAV module installed but will do so now. > > This leads me to a question... Is it better to upgrade MailScanner or is > it better to install the new version each time? > We've been using MailScanner for the last 3 years now. I didn't go thru > every version, but always skipped a few as it is always quite some hassel > to go thru all options and set them up appropriate. Is there a way to set > the seldom changed options like Company name, webpage etc. So after an > update these things stay the same... > > Thanks for your help > > Norbert AFAIK you should be fine with upgrading as long as you remember to go through with the upgrade_MailScanner_conf and upgrade_languages_conf scripts. Has worked very nicely for me so far (some years, rather many versions:-). BTW, my setting for that timeout is 300, without any intervention from me, other than the scripts(possibly);-). Use "MailScanner --changed" after an upgrade to see what defaults you've deviated from... This is a good way to see/fix the changes to the defaults that the upgrade scripts _might_ miss... Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From uxbod at splatnix.net Wed May 16 11:49:49 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Wed May 16 11:51:32 2007 Subject: MS & Lotus Notes In-Reply-To: <70fd045c73cf914284f93d8dec109052@solidstatelogic.com> References: <70fd045c73cf914284f93d8dec109052@solidstatelogic.com> Message-ID: <23d5715eb4c799996c16e7a952ce3bb0@62.49.223.244> To get around it I have created a second Postfix instance that performs no MS checks etc on a different port. The Lotus Notes administrator can now send outbound through that to get around the problem. Thanks for everyones help. On Wed, 16 May 2007 11:18:37 +0100, "Martin.Hepworth" wrote: > Yeah you can do this - but it'll still add in some headers. > > I'd bounce the problem at the third party - the email you are sending > complies to all rfc's so they should be able to accept it. > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- >> Sent: 16 May 2007 11:12 >> To: MailScanner discussion >> Subject: RE: MS & Lotus Notes >> >> Based on that I would say it is the supplier who is having issues, as > they >> potentially have not configured their Notes servers correctly with > that >> option. >> >> The problem is that I have installed this solution and emails out > bouncing >> to our biggest customers and suppliers. >> >> Hmmm, I suppose I could switch off all outbound scanning for those >> domains. Is this possible with MailScanner, or will I need to modify >> Postfix so that it does not HOLD them for those domains ? >> >> Thanks, >> >> On Wed, 16 May 2007 10:58:24 +0100, "Martin.Hepworth" >> wrote: >> > If that's the case a lot of email lists will break this default > setting >> > as then. I surprised it's just you who's having issues. >> > >> > -- >> > Martin Hepworth >> > Snr Systems Administrator >> > Solid State Logic >> > Tel: +44 (0)1865 842300 >> > >> >> -----Original Message----- >> >> From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- >> >> bounces@lists.mailscanner.info] On Behalf Of Budi Febrianto >> >> Sent: 16 May 2007 10:52 >> >> To: MailScanner discussion >> >> Subject: Re: MS & Lotus Notes >> >> >> >> mailscanner-bounces@lists.mailscanner.info wrote on 05-16-2007 >> > 04:26:51 >> >> PM: >> >> >> >> > Hi, >> >> > >> >> > We have received some helpdesk calls from users who have been >> >> > experiencing no delivery messages with the following text :- >> >> > >> >> > DELIVERY FAILURE: Error transferring to XXXXXXXXXX/XXX/XXX > mail.box; >> >> > Cannotstore document - database has too many unique field names. >> >> > Please set the'Allow more fields in database' option or ask your >> >> > administrator to compact the database. >> >> > >> >> > Has anybody else seen these ? This is happening when we send > emails >> >> > to a couple of our suppliers. I am wondering whether they have a >> >> > automated jobs which parses the email and stores the embedded > data. >> >> > >> >> > Any ideas ? >> >> > -- >> >> > --[ UxBoD ]-- >> >> > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg >> > --import" >> >> > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >> >> > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >> >> > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >> >> > >> >> >> >> I'm using lotus notes and mailscanner. >> >> Is you or your customer that using lotus notes? >> >> In standard lotus notes, there is limitation on how many fields > that >> > in >> >> one >> >> database can have, and simply enable 'allow more fields in > database' >> > will >> >> help. >> >> I think mailscanner add too much headers in outgoing emails. >> >> >> >> -- >> >> MailScanner mailing list >> >> mailscanner@lists.mailscanner.info >> >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> >> >> Support MailScanner development - buy the book off the website! >> > >> > >> > >> > >> > > ********************************************************************** >> > Confidentiality : This e-mail and any attachments are intended for > the >> > addressee only and may be confidential. If they come to you in error >> > you must take no action based on them, nor must you copy or show > them >> > to anyone. Please advise the sender by replying to this e-mail >> > immediately and then delete the original from your computer. >> > >> > Opinion : Any opinions expressed in this e-mail are entirely those > of >> > the author and unless specifically stated to the contrary, are not >> > necessarily those of the author's employer. >> > >> > Security Warning : Internet e-mail is not necessarily a secure >> > communications medium and can be subject to data corruption. We > advise >> > that you consider this fact when e-mailing us. >> > >> > Viruses : We have taken steps to ensure that this e-mail and any >> > attachments are free from known viruses but in keeping with good >> > computing practice, you should ensure that they are virus free. >> > >> > Red Lion 49 Ltd T/A Solid State Logic >> > Registered as a limited company in England and Wales >> > (Company No:5362730) >> > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, >> > United Kingdom >> > > ********************************************************************** >> > >> > -- >> > MailScanner mailing list >> > mailscanner@lists.mailscanner.info >> > http://lists.mailscanner.info/mailman/listinfo/mailscanner >> > >> > Before posting, read http://wiki.mailscanner.info/posting >> > >> > Support MailScanner development - buy the book off the website! >> > >> > >> -- >> --[ UxBoD ]-- >> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" >> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >> >> >> -- >> This message has been scanned for viruses and dangerous content by >> MailScanner, and is >> believed to be clean. >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From matt at coders.co.uk Wed May 16 12:00:53 2007 From: matt at coders.co.uk (Matt Hampton) Date: Wed May 16 11:58:32 2007 Subject: Does anyone catch this.... In-Reply-To: <46483AAB.7040800@coders.co.uk> References: <46483AAB.7040800@coders.co.uk> Message-ID: <464AE465.9030006@coders.co.uk> Matt Hampton wrote: > http://www.coders.co.uk/slipped.through.txt > > It has sailed through both a SA3.1.8 and SA3.2.0 (3.2.0-pre2-r512851) > running on recent versions of MailScanner > > cheers > > Matt > > Thanks to everyone who replied - guess I'll look at the ClamAV signatures matt From matt at coders.co.uk Wed May 16 12:01:24 2007 From: matt at coders.co.uk (Matt Hampton) Date: Wed May 16 11:59:02 2007 Subject: Does anyone catch this.... In-Reply-To: <46483AAB.7040800@coders.co.uk> References: <46483AAB.7040800@coders.co.uk> Message-ID: <464AE484.90100@coders.co.uk> Matt Hampton wrote: > http://www.coders.co.uk/slipped.through.txt > > It has sailed through both a SA3.1.8 and SA3.2.0 (3.2.0-pre2-r512851) > running on recent versions of MailScanner > > cheers > > Matt > > > > Thanks to everyone who replied - I'll look and the Clam signatures.... matt From ja at conviator.com Wed May 16 13:19:36 2007 From: ja at conviator.com (Jan Agermose) Date: Wed May 16 13:19:59 2007 Subject: OT: SPF Message-ID: <6B59FCF2EFD0334A8147A1BB463F111E026A2F8E@mail-17ps.atlarge.net> Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: image/gif Size: 534 bytes Desc: image001.gif Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070516/493c3602/attachment.gif From steve.swaney at fsl.com Wed May 16 13:34:15 2007 From: steve.swaney at fsl.com (Stephen Swaney) Date: Wed May 16 13:32:21 2007 Subject: SPF In-Reply-To: <6B59FCF2EFD0334A8147A1BB463F111E026A2F8E@mail-17ps.atlarge.net> References: <6B59FCF2EFD0334A8147A1BB463F111E026A2F8E@mail-17ps.atlarge.net> Message-ID: <03ab01c797b6$840c5030$8c24f090$@swaney@fsl.com> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Jan Agermose > Sent: Wednesday, May 16, 2007 8:20 AM > To: mailscanner@lists.mailscanner.info > Subject: OT: SPF > > Hi > > Im having trouble subscribing to the SPF list so Im going to ask you > guys ? > > I have a customer who has a domain on a mailserver we handle. The mails > that gets send to this domain are all forwarded to other email accounts > not on our servers ? nothing special about that I think. This means if > you send a mail to mail@domain-at-our-server.dk the mail gets forwarded > to say info@some-other-domain.dk. > > Now a person (sending@domain.dk) who has posted a SPF record for his > domain is sending to mail@domain-at-our-server.dk and the mail is of > cause forwarded to info@some-other-domain.dk like it should be, but the > problem is that now the mail is rejected by the end-receiver saying > that mail from sending@domain.dk is not allowed to come from our > server. Im thinking this must be a mistake on the part of the receiver? > > http://spf.pobox.com/why.html?sender=michael.a.hansen%40gmx.net&ip=213. > 150.56.221&receiver=mx3.one.com > > our mailserver is a std. Merak mailserver ? std. setup for forwarding > mails. How can I check this / verify it?s the end receiving server that > checks the SPF record the wrong way? > Mvh > Jan > > > > Jan Agermose > Conviator ApS > Tel. +45 70 20 27 31 > Fax +45 46 92 66 95 > > Jan, Why don't you just have the relay added to the SPF records? Best regards, Steve Swaney steve@fsl.com From list-mailscanner at linguaphone.com Wed May 16 13:38:45 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed May 16 13:38:58 2007 Subject: OT: SPF In-Reply-To: <6B59FCF2EFD0334A8147A1BB463F111E026A2F8E@mail-17ps.atlarge.net> References: <6B59FCF2EFD0334A8147A1BB463F111E026A2F8E@mail-17ps.atlarge.net> Message-ID: <1179319125.18357.24.camel@gblades-suse.linguaphone-intranet.co.uk> On Wed, 2007-05-16 at 13:19, Jan Agermose wrote: > Hi > > > > Im having trouble subscribing to the SPF list so Im going to ask you > guys J > > > > I have a customer who has a domain on a mailserver we handle. The > mails that gets send to this domain are all forwarded to other email > accounts not on our servers ? nothing special about that I think. This > means if you send a mail to mail@domain-at-our-server.dk the mail gets > forwarded to say info@some-other-domain.dk. > > > > Now a person (sending@domain.dk) who has posted a SPF record for his > domain is sending to mail@domain-at-our-server.dk and the mail is of > cause forwarded to info@some-other-domain.dk like it should be, but > the problem is that now the mail is rejected by the end-receiver > saying that mail from sending@domain.dk is not allowed to come from > our server. Im thinking this must be a mistake on the part of the > receiver? > > > > http://spf.pobox.com/why.html?sender=michael.a.hansen%40gmx.net&ip=213.150.56.221&receiver=mx3.one.com > > > > our mailserver is a std. Merak mailserver ? std. setup for forwarding > mails. How can I check this / verify it?s the end receiving server > that checks the SPF record the wrong way? Thats the way SPF is designed to work. If your users are using a forwarding service then you need to make sure that your mail server is considered to be trusted or turn off SPF checking altogether. If they are using a public email system (google, hotmail etc...) where this is not possible then you need to use SRS. See http://www.openspf.org/SRS From csweeney at osubucks.org Wed May 16 13:39:32 2007 From: csweeney at osubucks.org (Chris sweeney) Date: Wed May 16 13:39:45 2007 Subject: OT: SPF Message-ID: <200705161239.l4GCdGo5015193@stewie.osubucks.org> Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: image001.gif Type: application/octet-stream Size: 534 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070516/d437b0c3/image001.obj From housey at sme-ecom.co.uk Wed May 16 13:19:32 2007 From: housey at sme-ecom.co.uk (Paul Houselander) Date: Wed May 16 13:47:56 2007 Subject: Filename checks blocking docx files Message-ID: Hi Just had a situation with someone sending an email with an Office 2007 attachment. Its in docx format and was caught by the filename checks (Attempt to hide real filename) It seems that that docx format is a Zip container for packaging XML and other data files, within the docx file are files called document.xml.rel and settings.xml.rel amongst others - these are the files that caused the file to get blocked. Ive got a ruleset for Allow Filenames can I just add FromTo: * \.xml\.rel and that should be enough to allow them? Kind Regards Paul From bpumphrey at woodmclaw.com Wed May 16 13:55:09 2007 From: bpumphrey at woodmclaw.com (Billy A. Pumphrey) Date: Wed May 16 13:55:12 2007 Subject: Connection Deffered Message-ID: <04D932B0071FE34FA63EBB1977B48D15022CEB37@woodenex.woodmaclaw.local> I am hoping someone is willing to help me with this. I thought that I had the problem fixed but maybe not. I believe that current incoming email is coming through MailScanner and to the Exchange server. The problem is that ther are about 650 emails that will not go through. I get this: Command: sendmail -v -bp -OQueueDirectory=//var/spool/mqueue Result (about 650 of these): l4FL9c8I028182 998389 6606332+May 15 17:09 (Deferred: Connection refused by [10.1.1.22]) I have sendmail, Cent OS 4.4. I have not changed anything before this started happening. I restarted the Exchange server and that is allowing the new emails to come through ( I think, I will see for sure if this reaches the list during the problem phase). Please advise :) Thank you From ja at conviator.com Wed May 16 14:02:15 2007 From: ja at conviator.com (Jan Agermose) Date: Wed May 16 14:02:40 2007 Subject: SV: OT: SPF In-Reply-To: <200705161239.l4GCdGo5015193@stewie.osubucks.org> References: <200705161239.l4GCdGo5015193@stewie.osubucks.org> Message-ID: <6B59FCF2EFD0334A8147A1BB463F111E026A2FB1@mail-17ps.atlarge.net> Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: image/gif Size: 534 bytes Desc: image001.gif Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070516/339a71ce/attachment.gif From jonas.lilja at exallon.sigma.se Wed May 16 14:54:46 2007 From: jonas.lilja at exallon.sigma.se (Jonas Lilja) Date: Wed May 16 14:55:17 2007 Subject: warning in maillog after upgrading to latest ms Message-ID: <34D06C003AA0EA4D8D9B9443E7BDDD9503518F63@ikaros.exallon.sigma.se> Hi, I?ve just upgraded MS to mailscanner-4.59.4-2 and the latest stable Tarball package (install-Clam-0.90.2-SA-3.2.0.tar). Everything looked fine at the upgrade-process but after starting MS I get a lot of warnings in the maillog: WARNING: Can't parse the configuration file. What does this mean? I?we googled for it and also search in the list-archive but didn?t find any hints. MTA is sendmail-8.13.1-3.RHEL4.5 I use DCC, Rules du Jour and Razor2 plugins in spamassassin. Thanx for hints. Jonas Lilja PS - the MTA/MS is working so there is no panic with this case. I just wonder what?s wrong in my config. The version I upgraded from was 4.58.9-1 and didn?t generate any warnings in maillog. DS. From alex at nkpanama.com Wed May 16 14:55:24 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Wed May 16 14:56:06 2007 Subject: Connection Deffered In-Reply-To: <04D932B0071FE34FA63EBB1977B48D15022CEB37@woodenex.woodmaclaw.local> References: <04D932B0071FE34FA63EBB1977B48D15022CEB37@woodenex.woodmaclaw.local> Message-ID: <464B0D4C.8010702@nkpanama.com> Billy A. Pumphrey wrote: > I am hoping someone is willing to help me with this. I thought that I > had the problem fixed but maybe not. I believe that current incoming > email is coming through MailScanner and to the Exchange server. The > problem is that ther are about 650 emails that will not go through. I > get this: > > Command: > sendmail -v -bp -OQueueDirectory=//var/spool/mqueue > > /var/spool/mqueue holds stuff already processed by MailScanner and waiting to go out (or be delivered locally) > Result (about 650 of these): > l4FL9c8I028182 998389 6606332+May 15 17:09 > (Deferred: Connection refused by [10.1.1.22]) > > This says (to me) that 10.1.1.22, who was *supposed* to receive that e-mail, isn't accepting connections - or dropping them or something. > > > I have sendmail, Cent OS 4.4. > > Try ssh'ing into that CentOS box, then telnet'ing to the M Sexchange server's port 25 like: $ telnet 10.1.1.22 25 you should get: 220 Blablahblah Microsoft blahblah vulnerable blahblah if it weren't for MailScanner I'd be !%#!&%# blah blah version xxx.xxx If you don't, your M Sexchange server could have a problem with its SMTP process being broken/down/hung/etc. - you should look into restarting all M Sexchange-related processes just to be on the safe side, I think. > I have not changed anything before this started happening. I restarted > the Exchange server and that is allowing the new emails to come through > ( I think, I will see for sure if this reaches the list during the > problem phase). > > Please advise :) > Thank you > From uxbod at splatnix.net Wed May 16 15:27:08 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Wed May 16 15:27:18 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <4649CA97.5050802@ecs.soton.ac.uk> References: <4649CA97.5050802@ecs.soton.ac.uk> Message-ID: Hi Jules, No FPs at all today :) Thanks, On Tue, 15 May 2007 15:58:31 +0100, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Leland J. Steinke wrote: >> Julian Field wrote: >>> >>> # JKF 3/10/2005 >>> my $temp = @HitList; >>> $temp = $temp + 0; >>> $temp = 0 unless $HitList[0] =~ /a-z/i; >>> return ($temp, join(', ', @HitList)); >>> } >>> >>> Let's see if that helps. According to the book, the 2 middle lines >>> shouldn't be needed at all. >> >> Why not "my $temp = scalar(@HitList);"? > That should be the exact equivalent of "$temp = @HitList" as $temp is a > scalar anyway. > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: UTF-8 > > wj8DBQFGScqmEfZZRxQVtlQRAk0fAKDkHKSy1XfSr7NmFl7exuiR5RJmGgCcC79L > BZI+vdG3BNijd2m6HIXK/zA= > =311a > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From fabien.garziano at caliseo.com Wed May 16 16:11:38 2007 From: fabien.garziano at caliseo.com (Fabien GARZIANO) Date: Wed May 16 16:11:58 2007 Subject: Bayes disk space usage fast increase Message-ID: Sorry for my late answer Gareth, and thanks for yours. Here is a ll... Hope it's still readable : [root@califw3 spamassassin]# ll -S |more total 811828 -rw------- 1 postfix postfix 10104832 May 16 17:10 bayes_toks -rw------- 1 postfix postfix 5206016 May 2 13:47 bayes_seen -rw------- 1 postfix postfix 5079040 May 15 04:52 bayes_toks.expire32062 -rw------- 1 postfix postfix 5033984 May 15 06:54 bayes_toks.expire2565 -rw------- 1 postfix postfix 4820992 May 15 13:04 bayes_toks.expire13824 -rw------- 1 postfix postfix 4820992 May 15 13:27 bayes_toks.expire14416 -rw------- 1 postfix postfix 4820992 May 15 13:33 bayes_toks.expire14535 -rw------- 1 postfix postfix 4788224 May 15 14:09 bayes_toks.expire15616 -rw------- 1 postfix postfix 4788224 May 15 14:14 bayes_toks.expire15734 -rw------- 1 postfix postfix 4767744 May 15 14:44 bayes_toks.expire16590 -rw------- 1 postfix postfix 4661248 May 15 16:34 bayes_toks.expire20260 -rw------- 1 postfix postfix 4661248 May 15 16:51 bayes_toks.expire20788 -rw------- 1 postfix postfix 4648960 May 15 17:04 bayes_toks.expire21148 -rw------- 1 postfix postfix 4644864 May 15 17:22 bayes_toks.expire21811 -rw------- 1 postfix postfix 4599808 May 15 18:17 bayes_toks.expire23381 -rw------- 1 postfix postfix 4575232 May 15 19:18 bayes_toks.expire25081 -rw------- 1 postfix postfix 4571136 May 15 19:38 bayes_toks.expire25594 -rw------- 1 postfix postfix 4530176 May 15 20:38 bayes_toks.expire27515 -rw------- 1 postfix postfix 4530176 May 15 20:48 bayes_toks.expire27763 -rw------- 1 postfix postfix 4521984 May 15 21:02 bayes_toks.expire28262 [...] -rw------- 1 postfix postfix 303104 May 16 12:21 bayes_toks.expire21920 -rw------- 1 postfix postfix 303104 May 16 14:53 bayes_toks.expire26492 -rw------- 1 postfix postfix 294912 May 16 10:23 bayes_toks.expire17396 -rw------- 1 postfix postfix 294912 May 16 16:30 bayes_toks.expire29841 -rw------- 1 postfix postfix 274432 May 16 13:20 bayes_toks.expire23612 -rw------- 1 postfix postfix 225280 May 16 05:11 bayes_toks.expire8989 -rw------- 1 postfix postfix 212992 May 15 13:57 bayes_toks.expire15150 -rw------- 1 postfix postfix 151552 May 15 11:31 bayes_toks.expire10722 -rw------- 1 postfix postfix 147456 May 16 12:00 bayes_toks.expire21098 -rw------- 1 postfix postfix 143360 May 16 14:46 bayes_toks.expire26268 -rw------- 1 postfix postfix 143360 May 16 17:09 bayes_toks.expire31105 -rw------- 1 postfix postfix 73728 May 16 11:24 bayes_toks.expire19825 -rw------- 1 postfix postfix 73728 May 16 11:30 bayes_toks.expire20027 -rw------- 1 postfix postfix 73728 May 16 11:40 bayes_toks.expire20399 -rw------- 1 postfix postfix 73728 May 16 12:55 bayes_toks.expire22890 -rw-r--r-- 1 root root 34772 May 16 17:06 toto.txt -rw------- 1 postfix postfix 29184 May 16 17:10 bayes_journal -rw------- 1 postfix postfix 12288 May 15 06:01 bayes_toks.expire1178 -rw------- 1 postfix postfix 12288 May 14 17:40 bayes_toks.expire13716 -rw------- 1 postfix postfix 12288 May 16 09:08 bayes_toks.expire14923 -rw------- 1 postfix postfix 12288 May 16 09:26 bayes_toks.expire15556 -rw------- 1 postfix postfix 12288 May 15 14:26 bayes_toks.expire16013 -rw------- 1 postfix postfix 12288 May 15 16:39 bayes_toks.expire20385 -rw------- 1 postfix postfix 12288 May 14 11:25 bayes_toks.expire29031 -rw------- 1 postfix postfix 12288 May 15 04:03 bayes_toks.expire30002 -rw------- 1 postfix postfix 12288 May 14 12:55 bayes_toks.expire4298 -rw------- 1 postfix postfix 12288 May 16 04:01 bayes_toks.expire6450 -rw------- 1 postfix postfix 12288 May 14 15:35 bayes_toks.expire9437 -rw------- 1 postfix postfix 12288 Dec 26 11:25 __db.bayes_toks.expire12545 -rw------- 1 postfix postfix 12288 Dec 26 11:46 __db.bayes_toks.expire13897 -rw------- 1 postfix postfix 1212 May 16 17:10 bayes.mutex > -----Message d'origine----- > De : mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] De la > part de Gareth > Envoy? : mercredi 16 mai 2007 11:47 > ? : MailScanner discussion > Objet : Re: Bayes disk space usage fast increase > > On Wed, 2007-05-16 at 10:39, Fabien GARZIANO wrote: > > Hi, > > > > I'm stuck on an issue with my MailScanner mail gateway, > actually with > > the bayesian database. I don't use any database so my > bayesian files > > are on my /var FS. Since 2 days, disk space usage is fastly > increasing > > and I'll soon be short of disk space. As far as I can see > in logs, I > > don't find any explanation about this. I've looked in the > FAQ on the > > website, and I don't see any thing like this. > > Can you do a directory listing on the offending bayes files > so we can see how big each one of them is. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From MailScanner at ecs.soton.ac.uk Wed May 16 16:13:27 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 16 16:17:14 2007 Subject: Detecting forwarded spam In-Reply-To: References: <4649A54A.7FBE.00FC.3@medicine.wisc.edu> Message-ID: <464B1F97.4020001@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Scott Silva wrote: > Michael Masse spake the following on 5/15/2007 10:20 AM: > >> Is there a way for MailScanner to detect if a forwarded message has already been detected as spam by another system, therefore not needing to run it's own spam check? >> >> We have a large number of users who used to use a separate email provider and they now just have that email forwarded to their account here. Their old system detects spam and creates a header entry like: >> X-Spam-Report: IsSpam=yes >> >> Right now our system just ignores that, so I was wondering if I can get our Mailscanner to take this into account and not bother with spamassassin checks if it sees this in the header? I'm sure I could make a spamassassin rule to assign points if it saw this, but the whole point is to not have to get spamassassin involved. >> >> Is this possible, or should I just stick with a spamassassin rule? >> >> Mike >> >> >> > You could write a custom function to do this, and maybe you could get Julian > to write it for you for some $$$ (money, deniro, cash, mammon, greenbacks, > script, coinage, euros, pounds sterling, etc...). > Yes: for a suitable bribe, I could write you a Custom Function to do this. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGSyBUEfZZRxQVtlQRAsjhAKCAAwTxoBet4D9oLTStQHRNV5jDlACg8Uaz 76DXvWlg3dqGlFfiT8PBjVI= =ro91 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From fabien.garziano at caliseo.com Wed May 16 16:17:58 2007 From: fabien.garziano at caliseo.com (Fabien GARZIANO) Date: Wed May 16 16:18:26 2007 Subject: Bayes disk space usage fast increase Message-ID: Hi Martin, Bayes dir equals to 60% of my /var FS (the MailScanner working and spool directory) [root@califw3 var]# du -h /var/spool/MailScanner/ 794M /var/spool/MailScanner/spamassassin 4.0K /var/spool/MailScanner/quarantine 4.0K /var/spool/MailScanner/incoming/27432 4.0K /var/spool/MailScanner/incoming/27537 4.0K /var/spool/MailScanner/incoming/27518 4.0K /var/spool/MailScanner/incoming/27523 4.0K /var/spool/MailScanner/incoming/27578 564K /var/spool/MailScanner/incoming 795M /var/spool/MailScanner/ But it has never been so much ... > -----Message d'origine----- > De : mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] De la > part de Martin.Hepworth > Envoy? : mercredi 16 mai 2007 11:48 > ? : MailScanner discussion > Objet : RE: Bayes disk space usage fast increase > > Fabien > > Where's the file space use in /var? it is in the bayes area? > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Fabien GARZIANO > > Sent: 16 May 2007 10:39 > > To: MailScanner discussion > > Subject: Bayes disk space usage fast increase > > > > Hi, > > > > I'm stuck on an issue with my MailScanner mail gateway, > actually with > > the bayesian database. I don't use any database so my bayesian files > are > > on my /var FS. Since 2 days, disk space usage is fastly > increasing and > > I'll soon be short of disk space. As far as I can see in > logs, I don't > > find any explanation about this. I've looked in the FAQ on the > website, > > and I don't see any thing like this. > > I've checked > > http://wiki.apache.org/spamassassin/BayesFaq?highlight=%28bayes%29 > > I've also tried to look in the mail archive but without success. > > > > My baysian files are in the default dir => > > /var/spool/MailScanner/spamassassin > > > > [root@califw3 spamassassin]# pwd > > /var/spool/MailScanner/spamassassin > > [root@califw3 spamassassin]# du -h > > 731M . > > > > [root@califw3 MailScanner]# spamassassin -D --lint > > debug: SpamAssassin version 3.0.5 > > [...] > > debug: bayes: 19794 tie-ing to DB file R/O > > /root/.spamassassin/bayes_toks > > debug: bayes: 19794 tie-ing to DB file R/O > > /root/.spamassassin/bayes_seen > > debug: bayes: found bayes db version 3 > > debug: bayes: Not available for scanning, only 0 spam(s) in > Bayes DB < > > 200 > > debug: bayes: 19794 untie-ing > > debug: bayes: 19794 untie-ing db_toks > > debug: bayes: 19794 untie-ing db_seen > > > > Now, that's weird, cause I received some spam this morning, > and bayes > > scored them. > > > > For information : > > [root@califw3 MailScanner]# MailScanner -v Running on Linux > > califw3.caliseo.fr 2.6.16-1.2108_FC4 #1 Thu May 4 23:52:01 EDT > > 2006 i686 i686 i386 GNU/Linux > > This is Fedora Core release 4 (Stentz) This is Perl version > 5.008006 > > (5.8.6) This is MailScanner version 4.53.8 > > > > Is this behaviour usual ? I've been runnig this gateway for 1 year > now, > > and that's the first time I got something like this. Anyone > met this > > behaviour already ? > > Is there a way to limit bayes space usage ? > > > > Thanks ! > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are > intended for the addressee only and may be confidential. If > they come to you in error you must take no action based on > them, nor must you copy or show them to anyone. Please advise > the sender by replying to this e-mail immediately and then > delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely > those of the author and unless specifically stated to the > contrary, are not necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a > secure communications medium and can be subject to data > corruption. We advise that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and > any attachments are free from known viruses but in keeping > with good computing practice, you should ensure that they are > virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales (Company > No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, > Oxford OX5 1RU, United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From MailScanner at ecs.soton.ac.uk Wed May 16 16:19:25 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 16 16:22:13 2007 Subject: mailscanner error, but doesn't appear to affect delivery? In-Reply-To: <464A1BB9.4010501@slackadelic.com> References: <1E293D3FF63A3740B10AD5AAD88535D204ED7EE0@UBIMAIL1.ubisoft.org> <464A1BB9.4010501@slackadelic.com> Message-ID: <464B20FD.70802@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Matt Hayes wrote: > Daniel Maher wrote: >> Hi all, >> >> >> >> I recently built a brand-new incoming mail server, using Postfix >> 2.4.x, SpamAssassin 3.2.x, and the newest MailScanner and MailWatch >> packages. It works properly, in that it receives, scans, tags, and >> delivers mail; however, every mail that it parses produces the >> following error in the mail log: >> >> >> >> May 15 20:26:41 localhost MailScanner[3225]: >> /var/spool/MailScanner/incoming/3225/./23322FA4E.22E9F.header: Unable >> to open file or directory ERROR >> >> >> >> Of course, the path (which exists, and is readable by MailScanner) >> and filename are different for each mail, but the message is the >> same. Again, as I mentioned above, the mail is properly scanned and >> delivered, so the error doesn?t appear to be affecting behaviour at >> all. That said, it is worrisome that an error is being produced at >> all ? especially if it?s ?not really? an error. >> >> >> >> Any ideas? >> > > Its looking to use /dev/shm. More likely to be using tmpfs somewhere. You don't have to only mount /dev/shm with tmpfs, you can mount any directory you like with tmpfs. > > I had the same issue. Once I setup fstab to load /dev/shm and mounted > it.. the error went away. > > For some odd reason, with the newest release of MailScanner.. it > actually wants spamassassin to use /dev/shm.. which actually helps > speed up scan times. > > However, in previous versions, I found the same "if /dev/shm exists > use it" for SA and it wasn't being used... but suddenly it does hehe. > > Invoking MailScanner in debug mode would've helped you to figure this > out :) > > -Matt > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: windows-1252 wj8DBQFGSyGAEfZZRxQVtlQRAqrjAKCgg2d8wNfZZ+ke4gHWCXTvABovjACgjjHP w0bO1hUBS/8xVrlWFi+Z5Ok= =MGhP -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From martinh at solidstatelogic.com Wed May 16 16:24:07 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 16 16:24:16 2007 Subject: Bayes disk space usage fast increase In-Reply-To: Message-ID: Fabien How do toy clear this down? Either let MailScanner do this for you with the following in MailScanner.conf.... Rebuild Bayes Every = 86400 Wait During Bayes Rebuild = yes If this doesn't work, you'll have to create a cron jon that calls sa-learn --force-expire on the bayes DB every day or so.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Fabien GARZIANO > Sent: 16 May 2007 16:18 > To: MailScanner discussion > Subject: RE: Bayes disk space usage fast increase > > Hi Martin, > > Bayes dir equals to 60% of my /var FS (the MailScanner working and spool > directory) > [root@califw3 var]# du -h /var/spool/MailScanner/ > 794M /var/spool/MailScanner/spamassassin > 4.0K /var/spool/MailScanner/quarantine > 4.0K /var/spool/MailScanner/incoming/27432 > 4.0K /var/spool/MailScanner/incoming/27537 > 4.0K /var/spool/MailScanner/incoming/27518 > 4.0K /var/spool/MailScanner/incoming/27523 > 4.0K /var/spool/MailScanner/incoming/27578 > 564K /var/spool/MailScanner/incoming > 795M /var/spool/MailScanner/ > > But it has never been so much ... > > > > -----Message d'origine----- > > De : mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] De la > > part de Martin.Hepworth > > Envoy? : mercredi 16 mai 2007 11:48 > > ? : MailScanner discussion > > Objet : RE: Bayes disk space usage fast increase > > > > Fabien > > > > Where's the file space use in /var? it is in the bayes area? > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > > > -----Original Message----- > > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner- > > > bounces@lists.mailscanner.info] On Behalf Of Fabien GARZIANO > > > Sent: 16 May 2007 10:39 > > > To: MailScanner discussion > > > Subject: Bayes disk space usage fast increase > > > > > > Hi, > > > > > > I'm stuck on an issue with my MailScanner mail gateway, > > actually with > > > the bayesian database. I don't use any database so my bayesian files > > are > > > on my /var FS. Since 2 days, disk space usage is fastly > > increasing and > > > I'll soon be short of disk space. As far as I can see in > > logs, I don't > > > find any explanation about this. I've looked in the FAQ on the > > website, > > > and I don't see any thing like this. > > > I've checked > > > http://wiki.apache.org/spamassassin/BayesFaq?highlight=%28bayes%29 > > > I've also tried to look in the mail archive but without success. > > > > > > My baysian files are in the default dir => > > > /var/spool/MailScanner/spamassassin > > > > > > [root@califw3 spamassassin]# pwd > > > /var/spool/MailScanner/spamassassin > > > [root@califw3 spamassassin]# du -h > > > 731M . > > > > > > [root@califw3 MailScanner]# spamassassin -D --lint > > > debug: SpamAssassin version 3.0.5 > > > [...] > > > debug: bayes: 19794 tie-ing to DB file R/O > > > /root/.spamassassin/bayes_toks > > > debug: bayes: 19794 tie-ing to DB file R/O > > > /root/.spamassassin/bayes_seen > > > debug: bayes: found bayes db version 3 > > > debug: bayes: Not available for scanning, only 0 spam(s) in > > Bayes DB < > > > 200 > > > debug: bayes: 19794 untie-ing > > > debug: bayes: 19794 untie-ing db_toks > > > debug: bayes: 19794 untie-ing db_seen > > > > > > Now, that's weird, cause I received some spam this morning, > > and bayes > > > scored them. > > > > > > For information : > > > [root@califw3 MailScanner]# MailScanner -v Running on Linux > > > califw3.caliseo.fr 2.6.16-1.2108_FC4 #1 Thu May 4 23:52:01 EDT > > > 2006 i686 i686 i386 GNU/Linux > > > This is Fedora Core release 4 (Stentz) This is Perl version > > 5.008006 > > > (5.8.6) This is MailScanner version 4.53.8 > > > > > > Is this behaviour usual ? I've been runnig this gateway for 1 year > > now, > > > and that's the first time I got something like this. Anyone > > met this > > > behaviour already ? > > > Is there a way to limit bayes space usage ? > > > > > > Thanks ! > > > -- > > > MailScanner mailing list > > > mailscanner@lists.mailscanner.info > > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > > > Support MailScanner development - buy the book off the website! > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are > > intended for the addressee only and may be confidential. If > > they come to you in error you must take no action based on > > them, nor must you copy or show them to anyone. Please advise > > the sender by replying to this e-mail immediately and then > > delete the original from your computer. > > > > Opinion : Any opinions expressed in this e-mail are entirely > > those of the author and unless specifically stated to the > > contrary, are not necessarily those of the author's employer. > > > > Security Warning : Internet e-mail is not necessarily a > > secure communications medium and can be subject to data > > corruption. We advise that you consider this fact when e-mailing us. > > > > Viruses : We have taken steps to ensure that this e-mail and > > any attachments are free from known viruses but in keeping > > with good computing practice, you should ensure that they are > > virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic > > Registered as a limited company in England and Wales (Company > > No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, > > Oxford OX5 1RU, United Kingdom > > ********************************************************************** > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From list-mailscanner at linguaphone.com Wed May 16 16:25:01 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed May 16 16:25:10 2007 Subject: Bayes disk space usage fast increase In-Reply-To: References: Message-ID: <1179329101.18357.38.camel@gblades-suse.linguaphone-intranet.co.uk> On Wed, 2007-05-16 at 16:11, Fabien GARZIANO wrote: > Sorry for my late answer Gareth, and thanks for yours. > > Here is a ll... Hope it's still readable : > [root@califw3 spamassassin]# ll -S |more > total 811828 > -rw------- 1 postfix postfix 10104832 May 16 17:10 bayes_toks > -rw------- 1 postfix postfix 5206016 May 2 13:47 bayes_seen > -rw------- 1 postfix postfix 5079040 May 15 04:52 bayes_toks.expire32062 These bayes_toks.expire... files should not be there. It looks like spamassassin is trying to expire old tokens but failing part way through and leaving a file behind. Have you followed the mailscanner recomendation and setting spamassassin never to expire and letting mailscanner handle it. Maybe spamassassin is taking too long to expire and mailscanner is giving up waiting. From MailScanner at ecs.soton.ac.uk Wed May 16 16:24:07 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 16 16:27:12 2007 Subject: Detecting forwarded spam In-Reply-To: <638c6232e17f17489ffb8b869c7a9475@solidstatelogic.com> References: <638c6232e17f17489ffb8b869c7a9475@solidstatelogic.com> Message-ID: <464B2217.8020201@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 MailScanner has never actually relied on the contents of the headers for anything, except for the feature Sign Messages Already Processed = no as the only way that can work is to guess whether it has already been run through your MailScanner setup on a different server. MailScanner has *never* trusted the contents of the headers to actually skip any scanning or other processing of the message. One of the main reasons for the %org-name% was to try to pursuade people to customise their setups a bit, so when I get sent the headers of a message I stand a fighting chance of being able to find out which MailScanner installation in the world actually generated the headers. It also made the "Sign Messages Already Processed" work better as it would look for *your* MailScanner header rather than any old MailScanner header added by someone else's setup. Martin.Hepworth wrote: > Daniel > > We had a similar situation a few years back (3?). > > The X-MailScanner headers could be used as trust mechanism - ie it's got > the "X-MailScanner: Found to be clean", so we'll trust that and allow > the email through. > > Now the virus writers found out about this and inserted this header into > the emails they send out, in order to circumvent MailScanner doing > checks on the email. Jules had to rush a new release quickly where the > %org-name% was inserted into the headers to try and make this a little > unique, so there was some chance of the header being actually inserted > by MS. Can't see anything in the changelog, but it was around version > 4.22 from memory > > *IF* you trust this you may hold yourself open to false positives, ie > just because someone else's system says its spam doesn't mean yours > will. > > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Michael Masse >> Sent: 15 May 2007 18:21 >> To: > Subject: Detecting forwarded spam >> >> Is there a way for MailScanner to detect if a forwarded message has >> already been detected as spam by another system, therefore not needing >> > to > >> run it's own spam check? >> >> We have a large number of users who used to use a separate email >> > provider > >> and they now just have that email forwarded to their account here. >> Their old system detects spam and creates a header entry like: >> X-Spam-Report: IsSpam=yes >> >> Right now our system just ignores that, so I was wondering if I can >> > get > >> our Mailscanner to take this into account and not bother with >> > spamassassin > >> checks if it sees this in the header? I'm sure I could make a >> spamassassin rule to assign points if it saw this, but the whole point >> > is > >> to not have to get spamassassin involved. >> >> Is this possible, or should I just stick with a spamassassin rule? >> >> Mike >> >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGSyKsEfZZRxQVtlQRAn7YAKCTh+krWSETxvlMVVeH/zknwbbeTACg8Kbu dKOdVCs2ZjOAJ51q+b1T6SA= =n4fw -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Wed May 16 16:28:42 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 16 16:32:08 2007 Subject: Report: Denial of Service attack in message! In-Reply-To: References: Message-ID: <464B232A.80909@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Norbert Schmidt wrote: > * PGP Signed by an unverified key: 05/16/07 at 09:50:51 > > Hi Jules, > > the Value for "Virus Scanner Timeout" was still on the old standard (I > belive) 30 seconds. I haven't changed that, but I've changed the version > of clamav due to regular updates. This must have let to the problem. I've > now raised the timeout to 300 seconds and all is quiet now. > I didn't think it had ever been much less than 5 minutes. Are you sure you didn't just accidentally delete a 0 by mistake one day? :-) > I think there is a big problem with the classification as "Denial of > service attack" when the virusscanner times out because all messages in > that batch are marked as "containing a virus" and thus are thrown away. > Not true. When it times out scanning a batch, it then carefully goes through the batch again, scanning each message in turn to locate the exact message which caused the timeout. Only that message is marked as containing a denial-of-service attack. It has always worked that way. > This can lead to loss of a lot of legitimate mail that happened to be in > the same batch with a mail containing a "Denial of service attack". I > guess an option, to control this behaviour would be usefull. > > I do not have the Mail::ClamAV module installed but will do so now. > > This leads me to a question... Is it better to upgrade MailScanner or is > it better to install the new version each time? > We've been using MailScanner for the last 3 years now. I didn't go thru > every version, but always skipped a few as it is always quite some hassel > to go thru all options and set them up appropriate. Is there a way to set > the seldom changed options like Company name, webpage etc. So after an > update these things stay the same... > Oh dear, have you never read about the script upgrade_MailScanner_conf ? This does all the hard work for you and reduces an upgrade to being a 5 or 10 minute job. Just run it without any command-line parameters and it will tell you in detail how to use it, complete with sample commands you can just cut-and-paste. > Thanks for your help > > Norbert > > ----- Message from Julian Field on Tue, 15 > May 2007 15:12:02 +0100 ----- > To: > MailScanner discussion > Subject: > Re: Report: Denial of Service attack in message! > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > This could happen if for some reason clamscan is asking for user input. > This should not happen in normal situations, obviously. > > Have you changed the "Virus Scanner Timeout" setting from the default > (300 seconds == 5 minutes)? > Run the command > MailScanner --changed | grep 'timeout' > and tell me what it says. > It should be left at the default value of 300 seconds. The new 0.90 > clamscan is very slow to start up and could easily take 30 seconds to > scan a large batch of messages. From your log entries below, I think you > have changed the timeout :-( > > Do you have the clamavmodule Mail::ClamAV perl module installed? > "MailScanner -version" will tell you. And "MailScanner -lint" will tell > you if it thinks you have the support for the clamavmodule scanner all > installed. If you do have it all installed okay (and you need > Mail::ClamAV version 0.20 for ClamAV 0.90 !) then try using the > "clamavmodule" instead of the "clamav" virus scanner. > > Then see if this helps solve the problem. > > Jules. > > Norbert Schmidt wrote: > >> Hi, >> >> I am seeing quite a few "Report: Denial of Service attack in message!" >> > in > >> the logfiles. >> >> The mails are quarantined since I selected to quarantine silent viruses. >> >> >> May 15 13:52:52 localhost MailScanner[30916]: Virus and Content >> > Scanning: > >> Starting >> May 15 13:53:23 localhost MailScanner[30916]: Commercial scanner clamav >> timed out! >> May 15 13:53:23 localhost MailScanner[30916]: clamav: Failed to >> > complete, > >> timed out >> May 15 13:53:23 localhost MailScanner[30916]: Virus Scanning: Denial Of >> Service attack detected! >> May 15 13:53:54 localhost MailScanner[30916]: Commercial scanner clamav >> timed out! >> May 15 13:53:54 localhost MailScanner[30916]: clamav: Failed to >> > complete, > >> timed out >> May 15 13:53:54 localhost MailScanner[30916]: Virus Scanning: Denial Of >> Service attack is in message 096EAC42EE.ABDA7 >> May 15 13:54:56 localhost MailScanner[30916]: Infected message >> 096EAC42EE.ABDA7 came from xxx.11.206.74 >> May 15 13:54:56 localhost MailScanner[30916]: HTML Img tag found in >> message B34D6C441C.201C8 from cakrystyemi@iriomote.com >> May 15 13:54:56 localhost MailScanner[30916]: tag found in message >> 69E50C42EF.E6402 from >> May 15 13:54:56 localhost MailScanner[30916]: Virus Scanning completed >> > at > >> 479 bytes per second >> May 15 13:54:56 localhost MailScanner[30916]: Saved entire message to >> /var/spool/MailScanner/quarantine/20070515/096EAC42EE.ABDA7 >> May 15 13:54:56 localhost MailScanner[30916]: Viruses marked as silent: >> Denial of Service attack in message! >> May 15 13:54:5 >> >> >> The mails are legitimate and it doesn't look like there is anything >> > fishy > >> about them. >> >> >> The server is not experiencing a very heavy load the problem comes up a >> few minutes after the server is started. >> I've got a second machine running an older version of Mailscanner ( >> 4.55.10-3), which is also experiencing clamav time outs, but not marking >> > > >> those mails as Viruses. >> Is there any option I can set to still deliver these mails? >> >> OS: Debian Sarge >> Mailscanner Version is 4.57.6-1 >> Clamav Version is: 0.90.2-1+b1 >> >> Regards >> >> Norbert >> > > > * Norbert Schmidt > * Issuer: IS.Teledata AG - Unverified > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGSyPYEfZZRxQVtlQRAuFZAKCrNhkByT2P0zFLPQFxooqYrjcfUgCdFOH5 8jB9PXuEBu+LVmTcv1MekUo= =JxFr -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Wed May 16 16:30:30 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 16 16:32:13 2007 Subject: MS & Lotus Notes In-Reply-To: <1c270abf3654e0e354fb1ee4d48d1971@62.49.223.244> References: <1c270abf3654e0e354fb1ee4d48d1971@62.49.223.244> Message-ID: <464B2396.2080603@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - --[ UxBoD ]-- wrote: > It is a couple of suppliers we email too. Is it possible to disable all headers in MailScanner ? > You can set the headers to be blank, which should have the effect you are after. I very much doubt this is a good solution to your problem though. > On Wed, 16 May 2007 16:51:57 +0700, Budi Febrianto wrote: > >> mailscanner-bounces@lists.mailscanner.info wrote on 05-16-2007 04:26:51 PM: >> >> >>> Hi, >>> >>> We have received some helpdesk calls from users who have been >>> experiencing no delivery messages with the following text :- >>> >>> DELIVERY FAILURE: Error transferring to XXXXXXXXXX/XXX/XXX mail.box; >>> Cannotstore document - database has too many unique field names. >>> Please set the'Allow more fields in database' option or ask your >>> administrator to compact the database. >>> >>> Has anybody else seen these ? This is happening when we send emails >>> to a couple of our suppliers. I am wondering whether they have a >>> automated jobs which parses the email and stores the embedded data. >>> >>> Any ideas ? >>> -- >>> --[ UxBoD ]-- >>> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" >>> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >>> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >>> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >>> >>> >> I'm using lotus notes and mailscanner. >> Is you or your customer that using lotus notes? >> In standard lotus notes, there is limitation on how many fields that in >> one >> database can have, and simply enable 'allow more fields in database' will >> help. >> I think mailscanner add too much headers in outgoing emails. >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> -- >> This message has been scanned for viruses and dangerous content by >> MailScanner, and is >> believed to be clean. >> Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGSyPaEfZZRxQVtlQRAjLbAJ9knphRVPU5tcAc8eqq9UTAL4CkXgCgiweF EqJOC005l+Rcj8hlKY2hDhg= =urQz -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From Kevin_Miller at ci.juneau.ak.us Wed May 16 16:32:36 2007 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Wed May 16 16:32:21 2007 Subject: Bayes disk space usage fast increase In-Reply-To: References: Message-ID: Fabien GARZIANO wrote: > Sorry for my late answer Gareth, and thanks for yours. > > Here is a ll... Hope it's still readable : > [root@califw3 spamassassin]# ll -S |more > total 811828 > -rw------- 1 postfix postfix 10104832 May 16 17:10 bayes_toks > -rw------- 1 postfix postfix 5206016 May 2 13:47 bayes_seen > -rw------- 1 postfix postfix 5079040 May 15 04:52 > bayes_toks.expire32062 > -rw------- 1 postfix postfix 5033984 May 15 06:54 > bayes_toks.expire2565 You can get rid of the bayes_toks.expire* files. This problem is well covered in the archives - it used to bite people regularly. The bayes database is taking too long to be rebuilt - you can bump up the frequency that it happens, or even turn it off in MailScanner and do it via a cron job. Check the comments in MailScanner.conf for bayes auto expire and maybe the archives too. HTH... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From martinh at solidstatelogic.com Wed May 16 16:35:23 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 16 16:35:27 2007 Subject: Detecting forwarded spam In-Reply-To: <464B2217.8020201@ecs.soton.ac.uk> Message-ID: <37d28febbd0916478f7c070ad0161959@solidstatelogic.com> Jules Ah sorry - it *was* along time ago.... -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Julian Field > Sent: 16 May 2007 16:24 > To: MailScanner discussion > Subject: Re: Detecting forwarded spam > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > MailScanner has never actually relied on the contents of the headers for > anything, except for the feature > Sign Messages Already Processed = no > as the only way that can work is to guess whether it has already been > run through your MailScanner setup on a different server. > > MailScanner has *never* trusted the contents of the headers to actually > skip any scanning or other processing of the message. > > One of the main reasons for the %org-name% was to try to pursuade people > to customise their setups a bit, so when I get sent the headers of a > message I stand a fighting chance of being able to find out which > MailScanner installation in the world actually generated the headers. It > also made the "Sign Messages Already Processed" work better as it would > look for *your* MailScanner header rather than any old MailScanner > header added by someone else's setup. > > Martin.Hepworth wrote: > > Daniel > > > > We had a similar situation a few years back (3?). > > > > The X-MailScanner headers could be used as trust mechanism - ie it's got > > the "X-MailScanner: Found to be clean", so we'll trust that and allow > > the email through. > > > > Now the virus writers found out about this and inserted this header into > > the emails they send out, in order to circumvent MailScanner doing > > checks on the email. Jules had to rush a new release quickly where the > > %org-name% was inserted into the headers to try and make this a little > > unique, so there was some chance of the header being actually inserted > > by MS. Can't see anything in the changelog, but it was around version > > 4.22 from memory > > > > *IF* you trust this you may hold yourself open to false positives, ie > > just because someone else's system says its spam doesn't mean yours > > will. > > > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > > > >> -----Original Message----- > >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > >> bounces@lists.mailscanner.info] On Behalf Of Michael Masse > >> Sent: 15 May 2007 18:21 > >> To: >> Subject: Detecting forwarded spam > >> > >> Is there a way for MailScanner to detect if a forwarded message has > >> already been detected as spam by another system, therefore not needing > >> > > to > > > >> run it's own spam check? > >> > >> We have a large number of users who used to use a separate email > >> > > provider > > > >> and they now just have that email forwarded to their account here. > >> Their old system detects spam and creates a header entry like: > >> X-Spam-Report: IsSpam=yes > >> > >> Right now our system just ignores that, so I was wondering if I can > >> > > get > > > >> our Mailscanner to take this into account and not bother with > >> > > spamassassin > > > >> checks if it sees this in the header? I'm sure I could make a > >> spamassassin rule to assign points if it saw this, but the whole point > >> > > is > > > >> to not have to get spamassassin involved. > >> > >> Is this possible, or should I just stick with a spamassassin rule? > >> > >> Mike > >> > >> > >> -- > >> MailScanner mailing list > >> mailscanner@lists.mailscanner.info > >> http://lists.mailscanner.info/mailman/listinfo/mailscanner > >> > >> Before posting, read http://wiki.mailscanner.info/posting > >> > >> Support MailScanner development - buy the book off the website! > >> > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are intended for the > > addressee only and may be confidential. If they come to you in error > > you must take no action based on them, nor must you copy or show them > > to anyone. Please advise the sender by replying to this e-mail > > immediately and then delete the original from your computer. > > > > Opinion : Any opinions expressed in this e-mail are entirely those of > > the author and unless specifically stated to the contrary, are not > > necessarily those of the author's employer. > > > > Security Warning : Internet e-mail is not necessarily a secure > > communications medium and can be subject to data corruption. We advise > > that you consider this fact when e-mailing us. > > > > Viruses : We have taken steps to ensure that this e-mail and any > > attachments are free from known viruses but in keeping with good > > computing practice, you should ensure that they are virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic > > Registered as a limited company in England and Wales > > (Company No:5362730) > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > United Kingdom > > ********************************************************************** > > > > > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: ISO-8859-1 > > wj8DBQFGSyKsEfZZRxQVtlQRAn7YAKCTh+krWSETxvlMVVeH/zknwbbeTACg8Kbu > dKOdVCs2ZjOAJ51q+b1T6SA= > =n4fw > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From amaclach at yahoo.co.uk Wed May 16 16:37:13 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Wed May 16 16:37:17 2007 Subject: Detecting forwarded spam Message-ID: <224570.62886.qm@web26308.mail.ukl.yahoo.com> Might it be better to write that so that it can score the message in SA? Just my ?0.02... ----- Original Message ---- From: Julian Field To: MailScanner discussion Sent: Wednesday, 16 May, 2007 4:13:27 PM Subject: Re: Detecting forwarded spam -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Scott Silva wrote: > Michael Masse spake the following on 5/15/2007 10:20 AM: > >> Is there a way for MailScanner to detect if a forwarded message has already been detected as spam by another system, therefore not needing to run it's own spam check? >> >> We have a large number of users who used to use a separate email provider and they now just have that email forwarded to their account here. Their old system detects spam and creates a header entry like: >> X-Spam-Report: IsSpam=yes >> >> Right now our system just ignores that, so I was wondering if I can get our Mailscanner to take this into account and not bother with spamassassin checks if it sees this in the header? I'm sure I could make a spamassassin rule to assign points if it saw this, but the whole point is to not have to get spamassassin involved. >> >> Is this possible, or should I just stick with a spamassassin rule? >> >> Mike >> >> >> > You could write a custom function to do this, and maybe you could get Julian > to write it for you for some $$$ (money, deniro, cash, mammon, greenbacks, > script, coinage, euros, pounds sterling, etc...). > Yes: for a suitable bribe, I could write you a Custom Function to do this. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGSyBUEfZZRxQVtlQRAsjhAKCAAwTxoBet4D9oLTStQHRNV5jDlACg8Uaz 76DXvWlg3dqGlFfiT8PBjVI= =ro91 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Wed May 16 16:33:56 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 16 16:38:19 2007 Subject: Report: Denial of Service attack in message! In-Reply-To: <223f97700705160320mb365184ue3db81f74d3cef71@mail.gmail.com> References: <200705151744.l4FHiaX4012853@safir.blacknight.ie> <223f97700705160320mb365184ue3db81f74d3cef71@mail.gmail.com> Message-ID: <464B2464.9020704@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Glenn Steen wrote: > On 16/05/07, Norbert Schmidt wrote: >> Hi Jules, >> >> the Value for "Virus Scanner Timeout" was still on the old standard (I >> belive) 30 seconds. I haven't changed that, but I've changed the version >> of clamav due to regular updates. This must have let to the problem. >> I've >> now raised the timeout to 300 seconds and all is quiet now. >> >> I think there is a big problem with the classification as "Denial of >> service attack" when the virusscanner times out because all messages in >> that batch are marked as "containing a virus" and thus are thrown away. >> This can lead to loss of a lot of legitimate mail that happened to be in >> the same batch with a mail containing a "Denial of service attack". I >> guess an option, to control this behaviour would be usefull. >> >> I do not have the Mail::ClamAV module installed but will do so now. >> >> This leads me to a question... Is it better to upgrade MailScanner or is >> it better to install the new version each time? >> We've been using MailScanner for the last 3 years now. I didn't go thru >> every version, but always skipped a few as it is always quite some >> hassel >> to go thru all options and set them up appropriate. Is there a way to >> set >> the seldom changed options like Company name, webpage etc. So after an >> update these things stay the same... >> >> Thanks for your help >> >> Norbert > > AFAIK you should be fine with upgrading as long as you remember to go > through with the upgrade_MailScanner_conf and upgrade_languages_conf > scripts. > Has worked very nicely for me so far (some years, rather many > versions:-). BTW, my setting for that timeout is 300, without any > intervention from me, other than the scripts(possibly);-). > Use "MailScanner --changed" after an upgrade to see what defaults > you've deviated from... This is a good way to see/fix the changes to > the defaults that the upgrade scripts _might_ miss... If the default values change, the upgrade scripts can't distinguish this situation from the situation where you have changed a value. The upgrade scripts use nothing more than the contents of the 2 files you supply on the command line. They have no other knowledge at all. As a result they can upgrade or downgrade from any version to any other version. Incidentally upgrade_MailScanner_conf and upgrade_languages_conf are actually the same script, one is a soft-link to the other :-) Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGSyUFEfZZRxQVtlQRAklzAKD4tLzvBG2GkiwCi3juMWKihkP6ewCgvUdb nnLf268A+jdEuV25tYCMbFs= =B8pQ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Wed May 16 16:38:37 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 16 16:42:26 2007 Subject: Filename checks blocking docx files In-Reply-To: References: Message-ID: <464B257D.6010405@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Should I add this rule to the default supplied filename.rules.conf file? Paul Houselander wrote: > Hi > > Just had a situation with someone sending an email with an Office 2007 > attachment. > > Its in docx format and was caught by the filename checks (Attempt to hide > real filename) > > It seems that that docx format is a Zip container for packaging XML and > other data files, within the docx file are files called document.xml.rel and > settings.xml.rel amongst others - these are the files that caused the file > to get blocked. > > Ive got a ruleset for Allow Filenames can I just add > > FromTo: * \.xml\.rel > > and that should be enough to allow them? > > Kind Regards > > Paul > > > > > > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGSyYyEfZZRxQVtlQRAjy8AJ9xyYXYtMyYcM/Q/k7UKpO2ie+T2gCg0yU5 vrC5H7mqHBkMwpeyectn8As= =E/4o -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Wed May 16 16:37:29 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 16 16:42:48 2007 Subject: MS & Lotus Notes In-Reply-To: <23d5715eb4c799996c16e7a952ce3bb0@62.49.223.244> References: <70fd045c73cf914284f93d8dec109052@solidstatelogic.com> <23d5715eb4c799996c16e7a952ce3bb0@62.49.223.244> Message-ID: <464B2539.6040207@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 If you wanted to send some mail through without MailScanner doing anything to it, that's easy with a ruleset on the "Scan Messages" configuration option. Much simpler than a second Postfix running on some non-standard port. What you asked for, I believe, was a way of making MailScanner add no headers, not a way of making MailScanner pass through mail without scanning it at all. So I, and others (I believe), took your request to mean that you wanted MailScanner to do all its processing but not add any headers as a result. Which isn't what you wanted at all :-( - --[ UxBoD ]-- wrote: > To get around it I have created a second Postfix instance that performs no MS checks etc on a different port. The Lotus Notes administrator can now send outbound through that to get around the problem. > > Thanks for everyones help. > > On Wed, 16 May 2007 11:18:37 +0100, "Martin.Hepworth" wrote: > >> Yeah you can do this - but it'll still add in some headers. >> >> I'd bounce the problem at the third party - the email you are sending >> complies to all rfc's so they should be able to accept it. >> >> -- >> Martin Hepworth >> Snr Systems Administrator >> Solid State Logic >> Tel: +44 (0)1865 842300 >> >> >>> -----Original Message----- >>> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >>> bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- >>> Sent: 16 May 2007 11:12 >>> To: MailScanner discussion >>> Subject: RE: MS & Lotus Notes >>> >>> Based on that I would say it is the supplier who is having issues, as >>> >> they >> >>> potentially have not configured their Notes servers correctly with >>> >> that >> >>> option. >>> >>> The problem is that I have installed this solution and emails out >>> >> bouncing >> >>> to our biggest customers and suppliers. >>> >>> Hmmm, I suppose I could switch off all outbound scanning for those >>> domains. Is this possible with MailScanner, or will I need to modify >>> Postfix so that it does not HOLD them for those domains ? >>> >>> Thanks, >>> >>> On Wed, 16 May 2007 10:58:24 +0100, "Martin.Hepworth" >>> wrote: >>> >>>> If that's the case a lot of email lists will break this default >>>> >> setting >> >>>> as then. I surprised it's just you who's having issues. >>>> >>>> -- >>>> Martin Hepworth >>>> Snr Systems Administrator >>>> Solid State Logic >>>> Tel: +44 (0)1865 842300 >>>> >>>> >>>>> -----Original Message----- >>>>> From: mailscanner-bounces@lists.mailscanner.info >>>>> >> [mailto:mailscanner- >> >>>>> bounces@lists.mailscanner.info] On Behalf Of Budi Febrianto >>>>> Sent: 16 May 2007 10:52 >>>>> To: MailScanner discussion >>>>> Subject: Re: MS & Lotus Notes >>>>> >>>>> mailscanner-bounces@lists.mailscanner.info wrote on 05-16-2007 >>>>> >>>> 04:26:51 >>>> >>>>> PM: >>>>> >>>>> >>>>>> Hi, >>>>>> >>>>>> We have received some helpdesk calls from users who have been >>>>>> experiencing no delivery messages with the following text :- >>>>>> >>>>>> DELIVERY FAILURE: Error transferring to XXXXXXXXXX/XXX/XXX >>>>>> >> mail.box; >> >>>>>> Cannotstore document - database has too many unique field names. >>>>>> Please set the'Allow more fields in database' option or ask your >>>>>> administrator to compact the database. >>>>>> >>>>>> Has anybody else seen these ? This is happening when we send >>>>>> >> emails >> >>>>>> to a couple of our suppliers. I am wondering whether they have a >>>>>> automated jobs which parses the email and stores the embedded >>>>>> >> data. >> >>>>>> Any ideas ? >>>>>> -- >>>>>> --[ UxBoD ]-- >>>>>> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg >>>>>> >>>> --import" >>>> >>>>>> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >>>>>> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >>>>>> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >>>>>> >>>>>> >>>>> I'm using lotus notes and mailscanner. >>>>> Is you or your customer that using lotus notes? >>>>> In standard lotus notes, there is limitation on how many fields >>>>> >> that >> >>>> in >>>> >>>>> one >>>>> database can have, and simply enable 'allow more fields in >>>>> >> database' >> >>>> will >>>> >>>>> help. >>>>> I think mailscanner add too much headers in outgoing emails. >>>>> >>>>> -- >>>>> MailScanner mailing list >>>>> mailscanner@lists.mailscanner.info >>>>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>>>> >>>>> Before posting, read http://wiki.mailscanner.info/posting >>>>> >>>>> Support MailScanner development - buy the book off the website! >>>>> >>>> >>>> >>>> >>>> >> ********************************************************************** >> >>>> Confidentiality : This e-mail and any attachments are intended for >>>> >> the >> >>>> addressee only and may be confidential. If they come to you in error >>>> you must take no action based on them, nor must you copy or show >>>> >> them >> >>>> to anyone. Please advise the sender by replying to this e-mail >>>> immediately and then delete the original from your computer. >>>> >>>> Opinion : Any opinions expressed in this e-mail are entirely those >>>> >> of >> >>>> the author and unless specifically stated to the contrary, are not >>>> necessarily those of the author's employer. >>>> >>>> Security Warning : Internet e-mail is not necessarily a secure >>>> communications medium and can be subject to data corruption. We >>>> >> advise >> >>>> that you consider this fact when e-mailing us. >>>> >>>> Viruses : We have taken steps to ensure that this e-mail and any >>>> attachments are free from known viruses but in keeping with good >>>> computing practice, you should ensure that they are virus free. >>>> >>>> Red Lion 49 Ltd T/A Solid State Logic >>>> Registered as a limited company in England and Wales >>>> (Company No:5362730) >>>> Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, >>>> United Kingdom >>>> >>>> >> ********************************************************************** >> >>>> -- >>>> MailScanner mailing list >>>> mailscanner@lists.mailscanner.info >>>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>>> >>>> Before posting, read http://wiki.mailscanner.info/posting >>>> >>>> Support MailScanner development - buy the book off the website! >>>> >>>> >>>> >>> -- >>> --[ UxBoD ]-- >>> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" >>> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >>> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >>> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >>> >>> >>> -- >>> This message has been scanned for viruses and dangerous content by >>> MailScanner, and is >>> believed to be clean. >>> >>> -- >>> MailScanner mailing list >>> mailscanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! >>> >> >> >> ********************************************************************** >> Confidentiality : This e-mail and any attachments are intended for the >> addressee only and may be confidential. If they come to you in error >> you must take no action based on them, nor must you copy or show them >> to anyone. Please advise the sender by replying to this e-mail >> immediately and then delete the original from your computer. >> >> Opinion : Any opinions expressed in this e-mail are entirely those of >> the author and unless specifically stated to the contrary, are not >> necessarily those of the author's employer. >> >> Security Warning : Internet e-mail is not necessarily a secure >> communications medium and can be subject to data corruption. We advise >> that you consider this fact when e-mailing us. >> >> Viruses : We have taken steps to ensure that this e-mail and any >> attachments are free from known viruses but in keeping with good >> computing practice, you should ensure that they are virus free. >> >> Red Lion 49 Ltd T/A Solid State Logic >> Registered as a limited company in England and Wales >> (Company No:5362730) >> Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, >> United Kingdom >> ********************************************************************** >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> >> Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGSyYxEfZZRxQVtlQRAo7oAJ4kEWcnaifTRkEawNBuMxQV9xKBjwCfa6VU gI0RdBKeD5uTpDDnJD19LoM= =7/wG -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Wed May 16 16:40:19 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 16 16:43:18 2007 Subject: warning in maillog after upgrading to latest ms In-Reply-To: <34D06C003AA0EA4D8D9B9443E7BDDD9503518F63@ikaros.exallon.sigma.se> References: <34D06C003AA0EA4D8D9B9443E7BDDD9503518F63@ikaros.exallon.sigma.se> Message-ID: <464B25E3.8040109@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Jonas Lilja wrote: > Hi, > > I?ve just upgraded MS to mailscanner-4.59.4-2 and the latest stable Tarball package (install-Clam-0.90.2-SA-3.2.0.tar). Everything looked fine at the upgrade-process but after starting MS I get a lot of warnings in the maillog: > > WARNING: Can't parse the configuration file. > What process is generating these warnings? The line in the maillog should tell you. > What does this mean? I?we googled for it and also search in the list-archive but didn?t find any hints. > > MTA is sendmail-8.13.1-3.RHEL4.5 > I use DCC, Rules du Jour and Razor2 plugins in spamassassin. > > Thanx for hints. > > Jonas Lilja > > PS - the MTA/MS is working so there is no panic with this case. I just wonder what?s wrong in my config. The version I upgraded from was 4.58.9-1 and didn?t generate any warnings in maillog. DS. > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGSyYzEfZZRxQVtlQRAs4vAJ0af25Xlyg6K+NOLQ4L0qM8S3Q1BACgt5by ovXGkMopmzxEc9QVIiSO8J8= =/q/Z -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Wed May 16 16:41:37 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 16 16:43:20 2007 Subject: FPs and SA 3.2.0 In-Reply-To: References: <4649CA97.5050802@ecs.soton.ac.uk> Message-ID: <464B2631.4060202@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I'll put it in the main codebase then. Perl has some very subtle bugs in it... - --[ UxBoD ]-- wrote: > Hi Jules, > > No FPs at all today :) > > Thanks, > > On Tue, 15 May 2007 15:58:31 +0100, Julian Field wrote: > >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> >> >> Leland J. Steinke wrote: >> >>> Julian Field wrote: >>> >>>> # JKF 3/10/2005 >>>> my $temp = @HitList; >>>> $temp = $temp + 0; >>>> $temp = 0 unless $HitList[0] =~ /a-z/i; >>>> return ($temp, join(', ', @HitList)); >>>> } >>>> >>>> Let's see if that helps. According to the book, the 2 middle lines >>>> shouldn't be needed at all. >>>> >>> Why not "my $temp = scalar(@HitList);"? >>> >> That should be the exact equivalent of "$temp = @HitList" as $temp is a >> scalar anyway. >> >> Jules >> >> - -- >> Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> MailScanner customisation, or any advanced system administration help? >> Contact me at Jules@Jules.FM >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> For all your IT requirements visit www.transtec.co.uk >> >> >> >> -----BEGIN PGP SIGNATURE----- >> Version: PGP Desktop 9.6.1 (Build 1012) >> Charset: UTF-8 >> >> wj8DBQFGScqmEfZZRxQVtlQRAk0fAKDkHKSy1XfSr7NmFl7exuiR5RJmGgCcC79L >> BZI+vdG3BNijd2m6HIXK/zA= >> =311a >> -----END PGP SIGNATURE----- >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> For all your IT requirements visit www.transtec.co.uk >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> -- >> This message has been scanned for viruses and dangerous content by >> MailScanner, and is >> believed to be clean. >> Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGSyY5EfZZRxQVtlQRAoQpAJwJUy+9rEEX5Ahgs9uBptUgXVQArwCfdyIk /1e+HnmGwdVVcghNHmCl2jg= =/CbN -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From Kevin_Miller at ci.juneau.ak.us Wed May 16 16:50:30 2007 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Wed May 16 16:50:15 2007 Subject: Detecting forwarded spam In-Reply-To: <37d28febbd0916478f7c070ad0161959@solidstatelogic.com> References: <464B2217.8020201@ecs.soton.ac.uk> <37d28febbd0916478f7c070ad0161959@solidstatelogic.com> Message-ID: Martin.Hepworth wrote: > Jules > > Ah sorry - it *was* along time ago.... You got off easy. A long time ago, I was under the same mistaken impression and replied to someone to that affect. Jules' response to me was 'Even Microsoft wouldn't be that dumb.' Ouch. IIRC, at the time the setting in question suppressed further additional headers if the message had already passed through a MailScanner box - a big difference between not being scanned at all... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From uxbod at splatnix.net Wed May 16 16:57:59 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Wed May 16 16:58:46 2007 Subject: MS & Lotus Notes In-Reply-To: <464B2539.6040207@ecs.soton.ac.uk> References: <464B2539.6040207@ecs.soton.ac.uk> Message-ID: Yeah probably didn't explain myself well enough :( But your mailscanner script for RedHat allows for the handling of two Postfix instances, so thats cool ;) On Wed, 16 May 2007 16:37:29 +0100, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > If you wanted to send some mail through without MailScanner doing > anything to it, that's easy with a ruleset on the "Scan Messages" > configuration option. Much simpler than a second Postfix running on some > non-standard port. > > What you asked for, I believe, was a way of making MailScanner add no > headers, not a way of making MailScanner pass through mail without > scanning it at all. So I, and others (I believe), took your request to > mean that you wanted MailScanner to do all its processing but not add > any headers as a result. Which isn't what you wanted at all :-( > > > - --[ UxBoD ]-- wrote: >> To get around it I have created a second Postfix instance that performs > no MS checks etc on a different port. The Lotus Notes administrator can > now send outbound through that to get around the problem. >> >> Thanks for everyones help. >> >> On Wed, 16 May 2007 11:18:37 +0100, "Martin.Hepworth" > wrote: >> >>> Yeah you can do this - but it'll still add in some headers. >>> >>> I'd bounce the problem at the third party - the email you are sending >>> complies to all rfc's so they should be able to accept it. >>> >>> -- >>> Martin Hepworth >>> Snr Systems Administrator >>> Solid State Logic >>> Tel: +44 (0)1865 842300 >>> >>> >>>> -----Original Message----- >>>> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >>>> bounces@lists.mailscanner.info] On Behalf Of --[ UxBoD ]-- >>>> Sent: 16 May 2007 11:12 >>>> To: MailScanner discussion >>>> Subject: RE: MS & Lotus Notes >>>> >>>> Based on that I would say it is the supplier who is having issues, as >>>> >>> they >>> >>>> potentially have not configured their Notes servers correctly with >>>> >>> that >>> >>>> option. >>>> >>>> The problem is that I have installed this solution and emails out >>>> >>> bouncing >>> >>>> to our biggest customers and suppliers. >>>> >>>> Hmmm, I suppose I could switch off all outbound scanning for those >>>> domains. Is this possible with MailScanner, or will I need to modify >>>> Postfix so that it does not HOLD them for those domains ? >>>> >>>> Thanks, >>>> >>>> On Wed, 16 May 2007 10:58:24 +0100, "Martin.Hepworth" >>>> wrote: >>>> >>>>> If that's the case a lot of email lists will break this default >>>>> >>> setting >>> >>>>> as then. I surprised it's just you who's having issues. >>>>> >>>>> -- >>>>> Martin Hepworth >>>>> Snr Systems Administrator >>>>> Solid State Logic >>>>> Tel: +44 (0)1865 842300 >>>>> >>>>> >>>>>> -----Original Message----- >>>>>> From: mailscanner-bounces@lists.mailscanner.info >>>>>> >>> [mailto:mailscanner- >>> >>>>>> bounces@lists.mailscanner.info] On Behalf Of Budi Febrianto >>>>>> Sent: 16 May 2007 10:52 >>>>>> To: MailScanner discussion >>>>>> Subject: Re: MS & Lotus Notes >>>>>> >>>>>> mailscanner-bounces@lists.mailscanner.info wrote on 05-16-2007 >>>>>> >>>>> 04:26:51 >>>>> >>>>>> PM: >>>>>> >>>>>> >>>>>>> Hi, >>>>>>> >>>>>>> We have received some helpdesk calls from users who have been >>>>>>> experiencing no delivery messages with the following text :- >>>>>>> >>>>>>> DELIVERY FAILURE: Error transferring to XXXXXXXXXX/XXX/XXX >>>>>>> >>> mail.box; >>> >>>>>>> Cannotstore document - database has too many unique field names. >>>>>>> Please set the'Allow more fields in database' option or ask your >>>>>>> administrator to compact the database. >>>>>>> >>>>>>> Has anybody else seen these ? This is happening when we send >>>>>>> >>> emails >>> >>>>>>> to a couple of our suppliers. I am wondering whether they have a >>>>>>> automated jobs which parses the email and stores the embedded >>>>>>> >>> data. >>> >>>>>>> Any ideas ? >>>>>>> -- >>>>>>> --[ UxBoD ]-- >>>>>>> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg >>>>>>> >>>>> --import" >>>>> >>>>>>> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >>>>>>> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >>>>>>> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >>>>>>> >>>>>>> >>>>>> I'm using lotus notes and mailscanner. >>>>>> Is you or your customer that using lotus notes? >>>>>> In standard lotus notes, there is limitation on how many fields >>>>>> >>> that >>> >>>>> in >>>>> >>>>>> one >>>>>> database can have, and simply enable 'allow more fields in >>>>>> >>> database' >>> >>>>> will >>>>> >>>>>> help. >>>>>> I think mailscanner add too much headers in outgoing emails. >>>>>> >>>>>> -- >>>>>> MailScanner mailing list >>>>>> mailscanner@lists.mailscanner.info >>>>>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>>>>> >>>>>> Before posting, read http://wiki.mailscanner.info/posting >>>>>> >>>>>> Support MailScanner development - buy the book off the website! >>>>>> >>>>> >>>>> >>>>> >>>>> >>> ********************************************************************** >>> >>>>> Confidentiality : This e-mail and any attachments are intended for >>>>> >>> the >>> >>>>> addressee only and may be confidential. If they come to you in error >>>>> you must take no action based on them, nor must you copy or show >>>>> >>> them >>> >>>>> to anyone. Please advise the sender by replying to this e-mail >>>>> immediately and then delete the original from your computer. >>>>> >>>>> Opinion : Any opinions expressed in this e-mail are entirely those >>>>> >>> of >>> >>>>> the author and unless specifically stated to the contrary, are not >>>>> necessarily those of the author's employer. >>>>> >>>>> Security Warning : Internet e-mail is not necessarily a secure >>>>> communications medium and can be subject to data corruption. We >>>>> >>> advise >>> >>>>> that you consider this fact when e-mailing us. >>>>> >>>>> Viruses : We have taken steps to ensure that this e-mail and any >>>>> attachments are free from known viruses but in keeping with good >>>>> computing practice, you should ensure that they are virus free. >>>>> >>>>> Red Lion 49 Ltd T/A Solid State Logic >>>>> Registered as a limited company in England and Wales >>>>> (Company No:5362730) >>>>> Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, >>>>> United Kingdom >>>>> >>>>> >>> ********************************************************************** >>> >>>>> -- >>>>> MailScanner mailing list >>>>> mailscanner@lists.mailscanner.info >>>>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>>>> >>>>> Before posting, read http://wiki.mailscanner.info/posting >>>>> >>>>> Support MailScanner development - buy the book off the website! >>>>> >>>>> >>>>> >>>> -- >>>> --[ UxBoD ]-- >>>> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" >>>> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >>>> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >>>> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >>>> >>>> >>>> -- >>>> This message has been scanned for viruses and dangerous content by >>>> MailScanner, and is >>>> believed to be clean. >>>> >>>> -- >>>> MailScanner mailing list >>>> mailscanner@lists.mailscanner.info >>>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>>> >>>> Before posting, read http://wiki.mailscanner.info/posting >>>> >>>> Support MailScanner development - buy the book off the website! >>>> >>> >>> >>> ********************************************************************** >>> Confidentiality : This e-mail and any attachments are intended for the >>> addressee only and may be confidential. If they come to you in error >>> you must take no action based on them, nor must you copy or show them >>> to anyone. Please advise the sender by replying to this e-mail >>> immediately and then delete the original from your computer. >>> >>> Opinion : Any opinions expressed in this e-mail are entirely those of >>> the author and unless specifically stated to the contrary, are not >>> necessarily those of the author's employer. >>> >>> Security Warning : Internet e-mail is not necessarily a secure >>> communications medium and can be subject to data corruption. We advise >>> that you consider this fact when e-mailing us. >>> >>> Viruses : We have taken steps to ensure that this e-mail and any >>> attachments are free from known viruses but in keeping with good >>> computing practice, you should ensure that they are virus free. >>> >>> Red Lion 49 Ltd T/A Solid State Logic >>> Registered as a limited company in England and Wales >>> (Company No:5362730) >>> Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, >>> United Kingdom >>> ********************************************************************** >>> >>> -- >>> MailScanner mailing list >>> mailscanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! >>> >>> >>> > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: UTF-8 > > wj8DBQFGSyYxEfZZRxQVtlQRAo7oAJ4kEWcnaifTRkEawNBuMxQV9xKBjwCfa6VU > gI0RdBKeD5uTpDDnJD19LoM= > =7/wG > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From gmane at tippingmar.com Wed May 16 17:02:53 2007 From: gmane at tippingmar.com (Mark Nienberg) Date: Wed May 16 17:03:10 2007 Subject: OT: sendmail greetpause ruleset Message-ID: I've been running sendmail with the greetpause feature for some time now, and using the access file to exempt some of my users' home computers from the greetpause delay. Recently I added an MSA on port 587 for traveling users. It only accepts authenticated users so I'd like to turn off the greetpause feature completely for that port, but keep it for the standard MTA on port 25. in sendmail.mc I have: FEATURE(`greet_pause', `3500')dnl FEATURE(`no_default_msa',`dnl')dnl DAEMON_OPTIONS(`Port=smtp, Name=MTA')dnl DAEMON_OPTIONS(`Port=submission, Name=MSA, M=Ea')dnl I saw the following suggestion in a sendmail archive, but I haven't been able to get it working: LOCAL_RULESETS SLocal_greet_pause R$* $: $&{daemon_port} Rsubmission $# 0 Is the RULESET meant to replace the FEATURE(`greet_pause) or be in addition to it? Am I supposed to replace the {daemon_port} with a real port number? Or is there a better way altogether to accomplish this? I had hoped for a simple entry in the access file but haven't been able to see how to apply an access rule to a specific port. Any guidance appreciated, Mark From fabien.garziano at caliseo.com Wed May 16 17:08:23 2007 From: fabien.garziano at caliseo.com (Fabien GARZIANO) Date: Wed May 16 17:08:41 2007 Subject: Bayes disk space usage fast increase Message-ID: Thanks to all. Ow damn it ... If it was just this, I'm sorry to bother people for so less. Although I'm pretty sure I've already searched in MailScanner.conf without success, I just found the "Rebuild Bayes Every" line... Shame on me... Btw, what is the best between letting spamassassin auto expire tokens files or activating it in MailScanner.conf ? Again thanks ! > -----Message d'origine----- > De : mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] De la > part de Kevin Miller > Envoy? : mercredi 16 mai 2007 17:33 > ? : MailScanner discussion > Objet : RE: Bayes disk space usage fast increase > > Fabien GARZIANO wrote: > > Sorry for my late answer Gareth, and thanks for yours. > > > > Here is a ll... Hope it's still readable : > > [root@califw3 spamassassin]# ll -S |more total 811828 > > -rw------- 1 postfix postfix 10104832 May 16 17:10 bayes_toks > > -rw------- 1 postfix postfix 5206016 May 2 13:47 bayes_seen > > -rw------- 1 postfix postfix 5079040 May 15 04:52 > > bayes_toks.expire32062 > > -rw------- 1 postfix postfix 5033984 May 15 06:54 > > bayes_toks.expire2565 > > You can get rid of the bayes_toks.expire* files. This > problem is well covered in the archives - it used to bite > people regularly. The bayes database is taking too long to > be rebuilt - you can bump up the frequency that it happens, > or even turn it off in MailScanner and do it via a cron job. > Check the comments in MailScanner.conf for bayes auto expire > and maybe the archives too. > > HTH... > > ...Kevin > -- > Kevin Miller Registered Linux User No: 307357 > CBJ MIS Dept. Network Systems Admin., Mail Admin. > 155 South Seward Street ph: (907) 586-0242 > Juneau, Alaska 99801 fax: (907 586-4500 > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From list-mailscanner at linguaphone.com Wed May 16 17:51:04 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Wed May 16 17:51:13 2007 Subject: Bayes disk space usage fast increase In-Reply-To: Message-ID: I would let mailscanner do it and that way it will wait until the rebuild is finished. If you let spamassassin do it then you will need to increase the timeout to a sufficiently long time which could cause you problems in the future if a ruleset starts taking too long to run and slows down your processing. > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Fabien > GARZIANO > Sent: 16 May 2007 17:08 > To: MailScanner discussion > Subject: RE: Bayes disk space usage fast increase > > > Thanks to all. > > Ow damn it ... If it was just this, I'm sorry to bother people > for so less. Although I'm pretty sure I've already searched in > MailScanner.conf without success, I just found the "Rebuild Bayes > Every" line... > > Shame on me... > > Btw, what is the best between letting spamassassin auto expire > tokens files or activating it in MailScanner.conf ? > > Again thanks ! > > > -----Message d'origine----- > > De : mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] De la > > part de Kevin Miller > > Envoy? : mercredi 16 mai 2007 17:33 > > ? : MailScanner discussion > > Objet : RE: Bayes disk space usage fast increase > > > > Fabien GARZIANO wrote: > > > Sorry for my late answer Gareth, and thanks for yours. > > > > > > Here is a ll... Hope it's still readable : > > > [root@califw3 spamassassin]# ll -S |more total 811828 > > > -rw------- 1 postfix postfix 10104832 May 16 17:10 bayes_toks > > > -rw------- 1 postfix postfix 5206016 May 2 13:47 bayes_seen > > > -rw------- 1 postfix postfix 5079040 May 15 04:52 > > > bayes_toks.expire32062 > > > -rw------- 1 postfix postfix 5033984 May 15 06:54 > > > bayes_toks.expire2565 > > > > You can get rid of the bayes_toks.expire* files. This > > problem is well covered in the archives - it used to bite > > people regularly. The bayes database is taking too long to > > be rebuilt - you can bump up the frequency that it happens, > > or even turn it off in MailScanner and do it via a cron job. > > Check the comments in MailScanner.conf for bayes auto expire > > and maybe the archives too. > > > > HTH... > > > > ...Kevin > > -- > > Kevin Miller Registered Linux User No: 307357 > > CBJ MIS Dept. Network Systems Admin., Mail Admin. > > 155 South Seward Street ph: (907) 586-0242 > > Juneau, Alaska 99801 fax: (907 586-4500 > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > From ssilva at sgvwater.com Wed May 16 21:09:43 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed May 16 21:10:05 2007 Subject: Detecting forwarded spam In-Reply-To: <224570.62886.qm@web26308.mail.ukl.yahoo.com> References: <224570.62886.qm@web26308.mail.ukl.yahoo.com> Message-ID: >> Michael Masse spake the following on 5/15/2007 10:20 AM: > >>> Is there a way for MailScanner to detect if a forwarded message has already been detected as spam by another system, therefore not needing to run it's own spam check? >>> >>> We have a large number of users who used to use a separate email provider and they now just have that email forwarded to their account here. Their old system detects spam and creates a header entry like: >>> X-Spam-Report: IsSpam=yes >>> >>> Right now our system just ignores that, so I was wondering if I can get our Mailscanner to take this into account and not bother with spamassassin checks if it sees this in the header? I'm sure I could make a spamassassin rule to assign points if it saw this, but the whole point is to not have to get spamassassin involved. >>> >>> Is this possible, or should I just stick with a spamassassin rule? >>> >>> Mike >>> >>> >>> >> You could write a custom function to do this, and maybe you could get Julian >> to write it for you for some $$$ (money, deniro, cash, mammon, greenbacks, >> script, coinage, euros, pounds sterling, etc...). > > Yes: for a suitable bribe, I could write you a Custom Function to do this. > > Jules > >Andrew MacLachlan spake the following on 5/16/2007 8:37 AM: > Might it be better to write that so that it can score the message in SA? > Just my ?0.02... > That would be the easiest to write, with a suitable positive score if the header is there, but might not do exactly as he wants as he wanted to avoid spamassassin processing. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From jonas.lilja at exallon.sigma.se Wed May 16 21:12:00 2007 From: jonas.lilja at exallon.sigma.se (Jonas Lilja) Date: Wed May 16 21:16:17 2007 Subject: SV: warning in maillog after upgrading to latest ms References: <34D06C003AA0EA4D8D9B9443E7BDDD9503518F63@ikaros.exallon.sigma.se> <464B25E3.8040109@ecs.soton.ac.uk> Message-ID: <34D06C003AA0EA4D8D9B9443E7BDDD956BA9@ikaros.exallon.sigma.se> Hi again, it?s the MailScanner process generating these warnings: [root@tubes ~]# tail -f /var/log/maillog |grep WARNING May 16 22:11:07 tubes MailScanner[783]: WARNING: Can't parse the configuration file. [root@tubes ~]# ps -ef|grep 783 root 783 16984 0 19:20 ? 00:00:27 MailScanner: waiting for messages root 7610 7369 0 22:11 pts/0 00:00:00 grep 783 Ideas? Regards /Jonas ________________________________ Fr?n: mailscanner-bounces@lists.mailscanner.info genom Julian Field Skickat: on 2007-05-16 17:40 Till: MailScanner discussion ?mne: Re: warning in maillog after upgrading to latest ms -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Jonas Lilja wrote: > Hi, > > I?ve just upgraded MS to mailscanner-4.59.4-2 and the latest stable Tarball package (install-Clam-0.90.2-SA-3.2.0.tar). Everything looked fine at the upgrade-process but after starting MS I get a lot of warnings in the maillog: > > WARNING: Can't parse the configuration file. > What process is generating these warnings? The line in the maillog should tell you. > What does this mean? I?we googled for it and also search in the list-archive but didn?t find any hints. > > MTA is sendmail-8.13.1-3.RHEL4.5 > I use DCC, Rules du Jour and Razor2 plugins in spamassassin. > > Thanx for hints. > > Jonas Lilja > > PS - the MTA/MS is working so there is no panic with this case. I just wonder what?s wrong in my config. The version I upgraded from was 4.58.9-1 and didn?t generate any warnings in maillog. DS. > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGSyYzEfZZRxQVtlQRAs4vAJ0af25Xlyg6K+NOLQ4L0qM8S3Q1BACgt5by ovXGkMopmzxEc9QVIiSO8J8= =/q/Z -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/ms-tnef Size: 6136 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070516/c5fb97be/attachment.bin From dominian at slackadelic.com Wed May 16 21:20:35 2007 From: dominian at slackadelic.com (Matt Hayes) Date: Wed May 16 21:20:44 2007 Subject: SV: warning in maillog after upgrading to latest ms In-Reply-To: <34D06C003AA0EA4D8D9B9443E7BDDD956BA9@ikaros.exallon.sigma.se> References: <34D06C003AA0EA4D8D9B9443E7BDDD9503518F63@ikaros.exallon.sigma.se> <464B25E3.8040109@ecs.soton.ac.uk> <34D06C003AA0EA4D8D9B9443E7BDDD956BA9@ikaros.exallon.sigma.se> Message-ID: <464B6793.2030606@slackadelic.com> Jonas Lilja wrote: > Hi again, > > it?s the MailScanner process generating these warnings: > > [root@tubes ~]# tail -f /var/log/maillog |grep WARNING > > May 16 22:11:07 tubes MailScanner[783]: WARNING: Can't parse the configuration file. > > [root@tubes ~]# ps -ef|grep 783 > root 783 16984 0 19:20 ? 00:00:27 MailScanner: waiting for messages > root 7610 7369 0 22:11 pts/0 00:00:00 grep 783 > > Ideas? > > Regards /Jonas > Have you put MailScanner into debug mode? -Matt From jonas.lilja at exallon.sigma.se Wed May 16 21:35:50 2007 From: jonas.lilja at exallon.sigma.se (Jonas Lilja) Date: Wed May 16 21:40:27 2007 Subject: SV: SV: warning in maillog after upgrading to latest ms References: <34D06C003AA0EA4D8D9B9443E7BDDD9503518F63@ikaros.exallon.sigma.se> <464B25E3.8040109@ecs.soton.ac.uk> <34D06C003AA0EA4D8D9B9443E7BDDD956BA9@ikaros.exallon.sigma.se> <464B6793.2030606@slackadelic.com> Message-ID: <34D06C003AA0EA4D8D9B9443E7BDDD956BAA@ikaros.exallon.sigma.se> I just put MS into debug mode but the only error was on the last line: ERROR: Parse error at line 76: Option FixStaleSocket requires boolean argument. I don?t know if this had to do with the warning in the maillog. Thanks for all hints. /Jonas ________________________________ Fr?n: mailscanner-bounces@lists.mailscanner.info genom Matt Hayes Skickat: on 2007-05-16 22:20 Till: MailScanner discussion ?mne: Re: SV: warning in maillog after upgrading to latest ms Jonas Lilja wrote: > Hi again, > > it?s the MailScanner process generating these warnings: > > [root@tubes ~]# tail -f /var/log/maillog |grep WARNING > > May 16 22:11:07 tubes MailScanner[783]: WARNING: Can't parse the configuration file. > > [root@tubes ~]# ps -ef|grep 783 > root 783 16984 0 19:20 ? 00:00:27 MailScanner: waiting for messages > root 7610 7369 0 22:11 pts/0 00:00:00 grep 783 > > Ideas? > > Regards /Jonas > Have you put MailScanner into debug mode? -Matt -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/ms-tnef Size: 4896 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070516/a7d1d824/attachment.bin From waytotheweb at googlemail.com Wed May 16 21:55:05 2007 From: waytotheweb at googlemail.com (Sarah Trayser) Date: Wed May 16 21:55:08 2007 Subject: SV: warning in maillog after upgrading to latest ms In-Reply-To: <34D06C003AA0EA4D8D9B9443E7BDDD956BAA@ikaros.exallon.sigma.se> References: <34D06C003AA0EA4D8D9B9443E7BDDD9503518F63@ikaros.exallon.sigma.se> <464B25E3.8040109@ecs.soton.ac.uk> <34D06C003AA0EA4D8D9B9443E7BDDD956BA9@ikaros.exallon.sigma.se> <464B6793.2030606@slackadelic.com> <34D06C003AA0EA4D8D9B9443E7BDDD956BAA@ikaros.exallon.sigma.se> Message-ID: On 16/05/07, Jonas Lilja wrote: > I just put MS into debug mode but the only error was on the last line: > > ERROR: Parse error at line 76: Option FixStaleSocket requires boolean argument. > > I don?t know if this had to do with the warning in the maillog. > > Thanks for all hints. We have seen this a couple of times. I can't remember how we determined that it was a clamd issue, but when we changed "Virus Scanners =" from "auto" to "clamavmodule" the problem disappeared. Before that mailscanner was reporting that it found clamavmodule and clamd installed. (We normally just use clamavmodule anyway.) In /usr/local/etc/clamd.conf on our servers there is an option FixStaleSocket. Not sure how you would fix it, though. -- Regards, Sarah Trayser Way to the Web Ltd Server Management Services: http://www.configserver.com Web Hosting: http://www.waytotheweb.com From amaclach at yahoo.co.uk Wed May 16 22:04:22 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Wed May 16 22:04:24 2007 Subject: Detecting forwarded spam Message-ID: <869500.23831.qm@web26307.mail.ukl.yahoo.com> True enough. It would be prudent to not trust a foreign server too much - although you could give an arbitrary score of 2 to anything previously marked as spam, then let your own host add to that. Alternatively you could take the foreign MTAs word as gospel and assign a score of 1000 to such messages. I know that this isn't 100% what he wanted, but I guess it would be useful to some. Far more useful to me would be something that detects backscatter... ----- Original Message ---- From: Scott Silva To: mailscanner@lists.mailscanner.info Sent: Wednesday, 16 May, 2007 9:09:43 PM Subject: Re: Detecting forwarded spam >> Michael Masse spake the following on 5/15/2007 10:20 AM: > >>> Is there a way for MailScanner to detect if a forwarded message has already been detected as spam by another system, therefore not needing to run it's own spam check? >>> >>> We have a large number of users who used to use a separate email provider and they now just have that email forwarded to their account here. Their old system detects spam and creates a header entry like: >>> X-Spam-Report: IsSpam=yes >>> >>> Right now our system just ignores that, so I was wondering if I can get our Mailscanner to take this into account and not bother with spamassassin checks if it sees this in the header? I'm sure I could make a spamassassin rule to assign points if it saw this, but the whole point is to not have to get spamassassin involved. >>> >>> Is this possible, or should I just stick with a spamassassin rule? >>> >>> Mike >>> >>> >>> >> You could write a custom function to do this, and maybe you could get Julian >> to write it for you for some $$$ (money, deniro, cash, mammon, greenbacks, >> script, coinage, euros, pounds sterling, etc...). > > Yes: for a suitable bribe, I could write you a Custom Function to do this. > > Jules > >Andrew MacLachlan spake the following on 5/16/2007 8:37 AM: > Might it be better to write that so that it can score the message in SA? > Just my ?0.02... > That would be the easiest to write, with a suitable positive score if the header is there, but might not do exactly as he wants as he wanted to avoid spamassassin processing. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From jonas.lilja at exallon.sigma.se Wed May 16 22:16:45 2007 From: jonas.lilja at exallon.sigma.se (Jonas Lilja) Date: Wed May 16 22:17:33 2007 Subject: warning in maillog after upgrading to latest ms - Solved !!! References: <34D06C003AA0EA4D8D9B9443E7BDDD9503518F63@ikaros.exallon.sigma.se><464B25E3.8040109@ecs.soton.ac.uk><34D06C003AA0EA4D8D9B9443E7BDDD956BA9@ikaros.exallon.sigma.se><464B6793.2030606@slackadelic.com><34D06C003AA0EA4D8D9B9443E7BDDD956BAA@ikaros.exallon.sigma.se> Message-ID: <34D06C003AA0EA4D8D9B9443E7BDDD956BAB@ikaros.exallon.sigma.se> Hi again, I changed the "Virus Scanners =" from "auto" to "mcafee clamav". Then reloaded MS. No warnings in maillog after that :-) Thank Sarah and all for the hints. Regards /Jonas ________________________________ Fr?n: mailscanner-bounces@lists.mailscanner.info genom Sarah Trayser Skickat: on 2007-05-16 22:55 Till: MailScanner discussion ?mne: Re: SV: warning in maillog after upgrading to latest ms On 16/05/07, Jonas Lilja wrote: > I just put MS into debug mode but the only error was on the last line: > > ERROR: Parse error at line 76: Option FixStaleSocket requires boolean argument. > > I don?t know if this had to do with the warning in the maillog. > > Thanks for all hints. We have seen this a couple of times. I can't remember how we determined that it was a clamd issue, but when we changed "Virus Scanners =" from "auto" to "clamavmodule" the problem disappeared. Before that mailscanner was reporting that it found clamavmodule and clamd installed. (We normally just use clamavmodule anyway.) In /usr/local/etc/clamd.conf on our servers there is an option FixStaleSocket. Not sure how you would fix it, though. -- Regards, Sarah Trayser Way to the Web Ltd Server Management Services: http://www.configserver.com Web Hosting: http://www.waytotheweb.com -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/ms-tnef Size: 5277 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070516/2f643018/attachment.bin From cparker at swatgear.com Wed May 16 22:45:58 2007 From: cparker at swatgear.com (Chris W. Parker) Date: Wed May 16 22:46:02 2007 Subject: Confused about dangerous content scanning setup Message-ID: <97FD54B5E57A1842AA1A4B232E47611773E3B8@ati-ex-02.ati.local> Hello, I need to have the ability to exclude users from filetype checks and content scanning. I'm not sure if that's the right terminology but what I need is for certain people to have their email scanned for viruses and spam but NOT filetype or password protected archives. Specifically, the owner periodically receives password protected zip files and I want those files to get through without any problems. I've managed to get MailScanner setup to archive those files (after they've been stripped) but it's a pain to then manually get them to him. I thought that the following settings would do the trick but the files are still being stripped: # Do you want to scan the messages for potentially dangerous content? # Setting this to "no" will disable all the content-based checks except # Virus Scanning, Allow Partial Messages and Allow External Message Bodies. # This can also be the filename of a ruleset. Dangerous Content Scanning = %rules-dir%/scan.dangerous.rules scan.dangerous.rules: To:user@swatgear.comno FromOrTo:defaultyes I looked through my old emails (and tried searching Google) and it seems that this is the correct setting... but still I have files being stripped. Here are some pertinent log file entries: May 16 14:43:03 filter MailScanner[26763]: Password-protected archive (launcher_promo.zip) in l4GLgoNV026771 May 16 14:43:25 filter MailScanner[26763]: Saved entire message to /var/spool/MailScanner/quarantine/20070516/l4GLgoNV026771 May 16 14:43:25 filter MailScanner[26763]: Saved infected "launcher_promo.zip" to /var/spool/MailScanner/quarantine/20070516/l4GLgoNV026771 What am I missing? Thanks, Chris. From gmane at tippingmar.com Thu May 17 00:26:06 2007 From: gmane at tippingmar.com (Mark Nienberg) Date: Thu May 17 00:26:30 2007 Subject: OT: sendmail greetpause ruleset In-Reply-To: References: Message-ID: A lot more googling has yielded the following ruleset, which seems more likely to work, although I can't test until after hours. LOCAL_RULESETS SLocal_greet_pause R$* $:$1 $&{daemon_flags} R$* $* a $* $# 0 R$* $* $@ $1 This should have the effect of turning off greetpause for all daemons that have M=a, in other words, all daemons that require authentication. Mark From amaclach at yahoo.co.uk Thu May 17 01:00:26 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Thu May 17 01:00:28 2007 Subject: Confused about dangerous content scanning setup Message-ID: <503426.31881.qm@web26312.mail.ukl.yahoo.com> In MailScanner.conf: # Should archives which contain any password-protected files be allowed? # Leaving this set to "no" is a good way of protecting against all the # protected zip files used by viruses at the moment. # This can also be the filename of a ruleset. Allow Password-Protected Archives = no I guess for your purposes you would want to create a rule for specific users: Allow Password-Protected Archives = %rules-dir%/zip.password zip.password: To:user@swatgear.comno FromOrTo:defaultyes -Andy ----- Original Message ---- From: Chris W. Parker To: MailScanner discussion Sent: Wednesday, 16 May, 2007 10:45:58 PM Subject: Confused about dangerous content scanning setup Hello, I need to have the ability to exclude users from filetype checks and content scanning. I'm not sure if that's the right terminology but what I need is for certain people to have their email scanned for viruses and spam but NOT filetype or password protected archives. Specifically, the owner periodically receives password protected zip files and I want those files to get through without any problems. I've managed to get MailScanner setup to archive those files (after they've been stripped) but it's a pain to then manually get them to him. I thought that the following settings would do the trick but the files are still being stripped: # Do you want to scan the messages for potentially dangerous content? # Setting this to "no" will disable all the content-based checks except # Virus Scanning, Allow Partial Messages and Allow External Message Bodies. # This can also be the filename of a ruleset. Dangerous Content Scanning = %rules-dir%/scan.dangerous.rules scan.dangerous.rules: To:user@swatgear.comno FromOrTo:defaultyes I looked through my old emails (and tried searching Google) and it seems that this is the correct setting... but still I have files being stripped. Here are some pertinent log file entries: May 16 14:43:03 filter MailScanner[26763]: Password-protected archive (launcher_promo.zip) in l4GLgoNV026771 May 16 14:43:25 filter MailScanner[26763]: Saved entire message to /var/spool/MailScanner/quarantine/20070516/l4GLgoNV026771 May 16 14:43:25 filter MailScanner[26763]: Saved infected "launcher_promo.zip" to /var/spool/MailScanner/quarantine/20070516/l4GLgoNV026771 What am I missing? Thanks, Chris. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From alex at nkpanama.com Thu May 17 05:05:19 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Thu May 17 05:05:32 2007 Subject: Confused about dangerous content scanning setup In-Reply-To: <503426.31881.qm@web26312.mail.ukl.yahoo.com> References: <503426.31881.qm@web26312.mail.ukl.yahoo.com> Message-ID: Remember to add ".rules" to the filename at the end, otherwise it doesn't necessarily know it's a ruleset... On Thu, 17 May 2007 00:00:26 +0000 (GMT), Andrew MacLachlan wrote: > In MailScanner.conf: > > # Should archives which contain any password-protected files be allowed? > # Leaving this set to "no" is a good way of protecting against all the > # protected zip files used by viruses at the moment. > # This can also be the filename of a ruleset. > Allow Password-Protected Archives = no > > I guess for your purposes you would want to create a rule for specific > users: > > Allow Password-Protected Archives = %rules-dir%/zip.password > > zip.password: > To:user@swatgear.comno > FromOrTo:defaultyes > > -Andy > > ----- Original Message ---- > From: Chris W. Parker > To: MailScanner discussion > Sent: Wednesday, 16 May, 2007 10:45:58 PM > Subject: Confused about dangerous content scanning setup > > Hello, > > I need to have the ability to exclude users from filetype checks and > content scanning. I'm not sure if that's the right terminology but what > I need is for certain people to have their email scanned for viruses and > spam but NOT filetype or password protected archives. > > Specifically, the owner periodically receives password protected zip > files and I want those files to get through without any problems. I've > managed to get MailScanner setup to archive those files (after they've > been stripped) but it's a pain to then manually get them to him. > > I thought that the following settings would do the trick but the files > are still being stripped: > > # Do you want to scan the messages for potentially dangerous content? > # Setting this to "no" will disable all the content-based checks except > # Virus Scanning, Allow Partial Messages and Allow External Message > Bodies. > # This can also be the filename of a ruleset. > Dangerous Content Scanning = %rules-dir%/scan.dangerous.rules > > scan.dangerous.rules: > > To:user@swatgear.comno > FromOrTo:defaultyes > > > I looked through my old emails (and tried searching Google) and it seems > that this is the correct setting... but still I have files being > stripped. > > Here are some pertinent log file entries: > > May 16 14:43:03 filter MailScanner[26763]: Password-protected archive > (launcher_promo.zip) in l4GLgoNV026771 > May 16 14:43:25 filter MailScanner[26763]: Saved entire message to > /var/spool/MailScanner/quarantine/20070516/l4GLgoNV026771 > May 16 14:43:25 filter MailScanner[26763]: Saved infected > "launcher_promo.zip" to > /var/spool/MailScanner/quarantine/20070516/l4GLgoNV026771 > > > What am I missing? > > > Thanks, > Chris. > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! -- --- Alex Neuman van der Hans, N&K Technology Consultants From hvdkooij at vanderkooij.org Thu May 17 11:00:55 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Thu May 17 11:01:59 2007 Subject: Confused about dangerous content scanning setup In-Reply-To: <503426.31881.qm@web26312.mail.ukl.yahoo.com> References: <503426.31881.qm@web26312.mail.ukl.yahoo.com> Message-ID: On Thu, 17 May 2007, Andrew MacLachlan wrote: > In MailScanner.conf: > > # Should archives which contain any password-protected files be allowed? > # Leaving this set to "no" is a good way of protecting against all the > # protected zip files used by viruses at the moment. > # This can also be the filename of a ruleset. > Allow Password-Protected Archives = no > > I guess for your purposes you would want to create a rule for specific users: > > Allow Password-Protected Archives = %rules-dir%/zip.password > > zip.password: > To:user@swatgear.comno > FromOrTo:defaultyes I think you need to swap YES and NO here as we are talking about ALLOWING something. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From amaclach at yahoo.co.uk Thu May 17 11:38:51 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Thu May 17 11:38:52 2007 Subject: Confused about dangerous content scanning setup Message-ID: <192039.62098.qm@web26314.mail.ukl.yahoo.com> Many apologies - It was late and I was copy 'n' pasting from the hip... The main point was the "Allow Password-Protected Archives =" part of the message. -Andy ----- Original Message ---- From: Hugo van der Kooij To: MailScanner discussion Sent: Thursday, 17 May, 2007 11:00:55 AM Subject: Re: Confused about dangerous content scanning setup On Thu, 17 May 2007, Andrew MacLachlan wrote: > In MailScanner.conf: > > # Should archives which contain any password-protected files be allowed? > # Leaving this set to "no" is a good way of protecting against all the > # protected zip files used by viruses at the moment. > # This can also be the filename of a ruleset. > Allow Password-Protected Archives = no > > I guess for your purposes you would want to create a rule for specific users: > > Allow Password-Protected Archives = %rules-dir%/zip.password > > zip.password: > To:user@swatgear.comno > FromOrTo:defaultyes I think you need to swap YES and NO here as we are talking about ALLOWING something. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From mogens at fumlersoft.dk Thu May 17 12:05:39 2007 From: mogens at fumlersoft.dk (Mogens Melander) Date: Thu May 17 12:05:38 2007 Subject: Confused about dangerous content scanning setup In-Reply-To: <97FD54B5E57A1842AA1A4B232E47611773E3B8@ati-ex-02.ati.local> References: <97FD54B5E57A1842AA1A4B232E47611773E3B8@ati-ex-02.ati.local> Message-ID: <3193.90.184.17.152.1179399939.squirrel@mail.fumlersoft.dk> Maybe you are looking for : # Should archives which contain any password-protected files be allowed? # Leaving this set to "no" is a good way of protecting against all the # protected zip files used by viruses at the moment. # This can also be the filename of a ruleset. Allow Password-Protected Archives = no On Wed, May 16, 2007 23:45, Chris W. Parker wrote: > Hello, > > I need to have the ability to exclude users from filetype checks and > content scanning. I'm not sure if that's the right terminology but what > I need is for certain people to have their email scanned for viruses and > spam but NOT filetype or password protected archives. > > Specifically, the owner periodically receives password protected zip > files and I want those files to get through without any problems. I've > managed to get MailScanner setup to archive those files (after they've > been stripped) but it's a pain to then manually get them to him. > > I thought that the following settings would do the trick but the files > are still being stripped: > > # Do you want to scan the messages for potentially dangerous content? > # Setting this to "no" will disable all the content-based checks except > # Virus Scanning, Allow Partial Messages and Allow External Message > Bodies. > # This can also be the filename of a ruleset. > Dangerous Content Scanning = %rules-dir%/scan.dangerous.rules > > scan.dangerous.rules: > > To:user@swatgear.comno > FromOrTo:defaultyes > > > I looked through my old emails (and tried searching Google) and it seems > that this is the correct setting... but still I have files being > stripped. > > Here are some pertinent log file entries: > > May 16 14:43:03 filter MailScanner[26763]: Password-protected archive > (launcher_promo.zip) in l4GLgoNV026771 > May 16 14:43:25 filter MailScanner[26763]: Saved entire message to > /var/spool/MailScanner/quarantine/20070516/l4GLgoNV026771 > May 16 14:43:25 filter MailScanner[26763]: Saved infected > "launcher_promo.zip" to > /var/spool/MailScanner/quarantine/20070516/l4GLgoNV026771 > > > What am I missing? > > > Thanks, > Chris. > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by OpenProtect(http://www.openprotect.com), and is > believed to be clean. > > -- Later Mogens Melander +45 40 85 71 38 +66 870 133 224 -- This message has been scanned for viruses and dangerous content by OpenProtect(http://www.openprotect.com), and is believed to be clean. From support-lists at petdoctors.co.uk Thu May 17 14:19:03 2007 From: support-lists at petdoctors.co.uk (Nigel Kendrick) Date: Thu May 17 14:19:47 2007 Subject: "MailScanner: Could not analyze message" Message-ID: <01a601c79885$f1c3ecd0$0202fea9@support01> Hi Folks, I'm still having emails come in from one company that generate "MailScanner: Could not analyze message" and so the messages are quarantined and the sender notified. Previous feedback suggests that the messages are malformed, which is likely as they are autogenerated by a 'proof of delivery' application. Not being a mail format guru - can I post a sample message here or somewhere else for examination? Thanks Nigel Kendrick From martinh at solidstatelogic.com Thu May 17 14:26:46 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Thu May 17 14:27:00 2007 Subject: "MailScanner: Could not analyze message" In-Reply-To: <01a601c79885$f1c3ecd0$0202fea9@support01> Message-ID: <1da4f04f25f4534ea1fe673917a60a45@solidstatelogic.com> Nigel pastebin.ca is a good place for temporary files to live,... -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Nigel Kendrick > Sent: 17 May 2007 14:19 > To: MailScanner discussion > Subject: "MailScanner: Could not analyze message" > > Hi Folks, > > I'm still having emails come in from one company that generate > "MailScanner: > Could not analyze message" and so the messages are quarantined and the > sender notified. Previous feedback suggests that the messages are > malformed, > which is likely as they are autogenerated by a 'proof of delivery' > application. > > Not being a mail format guru - can I post a sample message here or > somewhere > else for examination? > > Thanks > > Nigel Kendrick > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From MailScanner at ecs.soton.ac.uk Thu May 17 14:24:44 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 17 14:27:52 2007 Subject: Detecting forwarded spam In-Reply-To: <869500.23831.qm@web26307.mail.ukl.yahoo.com> References: <869500.23831.qm@web26307.mail.ukl.yahoo.com> Message-ID: <464C579C.2090103@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Andrew MacLachlan wrote: > Far more useful to me would be something that detects backscatter... > That one's easy. Milter-null will do the trick. Works great. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGTFgsEfZZRxQVtlQRAhMiAJ0deQ2ltbNmvfunUXSzivjsuDvz6wCfbfHW /nL9femz4JLi/BhSivl7jAk= =GxCS -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From amoore at dekalbmemorial.com Thu May 17 14:29:39 2007 From: amoore at dekalbmemorial.com (Aaron K. Moore) Date: Thu May 17 14:29:42 2007 Subject: Bayes disk space usage fast increase In-Reply-To: References: Message-ID: <60D398EB2DB948409CA1F50D8AF1225702466806@exch1.dekalbmemorial.local> Gareth wrote: > I would let mailscanner do it and that way it will wait until the > rebuild is finished. If you let spamassassin do it then you will need > to increase the timeout to a sufficiently long time which could cause > you problems in the future if a ruleset starts taking too long to run > and slows down your processing. I found that configuring SpamAssassin to store the bayes database in SQL increased system performance on our system. I have disabled the expiration run in MailScanner, and have wrote a script that I run from cron that shuts down MailScanner, runs the expiration, dumps the bayes database, and then restarts MailScanner. I also keep the auto-whitelist in a SQL database and have wrote a few custom scripts to purge unused entries. If anyone is interested, I could probably write up some documentation and upload them somewhere. -- Aaron Kent Moore Information Technology Services DeKalb Memorial Hospital, Inc. Auburn, Indiana Phone: 260.920.2808 E-Mail: amoore@dekalbmemorial.com From martinh at solidstatelogic.com Thu May 17 14:35:47 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Thu May 17 14:35:58 2007 Subject: Detecting forwarded spam In-Reply-To: <464C579C.2090103@ecs.soton.ac.uk> Message-ID: <8a3933d8f1f1d34697d8884e7469a2f9@solidstatelogic.com> Jules For those running sendmail may well work well... ;-) http://www.timj.co.uk/linux/bogus-virus-warnings.cf helps stop virus notification backscatter - remember to zero score the mailscanner ones.. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Julian Field > Sent: 17 May 2007 14:25 > To: MailScanner discussion > Subject: Re: Detecting forwarded spam > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Andrew MacLachlan wrote: > > Far more useful to me would be something that detects backscatter... > > > That one's easy. Milter-null will do the trick. Works great. > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: ISO-8859-1 > > wj8DBQFGTFgsEfZZRxQVtlQRAhMiAJ0deQ2ltbNmvfunUXSzivjsuDvz6wCfbfHW > /nL9femz4JLi/BhSivl7jAk= > =GxCS > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From support-lists at petdoctors.co.uk Thu May 17 16:35:05 2007 From: support-lists at petdoctors.co.uk (Nigel Kendrick) Date: Thu May 17 16:47:22 2007 Subject: "MailScanner: Could not analyze message" In-Reply-To: <1da4f04f25f4534ea1fe673917a60a45@solidstatelogic.com> Message-ID: <01c901c79898$f12408b0$0202fea9@support01> -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Martin.Hepworth Sent: Thursday, May 17, 2007 2:27 PM To: MailScanner discussion Subject: RE: "MailScanner: Could not analyze message" Nigel pastebin.ca is a good place for temporary files to live,... Thanks Martin, The archived message file displays fine with postcat and the 'message' in quarantine looks OK, so I guess I need to look at the file 'in the raw' (which I am not sure will post at pastebin?). I have decided to take the bull by the horns and learn about message formatting by comparing the offending message to a 'normal one' - either that or find a parser that will check out the archived copy. Any recommendations on mail format specs or a message parser other than postcat? Incidentally, thanks for pointing out pastebin - looks a handy place to know. Nigel From ssilva at sgvwater.com Thu May 17 16:13:37 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 17 16:56:34 2007 Subject: Bayes disk space usage fast increase In-Reply-To: <60D398EB2DB948409CA1F50D8AF1225702466806@exch1.dekalbmemorial.local> References: <60D398EB2DB948409CA1F50D8AF1225702466806@exch1.dekalbmemorial.local> Message-ID: Aaron K. Moore spake the following on 5/17/2007 6:29 AM: > Gareth wrote: >> I would let mailscanner do it and that way it will wait until the >> rebuild is finished. If you let spamassassin do it then you will need >> to increase the timeout to a sufficiently long time which could cause >> you problems in the future if a ruleset starts taking too long to run >> and slows down your processing. > > I found that configuring SpamAssassin to store the bayes database in SQL > increased system performance on our system. I have disabled the > expiration run in MailScanner, and have wrote a script that I run from > cron that shuts down MailScanner, runs the expiration, dumps the bayes > database, and then restarts MailScanner. > > I also keep the auto-whitelist in a SQL database and have wrote a few > custom scripts to purge unused entries. > > If anyone is interested, I could probably write up some documentation > and upload them somewhere. > Sounds like good wiki fodder ;-) -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From cparker at swatgear.com Thu May 17 17:01:47 2007 From: cparker at swatgear.com (Chris W. Parker) Date: Thu May 17 17:01:50 2007 Subject: Confused about dangerous content scanning setup References: <503426.31881.qm@web26312.mail.ukl.yahoo.com> Message-ID: <97FD54B5E57A1842AA1A4B232E47611773E3BE@ati-ex-02.ati.local> Thanks everyone. It's working now. Apparently I was looking for the wrong option. :) -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Andrew MacLachlan Sent: Wednesday, May 16, 2007 5:00 PM To: MailScanner discussion Subject: Re: Confused about dangerous content scanning setup In MailScanner.conf: # Should archives which contain any password-protected files be allowed? # Leaving this set to "no" is a good way of protecting against all the # protected zip files used by viruses at the moment. # This can also be the filename of a ruleset. Allow Password-Protected Archives = no I guess for your purposes you would want to create a rule for specific users: Allow Password-Protected Archives = %rules-dir%/zip.password zip.password: To:user@swatgear.comno FromOrTo:defaultyes -Andy From MailScanner at ecs.soton.ac.uk Thu May 17 17:22:38 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 17 17:23:15 2007 Subject: Confused about dangerous content scanning setup In-Reply-To: <97FD54B5E57A1842AA1A4B232E47611773E3BE@ati-ex-02.ati.local> References: <503426.31881.qm@web26312.mail.ukl.yahoo.com> <97FD54B5E57A1842AA1A4B232E47611773E3BE@ati-ex-02.ati.local> Message-ID: <464C814E.9000207@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 The only time you must use tabs in configuration files is in filename.rules.conf and filetype.rules.conf files. That's because it must allow regular expressions with spaces in. All other configuration files in MailScanner will work with arbitrary amounts of tabs and/or spaces. Chris W. Parker wrote: > Thanks everyone. It's working now. > > Apparently I was looking for the wrong option. :) > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Andrew > MacLachlan > Sent: Wednesday, May 16, 2007 5:00 PM > To: MailScanner discussion > Subject: Re: Confused about dangerous content scanning setup > > In MailScanner.conf: > > # Should archives which contain any password-protected files be allowed? > # Leaving this set to "no" is a good way of protecting against all the > # protected zip files used by viruses at the moment. > # This can also be the filename of a ruleset. > Allow Password-Protected Archives = no > > I guess for your purposes you would want to create a rule for specific > users: > > Allow Password-Protected Archives = %rules-dir%/zip.password > > zip.password: > To:user@swatgear.comno > FromOrTo:defaultyes > > -Andy > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGTIFSEfZZRxQVtlQRApI/AJ9dmjbqTC02E+06f5N6jCavAVLKJwCgypo4 1Tdb3jU0g1/icK2s45lRTU8= =aeZQ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From mogens at fumlersoft.dk Thu May 17 17:30:56 2007 From: mogens at fumlersoft.dk (Mogens Melander) Date: Thu May 17 17:31:02 2007 Subject: Bayes disk space usage fast increase In-Reply-To: <60D398EB2DB948409CA1F50D8AF1225702466806@exch1.dekalbmemorial.local> References: <60D398EB2DB948409CA1F50D8AF1225702466806@exch1.dekalbmemorial.local> Message-ID: <3647.90.184.17.152.1179419456.squirrel@mail.fumlersoft.dk> On Thu, May 17, 2007 15:29, Aaron K. Moore wrote: > Gareth wrote: >> I would let mailscanner do it and that way it will wait until the >> rebuild is finished. If you let spamassassin do it then you will need >> to increase the timeout to a sufficiently long time which could cause >> you problems in the future if a ruleset starts taking too long to run >> and slows down your processing. > > I found that configuring SpamAssassin to store the bayes database in SQL > increased system performance on our system. I have disabled the > expiration run in MailScanner, and have wrote a script that I run from > cron that shuts down MailScanner, runs the expiration, dumps the bayes > database, and then restarts MailScanner. > > I also keep the auto-whitelist in a SQL database and have wrote a few > custom scripts to purge unused entries. > > If anyone is interested, I could probably write up some documentation > and upload them somewhere. > It's always interresting to see alternative configurations. -- Later Mogens Melander +45 40 85 71 38 +66 870 133 224 -- This message has been scanned for viruses and dangerous content by OpenProtect(http://www.openprotect.com), and is believed to be clean. From kendal at cachets.com Thu May 17 20:23:48 2007 From: kendal at cachets.com (KENDAL BEVIL) Date: Thu May 17 20:24:53 2007 Subject: LOOKING FOR ROSBACK PERFORATOR Message-ID: <002c01c798b8$e859eb80$15e85944@office> I am looking to purchase and old Rosback pedal-driven perforator. My email is kendal@cachets.com or you can call me at 800-274-9339. Thanks, Kendal Bevil -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070517/a01a3e4b/attachment.html From alex at nkpanama.com Thu May 17 20:30:44 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Thu May 17 20:31:27 2007 Subject: LOOKING FOR ROSBACK PERFORATOR In-Reply-To: <002c01c798b8$e859eb80$15e85944@office> References: <002c01c798b8$e859eb80$15e85944@office> Message-ID: <464CAD64.1060801@nkpanama.com> KENDAL BEVIL wrote: > I am looking to purchase and old Rosback pedal-driven perforator. > My email is kendal@cachets.com or you can > call me at 800-274-9339. > > Thanks, > Kendal Bevil You should try the postfix list, they're usually eager to "tear you a new one" every time you mention MailScanner. Somebody there might have a "pedal-driven perforator" for such a purpose... :-) From dominian at slackadelic.com Thu May 17 20:31:57 2007 From: dominian at slackadelic.com (Matt Hayes) Date: Thu May 17 20:32:05 2007 Subject: LOOKING FOR ROSBACK PERFORATOR In-Reply-To: <002c01c798b8$e859eb80$15e85944@office> References: <002c01c798b8$e859eb80$15e85944@office> Message-ID: <464CADAD.1060608@slackadelic.com> KENDAL BEVIL wrote: > I am looking to purchase and old Rosback pedal-driven perforator. > My email is kendal@cachets.com or you can > call me at 800-274-9339. > > Thanks, > Kendal Bevil > And I'm looking to purchase a 1977 Light Saber in true working condition.... From drew at technologytiger.net Thu May 17 20:40:35 2007 From: drew at technologytiger.net (Drew Marshall) Date: Thu May 17 20:40:50 2007 Subject: LOOKING FOR ROSBACK PERFORATOR In-Reply-To: <464CAD64.1060801@nkpanama.com> References: <002c01c798b8$e859eb80$15e85944@office> <464CAD64.1060801@nkpanama.com> Message-ID: On 17 May 2007, at 20:30, Alex Neuman van der Hans wrote: > KENDAL BEVIL wrote: >> I am looking to purchase and old Rosback pedal-driven perforator. >> My email is kendal@cachets.com or you >> can call me at 800-274-9339. >> Thanks, >> Kendal Bevil > You should try the postfix list, they're usually eager to "tear you > a new one" every time you mention MailScanner. Somebody there might > have a "pedal-driven perforator" for such a purpose... :-) LOL No, no stop it! I nearly spat my coffee across my keyboard.... :-D Seriously though, Alex is right. Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by the Technology Tiger MailScanner. Further information can be found at www.technologytiger.net/policy Technology Tiger Limited is registered in Scotland with registration number: 310997 Registered Office 55-57 West High Street Inverurie AB51 3QQ From drew at technologytiger.net Thu May 17 20:42:15 2007 From: drew at technologytiger.net (Drew Marshall) Date: Thu May 17 20:42:29 2007 Subject: LOOKING FOR ROSBACK PERFORATOR In-Reply-To: <464CADAD.1060608@slackadelic.com> References: <002c01c798b8$e859eb80$15e85944@office> <464CADAD.1060608@slackadelic.com> Message-ID: <7F851FAA-736E-4750-8391-8595742BECAD@technologytiger.net> On 17 May 2007, at 20:31, Matt Hayes wrote: > KENDAL BEVIL wrote: >> I am looking to purchase and old Rosback pedal-driven perforator. >> My email is kendal@cachets.com or you >> can call me at 800-274-9339. >> Thanks, >> Kendal Bevil > > > And I'm looking to purchase a 1977 Light Saber in true working > condition.... Any one in the UK old enough to remember Multi-Coloured Swap Shop? -- In line with our policy, this message has been scanned for viruses and dangerous content by the Technology Tiger MailScanner. Further information can be found at www.technologytiger.net/policy Technology Tiger Limited is registered in Scotland with registration number: 310997 Registered Office 55-57 West High Street Inverurie AB51 3QQ From ssilva at sgvwater.com Thu May 17 20:58:03 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 17 20:58:23 2007 Subject: LOOKING FOR ROSBACK PERFORATOR In-Reply-To: <464CADAD.1060608@slackadelic.com> References: <002c01c798b8$e859eb80$15e85944@office> <464CADAD.1060608@slackadelic.com> Message-ID: Matt Hayes spake the following on 5/17/2007 12:31 PM: > KENDAL BEVIL wrote: >> I am looking to purchase and old Rosback pedal-driven perforator. >> My email is kendal@cachets.com or you can >> call me at 800-274-9339. >> >> Thanks, >> Kendal Bevil >> > > > And I'm looking to purchase a 1977 Light Saber in true working > condition.... > > I'll jump in my TARDIS and go look for one! -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Thu May 17 20:54:55 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 17 21:00:19 2007 Subject: LOOKING FOR ROSBACK PERFORATOR In-Reply-To: References: <002c01c798b8$e859eb80$15e85944@office> <464CAD64.1060801@nkpanama.com> Message-ID: Drew Marshall spake the following on 5/17/2007 12:40 PM: > On 17 May 2007, at 20:30, Alex Neuman van der Hans wrote: > >> KENDAL BEVIL wrote: >>> I am looking to purchase and old Rosback pedal-driven perforator. >>> My email is kendal@cachets.com or you can >>> call me at 800-274-9339. >>> Thanks, >>> Kendal Bevil >> You should try the postfix list, they're usually eager to "tear you a >> new one" every time you mention MailScanner. Somebody there might have >> a "pedal-driven perforator" for such a purpose... :-) > > LOL > No, no stop it! I nearly spat my coffee across my keyboard.... :-D > > Seriously though, Alex is right. > > Drew > Is that something like the Gilligan's Island version? Pedal driven because they couldn't get enough amps from the coconut shell batteries. ;-P -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From lists at kush-t.co.uk Thu May 17 21:03:37 2007 From: lists at kush-t.co.uk (lists) Date: Thu May 17 21:05:07 2007 Subject: LOOKING FOR ROSBACK PERFORATOR In-Reply-To: <7F851FAA-736E-4750-8391-8595742BECAD@technologytiger.net> References: <002c01c798b8$e859eb80$15e85944@office> <464CADAD.1060608@slackadelic.com> <7F851FAA-736E-4750-8391-8595742BECAD@technologytiger.net> Message-ID: <464CB519.3010201@kush-t.co.uk> Drew Marshall wrote: > > Any one in the UK old enough to remember Multi-Coloured Swap Shop? Yes, I'll swap my little brother for a train set. ;-) Pete -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From drew at technologytiger.net Thu May 17 21:08:13 2007 From: drew at technologytiger.net (Drew Marshall) Date: Thu May 17 21:08:16 2007 Subject: LOOKING FOR ROSBACK PERFORATOR In-Reply-To: <464CB519.3010201@kush-t.co.uk> References: <002c01c798b8$e859eb80$15e85944@office> <464CADAD.1060608@slackadelic.com> <7F851FAA-736E-4750-8391-8595742BECAD@technologytiger.net> <464CB519.3010201@kush-t.co.uk> Message-ID: On 17 May 2007, at 21:03, lists wrote: > Drew Marshall wrote: > >> >> Any one in the UK old enough to remember Multi-Coloured Swap Shop? > Yes, I'll swap my little brother for a train set. ;-) And my pedal powered Rosback Perforator for a 1977 light sabre in Darth Vader red :-) -- In line with our policy, this message has been scanned for viruses and dangerous content by the Technology Tiger MailScanner. Further information can be found at www.technologytiger.net/policy Technology Tiger Limited is registered in Scotland with registration number: 310997 Registered Office 55-57 West High Street Inverurie AB51 3QQ From talora-listas at talora.com.br Thu May 17 21:21:06 2007 From: talora-listas at talora.com.br (Luis Fernando C. Talora) Date: Thu May 17 21:21:40 2007 Subject: VIP user/filename filtering problems Message-ID: <464CB932.5090501@talora.com.br> Fellows, I use MailScanner to filter both incoming and outgoing messages. Is there any way to tell MailScanner that, for messages sent from a specific sender (myboss@iesa.com.br, for example), no rules will be applied? I block some file types and would like my boss still to be able to send those file types... Is it possible? Another problem: I blocked most of extensions used by video files and, a few day ago, I realized that some files still get to users? mailboxes, even with the blocking rules enabled. That happens just if one of my two MailScanner servers, witch runs Fedora 6, postfix-2.3.3-2 and mailscanner-4.56.8-1. The other server, running Fedora 4, postfix-2.2.2-2 and mailscanner-4.47.4-2 does not seem to have those problems. Any tips are welcome! Thanks a lot! Regards, Luis Talora From root at doctor.nl2k.ab.ca Thu May 17 21:26:16 2007 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Thu May 17 21:32:58 2007 Subject: LOOKING FOR ROSBACK PERFORATOR In-Reply-To: References: <002c01c798b8$e859eb80$15e85944@office> <464CAD64.1060801@nkpanama.com> Message-ID: <20070517202616.GB11145@doctor.nl2k.ab.ca> On Thu, May 17, 2007 at 12:54:55PM -0700, Scott Silva wrote: > Drew Marshall spake the following on 5/17/2007 12:40 PM: > > On 17 May 2007, at 20:30, Alex Neuman van der Hans wrote: > > > >> KENDAL BEVIL wrote: > >>> I am looking to purchase and old Rosback pedal-driven perforator. > >>> My email is kendal@cachets.com or you can > >>> call me at 800-274-9339. > >>> Thanks, > >>> Kendal Bevil > >> You should try the postfix list, they're usually eager to "tear you a > >> new one" every time you mention MailScanner. Somebody there might have > >> a "pedal-driven perforator" for such a purpose... :-) > > > > LOL > > No, no stop it! I nearly spat my coffee across my keyboard.... :-D > > > > Seriously though, Alex is right. > > > > Drew > > > Is that something like the Gilligan's Island version? > Pedal driven because they couldn't get enough amps from the coconut shell > batteries. ;-P > Of course we can trace back the original sender and blackhole his mail server. > > > -- > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From root at doctor.nl2k.ab.ca Thu May 17 21:27:16 2007 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Thu May 17 21:33:51 2007 Subject: LOOKING FOR ROSBACK PERFORATOR In-Reply-To: References: <002c01c798b8$e859eb80$15e85944@office> <464CADAD.1060608@slackadelic.com> Message-ID: <20070517202715.GC11145@doctor.nl2k.ab.ca> On Thu, May 17, 2007 at 12:58:03PM -0700, Scott Silva wrote: > Matt Hayes spake the following on 5/17/2007 12:31 PM: > > KENDAL BEVIL wrote: > >> I am looking to purchase and old Rosback pedal-driven perforator. > >> My email is kendal@cachets.com or you can > >> call me at 800-274-9339. > >> > >> Thanks, > >> Kendal Bevil > >> > > > > > > And I'm looking to purchase a 1977 Light Saber in true working > > condition.... > > > > > > I'll jump in my TARDIS and go look for one! > You can't. The TARDIS only exists for the Doctor post-Time war. > > -- > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Thu May 17 21:35:42 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 17 21:36:24 2007 Subject: VIP user/filename filtering problems In-Reply-To: <464CB932.5090501@talora.com.br> References: <464CB932.5090501@talora.com.br> Message-ID: <464CBC9E.4090609@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Read up about rulesets. They are documented everywhere (the Wiki, the MAQ, the Book). Luis Fernando C. Talora wrote: > Fellows, > > I use MailScanner to filter both incoming and outgoing messages. Is > there any way to tell MailScanner that, for messages sent from a > specific sender (myboss@iesa.com.br, for example), no rules will be > applied? I block some file types and would like my boss still to be > able to send those file types... Is it possible? > > Another problem: I blocked most of extensions used by video files and, > a few day ago, I realized that some files still get to users? > mailboxes, even with the blocking rules enabled. That happens just if > one of my two MailScanner servers, witch runs Fedora 6, > postfix-2.3.3-2 and mailscanner-4.56.8-1. The other server, running > Fedora 4, postfix-2.2.2-2 and mailscanner-4.47.4-2 does not seem to > have those problems. > > Any tips are welcome! Thanks a lot! > > Regards, > > Luis Talora > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGTLymEfZZRxQVtlQRApRYAKCndrI9N5+jks2Ijr+iCV/CITWpNwCeNoSS 8YnU9A+WGg7TVUeYDpSuL8o= =kFM5 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Thu May 17 21:50:00 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 17 21:50:26 2007 Subject: LOOKING FOR ROSBACK PERFORATOR In-Reply-To: <20070517202715.GC11145@doctor.nl2k.ab.ca> References: <002c01c798b8$e859eb80$15e85944@office> <464CADAD.1060608@slackadelic.com> <20070517202715.GC11145@doctor.nl2k.ab.ca> Message-ID: Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem spake the following on 5/17/2007 1:27 PM: > On Thu, May 17, 2007 at 12:58:03PM -0700, Scott Silva wrote: >> Matt Hayes spake the following on 5/17/2007 12:31 PM: >>> KENDAL BEVIL wrote: >>>> I am looking to purchase and old Rosback pedal-driven perforator. >>>> My email is kendal@cachets.com or you can >>>> call me at 800-274-9339. >>>> >>>> Thanks, >>>> Kendal Bevil >>>> >>> >>> And I'm looking to purchase a 1977 Light Saber in true working >>> condition.... >>> >>> >> I'll jump in my TARDIS and go look for one! >> > > You can't. The TARDIS only exists for the Doctor post-Time war. > Maybe I am the Doctor! In my 11th regeneration.... ;-P -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From talora-listas at talora.com.br Thu May 17 22:18:21 2007 From: talora-listas at talora.com.br (Luis Fernando C. Talora) Date: Thu May 17 22:18:40 2007 Subject: VIP user/filename filtering problems In-Reply-To: <464CBC9E.4090609@ecs.soton.ac.uk> References: <464CB932.5090501@talora.com.br> <464CBC9E.4090609@ecs.soton.ac.uk> Message-ID: <464CC69D.4050908@talora.com.br> Julian, Thanks for your help. I tried reading the "EXAMPLES" file on rules dir, but none of them meet my needs. Do you knou any other source for rulesets I can use? Thanks again! Regards, Luis Talora Julian Field escreveu: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Read up about rulesets. They are documented everywhere (the Wiki, the > MAQ, the Book). > > Luis Fernando C. Talora wrote: > >> Fellows, >> >> I use MailScanner to filter both incoming and outgoing messages. Is >> there any way to tell MailScanner that, for messages sent from a >> specific sender (myboss@iesa.com.br, for example), no rules will be >> applied? I block some file types and would like my boss still to be >> able to send those file types... Is it possible? >> >> Another problem: I blocked most of extensions used by video files and, >> a few day ago, I realized that some files still get to users? >> mailboxes, even with the blocking rules enabled. That happens just if >> one of my two MailScanner servers, witch runs Fedora 6, >> postfix-2.3.3-2 and mailscanner-4.56.8-1. The other server, running >> Fedora 4, postfix-2.2.2-2 and mailscanner-4.47.4-2 does not seem to >> have those problems. >> >> Any tips are welcome! Thanks a lot! >> >> Regards, >> >> Luis Talora >> >> > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: ISO-8859-1 > > wj8DBQFGTLymEfZZRxQVtlQRApRYAKCndrI9N5+jks2Ijr+iCV/CITWpNwCeNoSS > 8YnU9A+WGg7TVUeYDpSuL8o= > =kFM5 > -----END PGP SIGNATURE----- > > From seamus at rheelweb.co.nz Fri May 18 03:23:37 2007 From: seamus at rheelweb.co.nz (Seamus Allan) Date: Fri May 18 03:22:28 2007 Subject: Connection Deffered In-Reply-To: <04D932B0071FE34FA63EBB1977B48D15022CEB37@woodenex.woodmaclaw.local> References: <04D932B0071FE34FA63EBB1977B48D15022CEB37@woodenex.woodmaclaw.local> Message-ID: <464D0E29.2050700@rheelweb.co.nz> I had a similar problem with my receiving mail server behind a MailScanner gateway. Turned out I just needed to turn up the number of connections per minute on the smtp on the mail server so that it didn't think the Mailscanner machine was flooding it. I don't know if this is the case with Exchange, but perhaps gives you something to look at? Cheers Seamus. Billy A. Pumphrey wrote: > I am hoping someone is willing to help me with this. I thought that I > had the problem fixed but maybe not. I believe that current incoming > email is coming through MailScanner and to the Exchange server. The > problem is that ther are about 650 emails that will not go through. I > get this: > > Command: > sendmail -v -bp -OQueueDirectory=//var/spool/mqueue > > Result (about 650 of these): > l4FL9c8I028182 998389 6606332+May 15 17:09 > (Deferred: Connection refused by [10.1.1.22]) > > > > I have sendmail, Cent OS 4.4. > > I have not changed anything before this started happening. I restarted > the Exchange server and that is allowing the new emails to come through > ( I think, I will see for sure if this reaches the list during the > problem phase). > > Please advise :) > Thank you > From MailScanner at ecs.soton.ac.uk Fri May 18 10:16:28 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri May 18 10:19:06 2007 Subject: VIP user/filename filtering problems In-Reply-To: <464CC69D.4050908@talora.com.br> References: <464CB932.5090501@talora.com.br> <464CBC9E.4090609@ecs.soton.ac.uk> <464CC69D.4050908@talora.com.br> Message-ID: <464D6EEC.6050302@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Have you read the wiki? Luis Fernando C. Talora wrote: > Julian, > > Thanks for your help. I tried reading the "EXAMPLES" file on rules > dir, but none of them meet my needs. Do you knou any other source for > rulesets I can use? > > Thanks again! > > Regards, > > Luis Talora > > Julian Field escreveu: >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> Read up about rulesets. They are documented everywhere (the Wiki, the >> MAQ, the Book). >> >> Luis Fernando C. Talora wrote: >> >>> Fellows, >>> >>> I use MailScanner to filter both incoming and outgoing messages. Is >>> there any way to tell MailScanner that, for messages sent from a >>> specific sender (myboss@iesa.com.br, for example), no rules will be >>> applied? I block some file types and would like my boss still to be >>> able to send those file types... Is it possible? >>> >>> Another problem: I blocked most of extensions used by video files >>> and, a few day ago, I realized that some files still get to users? >>> mailboxes, even with the blocking rules enabled. That happens just >>> if one of my two MailScanner servers, witch runs Fedora 6, >>> postfix-2.3.3-2 and mailscanner-4.56.8-1. The other server, running >>> Fedora 4, postfix-2.2.2-2 and mailscanner-4.47.4-2 does not seem to >>> have those problems. >>> >>> Any tips are welcome! Thanks a lot! >>> >>> Regards, >>> >>> Luis Talora >>> >>> >> >> Jules >> >> - -- Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> MailScanner customisation, or any advanced system administration help? >> Contact me at Jules@Jules.FM >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> For all your IT requirements visit www.transtec.co.uk >> >> >> >> >> -----BEGIN PGP SIGNATURE----- >> Version: PGP Desktop 9.6.1 (Build 1012) >> Charset: ISO-8859-1 >> >> wj8DBQFGTLymEfZZRxQVtlQRApRYAKCndrI9N5+jks2Ijr+iCV/CITWpNwCeNoSS >> 8YnU9A+WGg7TVUeYDpSuL8o= >> =kFM5 >> -----END PGP SIGNATURE----- >> >> > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGTW9eEfZZRxQVtlQRAv6yAKCrbepzTdYBC6zLX0U+/KdlzUKebgCcCqt6 0DwZpr6rRXb/hXpha6rwGzw= =5NLo -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From alex at nkpanama.com Fri May 18 14:49:15 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Fri May 18 14:50:28 2007 Subject: OT from the beginning... :-) Re: LOOKING FOR ROSBACK PERFORATOR In-Reply-To: References: <002c01c798b8$e859eb80$15e85944@office> <464CADAD.1060608@slackadelic.com> <20070517202715.GC11145@doctor.nl2k.ab.ca> Message-ID: <464DAEDB.9030205@nkpanama.com> Scott Silva wrote: > Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem > spake the following on 5/17/2007 1:27 PM: > >> On Thu, May 17, 2007 at 12:58:03PM -0700, Scott Silva wrote: >> >>> Matt Hayes spake the following on 5/17/2007 12:31 PM: >>> >>>> KENDAL BEVIL wrote: >>>> >>>>> I am looking to purchase and old Rosback pedal-driven perforator. >>>>> My email is kendal@cachets.com or you can >>>>> call me at 800-274-9339. >>>>> >>>>> Thanks, >>>>> Kendal Bevil >>>>> >>>>> >>>> And I'm looking to purchase a 1977 Light Saber in true working >>>> condition.... >>>> >>>> >>>> >>> I'll jump in my TARDIS and go look for one! >>> >>> >> You can't. The TARDIS only exists for the Doctor post-Time war. >> >> > Maybe I am the Doctor! > In my 11th regeneration.... ;-P > > > Sorry to take it so far off topic, but didn't the face of Boe say he wasn't "alone" (a little bit too much Yoda in TESB for my taste, but who cares...)? Just as some Daleks survived, maybe more Gallifreyans survived... And they may have working TARDISes... :-) From root at doctor.nl2k.ab.ca Fri May 18 16:06:32 2007 From: root at doctor.nl2k.ab.ca (Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem) Date: Fri May 18 16:14:06 2007 Subject: {Spam?} OT from the beginning... :-) Re: LOOKING FOR ROSBACK PERFORATOR In-Reply-To: <464DAEDB.9030205@nkpanama.com> References: <002c01c798b8$e859eb80$15e85944@office> <464CADAD.1060608@slackadelic.com> <20070517202715.GC11145@doctor.nl2k.ab.ca> <464DAEDB.9030205@nkpanama.com> Message-ID: <20070518150632.GA17655@doctor.nl2k.ab.ca> On Fri, May 18, 2007 at 08:49:15AM -0500, Alex Neuman van der Hans wrote: > Scott Silva wrote: > >Dave Shariff Yadallee - System Administrator a.k.a. The Root of the Problem > >spake the following on 5/17/2007 1:27 PM: > > > >>On Thu, May 17, 2007 at 12:58:03PM -0700, Scott Silva wrote: > >> > >>>Matt Hayes spake the following on 5/17/2007 12:31 PM: > >>> > >>>>KENDAL BEVIL wrote: > >>>> > >>>>>I am looking to purchase and old Rosback pedal-driven perforator. > >>>>>My email is kendal@cachets.com or you can > >>>>>call me at 800-274-9339. > >>>>> > >>>>>Thanks, > >>>>>Kendal Bevil > >>>>> > >>>>> > >>>>And I'm looking to purchase a 1977 Light Saber in true working > >>>>condition.... > >>>> > >>>> > >>>> > >>>I'll jump in my TARDIS and go look for one! > >>> > >>> > >>You can't. The TARDIS only exists for the Doctor post-Time war. > >> > >> > >Maybe I am the Doctor! > >In my 11th regeneration.... ;-P > > > > > > > Sorry to take it so far off topic, but didn't the face of Boe say he > wasn't "alone" (a little bit too much Yoda in TESB for my taste, but who > cares...)? Just as some Daleks survived, maybe more Gallifreyans > survived... And they may have working TARDISes... :-) > Join us at rec.arts.drwho , rec.arts.drwho.moderated or uk.media.tv.sf.drwho for more fun. -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From campbell at cnpapers.com Fri May 18 18:33:39 2007 From: campbell at cnpapers.com (Steve Campbell) Date: Fri May 18 18:34:11 2007 Subject: Clam update log location Message-ID: <000a01c79972$abda2430$0705000a@ddf5dw71> I'm not sure if I have some old leftovers from an RPM install or maybe a source install or whatever, but I have a couple of logrotate files (clamd and freshclam). They apparently don't do anything now as the files they rotate don't exist . The freshclam script might be handy though. It points to a file in /var/log/ but the /usr/lib/MailScanner/clamav-autoupdate that I have makes a different file name in /tmp. The logrotate script also does a postrotate "/bin/kill -HUP `cat /var/run/clamav/freshclam.pid", which might or might not matter for the way it works now. Is there any point to making the logrotate work with the autoupdate in Mailscanner? The /tmp/ClamAV.update.log file can get pretty large. Thanks for ideas. Steve Campbell campbell@cnpapers.com Charleston Newspapers From dominian at slackadelic.com Fri May 18 18:43:08 2007 From: dominian at slackadelic.com (Matt Hayes) Date: Fri May 18 18:43:16 2007 Subject: Clam update log location In-Reply-To: <000a01c79972$abda2430$0705000a@ddf5dw71> References: <000a01c79972$abda2430$0705000a@ddf5dw71> Message-ID: <464DE5AC.4020203@slackadelic.com> Steve Campbell wrote: > I'm not sure if I have some old leftovers from an RPM install or maybe a > source install or whatever, but I have a couple of logrotate files > (clamd and freshclam). They apparently don't do anything now as the > files they rotate don't exist . The freshclam script might be handy > though. It points to a file in /var/log/ but the > /usr/lib/MailScanner/clamav-autoupdate that I have makes a different > file name in /tmp. > > The logrotate script also does a postrotate "/bin/kill -HUP `cat > /var/run/clamav/freshclam.pid", which might or might not matter for the > way it works now. Is there any point to making the logrotate work with > the autoupdate in Mailscanner? The /tmp/ClamAV.update.log file can get > pretty large. > > Thanks for ideas. > > Steve Campbell > campbell@cnpapers.com > Charleston Newspapers > Personally, I manually edit that log location to be in my /var/log/clamav folder and that way logrotate still rotates the proper log out without my intervention. -Matt From ugob at lubik.ca Fri May 18 20:16:56 2007 From: ugob at lubik.ca (Ugo Bellavance) Date: Fri May 18 20:17:16 2007 Subject: stopping clamav detecting encrypted zip files In-Reply-To: <223f97700704200221k12c7e487td5002a7069a87c4a@mail.gmail.com> References: <223f97700704191134wd46ac07nced313d673fb6be0@mail.gmail.com> <223f97700704200221k12c7e487td5002a7069a87c4a@mail.gmail.com> Message-ID: Glenn Steen wrote: > On 19/04/07, Gareth wrote: >> > -----Original Message----- >> > From: mailscanner-bounces@lists.mailscanner.info >> > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Glenn >> > Steen >> > Sent: 19 April 2007 19:35 >> > To: MailScanner discussion >> > Subject: Re: stopping clamav detecting encrypted zip files >> > >> > >> > On 19/04/07, Gareth wrote: >> > > > -----Original Message----- >> > > > From: mailscanner-bounces@lists.mailscanner.info >> > > > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of >> Glenn >> > > > Steen >> > > > Sent: 19 April 2007 14:33 >> > > > To: MailScanner discussion >> > > > Subject: Re: stopping clamav detecting encrypted zip files >> > > > >> > > > >> > > > On 05/04/07, Gareth wrote: >> > > > > On Thu, 2007-04-05 at 10:10, Dhawal Doshy wrote: >> > > > > > Gareth wrote: >> > > > > > > On Wed, 2007-04-04 at 17:04, Aaron K. Moore wrote: >> > > > > > > >> > > > > > >> Are you using the clamavmodule? I've had the same >> > > > problem. There's a >> > > > > > >> commandline switch to turn that notice if when using >> > > > clamscan, but not >> > > > > > >> with the module. I'd suggested earlier that someone >> > > > should add code for >> > > > > > >> clamav, like the code for Sophos that allows you to >> > > > specify messages to >> > > > > > >> ignore. >> > > > > > > >> > > > > > > I think its a bug in Mailscanner. There appears to be code >> > > > in place in >> > > > > > > the routine which calls clamavmodule which disables >> blocking of >> > > > > > > encrypted files if there is a config option 'allowpasszips' >> > > > set but I >> > > > > > > cannot find that option. >> > > > > > > >> > > > > > > Anyway below is a diff which disables blocking of >> > encrypted archives >> > > > > > > which is working fine for me. >> > > > > > > >> > > > > > > /usr/lib/MailScanner/MailScanner/SweepViruses.pm >> > > > > > > 1069c1069 >> > > > > > > < >> > > > Mail::ClamAV::CL_SCAN_BLOCKENCRYPTED() >> > > > > > > | >> > > > > > > --- >> > > > > > >> # >> > > > Mail::ClamAV::CL_SCAN_BLOCKENCRYPTED() >> > > > > > > | >> > > > > > >> > > > > > [Quoting Julian from 07/20/2005] >> > > > > > If you have MailScanner set to allow password-protected >> > zip and rar >> > > > > > archives, then this option is disabled. If you have it >> > set to block >> > > > > > password-protected archives, then this option is enabled. >> > > > > > [Quoting Julian from 07/20/2005] >> > > > > > >> > > > > > See this thread: >> > > > http://thread.gmane.org/gmane.mail.virus.mailscanner/30201 >> > > > > >> > > > > Thanks. I wanted Mailscanner to block encrypted archives >> > which it does >> > > > > well by itself but not to tell clamav to identify encrypted >> > archives as >> > > > > viruses. >> > > > > >> > > > It's Ruleset Time: >> > > > You want MailScanner to block the initial message, hence you want a >> > > > default of "yes" in the ruleset, but not when releasing from >> > > > quarantine... so ... since this will likely be released from >> > > > 127.0.0.1, make a rule that sets it to "no" (or indeed do this >> on Scan >> > > > Message) for that IP address. Problem solved:-). >> > > > >> > > > Cheers >> > > > -- >> > > > -- Glenn >> > > >> > > Please read my question again. The problem was mailwatch not >> > allowing the >> > > file to be released from quaranteen because it was identified >> > as a virus. >> > > Not the fact that a released message was being re-quaranteened >> > which your >> > > answer would refer to. >> > > >> > Ah... Sorry for the sloppy reading, been on vacation.... not turned on >> > brain, such as that is, yet:-). >> > What you are really "griping" about is the default behaviour of MW to >> > not let you release (some) harmful content (by not including the >> > necessary checkboxes:). I do beleive Aaron mentioned how to get around >> > it... And it shouldn't be hard at all to modify MW to accomodate your >> > idea about letting admin do that. Or simply release the file from a >> > commandline (I'm pretty confident you know your way around that enough >> > to manage;-). If your aim is users releasing this file themselves.... >> > this moght be slightly more problematic. >> > As I'm sure you realise, one "solution" is to allow encrypted >> > archives, bad as that may seem.... Or switch to clamscan, where that >> > is more readily settable. >> > >> > Cheers >> > -- >> > -- Glenn >> >> I did manage to get it working as I wanted it by editing the perl code >> which >> calls clamavmodule so that password protected archives were not >> classed as a >> virus. That leaves it down to mailscanner to detect itself which then >> as it >> is just classed as a blocked attackment and not a virus allows >> mailwatch to >> release it. >> >> I have the patch togeter with a few other customisations I have made >> detailed on my webpage :- >> http://www.gbnetwork.co.uk/mailscanner/index.html >> > Ah great. Perhaps when Jules is better he'll grace us with yet another > config option for this:-). Anything new on this subject? I also agree that we should have an option, or that clamav should never identify a passwd-zip as a virus. The MS setting is there and at least, one can release it if MS stops it. Ugo From uxbod at splatnix.net Fri May 18 20:27:48 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Fri May 18 20:25:15 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <464B2631.4060202@ecs.soton.ac.uk> References: <4649CA97.5050802@ecs.soton.ac.uk> <464B2631.4060202@ecs.soton.ac.uk> Message-ID: <20070518202748.4bfdbd9d@uxbod.splatnix.net> May be worth a .dot release Jules as it it a significant perl buglet. On Wed, 16 May 2007 16:41:37 +0100 Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > I'll put it in the main codebase then. Perl has some very subtle bugs > in it... > > > - --[ UxBoD ]-- wrote: > > Hi Jules, > > > > No FPs at all today :) > > > > Thanks, > > > > On Tue, 15 May 2007 15:58:31 +0100, Julian Field > > wrote: > >> -----BEGIN PGP SIGNED MESSAGE----- > >> Hash: SHA1 > >> > >> > >> > >> Leland J. Steinke wrote: > >> > >>> Julian Field wrote: > >>> > >>>> # JKF 3/10/2005 > >>>> my $temp = @HitList; > >>>> $temp = $temp + 0; > >>>> $temp = 0 unless $HitList[0] =~ /a-z/i; > >>>> return ($temp, join(', ', @HitList)); > >>>> } > >>>> > >>>> Let's see if that helps. According to the book, the 2 middle > >>>> lines shouldn't be needed at all. > >>>> > >>> Why not "my $temp = scalar(@HitList);"? > >>> > >> That should be the exact equivalent of "$temp = @HitList" as $temp > >> is a scalar anyway. > >> > >> Jules > >> > >> - -- > >> Julian Field MEng CITP > >> www.MailScanner.info > >> Buy the MailScanner book at www.MailScanner.info/store > >> > >> MailScanner customisation, or any advanced system administration > >> help? Contact me at Jules@Jules.FM > >> > >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > >> For all your IT requirements visit www.transtec.co.uk > >> > >> > >> > >> -----BEGIN PGP SIGNATURE----- > >> Version: PGP Desktop 9.6.1 (Build 1012) > >> Charset: UTF-8 > >> > >> wj8DBQFGScqmEfZZRxQVtlQRAk0fAKDkHKSy1XfSr7NmFl7exuiR5RJmGgCcC79L > >> BZI+vdG3BNijd2m6HIXK/zA= > >> =311a > >> -----END PGP SIGNATURE----- > >> > >> -- > >> This message has been scanned for viruses and > >> dangerous content by MailScanner, and is > >> believed to be clean. > >> For all your IT requirements visit www.transtec.co.uk > >> > >> -- > >> MailScanner mailing list > >> mailscanner@lists.mailscanner.info > >> http://lists.mailscanner.info/mailman/listinfo/mailscanner > >> > >> Before posting, read http://wiki.mailscanner.info/posting > >> > >> Support MailScanner development - buy the book off the website! > >> > >> -- > >> This message has been scanned for viruses and dangerous content by > >> MailScanner, and is > >> believed to be clean. > >> > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: UTF-8 > > wj8DBQFGSyY5EfZZRxQVtlQRAoQpAJwJUy+9rEEX5Ahgs9uBptUgXVQArwCfdyIk > /1e+HnmGwdVVcghNHmCl2jg= > =/CbN > -----END PGP SIGNATURE----- > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 845 869 2749 // SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Fri May 18 20:42:19 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri May 18 20:43:39 2007 Subject: stopping clamav detecting encrypted zip files In-Reply-To: References: <223f97700704191134wd46ac07nced313d673fb6be0@mail.gmail.com> <223f97700704200221k12c7e487td5002a7069a87c4a@mail.gmail.com> Message-ID: <464E019B.8030000@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Ugo Bellavance wrote: > Glenn Steen wrote: >> On 19/04/07, Gareth wrote: >>> > -----Original Message----- >>> > From: mailscanner-bounces@lists.mailscanner.info >>> > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf Of Glenn >>> > Steen >>> > Sent: 19 April 2007 19:35 >>> > To: MailScanner discussion >>> > Subject: Re: stopping clamav detecting encrypted zip files >>> > >>> > >>> > On 19/04/07, Gareth wrote: >>> > > > -----Original Message----- >>> > > > From: mailscanner-bounces@lists.mailscanner.info >>> > > > [mailto:mailscanner-bounces@lists.mailscanner.info]On Behalf >>> Of Glenn >>> > > > Steen >>> > > > Sent: 19 April 2007 14:33 >>> > > > To: MailScanner discussion >>> > > > Subject: Re: stopping clamav detecting encrypted zip files >>> > > > >>> > > > >>> > > > On 05/04/07, Gareth wrote: >>> > > > > On Thu, 2007-04-05 at 10:10, Dhawal Doshy wrote: >>> > > > > > Gareth wrote: >>> > > > > > > On Wed, 2007-04-04 at 17:04, Aaron K. Moore wrote: >>> > > > > > > >>> > > > > > >> Are you using the clamavmodule? I've had the same >>> > > > problem. There's a >>> > > > > > >> commandline switch to turn that notice if when using >>> > > > clamscan, but not >>> > > > > > >> with the module. I'd suggested earlier that someone >>> > > > should add code for >>> > > > > > >> clamav, like the code for Sophos that allows you to >>> > > > specify messages to >>> > > > > > >> ignore. >>> > > > > > > >>> > > > > > > I think its a bug in Mailscanner. There appears to be code >>> > > > in place in >>> > > > > > > the routine which calls clamavmodule which disables >>> blocking of >>> > > > > > > encrypted files if there is a config option 'allowpasszips' >>> > > > set but I >>> > > > > > > cannot find that option. >>> > > > > > > >>> > > > > > > Anyway below is a diff which disables blocking of >>> > encrypted archives >>> > > > > > > which is working fine for me. >>> > > > > > > >>> > > > > > > /usr/lib/MailScanner/MailScanner/SweepViruses.pm >>> > > > > > > 1069c1069 >>> > > > > > > < >>> > > > Mail::ClamAV::CL_SCAN_BLOCKENCRYPTED() >>> > > > > > > | >>> > > > > > > --- >>> > > > > > >> # >>> > > > Mail::ClamAV::CL_SCAN_BLOCKENCRYPTED() >>> > > > > > > | >>> > > > > > >>> > > > > > [Quoting Julian from 07/20/2005] >>> > > > > > If you have MailScanner set to allow password-protected >>> > zip and rar >>> > > > > > archives, then this option is disabled. If you have it >>> > set to block >>> > > > > > password-protected archives, then this option is enabled. >>> > > > > > [Quoting Julian from 07/20/2005] >>> > > > > > >>> > > > > > See this thread: >>> > > > http://thread.gmane.org/gmane.mail.virus.mailscanner/30201 >>> > > > > >>> > > > > Thanks. I wanted Mailscanner to block encrypted archives >>> > which it does >>> > > > > well by itself but not to tell clamav to identify encrypted >>> > archives as >>> > > > > viruses. >>> > > > > >>> > > > It's Ruleset Time: >>> > > > You want MailScanner to block the initial message, hence you >>> want a >>> > > > default of "yes" in the ruleset, but not when releasing from >>> > > > quarantine... so ... since this will likely be released from >>> > > > 127.0.0.1, make a rule that sets it to "no" (or indeed do this >>> on Scan >>> > > > Message) for that IP address. Problem solved:-). >>> > > > >>> > > > Cheers >>> > > > -- >>> > > > -- Glenn >>> > > >>> > > Please read my question again. The problem was mailwatch not >>> > allowing the >>> > > file to be released from quaranteen because it was identified >>> > as a virus. >>> > > Not the fact that a released message was being re-quaranteened >>> > which your >>> > > answer would refer to. >>> > > >>> > Ah... Sorry for the sloppy reading, been on vacation.... not >>> turned on >>> > brain, such as that is, yet:-). >>> > What you are really "griping" about is the default behaviour of MW to >>> > not let you release (some) harmful content (by not including the >>> > necessary checkboxes:). I do beleive Aaron mentioned how to get >>> around >>> > it... And it shouldn't be hard at all to modify MW to accomodate your >>> > idea about letting admin do that. Or simply release the file from a >>> > commandline (I'm pretty confident you know your way around that >>> enough >>> > to manage;-). If your aim is users releasing this file themselves.... >>> > this moght be slightly more problematic. >>> > As I'm sure you realise, one "solution" is to allow encrypted >>> > archives, bad as that may seem.... Or switch to clamscan, where that >>> > is more readily settable. >>> > >>> > Cheers >>> > -- >>> > -- Glenn >>> >>> I did manage to get it working as I wanted it by editing the perl >>> code which >>> calls clamavmodule so that password protected archives were not >>> classed as a >>> virus. That leaves it down to mailscanner to detect itself which >>> then as it >>> is just classed as a blocked attackment and not a virus allows >>> mailwatch to >>> release it. >>> >>> I have the patch togeter with a few other customisations I have made >>> detailed on my webpage :- >>> http://www.gbnetwork.co.uk/mailscanner/index.html >>> >> Ah great. Perhaps when Jules is better he'll grace us with yet another >> config option for this:-). > > Anything new on this subject? > > I also agree that we should have an option, or that clamav should > never identify a passwd-zip as a virus. The MS setting is there and > at least, one can release it if MS stops it. How about I just apply your patch and stop ClamAV blocking password-protected archives? MailScanner itself can only detect password-protected zips, tars and rars (from memory), whereas ClamAV might well be able to detect passworded archives of more formats. But the others are very rare anyway so it probably isn't a problem. But I thought I should let you know. Still want me to apply your patch? Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGTgG9EfZZRxQVtlQRAhSAAJ0VH6SWXyYaRxAzUWRJS8xHt+pXgwCeLSPm KC+gaZdqOifvwXNf7vxGdiY= =iezV -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Fri May 18 20:44:16 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri May 18 20:45:00 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <20070518202748.4bfdbd9d@uxbod.splatnix.net> References: <4649CA97.5050802@ecs.soton.ac.uk> <464B2631.4060202@ecs.soton.ac.uk> <20070518202748.4bfdbd9d@uxbod.splatnix.net> Message-ID: <464E0210.5050001@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Once Ugo (or anyone else) responds to my other posting just now, I'll do a first beta release and a new version on 1st June, if that's okay? - --[ UxBoD ]-- wrote: > May be worth a .dot release Jules as it it a significant perl buglet. > > On Wed, 16 May 2007 16:41:37 +0100 > Julian Field wrote: > > >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> I'll put it in the main codebase then. Perl has some very subtle bugs >> in it... >> >> >> - --[ UxBoD ]-- wrote: >> >>> Hi Jules, >>> >>> No FPs at all today :) >>> >>> Thanks, >>> >>> On Tue, 15 May 2007 15:58:31 +0100, Julian Field >>> wrote: >>> >>>> -----BEGIN PGP SIGNED MESSAGE----- >>>> Hash: SHA1 >>>> >>>> >>>> >>>> Leland J. Steinke wrote: >>>> >>>> >>>>> Julian Field wrote: >>>>> >>>>> >>>>>> # JKF 3/10/2005 >>>>>> my $temp = @HitList; >>>>>> $temp = $temp + 0; >>>>>> $temp = 0 unless $HitList[0] =~ /a-z/i; >>>>>> return ($temp, join(', ', @HitList)); >>>>>> } >>>>>> >>>>>> Let's see if that helps. According to the book, the 2 middle >>>>>> lines shouldn't be needed at all. >>>>>> >>>>>> >>>>> Why not "my $temp = scalar(@HitList);"? >>>>> >>>>> >>>> That should be the exact equivalent of "$temp = @HitList" as $temp >>>> is a scalar anyway. >>>> >>>> Jules >>>> >>>> - -- >>>> Julian Field MEng CITP >>>> www.MailScanner.info >>>> Buy the MailScanner book at www.MailScanner.info/store >>>> >>>> MailScanner customisation, or any advanced system administration >>>> help? Contact me at Jules@Jules.FM >>>> >>>> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >>>> For all your IT requirements visit www.transtec.co.uk >>>> >>>> >>>> >>>> -----BEGIN PGP SIGNATURE----- >>>> Version: PGP Desktop 9.6.1 (Build 1012) >>>> Charset: UTF-8 >>>> >>>> wj8DBQFGScqmEfZZRxQVtlQRAk0fAKDkHKSy1XfSr7NmFl7exuiR5RJmGgCcC79L >>>> BZI+vdG3BNijd2m6HIXK/zA= >>>> =311a >>>> -----END PGP SIGNATURE----- >>>> >>>> -- >>>> This message has been scanned for viruses and >>>> dangerous content by MailScanner, and is >>>> believed to be clean. >>>> For all your IT requirements visit www.transtec.co.uk >>>> >>>> -- >>>> MailScanner mailing list >>>> mailscanner@lists.mailscanner.info >>>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>>> >>>> Before posting, read http://wiki.mailscanner.info/posting >>>> >>>> Support MailScanner development - buy the book off the website! >>>> >>>> -- >>>> This message has been scanned for viruses and dangerous content by >>>> MailScanner, and is >>>> believed to be clean. >>>> >>>> >> Jules >> >> - -- >> Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> MailScanner customisation, or any advanced system administration help? >> Contact me at Jules@Jules.FM >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> For all your IT requirements visit www.transtec.co.uk >> >> >> >> -----BEGIN PGP SIGNATURE----- >> Version: PGP Desktop 9.6.1 (Build 1012) >> Charset: UTF-8 >> >> wj8DBQFGSyY5EfZZRxQVtlQRAoQpAJwJUy+9rEEX5Ahgs9uBptUgXVQArwCfdyIk >> /1e+HnmGwdVVcghNHmCl2jg= >> =/CbN >> -----END PGP SIGNATURE----- >> >> > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGTgIVEfZZRxQVtlQRAhnTAKDkfXx0ZFYpD71w46crGM5C4xHD2gCg4rpP it2YAs2o787yxbvzNajfCJQ= =lLWs -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ugob at lubik.ca Fri May 18 21:42:05 2007 From: ugob at lubik.ca (Ugo Bellavance) Date: Fri May 18 21:42:28 2007 Subject: stopping clamav detecting encrypted zip files In-Reply-To: <464E019B.8030000@ecs.soton.ac.uk> References: <223f97700704191134wd46ac07nced313d673fb6be0@mail.gmail.com> <223f97700704200221k12c7e487td5002a7069a87c4a@mail.gmail.com> <464E019B.8030000@ecs.soton.ac.uk> Message-ID: Julian Field wrote: >>>> I did manage to get it working as I wanted it by editing the perl >>>> code which >>>> calls clamavmodule so that password protected archives were not >>>> classed as a >>>> virus. That leaves it down to mailscanner to detect itself which >>>> then as it >>>> is just classed as a blocked attackment and not a virus allows >>>> mailwatch to >>>> release it. >>>> >>>> I have the patch togeter with a few other customisations I have made >>>> detailed on my webpage :- >>>> http://www.gbnetwork.co.uk/mailscanner/index.html >>>> >>> Ah great. Perhaps when Jules is better he'll grace us with yet another >>> config option for this:-). >> Anything new on this subject? >> >> I also agree that we should have an option, or that clamav should >> never identify a passwd-zip as a virus. The MS setting is there and >> at least, one can release it if MS stops it. > How about I just apply your patch and stop ClamAV blocking > password-protected archives? > > MailScanner itself can only detect password-protected zips, tars and > rars (from memory), whereas ClamAV might well be able to detect > passworded archives of more formats. But the others are very rare anyway > so it probably isn't a problem. But I thought I should let you know. > > Still want me to apply your patch? > > Jules I think that this would be the best thing. From hvdkooij at vanderkooij.org Fri May 18 21:48:17 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Fri May 18 21:48:50 2007 Subject: stopping clamav detecting encrypted zip files In-Reply-To: References: <223f97700704191134wd46ac07nced313d673fb6be0@mail.gmail.com> <223f97700704200221k12c7e487td5002a7069a87c4a@mail.gmail.com> Message-ID: On Fri, 18 May 2007, Ugo Bellavance wrote: > I also agree that we should have an option, or that clamav should never > identify a passwd-zip as a virus. The MS setting is there and at least, one > can release it if MS stops it. How about adjusting the scripts for the scanners to follow the preferences? So if the normal action would be to allow password protected zip files it should also trickle down as option to each AV ascanner called upon by MS. It's just a suggestion but perhaps others may think the idea makes sense. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From MailScanner at ecs.soton.ac.uk Fri May 18 22:08:18 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri May 18 22:11:25 2007 Subject: stopping clamav detecting encrypted zip files In-Reply-To: References: <223f97700704191134wd46ac07nced313d673fb6be0@mail.gmail.com> <223f97700704200221k12c7e487td5002a7069a87c4a@mail.gmail.com> Message-ID: <464E15C2.6020407@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hugo van der Kooij wrote: > On Fri, 18 May 2007, Ugo Bellavance wrote: > >> I also agree that we should have an option, or that clamav should >> never identify a passwd-zip as a virus. The MS setting is there and >> at least, one can release it if MS stops it. > > How about adjusting the scripts for the scanners to follow the > preferences? > > So if the normal action would be to allow password protected zip files > it should also trickle down as option to each AV ascanner called upon > by MS. That's what it does at the moment (without the proposed patch). The problem is that MailWatch doesn't like releasing a file that contains a virus. The clamavmodule scanner only has 2 options with password-protected archives: either ignore them completely or tag them as viruses. Hence the patch to make clamavmodule ignore them, and MailScanner finds them on its own when it unpacks all the message attachments. As they are tagged as passworded archives instead of viruses, MailWatch will let you have them. Jules. > > It's just a suggestion but perhaps others may think the idea makes sense. > > Hugo. > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGThY+EfZZRxQVtlQRAtiZAJ9+7GHSWigdlECwfup8kfDIeawaKACeLq+h l/Ubwcvgo27d7BhSMx0rqIA= =JzZ1 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From TGFurnish at herffjones.com Fri May 18 22:58:21 2007 From: TGFurnish at herffjones.com (Furnish, Trever G) Date: Fri May 18 22:58:26 2007 Subject: way OT: add header (mailscanner) to be parsed by Outlook plugin for reporting false-negatives? Message-ID: <57573D714A832C43B9D80EAFBDA48D03057BDBA8@inex3.herffjones.hj-int> Ok, sorry to go so far OT, but if you all can wax sentimental about perforators and the Tardis, I this this ought to be ok. :-) I even added a mailscanner function (adding a header to a processed message) to make it slightly more ON-topic. I already have a modified MailWatch in place that let's users see their quarantined mail and release messages one at a time, and I can easily have MailScanner add a header to "ham" containing information to be acted on by a user agent (Outlook). I'm wondering though, has anyone put together an add-on for Outlook to allow easy "Report this message as spam" functionality? I'd like my (Outlook) users to be able to report spam that I've missed without having to leave the client to do so. I'd imagine it working like so: For "ham", MS would add a header with uniquely identifiable info, such as the message ID. When the message is viewed in Outlook, the user would say, "Hey, this is missed spam!", and click a checkbox, which would in turn causethis (as yet non-existant?) Outlook plugin to do *something* (such as executing a program in another thread, quietly) which would connect to my mailscanner system and report the message as spam. I'm seriously considering writing such a plugin, but if anyone's already done so or has a better solution, I'd rather avoid the wasted effort. -- Trever Furnish, tgfurnish@herffjones.com Herff Jones, Inc. Unix / Network Administrator Phone: 317.612.3519 Any sufficiently advanced technology is indistinguishable from Unix. From arturs at netvision.net.il Fri May 18 23:20:41 2007 From: arturs at netvision.net.il (Arthur Sherman) Date: Fri May 18 23:23:40 2007 Subject: way OT: add header (mailscanner) to be parsed by Outlook plugin forreporting false-negatives? In-Reply-To: <57573D714A832C43B9D80EAFBDA48D03057BDBA8@inex3.herffjones.hj-int> Message-ID: <0JI900AYDCVC4SA0@mxout5.netvision.net.il> Trever, This would be fantastic plugin! Best, -- Arthur > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Furnish, Trever G > Sent: Saturday, May 19, 2007 12:58 AM > To: MailScanner discussion > Subject: way OT: add header (mailscanner) to be parsed by > Outlook plugin forreporting false-negatives? > > Ok, sorry to go so far OT, but if you all can wax sentimental about > perforators and the Tardis, I this this ought to be ok. :-) I even > added a mailscanner function (adding a header to a processed > message) to > make it slightly more ON-topic. > > I already have a modified MailWatch in place that let's users > see their > quarantined mail and release messages one at a time, and I can easily > have MailScanner add a header to "ham" containing information to be > acted on by a user agent (Outlook). I'm wondering though, has anyone > put together an add-on for Outlook to allow easy "Report this > message as > spam" functionality? I'd like my (Outlook) users to be able to report > spam that I've missed without having to leave the client to do so. > > I'd imagine it working like so: > For "ham", MS would add a header with uniquely identifiable info, such > as the message ID. When the message is viewed in Outlook, the user > would say, "Hey, this is missed spam!", and click a checkbox, which > would in turn causethis (as yet non-existant?) Outlook plugin to do > *something* (such as executing a program in another thread, quietly) > which would connect to my mailscanner system and report the message as > spam. > > I'm seriously considering writing such a plugin, but if > anyone's already > done so or has a better solution, I'd rather avoid the wasted effort. > > -- > Trever Furnish, tgfurnish@herffjones.com > Herff Jones, Inc. Unix / Network Administrator > Phone: 317.612.3519 > Any sufficiently advanced technology is indistinguishable from Unix. > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From hvdkooij at vanderkooij.org Sat May 19 10:20:23 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sat May 19 10:21:09 2007 Subject: way OT: add header (mailscanner) to be parsed by Outlook plugin for reporting false-negatives? In-Reply-To: <57573D714A832C43B9D80EAFBDA48D03057BDBA8@inex3.herffjones.hj-int> References: <57573D714A832C43B9D80EAFBDA48D03057BDBA8@inex3.herffjones.hj-int> Message-ID: On Fri, 18 May 2007, Furnish, Trever G wrote: > Ok, sorry to go so far OT, but if you all can wax sentimental about > perforators and the Tardis, I this this ought to be ok. :-) I even > added a mailscanner function (adding a header to a processed message) to > make it slightly more ON-topic. > > I already have a modified MailWatch in place that let's users see their > quarantined mail and release messages one at a time, and I can easily > have MailScanner add a header to "ham" containing information to be > acted on by a user agent (Outlook). I'm wondering though, has anyone > put together an add-on for Outlook to allow easy "Report this message as > spam" functionality? I'd like my (Outlook) users to be able to report > spam that I've missed without having to leave the client to do so. > > I'd imagine it working like so: > For "ham", MS would add a header with uniquely identifiable info, such > as the message ID. When the message is viewed in Outlook, the user > would say, "Hey, this is missed spam!", and click a checkbox, which > would in turn causethis (as yet non-existant?) Outlook plugin to do > *something* (such as executing a program in another thread, quietly) > which would connect to my mailscanner system and report the message as > spam. > > I'm seriously considering writing such a plugin, but if anyone's already > done so or has a better solution, I'd rather avoid the wasted effort. There is a similar plugin for the competition. Based on the unique identifier and URL to the webinterface the plugin can be used to mark both SPAM and HAM or just jump to the webinterface. With MailScanner you can point to each and every message with a direct URL. So if you add that as header then you can use the plugin to mark it as HAM or SPAM or even blacklist/whitelist the sender. Given that the casual outlook user will not be able to tell the difference between a sender and the From: line such a blacklist/whitelist option may not entirely work as they expect. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From uxbod at splatnix.net Sat May 19 11:43:57 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Sat May 19 11:41:50 2007 Subject: way OT: add header (mailscanner) to be parsed by Outlook plugin for reporting false-negatives? In-Reply-To: <57573D714A832C43B9D80EAFBDA48D03057BDBA8@inex3.herffjones.hj-int> References: <57573D714A832C43B9D80EAFBDA48D03057BDBA8@inex3.herffjones.hj-int> Message-ID: <20070519114357.104ddd35@uxbod.splatnix.net> Why not just have a shared IMAP folder and let the users drop SPAM into that ? Saves writing a plugin. On Fri, 18 May 2007 17:58:21 -0400 "Furnish, Trever G" wrote: > Ok, sorry to go so far OT, but if you all can wax sentimental about > perforators and the Tardis, I this this ought to be ok. :-) I even > added a mailscanner function (adding a header to a processed message) > to make it slightly more ON-topic. > > I already have a modified MailWatch in place that let's users see > their quarantined mail and release messages one at a time, and I can > easily have MailScanner add a header to "ham" containing information > to be acted on by a user agent (Outlook). I'm wondering though, has > anyone put together an add-on for Outlook to allow easy "Report this > message as spam" functionality? I'd like my (Outlook) users to be > able to report spam that I've missed without having to leave the > client to do so. > I'd imagine it working like so: > For "ham", MS would add a header with uniquely identifiable info, such > as the message ID. When the message is viewed in Outlook, the user > would say, "Hey, this is missed spam!", and click a checkbox, which > would in turn causethis (as yet non-existant?) Outlook plugin to do > *something* (such as executing a program in another thread, quietly) > which would connect to my mailscanner system and report the message as > spam. > > I'm seriously considering writing such a plugin, but if anyone's > already done so or has a better solution, I'd rather avoid the wasted > effort. > -- > Trever Furnish, tgfurnish@herffjones.com > Herff Jones, Inc. Unix / Network Administrator > Phone: 317.612.3519 > Any sufficiently advanced technology is indistinguishable from Unix. > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 845 869 2749 // SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Sat May 19 13:00:09 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat May 19 13:01:09 2007 Subject: Release 4.60.1 Message-ID: <464EE6C9.5000703@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I have just released the first beta version of 4.60. - -- Fixed problem causing a few false alarms in RBLs. - -- Custom Functions now take parameters to their per-message invocation as well as to the Init and End functions. - -- "clamavmodule" scanner no longer detects password-protected archives as viruses, allowing them to be easily released in MailWatch. - -- Phishing net now correctly handles HTML tags inside links. Download as usual from www.mailscanner.info. Please do help me by testing this release! Many thanks. The full Change Log is this: * New Features and Improvements * 1 Improved Sophos.install script so that it sets up /etc/ld.so.conf ready for installation of Perl-SAVI module required for "sophossavi" virus scanner. 1 Custom Functions can now receive parameters not only to their Init and End functions, but also to their run-time calculation functions (i.e. the real custom function itself used when processing each message). The Custom Function is now passed not only the message, but also a ref to a list of parameters specified in the MailScanner.conf file. 1 Improvement to phishing net. 1 'clamavmodule' scanner no longer detects encrypted zips/rars as viruses, leaving MailScanner to do the check later in the dangerous content scanning. The consequence is that MailWatch will allow them to be released from quarantine. * Fixes * 1 Phishing net now correctly handles HTML tags inside links. 1 Deprecated clamscan flag replaced with supported one to stop it printing the summary. 1 Added '-b' to nod32-1.99 command-line options in SweepViruses.pm to stop scanner producing licensing details. Thanks to UxBoD. 1 Removed test in RPM distribution's test for RedHat 6 as it will clash with RHEL 6 and Fedora. Anyone still running RedHat 6 has bigger problems! :-) 1 Worked round Perl bug in returning number of RBLs hit by a message. 1 Fixed problem causing some password-protected RAR archives to be missed. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGTubTEfZZRxQVtlQRAnFIAJ9DTJsWHMBcZXbnpY0upDTMBchTtwCfXbop IrVtk9XCum0sBrn0VVUUztI= =61c6 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From amaclach at yahoo.co.uk Sat May 19 22:10:04 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Sat May 19 22:10:09 2007 Subject: way OT: add header (mailscanner) to be parsed by Outlook plugin for reporting false-negatives? Message-ID: <567041.68007.qm@web26304.mail.ukl.yahoo.com> I have implemented this in the latest release of ESVA. It's not a button, but a URL in the footer of the message, which is included in the inline sig:
--
This message was scanned by ESVA and is believed to be clean. Click'>http://mail-gw.domain.tld/cgi-bin/learn-msg.cgi?id=$id">Click here to report this message as spam. which works nicely - although I certainly don't consider it to be a perfect solution. The CGI that does the actual work is: #!/usr/bin/perl use CGI::Carp qw(fatalsToBrowser); use CGI qw(:standard); print "Content-type: text/html \n\n"; $query = new CGI; $sendmail = "/usr/sbin/sendmail.postfix"; $id = param("id"); $datenumber = param("datenumber"); $to = param("to"); $msgtorelease = "/var/spool/MailScanner/quarantine/$datenumber/spam/$id"; open(MAIL, "|$sendmail $to <$msgtorelease") or die "Cannot open $sendmail: $!"; close(MAIL); # redirect to success page print ""; The reason I'm using sendmail.postfix is two-fold: a) I use Postfix b) Sendmail releases the message just fine - but to everyone in the headers (doesn't go down well with everyone) There is also a very similar release mechanism. The beauty with this method is that it doesn't care which mail client you use, so no mods to make. -Andy ----- Original Message ---- From: --[ UxBoD ]-- To: mailscanner@lists.mailscanner.info Sent: Saturday, 19 May, 2007 11:43:57 AM Subject: Re: way OT: add header (mailscanner) to be parsed by Outlook plugin for reporting false-negatives? Why not just have a shared IMAP folder and let the users drop SPAM into that ? Saves writing a plugin. On Fri, 18 May 2007 17:58:21 -0400 "Furnish, Trever G" wrote: > Ok, sorry to go so far OT, but if you all can wax sentimental about > perforators and the Tardis, I this this ought to be ok. :-) I even > added a mailscanner function (adding a header to a processed message) > to make it slightly more ON-topic. > > I already have a modified MailWatch in place that let's users see > their quarantined mail and release messages one at a time, and I can > easily have MailScanner add a header to "ham" containing information > to be acted on by a user agent (Outlook). I'm wondering though, has > anyone put together an add-on for Outlook to allow easy "Report this > message as spam" functionality? I'd like my (Outlook) users to be > able to report spam that I've missed without having to leave the > client to do so. > I'd imagine it working like so: > For "ham", MS would add a header with uniquely identifiable info, such > as the message ID. When the message is viewed in Outlook, the user > would say, "Hey, this is missed spam!", and click a checkbox, which > would in turn causethis (as yet non-existant?) Outlook plugin to do > *something* (such as executing a program in another thread, quietly) > which would connect to my mailscanner system and report the message as > spam. > > I'm seriously considering writing such a plugin, but if anyone's > already done so or has a better solution, I'd rather avoid the wasted > effort. > -- > Trever Furnish, tgfurnish@herffjones.com > Herff Jones, Inc. Unix / Network Administrator > Phone: 317.612.3519 > Any sufficiently advanced technology is indistinguishable from Unix. > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 845 869 2749 // SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From wilson.galafassi at gmail.com Sun May 20 07:36:52 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Sun May 20 07:37:05 2007 Subject: block messages based on content Message-ID: From hvdkooij at vanderkooij.org Sun May 20 11:25:43 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sun May 20 11:26:19 2007 Subject: block messages based on content In-Reply-To: References: Message-ID: On Sun, 20 May 2007, Wilson A. Galafassi Jr. wrote: I would love to see an option to kill such empty messages ;-) Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From MailScanner at ecs.soton.ac.uk Sun May 20 12:56:00 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun May 20 12:56:46 2007 Subject: Release 4.60.2 Message-ID: <46503750.50401@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I have just released another beta. I have updated a whole load of the required Perl modules, and have added a command-line option --nomodules which will stop it installing the required Perl modules, should you wish to do that. I have also fixed a whole bunch of bugs in the installer, so it shouldn't overwrite modules with older ones, which was happening in a few cases. Download as usual from www.mailscanner.info. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGUDdWEfZZRxQVtlQRAjRoAKCEo4hMuvzD6qW9n65RPcwBy3mg7ACg28jS lszMrqePEF33syo5oG9uFkI= =ZKo6 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From denis at croombs.org Sun May 20 13:56:32 2007 From: denis at croombs.org (Denis Croombs) Date: Sun May 20 13:59:26 2007 Subject: Release 4.60.2 In-Reply-To: <46503750.50401@ecs.soton.ac.uk> Message-ID: <200705201259.l4KCxJ5W006346@mail.deniscroombs.org> > I have just released another beta. > I have updated a whole load of the required Perl modules, and > have added a command-line option > --nomodules > which will stop it installing the required Perl modules, > should you wish to do that. > > I have also fixed a whole bunch of bugs in the installer, so > it shouldn't overwrite modules with older ones, which was > happening in a few cases. > > Download as usual from www.mailscanner.info. > > Jules All looks good on 2 of my Centos servers, 3 more to go. Regards Denis From hvdkooij at vanderkooij.org Sun May 20 15:40:23 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sun May 20 15:41:03 2007 Subject: Release 4.60.2 In-Reply-To: <46503750.50401@ecs.soton.ac.uk> References: <46503750.50401@ecs.soton.ac.uk> Message-ID: On Sun, 20 May 2007, Julian Field wrote: > I have just released another beta. Just a thought. Could you indicate in the subject line this is a beta announcement? It would be easier to distinguish beta announcements from the main announcements. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From wilson.galafassi at gmail.com Sun May 20 17:43:32 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Sun May 20 17:43:41 2007 Subject: RES: block messages based on content In-Reply-To: References: Message-ID: sorry. I don't understand your answer. -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Hugo van der Kooij Enviada em: domingo, 20 de maio de 2007 07:26 Para: MailScanner discussion Assunto: Re: block messages based on content On Sun, 20 May 2007, Wilson A. Galafassi Jr. wrote: I would love to see an option to kill such empty messages ;-) Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Sun May 20 17:47:28 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun May 20 17:49:32 2007 Subject: Release 4.60.2 In-Reply-To: References: <46503750.50401@ecs.soton.ac.uk> Message-ID: <46507BA0.2030206@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hugo van der Kooij wrote: > On Sun, 20 May 2007, Julian Field wrote: > >> I have just released another beta. > > Just a thought. Could you indicate in the subject line this is a beta > announcement? It would be easier to distinguish beta announcements > from the main announcements. > The main announcements always have "MailScanner ANNOUNCE" in the subject line. And they are (virtually) always at the start of the month. But I agree with you, I should put "beta" in the subject line somewhere. I will try to remember in future, Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGUHulEfZZRxQVtlQRAk3xAKCsUgm7N5bD04Gqy+pAK7hpLIFZqwCgq5AT +fnnrO3mzhaHxxFXvVCuq7E= =CpGv -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From am.lists at gmail.com Sun May 20 18:51:53 2007 From: am.lists at gmail.com (am.lists) Date: Sun May 20 18:52:01 2007 Subject: way OT: add header (mailscanner) to be parsed by Outlook plugin for reporting false-negatives? In-Reply-To: <567041.68007.qm@web26304.mail.ukl.yahoo.com> References: <567041.68007.qm@web26304.mail.ukl.yahoo.com> Message-ID: <25a66d840705201051v662b2983j894999dc49a41edd@mail.gmail.com> What happens when something like this occurs: 1) I get a message to me through my hosted ESVA. It has that footer. I know it's not spam, so I don't click it. 2) It's something important so I forward it to the wife, the brother-in-law, etc. 3) They, not being as savvy, mistekenly click the link after it's left my control. As Andy says, it's not a perfect solution... From mogens at fumlersoft.dk Sun May 20 19:37:15 2007 From: mogens at fumlersoft.dk (Mogens Melander) Date: Sun May 20 19:37:04 2007 Subject: RES: block messages based on content In-Reply-To: References: Message-ID: <1992.90.184.17.152.1179686235.squirrel@mail.fumlersoft.dk> Well, what was the question :^) On Sun, May 20, 2007 18:43, Wilson A. Galafassi Jr. wrote: > sorry. I don't understand your answer. > > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Hugo van > der > Kooij > Enviada em: domingo, 20 de maio de 2007 07:26 > Para: MailScanner discussion > Assunto: Re: block messages based on content > > On Sun, 20 May 2007, Wilson A. Galafassi Jr. wrote: > > > > I would love to see an option to kill such empty messages ;-) > > Hugo. > > -- > hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ > This message is using 100% recycled electrons. > > Some men see computers as they are and say "Windows" > I use computers with Linux and say "Why Windows?" > (Thanks JFK, for the insight.) > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by OpenProtect(http://www.openprotect.com), and is > believed to be clean. > -- Later Mogens Melander +45 40 85 71 38 +66 870 133 224 -- This message has been scanned for viruses and dangerous content by OpenProtect(http://www.openprotect.com), and is believed to be clean. From hvdkooij at vanderkooij.org Sun May 20 20:57:37 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sun May 20 20:58:12 2007 Subject: RES: block messages based on content In-Reply-To: References: Message-ID: On Sun, 20 May 2007, Wilson A. Galafassi Jr. wrote: > sorry. I don't understand your answer. Which fits the question. Because there was none at all. You did not bother to write anything in your message. So was it a question? Was it spam? Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From hvdkooij at vanderkooij.org Sun May 20 21:00:10 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sun May 20 21:00:43 2007 Subject: way OT: add header (mailscanner) to be parsed by Outlook plugin for reporting false-negatives? In-Reply-To: <25a66d840705201051v662b2983j894999dc49a41edd@mail.gmail.com> References: <567041.68007.qm@web26304.mail.ukl.yahoo.com> <25a66d840705201051v662b2983j894999dc49a41edd@mail.gmail.com> Message-ID: On Sun, 20 May 2007, am.lists wrote: > What happens when something like this occurs: > > 1) I get a message to me through my hosted ESVA. It has that footer. I > know it's not spam, so I don't click it. > 2) It's something important so I forward it to the wife, the > brother-in-law, etc. > 3) They, not being as savvy, mistekenly click the link after it's left > my control. > > As Andy says, it's not a perfect solution... If you put it in a header it will not show up by default. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From res at ausics.net Sun May 20 21:56:34 2007 From: res at ausics.net (Res) Date: Sun May 20 21:56:46 2007 Subject: RES: block messages based on content In-Reply-To: References: Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sun, 20 May 2007, Wilson A. Galafassi Jr. wrote: > sorry. I don't understand your answer. Your post had no content, Hugo was being a bit anal with his comment (somthing usually reverved for me to be hehehe), but not all are like us. If you have a question please repost it. - -- Cheers Res Vote for your favourite MTA at http://polls.ausics.net/v3.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGULYEsWhAmSIQh7MRAvriAJ0W45mIMJ9tp1lU2/u8a/mxHk/VegCglWhX ApCaDQ6Sp04WKr46Svax+OI= =Duqm -----END PGP SIGNATURE----- From amaclach at yahoo.co.uk Sun May 20 22:44:32 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Sun May 20 22:44:34 2007 Subject: way OT: add header (mailscanner) to be parsed by Outlook plugin for reporting false-negatives? Message-ID: <220387.88634.qm@web26310.mail.ukl.yahoo.com> This is getting waaaay OT now, but feel free to continue on the GD forum ;-) This is something I agonise over, but maybe a confirm report as spam button on report-msg.cgi? This isn't completely idiotproof, but it's all a matter of reducing percentages... ----- Original Message ---- From: am.lists To: MailScanner discussion Sent: Sunday, 20 May, 2007 6:51:53 PM Subject: Re: way OT: add header (mailscanner) to be parsed by Outlook plugin for reporting false-negatives? What happens when something like this occurs: 1) I get a message to me through my hosted ESVA. It has that footer. I know it's not spam, so I don't click it. 2) It's something important so I forward it to the wife, the brother-in-law, etc. 3) They, not being as savvy, mistekenly click the link after it's left my control. As Andy says, it's not a perfect solution... -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From jan-peter at koopmann.eu Mon May 21 08:23:02 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Mon May 21 08:23:32 2007 Subject: way OT: add header (mailscanner) to be parsed by Outlook plugin for reporting false-negatives? In-Reply-To: <20070519114357.104ddd35@uxbod.splatnix.net> References: <57573D714A832C43B9D80EAFBDA48D03057BDBA8@inex3.herffjones.hj-int> <20070519114357.104ddd35@uxbod.splatnix.net> Message-ID: On Saturday, May 19, 2007 12:44 PM -- wrote: > Why not just have a shared IMAP folder and let the users drop SPAM > into that ? Saves writing a plugin. This is something we setup for our clients. Nevertheless to make this work efficiently you have to use a public folder and tell Outlook to display these folders in the personal favorites (which Outlook tends to forget from time to time). Therefore this is not a perfect solution. We are now using SMTPTracker to convert SpamAssassin SpamScore to Exchange SCL and have spam thrown into "Junk E-Mails" automatically. I would love to have a plugin that does the following: Spam-Button - Move marked messages to public folder "SPAM" (should be configurable of course) Ham-Button - Copy marked messages to public folder "NOSPAM" - If message is in Junk E-Mail Folder, move it to the Inbox On the MailScanner server we already read the mails from SPAM/NOSPAM folders, try to get the original mails from a 5-day archive and feed it to SA bayes and reporting. If we cannot get the original (e.g. the user marks a 10-day old message as spam) we at least feed what we get from Exchange to Bayes. Unfortunatly I do not currently have the skill to program this probably rather simple plugin myself at this moment. Any volunteers? :-) Kind regards, JP From mogens at fumlersoft.dk Mon May 21 09:02:13 2007 From: mogens at fumlersoft.dk (Mogens Melander) Date: Mon May 21 09:01:52 2007 Subject: SA not working in MS Message-ID: <4698.90.184.17.152.1179734533.squirrel@mail.fumlersoft.dk> Hi, Running on i686, Slackware 10 (2.4.26), MS 4.58.9-1, SA 3.2.0 I'm probably missing something obviously, starring me blind, trying to spot what's wrong. It seems that SA is not working with MS. It do work when invoked 'alone' like: spamassassin -D < /etc/MailScanner/testmessages/sample-spam.txt X-Spam-Flag: YES X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on styx.fumlersoft.dk X-Spam-Level: ******* X-Spam-Status: Yes, score=7.6 required=5.0 tests=BAYES_99,DATE_IN_PAST_12_24, INVALID_DATE,INVALID_MSGID autolearn=no version=3.2.0 Content analysis details: (7.6 points, 5.0 required) pts rule name description ---- ---------------------- --------------------------------------------- 3.5 BAYES_99 BODY: Bayesian spam probability is 99 to 100% [score: 1.0000] 1.2 INVALID_DATE Invalid Date: header (not RFC 2822) 1.0 DATE_IN_PAST_12_24 Date: is 12 to 24 hours before Received: date 1.9 INVALID_MSGID Message-Id is not valid, according to RFC 2822 But message retrieved in as mail give me headers like this: (BTW: the message is from RulesDuJour failing 'bogus-virus' update) Return-Path: Received: from styx.fumlersoft.dk ([unix socket]) by fumlersoft.dk (Cyrus v2.3.8) with LMTPA; Mon, 21 May 2007 06:47:15 +0200 X-Sieve: CMU Sieve 2.3 Received: from styx.fumlersoft.dk (IDENT:25@localhost [127.0.0.1]) by styx.fumlersoft.dk (8.13.8/8.13.8) with ESMTP id l4L4kObE022924 for ; Mon, 21 May 2007 06:46:24 +0200 Received: (from root@localhost) by styx.fumlersoft.dk (8.13.8/8.13.8/Submit) id l4L4kO08022903 for admin; Mon, 21 May 2007 06:46:24 +0200 From: root@styx.fumlersoft.dk Date: Mon, 21 May 2007 06:46:24 +0200 To: admin@styx.fumlersoft.dk Subject: RulesDuJour Run Summary on styx Message-ID: <46512420.nailHO517JG5V@styx.fumlersoft.dk> User-Agent: nail 11.1 8/8/04 MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit X-TIT-styx-Information: Please contact the ISP for more information X-TIT-styx: Found to be clean X-TIT-styx-MCPCheck: MCP-Clean, MCP-Checker (score=0, required 3.5) X-TIT-styx-SpamCheck: not spam, SpamAssassin (score=0, required 999, autolearn=) X-TIT-styx-From: root@styx.fumlersoft.dk Any ideas, anybody ? -- Later Mogens Melander +45 40 85 71 38 +66 870 133 224 -- This message has been scanned for viruses and dangerous content by OpenProtect(http://www.openprotect.com), and is believed to be clean. From uxbod at splatnix.net Mon May 21 09:18:57 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Mon May 21 09:19:05 2007 Subject: SA not working in MS In-Reply-To: <4698.90.184.17.152.1179734533.squirrel@mail.fumlersoft.dk> References: <4698.90.184.17.152.1179734533.squirrel@mail.fumlersoft.dk> Message-ID: Have you tried running MS in Debug mode ? /opt/MailScanner/bin/MailScanner --debug. Ensure no other MS instances are running while this is performed. It should point you to any potential problems. On Mon, 21 May 2007 10:02:13 +0200 (CEST), "Mogens Melander" wrote: > Hi, > > Running on i686, Slackware 10 (2.4.26), MS 4.58.9-1, SA 3.2.0 > > I'm probably missing something obviously, starring me blind, > trying to spot what's wrong. > > It seems that SA is not working with MS. It do work when > invoked 'alone' like: > > spamassassin -D < /etc/MailScanner/testmessages/sample-spam.txt > > X-Spam-Flag: YES > X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on > styx.fumlersoft.dk > X-Spam-Level: ******* > X-Spam-Status: Yes, score=7.6 required=5.0 > tests=BAYES_99,DATE_IN_PAST_12_24, > INVALID_DATE,INVALID_MSGID autolearn=no version=3.2.0 > > Content analysis details: (7.6 points, 5.0 required) > > pts rule name description > ---- ---------------------- --------------------------------------------- > 3.5 BAYES_99 BODY: Bayesian spam probability is 99 to 100% > [score: 1.0000] > 1.2 INVALID_DATE Invalid Date: header (not RFC 2822) > 1.0 DATE_IN_PAST_12_24 Date: is 12 to 24 hours before Received: date > 1.9 INVALID_MSGID Message-Id is not valid, according to RFC 2822 > > But message retrieved in as mail give me headers like this: > (BTW: the message is from RulesDuJour failing 'bogus-virus' update) > > Return-Path: > Received: from styx.fumlersoft.dk ([unix socket]) > by fumlersoft.dk (Cyrus v2.3.8) with LMTPA; > Mon, 21 May 2007 06:47:15 +0200 > X-Sieve: CMU Sieve 2.3 > Received: from styx.fumlersoft.dk (IDENT:25@localhost [127.0.0.1]) > by styx.fumlersoft.dk (8.13.8/8.13.8) with ESMTP id l4L4kObE022924 > for ; Mon, 21 May 2007 06:46:24 +0200 > Received: (from root@localhost) > by styx.fumlersoft.dk (8.13.8/8.13.8/Submit) id l4L4kO08022903 > for admin; Mon, 21 May 2007 06:46:24 +0200 > From: root@styx.fumlersoft.dk > Date: Mon, 21 May 2007 06:46:24 +0200 > To: admin@styx.fumlersoft.dk > Subject: RulesDuJour Run Summary on styx > Message-ID: <46512420.nailHO517JG5V@styx.fumlersoft.dk> > User-Agent: nail 11.1 8/8/04 > MIME-Version: 1.0 > Content-Type: text/plain; charset=us-ascii > Content-Transfer-Encoding: 7bit > X-TIT-styx-Information: Please contact the ISP for more information > X-TIT-styx: Found to be clean > X-TIT-styx-MCPCheck: MCP-Clean, MCP-Checker (score=0, required 3.5) > X-TIT-styx-SpamCheck: not spam, SpamAssassin (score=0, required 999, > autolearn=) > X-TIT-styx-From: root@styx.fumlersoft.dk > > Any ideas, anybody ? > > -- > Later > > Mogens Melander > +45 40 85 71 38 > +66 870 133 224 > > > > -- > This message has been scanned for viruses and > dangerous content by OpenProtect(http://www.openprotect.com), and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From res at ausics.net Mon May 21 09:19:15 2007 From: res at ausics.net (Res) Date: Mon May 21 09:19:47 2007 Subject: SA not working in MS In-Reply-To: <4698.90.184.17.152.1179734533.squirrel@mail.fumlersoft.dk> References: <4698.90.184.17.152.1179734533.squirrel@mail.fumlersoft.dk> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Please stop mailscanner, then run MailScanner --lint On Mon, 21 May 2007, Mogens Melander wrote: > Hi, > > Running on i686, Slackware 10 (2.4.26), MS 4.58.9-1, SA 3.2.0 > > I'm probably missing something obviously, starring me blind, > trying to spot what's wrong. > > It seems that SA is not working with MS. It do work when > invoked 'alone' like: > > spamassassin -D < /etc/MailScanner/testmessages/sample-spam.txt > > X-Spam-Flag: YES > X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on styx.fumlersoft.dk > X-Spam-Level: ******* > X-Spam-Status: Yes, score=7.6 required=5.0 tests=BAYES_99,DATE_IN_PAST_12_24, > INVALID_DATE,INVALID_MSGID autolearn=no version=3.2.0 > > Content analysis details: (7.6 points, 5.0 required) > > pts rule name description > ---- ---------------------- --------------------------------------------- > 3.5 BAYES_99 BODY: Bayesian spam probability is 99 to 100% > [score: 1.0000] > 1.2 INVALID_DATE Invalid Date: header (not RFC 2822) > 1.0 DATE_IN_PAST_12_24 Date: is 12 to 24 hours before Received: date > 1.9 INVALID_MSGID Message-Id is not valid, according to RFC 2822 > > But message retrieved in as mail give me headers like this: > (BTW: the message is from RulesDuJour failing 'bogus-virus' update) > > Return-Path: > Received: from styx.fumlersoft.dk ([unix socket]) > by fumlersoft.dk (Cyrus v2.3.8) with LMTPA; > Mon, 21 May 2007 06:47:15 +0200 > X-Sieve: CMU Sieve 2.3 > Received: from styx.fumlersoft.dk (IDENT:25@localhost [127.0.0.1]) > by styx.fumlersoft.dk (8.13.8/8.13.8) with ESMTP id l4L4kObE022924 > for ; Mon, 21 May 2007 06:46:24 +0200 > Received: (from root@localhost) > by styx.fumlersoft.dk (8.13.8/8.13.8/Submit) id l4L4kO08022903 > for admin; Mon, 21 May 2007 06:46:24 +0200 > From: root@styx.fumlersoft.dk > Date: Mon, 21 May 2007 06:46:24 +0200 > To: admin@styx.fumlersoft.dk > Subject: RulesDuJour Run Summary on styx > Message-ID: <46512420.nailHO517JG5V@styx.fumlersoft.dk> > User-Agent: nail 11.1 8/8/04 > MIME-Version: 1.0 > Content-Type: text/plain; charset=us-ascii > Content-Transfer-Encoding: 7bit > X-TIT-styx-Information: Please contact the ISP for more information > X-TIT-styx: Found to be clean > X-TIT-styx-MCPCheck: MCP-Clean, MCP-Checker (score=0, required 3.5) > X-TIT-styx-SpamCheck: not spam, SpamAssassin (score=0, required 999, > autolearn=) > X-TIT-styx-From: root@styx.fumlersoft.dk > > Any ideas, anybody ? > > - -- Cheers Res Vote for your favourite Operating System: http://polls.ausics.net/v1.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGUVYFsWhAmSIQh7MRAhbIAJ4hgYk8BwZ955te7is03ArTb5ne/wCeOTOG GQku6nQogG0ahpF5bDWtJ/U= =KwsJ -----END PGP SIGNATURE----- From Q.G.Campbell at newcastle.ac.uk Mon May 21 10:06:37 2007 From: Q.G.Campbell at newcastle.ac.uk (Quentin Campbell) Date: Mon May 21 10:08:10 2007 Subject: Scalability of 'spam.whitelist.rules' facility Message-ID: <4165CF7A7F12DE4B96622CCBB90586470A4D0CA0@largo.campus.ncl.ac.uk> Our 'spam.whitelist.rules' file currently has over 4,000 entries and is growing at the rate of about 200-300 entries each week. At what point does the number of entries in the whitelist file become 'too many' and impact the performance of MailScanner? If all of our users requested just one address each to be whitelisted then 'spam.whitelist.rules' would have more than 20,000 entries! [The increase in requests to whitelist is probably because the recently enabled Bayesian filter in SpamAssassin has had a significant impact on increasing the amount of tagged spam but at the cost of an increase in false positives.] Quentin --- PHONE: +44 191 222 8209 Information Systems and Services (ISS), Newcastle University, Newcastle upon Tyne, FAX: +44 191 222 8765 United Kingdom, NE1 7RU. ------------------------------------------------------------------ From uxbod at splatnix.net Mon May 21 10:21:16 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Mon May 21 10:22:20 2007 Subject: Scalability of 'spam.whitelist.rules' facility In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470A4D0CA0@largo.campus.ncl.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0CA0@largo.campus.ncl.ac.uk> Message-ID: <23cdb2cad6f2304fb039e2baabc521ac@62.49.223.244> Why not migrate them to MySQL and use the SQLBlackWhiteList.pm that is available from the MailWatch package ? On Mon, 21 May 2007 10:06:37 +0100, "Quentin Campbell" wrote: > Our 'spam.whitelist.rules' file currently has over 4,000 entries and is > growing at the rate of about 200-300 entries each week. > > At what point does the number of entries in the whitelist file become > 'too many' and impact the performance of MailScanner? > > If all of our users requested just one address each to be whitelisted > then 'spam.whitelist.rules' would have more than 20,000 entries! > > [The increase in requests to whitelist is probably because the recently > enabled Bayesian filter in SpamAssassin has had a significant impact on > increasing the amount of tagged spam but at the cost of an increase in > false positives.] > > Quentin > --- > PHONE: +44 191 222 8209 Information Systems and Services (ISS), > Newcastle University, > Newcastle upon Tyne, > FAX: +44 191 222 8765 United Kingdom, NE1 7RU. > ------------------------------------------------------------------ > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From res at ausics.net Mon May 21 10:35:09 2007 From: res at ausics.net (Res) Date: Mon May 21 10:35:18 2007 Subject: Scalability of 'spam.whitelist.rules' facility In-Reply-To: <23cdb2cad6f2304fb039e2baabc521ac@62.49.223.244> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0CA0@largo.campus.ncl.ac.uk> <23cdb2cad6f2304fb039e2baabc521ac@62.49.223.244> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Mon, 21 May 2007, --[ UxBoD ]-- wrote: > Why not migrate them to MySQL and use the SQLBlackWhiteList.pm that is > available from the MailWatch package ? This might be fine on low loaded systems, but to do a lookup for every email on major networks would fail, as sql would not keep up unless you clustered and nobody is going to do that just for whitelisting. I've seen it with vpopmail for instance the cdb file can handle over 6000 concurrent connections with no ill affect, sql spits farts and dies at 1/5th of that value unless you cluster, so it's a pointless expense. - -- Cheers Res Vote for your favourite Operating System: http://polls.ausics.net/v1.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGUWfPsWhAmSIQh7MRAidCAJ455aRi9hQ2BF7NBtlyIt6554m9NgCfUwk5 a4yqWa7+AD0AbtLAIiYXOOM= =vA6v -----END PGP SIGNATURE----- From uxbod at splatnix.net Mon May 21 10:40:17 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Mon May 21 10:40:31 2007 Subject: Scalability of 'spam.whitelist.rules' facility In-Reply-To: References: Message-ID: Hmmm, okay. So how about a hash ? On Mon, 21 May 2007 19:35:09 +1000 (EST), Res wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > On Mon, 21 May 2007, --[ UxBoD ]-- wrote: > >> Why not migrate them to MySQL and use the SQLBlackWhiteList.pm that is >> available from the MailWatch package ? > > This might be fine on low loaded systems, but to do a lookup for every > email on major networks would fail, as sql would not keep up unless you > clustered and nobody is going to do that just for whitelisting. > > I've seen it with vpopmail for instance the cdb file can handle over 6000 > concurrent connections with no ill affect, sql spits farts and dies at > 1/5th of that value unless you cluster, so it's a pointless expense. > > > - -- > > Cheers > Res > > > Vote for your favourite Operating System: http://polls.ausics.net/v1.php > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.6 (GNU/Linux) > > iD8DBQFGUWfPsWhAmSIQh7MRAidCAJ455aRi9hQ2BF7NBtlyIt6554m9NgCfUwk5 > a4yqWa7+AD0AbtLAIiYXOOM= > =vA6v > -----END PGP SIGNATURE----- > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From pete at enitech.com.au Mon May 21 10:43:51 2007 From: pete at enitech.com.au (Pete Russell) Date: Mon May 21 10:44:25 2007 Subject: Release 4.60.2 In-Reply-To: <46503750.50401@ecs.soton.ac.uk> References: <46503750.50401@ecs.soton.ac.uk> Message-ID: <465169D7.7030203@enitech.com.au> I havent tracked all of the postfix changes of late, can i expect any hassles going from MS 455.9 and POstfix 2.3.3 To the latest MS? Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > I have just released another beta. > I have updated a whole load of the required Perl modules, and have added > a command-line option > --nomodules > which will stop it installing the required Perl modules, should you wish > to do that. > > I have also fixed a whole bunch of bugs in the installer, so it > shouldn't overwrite modules with older ones, which was happening in a > few cases. > > Download as usual from www.mailscanner.info. > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: ISO-8859-1 > > wj8DBQFGUDdWEfZZRxQVtlQRAjRoAKCEo4hMuvzD6qW9n65RPcwBy3mg7ACg28jS > lszMrqePEF33syo5oG9uFkI= > =ZKo6 > -----END PGP SIGNATURE----- > From prandal at herefordshire.gov.uk Mon May 21 10:49:01 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Mon May 21 10:49:40 2007 Subject: Scalability of 'spam.whitelist.rules' facility In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470A4D0CA0@largo.campus.ncl.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0CA0@largo.campus.ncl.ac.uk> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBAB257D4@HC-MBX02.herefordshire.gov.uk> Is there no obvious pattern in the email addresses to be whitelisted? Or spamassassin rules they are falling foul of? The problem with whitelisting "From:" email addresses is that this will let in spams spoofing these from addresses. You should only really be using whitelist_from_rcvd, whitelist_from_spf, whitelist_from_dkim etc in spamassassin. Our spam.whitelist.rules only includes 127.0.0.1, nothing more. It looks like you're trying to work around another problem rather than trying to address root causes. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Quentin Campbell > Sent: 21 May 2007 10:07 > To: mailscanner@lists.mailscanner.info > Subject: Scalability of 'spam.whitelist.rules' facility > > Our 'spam.whitelist.rules' file currently has over 4,000 > entries and is > growing at the rate of about 200-300 entries each week. > > At what point does the number of entries in the whitelist file become > 'too many' and impact the performance of MailScanner? > > If all of our users requested just one address each to be whitelisted > then 'spam.whitelist.rules' would have more than 20,000 entries! > > [The increase in requests to whitelist is probably because > the recently > enabled Bayesian filter in SpamAssassin has had a significant > impact on > increasing the amount of tagged spam but at the cost of an increase in > false positives.] > > Quentin > --- > PHONE: +44 191 222 8209 Information Systems and Services (ISS), > Newcastle University, > Newcastle upon Tyne, > FAX: +44 191 222 8765 United Kingdom, NE1 7RU. > ------------------------------------------------------------------ > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From uxbod at splatnix.net Mon May 21 10:54:40 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Mon May 21 10:55:29 2007 Subject: Release 4.60.2 In-Reply-To: <465169D7.7030203@enitech.com.au> References: <465169D7.7030203@enitech.com.au> Message-ID: I have not experienced any issues so far. On Mon, 21 May 2007 19:43:51 +1000, Pete Russell wrote: > I havent tracked all of the postfix changes of late, can i expect any > hassles going from > > MS 455.9 and POstfix 2.3.3 > > To the latest MS? > > > > Julian Field wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> I have just released another beta. >> I have updated a whole load of the required Perl modules, and have added >> a command-line option >> --nomodules >> which will stop it installing the required Perl modules, should you wish >> to do that. >> >> I have also fixed a whole bunch of bugs in the installer, so it >> shouldn't overwrite modules with older ones, which was happening in a >> few cases. >> >> Download as usual from www.mailscanner.info. >> >> Jules >> >> - -- >> Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> MailScanner customisation, or any advanced system administration help? >> Contact me at Jules@Jules.FM >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> For all your IT requirements visit www.transtec.co.uk >> >> >> >> -----BEGIN PGP SIGNATURE----- >> Version: PGP Desktop 9.6.1 (Build 1012) >> Charset: ISO-8859-1 >> >> wj8DBQFGUDdWEfZZRxQVtlQRAjRoAKCEo4hMuvzD6qW9n65RPcwBy3mg7ACg28jS >> lszMrqePEF33syo5oG9uFkI= >> =ZKo6 >> -----END PGP SIGNATURE----- >> > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From gmatt at nerc.ac.uk Mon May 21 10:55:49 2007 From: gmatt at nerc.ac.uk (Greg Matthews) Date: Mon May 21 10:56:19 2007 Subject: locking bayes? Message-ID: <46516CA5.7040207@nerc.ac.uk> I have developed a shell script that takes uses LVM snapshots to backup volumes on a mail server. I am able to get a read-lock on the MySQL MailWatch table and was wondering if I could do the same with the bayes database to ensure it is consistent. At the moment, I am relying on the robustness of BerkeleyDB to be able to recover from a possibly inconsistent state. This is not ideal. The snapshot process is very quick so the lock could be released almost immediately. GREG -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford -- This message (and any attachments) is for the recipient only. NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. From arjan at anymore.nl Mon May 21 11:07:05 2007 From: arjan at anymore.nl (Arjan Schrijver) Date: Mon May 21 11:07:07 2007 Subject: Release 4.60.2 In-Reply-To: <465169D7.7030203@enitech.com.au> References: <46503750.50401@ecs.soton.ac.uk> <465169D7.7030203@enitech.com.au> Message-ID: <46516F49.1090400@anymore.nl> No problem here with MS 4.59.4.1 and Postfix 2.3.6. Pete Russell wrote: > I havent tracked all of the postfix changes of late, can i expect any > hassles going from > > MS 455.9 and POstfix 2.3.3 > > To the latest MS? > > > > Julian Field wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> I have just released another beta. >> I have updated a whole load of the required Perl modules, and have >> added a command-line option >> --nomodules >> which will stop it installing the required Perl modules, should you >> wish to do that. >> >> I have also fixed a whole bunch of bugs in the installer, so it >> shouldn't overwrite modules with older ones, which was happening in a >> few cases. >> >> Download as usual from www.mailscanner.info. >> >> Jules >> >> - -- Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> MailScanner customisation, or any advanced system administration help? >> Contact me at Jules@Jules.FM >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> For all your IT requirements visit www.transtec.co.uk >> >> >> >> -----BEGIN PGP SIGNATURE----- >> Version: PGP Desktop 9.6.1 (Build 1012) >> Charset: ISO-8859-1 >> >> wj8DBQFGUDdWEfZZRxQVtlQRAjRoAKCEo4hMuvzD6qW9n65RPcwBy3mg7ACg28jS >> lszMrqePEF33syo5oG9uFkI= >> =ZKo6 >> -----END PGP SIGNATURE----- >> From prandal at herefordshire.gov.uk Mon May 21 11:05:37 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Mon May 21 11:08:15 2007 Subject: locking bayes? In-Reply-To: <46516CA5.7040207@nerc.ac.uk> References: <46516CA5.7040207@nerc.ac.uk> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBAB257E5@HC-MBX02.herefordshire.gov.uk> Why not go for the simple and obvious solution: stop MailScanner snapshot restart MailScanner Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Greg Matthews > Sent: 21 May 2007 10:56 > To: MailScanner discussion > Subject: locking bayes? > > I have developed a shell script that takes uses LVM snapshots > to backup > volumes on a mail server. I am able to get a read-lock on the MySQL > MailWatch table and was wondering if I could do the same with > the bayes > database to ensure it is consistent. > > At the moment, I am relying on the robustness of BerkeleyDB > to be able > to recover from a possibly inconsistent state. This is not ideal. > > The snapshot process is very quick so the lock could be > released almost > immediately. > > GREG > -- > Greg Matthews 01491 692445 > Head of UNIX/Linux, iTSS Wallingford > > -- > This message (and any attachments) is for the recipient only. NERC > is subject to the Freedom of Information Act 2000 and the contents > of this email and any reply you make may be disclosed by NERC unless > it is exempt from release under the Act. Any material supplied to > NERC may be stored in an electronic records management system. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From list-mailscanner at linguaphone.com Mon May 21 11:18:29 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon May 21 11:18:42 2007 Subject: Scalability of 'spam.whitelist.rules' facility In-Reply-To: References: <4165CF7A7F12DE4B96622CCBB90586470A4D0CA0@largo.campus.ncl.ac.uk> <23cdb2cad6f2304fb039e2baabc521ac@62.49.223.244> Message-ID: <1179742709.30858.1.camel@gblades-suse.linguaphone-intranet.co.uk> On Mon, 2007-05-21 at 10:35, Res wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > On Mon, 21 May 2007, --[ UxBoD ]-- wrote: > > > Why not migrate them to MySQL and use the SQLBlackWhiteList.pm that is > > available from the MailWatch package ? > > This might be fine on low loaded systems, but to do a lookup for every > email on major networks would fail, as sql would not keep up unless you > clustered and nobody is going to do that just for whitelisting. > > I've seen it with vpopmail for instance the cdb file can handle over 6000 > concurrent connections with no ill affect, sql spits farts and dies at > 1/5th of that value unless you cluster, so it's a pointless expense. It doesn't work like that though. When the mailscanner instance starts the code loads the contents of the black/whitelist into memory and then checks to see if any changes have been made every 15 minutes. This reduces the load on the sql server but of course does increase memory usage and the startup time for the mailscanner process. From list-mailscanner at linguaphone.com Mon May 21 11:20:04 2007 From: list-mailscanner at linguaphone.com (Gareth) Date: Mon May 21 11:20:08 2007 Subject: locking bayes? In-Reply-To: <46516CA5.7040207@nerc.ac.uk> References: <46516CA5.7040207@nerc.ac.uk> Message-ID: <1179742804.30859.3.camel@gblades-suse.linguaphone-intranet.co.uk> On Mon, 2007-05-21 at 10:55, Greg Matthews wrote: > I have developed a shell script that takes uses LVM snapshots to backup > volumes on a mail server. I am able to get a read-lock on the MySQL > MailWatch table and was wondering if I could do the same with the bayes > database to ensure it is consistent. > > At the moment, I am relying on the robustness of BerkeleyDB to be able > to recover from a possibly inconsistent state. This is not ideal. > > The snapshot process is very quick so the lock could be released almost > immediately. You could always configure bayes to use the sql database. From Q.G.Campbell at newcastle.ac.uk Mon May 21 11:39:01 2007 From: Q.G.Campbell at newcastle.ac.uk (Quentin Campbell) Date: Mon May 21 11:40:13 2007 Subject: Scalability of 'spam.whitelist.rules' facility In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBAB257D4@HC-MBX02.herefordshire.gov.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0CA0@largo.campus.ncl.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBAB257D4@HC-MBX02.herefordshire.gov.uk> Message-ID: <4165CF7A7F12DE4B96622CCBB90586470A4D0CFC@largo.campus.ncl.ac.uk> >-----Original Message----- >From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >bounces@lists.mailscanner.info] On Behalf Of Randal, Phil >Sent: 21 May 2007 10:49 >To: MailScanner discussion >Subject: RE: Scalability of 'spam.whitelist.rules' facility > >Is there no obvious pattern in the email addresses to be whitelisted? Phil Not usually. A large number may be from AOL or Yahoo accounts but I am not about to whitelist those domains! > >Or spamassassin rules they are falling foul of? As I said in my original mail we rely mostly now on the SA Bayesian filter score. If that gives a low score (<60% certainty, say) but a local rule pushes the score over the threshold then I will consider removing/modifying the local rule if its weighting is too aggressive. > >The problem with whitelisting "From:" email addresses is that this will >let in spams spoofing these from addresses. Rarely a problem with individual addresses but a problem if I whitelist domains such as 'ac.uk'. > >You should only really be using whitelist_from_rcvd, whitelist_from_spf, >whitelist_from_dkim etc in spamassassin. I was not aware of these features in SA. Not sure why they might help? Have not found SPF particularly useful given the very wide range of sources from which we receive genuine e-mail many of which do not advertise SPF records or they use 'softfail' when they do. > >Our spam.whitelist.rules only includes 127.0.0.1, nothing more. > >It looks like you're trying to work around another problem rather than >trying to address root causes. What problems do you think we are trying to address? The main problem is the rather informal or juvenile nature of the e-mail formats used by lots of young people corresponding with lots of other young people. Their messages tend to have some/lots of the characteristics of spam. That, coupled with the sending ISP perhaps being listed on one of the DNSBLs used by SA (_not_ the two DNSBLs we check during the SMTP exchange), makes it more likely that their messages achieve a score that is over the tagging threshold. Our recipients can usually set up a personal mail filter to catch mail from all their usual recipients whether MS tagged it or not. However they cannot be bothered to do this. Our Helpdesk staff who field all enquiries/complaints about false positives do not have the time to investigate each request to whitelist (more than 300 last week); they just add them to the file (using a web interface and CGI script I provide). Quentin --- PHONE: +44 191 222 8209 Information Systems and Services (ISS), Newcastle University, Newcastle upon Tyne, FAX: +44 191 222 8765 United Kingdom, NE1 7RU. ------------------------------------------------------------------ From martinh at solidstatelogic.com Mon May 21 11:47:14 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Mon May 21 11:47:29 2007 Subject: Scalability of 'spam.whitelist.rules' facility In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470A4D0CFC@largo.campus.ncl.ac.uk> Message-ID: Quentin What about whitelisting via domain-keys for yahoo? I've used this successfully. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Quentin Campbell > Sent: 21 May 2007 11:39 > To: MailScanner discussion > Subject: RE: Scalability of 'spam.whitelist.rules' facility > > >-----Original Message----- > >From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > >bounces@lists.mailscanner.info] On Behalf Of Randal, Phil > >Sent: 21 May 2007 10:49 > >To: MailScanner discussion > >Subject: RE: Scalability of 'spam.whitelist.rules' facility > > > >Is there no obvious pattern in the email addresses to be whitelisted? > > Phil > > Not usually. A large number may be from AOL or Yahoo accounts but I am > not about to whitelist those domains! > > > > >Or spamassassin rules they are falling foul of? > > As I said in my original mail we rely mostly now on the SA Bayesian > filter score. If that gives a low score (<60% certainty, say) but a > local rule pushes the score over the threshold then I will consider > removing/modifying the local rule if its weighting is too aggressive. > > > > >The problem with whitelisting "From:" email addresses is that this will > >let in spams spoofing these from addresses. > > Rarely a problem with individual addresses but a problem if I whitelist > domains such as 'ac.uk'. > > > > >You should only really be using whitelist_from_rcvd, > whitelist_from_spf, > >whitelist_from_dkim etc in spamassassin. > > I was not aware of these features in SA. Not sure why they might help? > > Have not found SPF particularly useful given the very wide range of > sources from which we receive genuine e-mail many of which do not > advertise SPF records or they use 'softfail' when they do. > > > > >Our spam.whitelist.rules only includes 127.0.0.1, nothing more. > > > >It looks like you're trying to work around another problem rather than > >trying to address root causes. > > What problems do you think we are trying to address? > > The main problem is the rather informal or juvenile nature of the e-mail > formats used by lots of young people corresponding with lots of other > young people. Their messages tend to have some/lots of the > characteristics of spam. That, coupled with the sending ISP perhaps > being listed on one of the DNSBLs used by SA (_not_ the two DNSBLs we > check during the SMTP exchange), makes it more likely that their > messages achieve a score that is over the tagging threshold. > > Our recipients can usually set up a personal mail filter to catch mail > from all their usual recipients whether MS tagged it or not. However > they cannot be bothered to do this. Our Helpdesk staff who field all > enquiries/complaints about false positives do not have the time to > investigate each request to whitelist (more than 300 last week); they > just add them to the file (using a web interface and CGI script I > provide). > > Quentin > --- > PHONE: +44 191 222 8209 Information Systems and Services (ISS), > Newcastle University, > Newcastle upon Tyne, > FAX: +44 191 222 8765 United Kingdom, NE1 7RU. > ------------------------------------------------------------------ > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From gmatt at nerc.ac.uk Mon May 21 12:49:22 2007 From: gmatt at nerc.ac.uk (Greg Matthews) Date: Mon May 21 12:49:37 2007 Subject: locking bayes? In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBAB257E5@HC-MBX02.herefordshire.gov.uk> References: <46516CA5.7040207@nerc.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBAB257E5@HC-MBX02.herefordshire.gov.uk> Message-ID: <46518742.6080105@nerc.ac.uk> Randal, Phil wrote: > Why not go for the simple and obvious solution: > > stop MailScanner > snapshot > restart MailScanner simple perhaps but not particularly elegant. > > Cheers, > > Phil -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford -- This message (and any attachments) is for the recipient only. NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. From sandrews at andrewscompanies.com Mon May 21 13:30:51 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Mon May 21 13:30:54 2007 Subject: Release 4.60.2 In-Reply-To: <46507BA0.2030206@ecs.soton.ac.uk> References: <46503750.50401@ecs.soton.ac.uk> <46507BA0.2030206@ecs.soton.ac.uk> Message-ID: <1964AAFBC212F742958F9275BF63DBB04B0A46@winchester.andrewscompanies.com> Didn't we have a beta list for this stuff specifically? -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian Field Sent: Sunday, May 20, 2007 12:47 PM To: MailScanner discussion Subject: Re: Release 4.60.2 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hugo van der Kooij wrote: > On Sun, 20 May 2007, Julian Field wrote: > >> I have just released another beta. > > Just a thought. Could you indicate in the subject line this is a beta > announcement? It would be easier to distinguish beta announcements > from the main announcements. > The main announcements always have "MailScanner ANNOUNCE" in the subject line. And they are (virtually) always at the start of the month. But I agree with you, I should put "beta" in the subject line somewhere. I will try to remember in future, Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGUHulEfZZRxQVtlQRAk3xAKCsUgm7N5bD04Gqy+pAK7hpLIFZqwCgq5AT +fnnrO3mzhaHxxFXvVCuq7E= =CpGv -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From dominian at slackadelic.com Mon May 21 13:46:00 2007 From: dominian at slackadelic.com (Matt Hayes) Date: Mon May 21 13:46:08 2007 Subject: SA not working in MS In-Reply-To: <4698.90.184.17.152.1179734533.squirrel@mail.fumlersoft.dk> References: <4698.90.184.17.152.1179734533.squirrel@mail.fumlersoft.dk> Message-ID: <46519488.7030204@slackadelic.com> Mogens Melander wrote: > Hi, > > Running on i686, Slackware 10 (2.4.26), MS 4.58.9-1, SA 3.2.0 > *snip* Mogens, Have a look at http://wiki.slackadelic.com/doku.php/howto:mailserver I wrote that tutorial using Slackware 11 and should be relevant to your issue. -Matt From dave.list at pixelhammer.com Mon May 21 13:45:07 2007 From: dave.list at pixelhammer.com (DAve) Date: Mon May 21 13:46:24 2007 Subject: way OT: add header (mailscanner) to be parsed by Outlook plugin for reporting false-negatives? In-Reply-To: <57573D714A832C43B9D80EAFBDA48D03057BDBA8@inex3.herffjones.hj-int> References: <57573D714A832C43B9D80EAFBDA48D03057BDBA8@inex3.herffjones.hj-int> Message-ID: <46519453.4070901@pixelhammer.com> Furnish, Trever G wrote: > Ok, sorry to go so far OT, but if you all can wax sentimental about > perforators and the Tardis, I this this ought to be ok. :-) I even > added a mailscanner function (adding a header to a processed message) to > make it slightly more ON-topic. > > I already have a modified MailWatch in place that let's users see their > quarantined mail and release messages one at a time, and I can easily > have MailScanner add a header to "ham" containing information to be > acted on by a user agent (Outlook). I'm wondering though, has anyone > put together an add-on for Outlook to allow easy "Report this message as > spam" functionality? I'd like my (Outlook) users to be able to report > spam that I've missed without having to leave the client to do so. > > I'd imagine it working like so: > For "ham", MS would add a header with uniquely identifiable info, such > as the message ID. When the message is viewed in Outlook, the user > would say, "Hey, this is missed spam!", and click a checkbox, which > would in turn causethis (as yet non-existant?) Outlook plugin to do > *something* (such as executing a program in another thread, quietly) > which would connect to my mailscanner system and report the message as > spam. > > I'm seriously considering writing such a plugin, but if anyone's already > done so or has a better solution, I'd rather avoid the wasted effort. Please don't, please. Currently that is how AOL works, anyone can determine for any reason that the message you sent them is spam. Next thing you know you get blocked, or greylisted, or stuck on a BL. You know they completed a double opt in, you have their response, you held the hoop for them to jump through, and still they mark it as Spam. The best part is AOL, Hotmail, Comcast, don't give a rat's A*& that you can prove the user chose to receive the mail. It's still Spam and weeeeeee on to the deferred list you go, you evil spammer. I spend several hours a month cleaning up behind users who think the "Spam" button is the cure for their ill, if more systems allowed users that power it will just make things worse. I have had the eye opening experience on two occasions to hear a degreed individual give the advice, "go ahead and sign up now and then mark it as Spam later". My wife has to keep sharp objects away from me when other people talk about email. DAve -- Three years now I've asked Google why they don't have a logo change for Memorial Day. Why do they choose to do logos for other non-international holidays, but nothing for Veterans? Maybe they forgot who made that choice possible. From Paul.Bijnens at xplanation.com Mon May 21 13:47:14 2007 From: Paul.Bijnens at xplanation.com (Paul Bijnens) Date: Mon May 21 13:47:18 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <464B2631.4060202@ecs.soton.ac.uk> References: <4649CA97.5050802@ecs.soton.ac.uk> <464B2631.4060202@ecs.soton.ac.uk> Message-ID: <465194D2.5060203@xplanation.com> On 2007-05-16 17:41, Julian Field wrote: > I'll put it in the main codebase then. Perl has some very subtle bugs in > it... I believe I don't need to teach perl to Julian (rather the other way around :-) ), but anyway... >>>> >>>>> # JKF 3/10/2005 >>>>> my $temp = @HitList; >>>>> $temp = $temp + 0; >>>>> $temp = 0 unless $HitList[0] =~ /a-z/i; >>>>> return ($temp, join(', ', @HitList)); >>>>> } >>>>> >>>>> Let's see if that helps. According to the book, the 2 middle lines >>>>> shouldn't be needed at all. To me this seems like the array @HitList contains an empty or undef value. The match against "/[a-z]/i" (or was that really intended "/a-z/i"??) just hides the source of the real error: getting an empty value for RBL name. Now finding out where the empty value is coming from, is -- at my current understanding of the code -- not yet successful. -- Paul Bijnens, xplanation Technology Services Tel +32 16 397.511 Technologielaan 21 bus 2, B-3001 Leuven, BELGIUM Fax +32 16 397.512 http://www.xplanation.com/ email: Paul.Bijnens@xplanation.com *********************************************************************** * I think I've got the hang of it now: exit, ^D, ^C, ^\, ^Z, ^Q, ^^, * * F6, quit, ZZ, :q, :q!, M-Z, ^X^C, logoff, logout, close, bye, /bye, * * stop, end, F3, ~., ^]c, +++ ATH, disconnect, halt, abort, hangup, * * PF4, F20, ^X^X, :D::D, KJOB, F14-f-e, F8-e, kill -1 $$, shutdown, * * init 0, kill -9 1, Alt-F4, Ctrl-Alt-Del, AltGr-NumLock, Stop-A, ... * * ... "Are you sure?" ... YES ... Phew ... I'm out * *********************************************************************** From hvdkooij at vanderkooij.org Mon May 21 13:51:53 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Mon May 21 13:52:28 2007 Subject: MailScanner on Centos 5: updated Message-ID: Hi, I am making some notes on how I am doing with the installation of MailScanner on Centos 5. In the process I needed to make a slight change to the perl-Filesys-Df package to make it work. There might be a better way to this but at least it got me a working package. The patch to the spec file is: --- perl-Filesys-Df.spec.OLD 2006-05-17 09:55:06.000000000 +0200 +++ perl-Filesys-Df.spec 2007-05-21 14:47:01.000000000 +0200 @@ -1,7 +1,7 @@ Summary: perl-Filesys-Df Perl module Name: perl-Filesys-Df Version: 0.90 -Release: 1 +Release: 2 Packager: mailscanner@ecs.soton.ac.uk License: GPL or Artistic Group: Development/Libraries @@ -35,6 +35,10 @@ [ -x /usr/lib/rpm/brp-compress ] && /usr/lib/rpm/brp-compress +# 2007-05-21 (HvdK) +rm $RPM_BUILD_ROOT/usr/lib/perl5/*/i386-linux-thread-multi/perllocal.pod +rm $RPM_BUILD_ROOT/usr/lib/perl5/site_perl/*/i386-linux-thread-multi/auto/Filesys/Df/.packlist + find $RPM_BUILD_ROOT/usr -type f -print | \ sed "s@^$RPM_BUILD_ROOT@@g" | \ grep -v perllocal.pod | \ @@ -48,6 +52,8 @@ %defattr(-,root,root) %changelog +* Mon May 21 2007 Hugo vand er Kooij +- Removed extra files not needed to package * Wed May 17 2006 Julian Field - Updated to use Filesys-Df version 0.90. * Sun Apr 16 2006 Julian Field Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From hvdkooij at vanderkooij.org Mon May 21 14:08:36 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Mon May 21 14:09:13 2007 Subject: MailScanner on Centos 5: updated In-Reply-To: References: Message-ID: On Mon, 21 May 2007, Hugo van der Kooij wrote: > I am making some notes on how I am doing with the installation of MailScanner > on Centos 5. Just checking old files and I needed to do a similar thing for Centos 4.4 Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From pedretti at eco.unibs.it Mon May 21 15:11:34 2007 From: pedretti at eco.unibs.it (Fabio Pedretti) Date: Mon May 21 15:08:09 2007 Subject: Fwd: Clamav suggestions post Message-ID: <20070521161134.mocmhn78qokocw4k@luna.eco.unibs.it> Forwarding Steve Basford comment to the list. ----- Messaggio inoltrato da steveb_clamav@sanesecurity.com ----- Data: Mon, 21 May 2007 14:04:58 +0100 (BST) Da: Steve Basford Rispondi-A:Steve Basford Oggetto: Clamav suggestions post A: pedretti@eco.unibs.it Hi, > No, in fact the string I have posted was taken from clamav signatures > and not sanesecurity signatures. > The problem is for all signatures that uses the "signature format #4" > (the signature for checking mail), as specified in signatures.pdf in > clamav source. Thanks correct! ALL type 4 sigs will not match unless there are some headers present in the file that is passed to Clamd for scanning: Look at the code: http://svn.clamav.net/websvn/filedetails.php?repname=clamav-devel&path=%2Ftrunk%2Flibclamav%2Ffiletypes.c&rev=0&sc=0 If any of the following are there... ClamAV knows it's a type 4 file being scanned: /* Mail */ {0, "From ", 5, "MBox", CL_TYPE_MAIL}, {0, "Received: ", 10, "Raw mail", CL_TYPE_MAIL}, {0, "Return-Path: ", 13, "Maildir", CL_TYPE_MAIL}, {0, "Return-path: ", 13, "Maildir", CL_TYPE_MAIL}, {0, "Delivered-To: ", 14, "Mail", CL_TYPE_MAIL}, {0, "X-UIDL: ", 8, "Mail", CL_TYPE_MAIL}, {0, "X-Apparently-To: ", 17, "Mail", CL_TYPE_MAIL}, {0, "X-Envelope-From: ", 17, "Mail", CL_TYPE_MAIL}, {0, "X-Original-To: ", 15, "Mail", CL_TYPE_MAIL}, {0, "X-Symantec-", 11, "Symantec", CL_TYPE_MAIL}, {0, "X-EVS", 5, "EVS mail", CL_TYPE_MAIL}, {0, "X-Real-To: ", 11, "Mail", CL_TYPE_MAIL}, {0, "X-Sieve: ", 9, "Mail", CL_TYPE_MAIL}, {0, ">From ", 6, "Mail", CL_TYPE_MAIL}, {0, "Date: ", 6, "Mail", CL_TYPE_MAIL}, {0, "Message-Id: ", 12, "Mail", CL_TYPE_MAIL}, {0, "Message-ID: ", 12, "Mail", CL_TYPE_MAIL}, {0, "Envelope-to: ", 13, "Mail", CL_TYPE_MAIL}, {0, "Delivery-date: ", 15, "Mail", CL_TYPE_MAIL}, {0, "To: ", 4, "Mail", CL_TYPE_MAIL}, {0, "Subject: ", 9, "Mail", CL_TYPE_MAIL}, {0, "For: ", 5, "Eserv mail", CL_TYPE_MAIL}, {0, "From: ", 6, "Exim mail", CL_TYPE_MAIL}, {0, "v:\015\012Received: ", 14, "VPOP3 Mail (DOS)", CL_TYPE_MAIL}, {0, "v:\012Received: ", 13, "VPOP3 Mail (UNIX)", CL_TYPE_MAIL}, {0, "Hi. This is the qmail-send", 26, "Qmail bounce", CL_TYPE_MAIL}, If you changed all the type 4 signatures to a type 0 (ALL files) you would get detection... but... in ALL files including word documents, jpgs, etc, etc. which isn't what you want. So, I would think for the best detection rates from the official ClamAV sigs and certainly from my Sanesecurity sigs... you HAVE to scan the whole email, including headers. Must of my image spam sigs will not work... UNLESS you have headers too :( Hope it helps, Steve Sanesecurity.com ----- Fine del messaggio inoltrato ----- From MailScanner at ecs.soton.ac.uk Mon May 21 15:39:58 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 21 15:41:40 2007 Subject: Scalability of 'spam.whitelist.rules' facility In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470A4D0CA0@largo.campus.ncl.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0CA0@largo.campus.ncl.ac.uk> Message-ID: <4651AF3E.3030205@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Quentin Campbell wrote: > Our 'spam.whitelist.rules' file currently has over 4,000 entries and is > growing at the rate of about 200-300 entries each week. > > At what point does the number of entries in the whitelist file become > 'too many' and impact the performance of MailScanner? > I would not advise more than about 1,000 entries in a ruleset. If you are doing more, then far better to have a little Custom Function that slurps in a db file at start time (and every "Restart Every" period) and just does a quick hash table lookup for each message. This would be hugely faster. If you set Restart Every = 3600 then it will re-read the whitelist every hour, which is probably frequent enough for most people most of the time, and makes it dead easy to implement. The only restriction would be that each whitelist entry was a complete email address or complete domain name. Also, would they all be "From" rules? Is that okay? If this is beyond your coding abilities, drop me a line off-list with as complete a spec as possible, including some examples lines from the input file you would use to hold the list. In return for my writing it for you, a donation of some sort would be much appreciated. :-) Jules. > If all of our users requested just one address each to be whitelisted > then 'spam.whitelist.rules' would have more than 20,000 entries! > > [The increase in requests to whitelist is probably because the recently > enabled Bayesian filter in SpamAssassin has had a significant impact on > increasing the amount of tagged spam but at the cost of an increase in > false positives.] > > Quentin > --- > PHONE: +44 191 222 8209 Information Systems and Services (ISS), > Newcastle University, > Newcastle upon Tyne, > FAX: +44 191 222 8765 United Kingdom, NE1 7RU. > ------------------------------------------------------------------ > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj4DBQFGUa92EfZZRxQVtlQRAkp3AJ9VNn4x62I5qyT6AhRJ/i3Fev+2KQCY1Hpp LC9gmquWx+GowNz8Ks+hTQ== =RfdV -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Mon May 21 15:47:10 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 21 15:51:52 2007 Subject: locking bayes? In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBAB257E5@HC-MBX02.herefordshire.gov.uk> References: <46516CA5.7040207@nerc.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBAB257E5@HC-MBX02.herefordshire.gov.uk> Message-ID: <4651B0EE.8090308@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 As opposed to actually stopping (ie shutting down) MailScanner, why not just suspend the processes? PID=`cat /var/run/MailScanner.pid` kill -STOP -$PID # Do your snapshot here kill -CONT -$PID Will Bayes survive that? Randal, Phil wrote: > Why not go for the simple and obvious solution: > > stop MailScanner > snapshot > restart MailScanner > > Cheers, > > Phil > -- > Phil Randal > Network Engineer > Herefordshire Council > Hereford, UK > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf >> Of Greg Matthews >> Sent: 21 May 2007 10:56 >> To: MailScanner discussion >> Subject: locking bayes? >> >> I have developed a shell script that takes uses LVM snapshots >> to backup >> volumes on a mail server. I am able to get a read-lock on the MySQL >> MailWatch table and was wondering if I could do the same with >> the bayes >> database to ensure it is consistent. >> >> At the moment, I am relying on the robustness of BerkeleyDB >> to be able >> to recover from a possibly inconsistent state. This is not ideal. >> >> The snapshot process is very quick so the lock could be >> released almost >> immediately. >> >> GREG >> -- >> Greg Matthews 01491 692445 >> Head of UNIX/Linux, iTSS Wallingford >> >> -- >> This message (and any attachments) is for the recipient only. NERC >> is subject to the Freedom of Information Act 2000 and the contents >> of this email and any reply you make may be disclosed by NERC unless >> it is exempt from release under the Act. Any material supplied to >> NERC may be stored in an electronic records management system. >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGUbHOEfZZRxQVtlQRAmjqAKDRmEfJbOhwow+j6a4K7s2Nj6ZGrgCg1dzn 3Ff/icCSgmh7QxK8FQ37pMg= =dun4 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Mon May 21 15:54:14 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 21 15:56:39 2007 Subject: Scalability of 'spam.whitelist.rules' facility In-Reply-To: <1179742709.30858.1.camel@gblades-suse.linguaphone-intranet.co.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0CA0@largo.campus.ncl.ac.uk> <23cdb2cad6f2304fb039e2baabc521ac@62.49.223.244> <1179742709.30858.1.camel@gblades-suse.linguaphone-intranet.co.uk> Message-ID: <4651B296.5030509@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Gareth wrote: > On Mon, 2007-05-21 at 10:35, Res wrote: > >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> On Mon, 21 May 2007, --[ UxBoD ]-- wrote: >> >> >>> Why not migrate them to MySQL and use the SQLBlackWhiteList.pm that is >>> available from the MailWatch package ? >>> >> This might be fine on low loaded systems, but to do a lookup for every >> email on major networks would fail, as sql would not keep up unless you >> clustered and nobody is going to do that just for whitelisting. >> >> I've seen it with vpopmail for instance the cdb file can handle over 6000 >> concurrent connections with no ill affect, sql spits farts and dies at >> 1/5th of that value unless you cluster, so it's a pointless expense. >> > > It doesn't work like that though. When the mailscanner instance starts > the code loads the contents of the black/whitelist into memory and then > checks to see if any changes have been made every 15 minutes. > MailWatch might do that, but MailScanner doesn't. Since every rule can be an arbitrary regular expression, each and every rule must be checked against the addressing information of each message. You can't just do a quick lookup. This is why slurping it into a hash table is faster, so long as you can impose the restriction that every rule is only a complete email address or a complete domain name. Imposing the artificial restriction enables you to greatly optimise the way you can look up the rules for each message. The MailScanner configuration compiler does not (yet) include such as optimisation. But it does contain the means for you to be able to write your own (Custom Functions). > This reduces the load on the sql server but of course does increase > memory usage and the startup time for the mailscanner process. > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGUbL6EfZZRxQVtlQRAs63AJ9NtSVKA6aSLL5sQndvNpjPAMgvrgCgp1rX ykkla3gC4LlzXN/otuTRZNs= =SoUv -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Mon May 21 15:58:49 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 21 16:02:09 2007 Subject: Release 4.60.2 In-Reply-To: <1964AAFBC212F742958F9275BF63DBB04B0A46@winchester.andrewscompanies.com> References: <46503750.50401@ecs.soton.ac.uk> <46507BA0.2030206@ecs.soton.ac.uk> <1964AAFBC212F742958F9275BF63DBB04B0A46@winchester.andrewscompanies.com> Message-ID: <4651B3A9.1000809@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Yes, but I post announcements of betas to the beta list and the main list. The last thing I want to do is to restrict the number of people who try betas to only those on the beta list (there are only a few on it). If people feel like replying to both lists, then they can. Most of the discussion takes place on the beta list, I don't think a bit of overspill causes any problem. Steven Andrews wrote: > Didn't we have a beta list for this stuff specifically? > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian > Field > Sent: Sunday, May 20, 2007 12:47 PM > To: MailScanner discussion > Subject: Re: Release 4.60.2 > > > * PGP Bad Signature, Signed by an unverified key: 05/20/07 at 17:47:33 > > > > Hugo van der Kooij wrote: > >> On Sun, 20 May 2007, Julian Field wrote: >> >> >>> I have just released another beta. >>> >> Just a thought. Could you indicate in the subject line this is a beta >> announcement? It would be easier to distinguish beta announcements >> from the main announcements. >> >> > The main announcements always have "MailScanner ANNOUNCE" in the subject > line. And they are (virtually) always at the start of the month. But I > agree with you, I should put "beta" in the subject line somewhere. I > will try to remember in future, > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all > your IT requirements visit www.transtec.co.uk > > > > * Julian Field > * 0x1415B654 - Unverified(L) > > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGUbQmEfZZRxQVtlQRAv4RAKCGTILx06BZXrwrZ+3IwmuLmdvr8ACff3SL convnzJWeD0W/8YoUnxU2IE= =dxwG -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From gmatt at nerc.ac.uk Mon May 21 16:02:52 2007 From: gmatt at nerc.ac.uk (Greg Matthews) Date: Mon May 21 16:03:02 2007 Subject: locking bayes? In-Reply-To: <4651B0EE.8090308@ecs.soton.ac.uk> References: <46516CA5.7040207@nerc.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBAB257E5@HC-MBX02.herefordshire.gov.uk> <4651B0EE.8090308@ecs.soton.ac.uk> Message-ID: <4651B49C.7000002@nerc.ac.uk> Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > As opposed to actually stopping (ie shutting down) MailScanner, why not > just suspend the processes? > > PID=`cat /var/run/MailScanner.pid` > kill -STOP -$PID > # Do your snapshot here > kill -CONT -$PID without testing it (my dev box is currently in the middle of testing something else) I would expect to have to hang around waiting for the child processes to finish or will they all be "stopped" too? > > Will Bayes survive that? I dont think it will be much different from taking a snap of the live database as presumably it could still be inconsistent, ie partial commits etc. ah nevermind... dont think its that important! G -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford -- This message (and any attachments) is for the recipient only. NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. From MailScanner at ecs.soton.ac.uk Mon May 21 16:10:08 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 21 16:12:09 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <465194D2.5060203@xplanation.com> References: <4649CA97.5050802@ecs.soton.ac.uk> <464B2631.4060202@ecs.soton.ac.uk> <465194D2.5060203@xplanation.com> Message-ID: <4651B64F.4070901@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Paul Bijnens wrote: > On 2007-05-16 17:41, Julian Field wrote: > >> I'll put it in the main codebase then. Perl has some very subtle bugs in >> it... >> > > I believe I don't need to teach perl to Julian (rather the other way > around :-) ), but anyway... > > >>>>> >>>>> >>>>>> # JKF 3/10/2005 >>>>>> my $temp = @HitList; >>>>>> $temp = $temp + 0; >>>>>> $temp = 0 unless $HitList[0] =~ /a-z/i; >>>>>> return ($temp, join(', ', @HitList)); >>>>>> } >>>>>> >>>>>> Let's see if that helps. According to the book, the 2 middle lines >>>>>> shouldn't be needed at all. >>>>>> > > To me this seems like the array @HitList contains an empty or undef > value. The match against "/[a-z]/i" (or was that really intended > "/a-z/i"??) No, your version would match against any string that contained the string "a-z" in it (in upper or lower case). > just hides the source of the real error: getting an empty > value for RBL name. > If I printed the string of @HitList it turned out to have no contents, so the scalar of it should have been zero. I have seen the problem of "0" not always equaling zero a few other times, hence the addition of zero to it to try to fix it, which has normally fixed the problem elsewhere. The new modification has only been recently needed, the code has worked perfectly well for years (the previous version was very old code). If it had been needed before, people would have been complaining loudly about this for the past few years, and they haven't been. So if the start of the list doesn't contain a letter (all RBL names must contain at least 1 letter or they wouldn't work) then the list must actually be empty, so I force it to return zero. > Now finding out where the empty value is coming from, is -- at my > current understanding of the code -- not yet successful. > Yes. I have another demo of a Perl bug which I'll post for you if you like. Perl is not bug-free. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGUbZ+EfZZRxQVtlQRAtNTAJ9GxR/uO9U18R2XYP+0pXP8ZpdvcQCfVfgX vhTJwQ8OECaV+S2h8XD6pIE= =93yr -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From gdoris at rogers.com Mon May 21 16:11:50 2007 From: gdoris at rogers.com (Gerry Doris) Date: Mon May 21 16:12:17 2007 Subject: Release 4.60.2 In-Reply-To: <46503750.50401@ecs.soton.ac.uk> References: <46503750.50401@ecs.soton.ac.uk> Message-ID: <4651B6B6.1010405@rogers.com> Something appears to have happened to your ClamAV/SpamAssassin tarballs. I'm getting a "can't find the file" message when I click on the website link for them. Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > I have just released another beta. > I have updated a whole load of the required Perl modules, and have added > a command-line option > --nomodules > which will stop it installing the required Perl modules, should you wish > to do that. > > I have also fixed a whole bunch of bugs in the installer, so it > shouldn't overwrite modules with older ones, which was happening in a > few cases. > > Download as usual from www.mailscanner.info. > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: ISO-8859-1 > > wj8DBQFGUDdWEfZZRxQVtlQRAjRoAKCEo4hMuvzD6qW9n65RPcwBy3mg7ACg28jS > lszMrqePEF33syo5oG9uFkI= > =ZKo6 > -----END PGP SIGNATURE----- > From doc at maddoc.net Mon May 21 16:14:43 2007 From: doc at maddoc.net (Doc Schneider) Date: Mon May 21 16:14:48 2007 Subject: Rules fixed Message-ID: <4651B763.2090908@maddoc.net> Just wanted to let you all know I have fixed the various SARE rules which were causing issues with SpamAssassin 3.2.0 and perl < 5.8.8 Please let me know if you still see this issue happening. Thanks! -- -Doc Lincoln, NE. http://www.genealogyforyou.com/ http://www.cairnproductions.com/ From mkettler at evi-inc.com Mon May 21 16:26:21 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Mon May 21 16:26:30 2007 Subject: locking bayes? In-Reply-To: <46518742.6080105@nerc.ac.uk> References: <46516CA5.7040207@nerc.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBAB257E5@HC-MBX02.herefordshire.gov.uk> <46518742.6080105@nerc.ac.uk> Message-ID: <4651BA1D.1090603@evi-inc.com> Greg Matthews wrote: > Randal, Phil wrote: >> Why not go for the simple and obvious solution: >> >> stop MailScanner >> snapshot >> restart MailScanner > > simple perhaps but not particularly elegant. True, but if you stop MailScaner without stopping the inbound/outbound sendmails, this would be quite reasonable. All you'd be stopping is the scanning of mail. This way the sendmails would continue to accept inbound messages and deliver already scanned messages. ie: on a redhatish box: service MailScanner stopms service MailScanner start (at present there's no startms, but this should work) From steve.swaney at fsl.com Mon May 21 16:34:14 2007 From: steve.swaney at fsl.com (Stephen Swaney) Date: Mon May 21 16:32:21 2007 Subject: Rules fixed In-Reply-To: <4651B763.2090908@maddoc.net> References: <4651B763.2090908@maddoc.net> Message-ID: <1ea401c79bbd$7d01c260$77054720$@swaney@fsl.com> Doc, Can you install on mta30.fsl.com and also check out the SA 3.2 install there as well. Thanks, Steve Steve Swaney steve@fsl.com > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Doc Schneider > Sent: Monday, May 21, 2007 11:15 AM > To: MailScanner discussion > Subject: Rules fixed > > Just wanted to let you all know I have fixed the various SARE rules > which were causing issues with SpamAssassin 3.2.0 and perl < 5.8.8 > > Please let me know if you still see this issue happening. > > Thanks! > -- > -Doc > Lincoln, NE. > http://www.genealogyforyou.com/ > http://www.cairnproductions.com/ > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From ssilva at sgvwater.com Mon May 21 16:51:03 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 21 16:51:26 2007 Subject: Release 4.60.2 In-Reply-To: <4651B6B6.1010405@rogers.com> References: <46503750.50401@ecs.soton.ac.uk> <4651B6B6.1010405@rogers.com> Message-ID: Gerry Doris spake the following on 5/21/2007 8:11 AM: > Something appears to have happened to your ClamAV/SpamAssassin tarballs. > I'm getting a "can't find the file" message when I click on the website > link for them. > > Seems to be working now. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From gmatt at nerc.ac.uk Mon May 21 16:02:52 2007 From: gmatt at nerc.ac.uk (Greg Matthews) Date: Mon May 21 16:55:50 2007 Subject: locking bayes? In-Reply-To: <4651B0EE.8090308@ecs.soton.ac.uk> References: <46516CA5.7040207@nerc.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBAB257E5@HC-MBX02.herefordshire.gov.uk> <4651B0EE.8090308@ecs.soton.ac.uk> Message-ID: <4651B49C.7000002@nerc.ac.uk> Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > As opposed to actually stopping (ie shutting down) MailScanner, why not > just suspend the processes? > > PID=`cat /var/run/MailScanner.pid` > kill -STOP -$PID > # Do your snapshot here > kill -CONT -$PID without testing it (my dev box is currently in the middle of testing something else) I would expect to have to hang around waiting for the child processes to finish or will they all be "stopped" too? > > Will Bayes survive that? I dont think it will be much different from taking a snap of the live database as presumably it could still be inconsistent, ie partial commits etc. ah nevermind... dont think its that important! G -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford -- This message (and any attachments) is for the recipient only. NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. From gmatt at nerc.ac.uk Mon May 21 16:56:29 2007 From: gmatt at nerc.ac.uk (Greg Matthews) Date: Mon May 21 16:56:39 2007 Subject: [Fwd: wtf? (WAS: Re: locking bayes?)] Message-ID: <4651C12D.7020601@nerc.ac.uk> now resent the mangled mail. -- Greg Matthews 01491 692445 Head of UNIX/Linux, iTSS Wallingford -- This message (and any attachments) is for the recipient only. NERC is subject to the Freedom of Information Act 2000 and the contents of this email and any reply you make may be disclosed by NERC unless it is exempt from release under the Act. Any material supplied to NERC may be stored in an electronic records management system. -------------- next part -------------- An embedded message was scrubbed... From: Greg Matthews Subject: wtf? (WAS: Re: locking bayes?) Date: Mon, 21 May 2007 16:53:03 +0100 Size: 2803 Url: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070521/dbff742f/lockingbayes.mht From doc at maddoc.net Mon May 21 17:07:46 2007 From: doc at maddoc.net (Doc Schneider) Date: Mon May 21 17:07:50 2007 Subject: Rules fixed In-Reply-To: <1ea401c79bbd$7d01c260$77054720$@swaney@fsl.com> References: <4651B763.2090908@maddoc.net> <1ea401c79bbd$7d01c260$77054720$@swaney@fsl.com> Message-ID: <4651C3D2.6070309@maddoc.net> No errors anymore from mta30.fsl.com !! Everything seems to be there for SA 3.2.0 and it even compiles cleanly now. 8*) Stephen Swaney wrote: > Doc, > > Can you install on mta30.fsl.com and also check out the SA 3.2 install there > as well. > > Thanks, > > Steve > > Steve Swaney > steve@fsl.com > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Doc Schneider >> Sent: Monday, May 21, 2007 11:15 AM >> To: MailScanner discussion >> Subject: Rules fixed >> >> Just wanted to let you all know I have fixed the various SARE rules >> which were causing issues with SpamAssassin 3.2.0 and perl < 5.8.8 >> >> Please let me know if you still see this issue happening. >> >> Thanks! >> -- >> -Doc >> Lincoln, NE. >> http://www.genealogyforyou.com/ >> http://www.cairnproductions.com/ >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! > -- -Doc Lincoln, NE. http://www.genealogyforyou.com/ http://www.cairnproductions.com/ From gdoris at rogers.com Mon May 21 17:14:15 2007 From: gdoris at rogers.com (Gerry Doris) Date: Mon May 21 17:14:34 2007 Subject: Release 4.60.2 In-Reply-To: References: <46503750.50401@ecs.soton.ac.uk> <4651B6B6.1010405@rogers.com> Message-ID: <4651C557.2050502@rogers.com> Scott Silva wrote: > Gerry Doris spake the following on 5/21/2007 8:11 AM: >> Something appears to have happened to your ClamAV/SpamAssassin tarballs. >> I'm getting a "can't find the file" message when I click on the website >> link for them. >> >> > Seems to be working now. > Strange, it still isn't working for me??? I was able to download and install the new beta version of MailScanner but I can't find the tarball for the updated SpamAssassin and ClamAV. I'll try some different things and see what happens. From ecasarero at gmail.com Mon May 21 17:34:30 2007 From: ecasarero at gmail.com (Eduardo Casarero) Date: Mon May 21 17:34:33 2007 Subject: 2 recpientis with diferent spam.actions Message-ID: <7d9b3cf20705210934v255ee625wab058bc28a29d4b5@mail.gmail.com> Hi, i need your advice, one of my users told me that a email with the spam tag did not stay in quarantine and was deliver to his inbox. Checking the email, it was a mail with 2 recpients one belongs to 1 domain that has an spam action 'store,deliver,header' and the other recipient just 'store,header'. Checking the Mailscanner.conf i found the parameter 'Use Default Rules With Multiple Recipients' that is set to 'no' . The comments on mailscanner.confsays that if you set 'no' it will match the first rule aviable and exit. is that correct? Should i put 'yes'?? Thanks!!! Eduardo. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070521/84085f65/attachment.html From hvdkooij at vanderkooij.org Mon May 21 17:35:11 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Mon May 21 17:35:51 2007 Subject: Release 4.60.2 In-Reply-To: <4651B3A9.1000809@ecs.soton.ac.uk> References: <46503750.50401@ecs.soton.ac.uk> <46507BA0.2030206@ecs.soton.ac.uk> <1964AAFBC212F742958F9275BF63DBB04B0A46@winchester.andrewscompanies.com> <4651B3A9.1000809@ecs.soton.ac.uk> Message-ID: On Mon, 21 May 2007, Julian Field wrote: > Yes, but I post announcements of betas to the beta list and the main > list. The last thing I want to do is to restrict the number of people > who try betas to only those on the beta list (there are only a few on > it). If people feel like replying to both lists, then they can. Most of > the discussion takes place on the beta list, I don't think a bit of > overspill causes any problem. I like to keep be informed of the beta releases but may not test them. But if a new feature or fix sound promising I might run a Beta on one of the servers. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From hvdkooij at vanderkooij.org Mon May 21 17:40:18 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Mon May 21 17:40:53 2007 Subject: Release 4.60.2 In-Reply-To: <4651B6B6.1010405@rogers.com> References: <46503750.50401@ecs.soton.ac.uk> <4651B6B6.1010405@rogers.com> Message-ID: On Mon, 21 May 2007, Gerry Doris wrote: > Something appears to have happened to your ClamAV/SpamAssassin tarballs. I'm > getting a "can't find the file" message when I click on the website link for > them. Just for fun. Can you tell me which exact page (URL) you are on? It seems that google had some obsolete pages at the top of the list. It bit me just recently when I did follow google hits instead of going to the website and following the menu. That would explain your trouble to download some files. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From MailScanner at ecs.soton.ac.uk Mon May 21 17:59:27 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 21 18:01:57 2007 Subject: locking bayes? In-Reply-To: <4651BA1D.1090603@evi-inc.com> References: <46516CA5.7040207@nerc.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBAB257E5@HC-MBX02.herefordshire.gov.uk> <46518742.6080105@nerc.ac.uk> <4651BA1D.1090603@evi-inc.com> Message-ID: <4651CFEF.4010100@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Matt Kettler wrote: > Greg Matthews wrote: > >> Randal, Phil wrote: >> >>> Why not go for the simple and obvious solution: >>> >>> stop MailScanner >>> snapshot >>> restart MailScanner >>> >> simple perhaps but not particularly elegant. >> > > True, but if you stop MailScaner without stopping the inbound/outbound > sendmails, this would be quite reasonable. All you'd be stopping is the scanning > of mail. > > This way the sendmails would continue to accept inbound messages and deliver > already scanned messages. > > ie: on a redhatish box: > > service MailScanner stopms > > service MailScanner start > > (at present there's no startms, but this should work) > "check_MailScanner" should do as a replacement for the "service MailScanner start" command. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGUdBGEfZZRxQVtlQRAt/YAJ9zf/16zoYqNUJGHYHOAyr4976hpwCgjnwq H3wrZZtVqLAOtaBmIPIiY9E= =v/8m -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Mon May 21 18:03:03 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 21 18:03:18 2007 Subject: Release 4.60.2 In-Reply-To: <4651C557.2050502@rogers.com> References: <46503750.50401@ecs.soton.ac.uk> <4651B6B6.1010405@rogers.com> <4651C557.2050502@rogers.com> Message-ID: Gerry Doris spake the following on 5/21/2007 9:14 AM: > Scott Silva wrote: >> Gerry Doris spake the following on 5/21/2007 8:11 AM: >>> Something appears to have happened to your ClamAV/SpamAssassin tarballs. >>> I'm getting a "can't find the file" message when I click on the website >>> link for them. >>> >>> >> Seems to be working now. >> > > Strange, it still isn't working for me??? I was able to download and > install the new beta version of MailScanner but I can't find the tarball > for the updated SpamAssassin and ClamAV. > > I'll try some different things and see what happens. Is this the link you see? http://www.mailscanner.info/files/4/install-Clam-0.90.2-SA-3.2.0.tar.gz -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From MailScanner at ecs.soton.ac.uk Mon May 21 18:03:04 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 21 18:03:51 2007 Subject: Release 4.60.2 In-Reply-To: References: <46503750.50401@ecs.soton.ac.uk> <4651B6B6.1010405@rogers.com> Message-ID: <4651D0C8.3040602@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hugo van der Kooij wrote: > On Mon, 21 May 2007, Gerry Doris wrote: > >> Something appears to have happened to your ClamAV/SpamAssassin >> tarballs. I'm getting a "can't find the file" message when I click >> on the website link for them. > > Just for fun. Can you tell me which exact page (URL) you are on? > > It seems that google had some obsolete pages at the top of the list. > It bit me just recently when I did follow google hits instead of going > to the website and following the menu. Google had its "Download" link pointing to downloads.shtml and not .html. So I just deleted the .shtml and made it a soft link to the .html. So any difference in the files you are seeing now is your web browser's cache being old. > > That would explain your trouble to download some files. > > Hugo. > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGUdDMEfZZRxQVtlQRAjhcAKC5d9EJg81O/Uj1xPAktPCoiOrFfACglCpj 7thNxwH+7+k/TY8PPMyf5CI= =8Jeb -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Mon May 21 18:04:49 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 21 18:10:34 2007 Subject: 2 recpientis with diferent spam.actions In-Reply-To: <7d9b3cf20705210934v255ee625wab058bc28a29d4b5@mail.gmail.com> References: <7d9b3cf20705210934v255ee625wab058bc28a29d4b5@mail.gmail.com> Message-ID: Eduardo Casarero spake the following on 5/21/2007 9:34 AM: > Hi, i need your advice, one of my users told me that a email with the > spam tag did not stay in quarantine and was deliver to his inbox. > Checking the email, it was a mail with 2 recpients one belongs to 1 > domain that has an spam action 'store,deliver,header' and the other > recipient just 'store,header'. > > Checking the Mailscanner.conf i found the parameter 'Use Default Rules > With Multiple Recipients' that is set to 'no' . The comments on > mailscanner.conf says that if you set 'no' it will match the first rule > aviable and exit. is that correct? Should i put 'yes'?? > > Thanks!!! > > Eduardo. > You need to split messages for multiple recipients if you want it to work reliably. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From Kevin_Miller at ci.juneau.ak.us Mon May 21 18:17:59 2007 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Mon May 21 18:17:44 2007 Subject: Archiving non-spam Message-ID: I've been toying with the idea of archiving incoming mail (non-spam). My MailScanner box is just a gateway and forwards non-spam on to our Exchange server. I've been thinking it would be a good idea to have it store inbound non-spam for a couple weeks to a month, in case the Exchange server goes south for some reason. That way, no mail would be lost between the time of the last backup and the time of the last rites (and whenever Exchange gets restored). I've got a couple questions on doing so though. Right now, the Archive Mail setting is as follows: #Archive Mail = /var/spool/MailScanner/archive Archive Mail = Will mail be archived if I simply uncomment the path (and, of course, comment out the null path)? Or will I have to add the store command in the Non Spam actions? Is /var/spool/MailScanner/archive the default and doesn't need to be uncommented or must it be explicitly set? The comment in the Non Spam Actions says "# store - store the message in the quarantine" Is the word "quarantine" a copy/paste carry over from the Spam Actions comments? Or will the messages be stored in quarantine? I'd expect they'd end up in /var/spool/MailScanner/archive. I've been quarantining spam for some time, and was looking at the messages in there and noticed that the headers and body were combined - they weren't in sendmail format. I expect that archived mail will be stored the same way. I can easily release a quarantined message with MailWatch w/o having to worry about the storage format but I'm not not sure how to do the same with archived mail. I was hoping I could just move all the messages back to /var/spool/mqueue.in but since they're not in df/qf format I doubt that will work. How does one get them back in sendmail format. Mostly I'd be doing this in a batch - i.e., thousands of messages, not one or two at a time. Finally, the quarantined messages are stored in directories named by date (i.e. 20070521) - will archive do the same thing or will I have to use the _DATE_ string? Any issues with modifying the /etc/cron.daily/clean.quarantine script to get rid of archives older than X days? Thanks much... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From Paul.Bijnens at xplanation.com Mon May 21 18:28:01 2007 From: Paul.Bijnens at xplanation.com (Paul Bijnens) Date: Mon May 21 18:28:05 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <4651B64F.4070901@ecs.soton.ac.uk> References: <4649CA97.5050802@ecs.soton.ac.uk> <464B2631.4060202@ecs.soton.ac.uk> <465194D2.5060203@xplanation.com> <4651B64F.4070901@ecs.soton.ac.uk> Message-ID: <4651D6A1.4000506@xplanation.com> On 2007-05-21 17:10, Julian Field wrote: > > > Paul Bijnens wrote: >> On 2007-05-16 17:41, Julian Field wrote: > >>> I'll put it in the main codebase then. Perl has some very subtle bugs in >>> it... >>> >> I believe I don't need to teach perl to Julian (rather the other way >> around :-) ), but anyway... > > >>>>>> >>>>>> >>>>>>> # JKF 3/10/2005 >>>>>>> my $temp = @HitList; >>>>>>> $temp = $temp + 0; >>>>>>> $temp = 0 unless $HitList[0] =~ /a-z/i; >>>>>>> return ($temp, join(', ', @HitList)); >>>>>>> } >>>>>>> >>>>>>> Let's see if that helps. According to the book, the 2 middle lines >>>>>>> shouldn't be needed at all. >>>>>>> >> To me this seems like the array @HitList contains an empty or undef >> value. The match against "/[a-z]/i" (or was that really intended >> "/a-z/i"??) > No, your version would match against any string that contained the > string "a-z" in it (in upper or lower case). Excuse me :-) but "/a-z/i" is your version and that will search for a string "a-z" lower or upper case. My version, "/[a-z]/i", will match a name with at least one letter in it. Which is what you're trying to do, I believe. You're effectively removing any RBL hits now, which is the main reason why no more FP's got hit by the current beta tester(-s? -- only one person as far I see had the problem). http://lists.mailscanner.info/pipermail/mailscanner/2007-May/073331.html I'm still interested in the exact list of RBLs in his config. Does it happen when 1 list is added? Two? Some particular list only? >> just hides the source of the real error: getting an empty >> value for RBL name. > > If I printed the string of @HitList it turned out to have no contents, How? Something like: @HitList = ( "" ); # somehow this ended up in the list $temp = @HitList; warn("HitList contains $temp entries: '@HitList'\n"); No (visible) contents, but still one element in the array. > so the scalar of it should have been zero. I have seen the problem of > "0" not always equaling zero a few other times, hence the addition of > zero to it to try to fix it, which has normally fixed the problem You can have that problem with "" or undef, acting as 0 in calculations but not showing up as a "0" when printed. Indeed fixed by explicitly converting to number by adding "+ 0". > elsewhere. The new modification has only been recently needed, the code > has worked perfectly well for years (the previous version was very old > code). If it had been needed before, people would have been complaining > loudly about this for the past few years, and they haven't been. So if > the start of the list doesn't contain a letter (all RBL names must > contain at least 1 letter or they wouldn't work) then the list must > actually be empty, so I force it to return zero. So we have to find out where the list element comes from that does not contain a letter, but is empty instead. Instead of covering up the bug here. (Still not convinced it is a perl bug.) Maybe most people use some RBLs at the MTA-level to block the incoming mail completely and/or use other RBLs in SA for scoring, and let the spam list entry in MailScanner empty. Or the bug happens only on a timeout, like suggested in the OP problem, or only for certain combinations of timeout values, etc, etc. > >> Now finding out where the empty value is coming from, is -- at my >> current understanding of the code -- not yet successful. > > Yes. I have another demo of a Perl bug which I'll post for you if you > like. Perl is not bug-free. Sure not. But, speaking for myself, it's usually in my own programs, and not in the perl compiler, that I find the bugs. :-) -- Paul Bijnens, xplanation Technology Services Tel +32 16 397.511 Technologielaan 21 bus 2, B-3001 Leuven, BELGIUM Fax +32 16 397.512 http://www.xplanation.com/ email: Paul.Bijnens@xplanation.com *********************************************************************** * I think I've got the hang of it now: exit, ^D, ^C, ^\, ^Z, ^Q, ^^, * * F6, quit, ZZ, :q, :q!, M-Z, ^X^C, logoff, logout, close, bye, /bye, * * stop, end, F3, ~., ^]c, +++ ATH, disconnect, halt, abort, hangup, * * PF4, F20, ^X^X, :D::D, KJOB, F14-f-e, F8-e, kill -1 $$, shutdown, * * init 0, kill -9 1, Alt-F4, Ctrl-Alt-Del, AltGr-NumLock, Stop-A, ... * * ... "Are you sure?" ... YES ... Phew ... I'm out * *********************************************************************** From ecasarero at gmail.com Mon May 21 18:45:32 2007 From: ecasarero at gmail.com (Eduardo Casarero) Date: Mon May 21 18:45:36 2007 Subject: 2 recpientis with diferent spam.actions In-Reply-To: References: <7d9b3cf20705210934v255ee625wab058bc28a29d4b5@mail.gmail.com> Message-ID: <7d9b3cf20705211045o7f7905das94d9abe8cf9dbf74@mail.gmail.com> 2007/5/21, Scott Silva : > > Eduardo Casarero spake the following on 5/21/2007 9:34 AM: > > Hi, i need your advice, one of my users told me that a email with the > > spam tag did not stay in quarantine and was deliver to his inbox. > > Checking the email, it was a mail with 2 recpients one belongs to 1 > > domain that has an spam action 'store,deliver,header' and the other > > recipient just 'store,header'. > > > > Checking the Mailscanner.conf i found the parameter 'Use Default Rules > > With Multiple Recipients' that is set to 'no' . The comments on > > mailscanner.conf says that if you set 'no' it will match the first rule > > aviable and exit. is that correct? Should i put 'yes'?? > > > > Thanks!!! > > > > Eduardo. > > > You need to split messages for multiple recipients if you want it to work > reliably. the splitting is done at mta level? -- > > MailScanner is like deodorant... > You hope everybody uses it, and > you notice quickly if they don't!!!! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070521/52b1e8d6/attachment.html From ssilva at sgvwater.com Mon May 21 18:52:32 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 21 18:52:48 2007 Subject: Archiving non-spam In-Reply-To: References: Message-ID: Kevin Miller spake the following on 5/21/2007 10:17 AM: > I've been toying with the idea of archiving incoming mail (non-spam). > My MailScanner box is just a gateway and forwards non-spam on to our > Exchange server. I've been thinking it would be a good idea to have it > store inbound non-spam for a couple weeks to a month, in case the > Exchange server goes south for some reason. That way, no mail would be > lost between the time of the last backup and the time of the last rites > (and whenever Exchange gets restored). I've got a couple questions on > doing so though. > > Right now, the Archive Mail setting is as follows: > #Archive Mail = /var/spool/MailScanner/archive > Archive Mail = > > Will mail be archived if I simply uncomment the path (and, of course, > comment out the null path)? Or will I have to add the store command in > the Non Spam actions? Using this setting will archive ALL mail (ham, spam, high spam). If you only want to store non spam you could add a "store" directive to your non-spam actions. If you use Mailwatch, this works good, as it will be stored along with any spam you archive. > > Is /var/spool/MailScanner/archive the default and doesn't need to be > uncommented or must it be explicitly set? > > The comment in the Non Spam Actions says > "# store - store the message in the quarantine" > > Is the word "quarantine" a copy/paste carry over from the Spam Actions > comments? Or will the messages be stored in quarantine? I'd expect > they'd end up in /var/spool/MailScanner/archive. The store directive will store in quarantine, under a nonspam directory. > > I've been quarantining spam for some time, and was looking at the > messages in there and noticed that the headers and body were combined - > they weren't in sendmail format. I expect that archived mail will be > stored the same way. I can easily release a quarantined message with > MailWatch w/o having to worry about the storage format but I'm not not > sure how to do the same with archived mail. I was hoping I could just > move all the messages back to /var/spool/mqueue.in but since they're not > in df/qf format I doubt that will work. How does one get them back in > sendmail format. Mostly I'd be doing this in a batch - i.e., thousands > of messages, not one or two at a time. You could forward all the nonspam to a separate account, and use an IMAP client to move the mails from one place to another. > > Finally, the quarantined messages are stored in directories named by > date (i.e. 20070521) - will archive do the same thing or will I have to > use the _DATE_ string? Any issues with modifying the > /etc/cron.daily/clean.quarantine script to get rid of archives older > than X days? Archive needs the data setting to split by date. The conf file has the examples for the different choices for the archive mail setting. > > Thanks much... > > ...Kevin -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From gdoris at rogers.com Mon May 21 19:00:32 2007 From: gdoris at rogers.com (Gerry Doris) Date: Mon May 21 19:01:57 2007 Subject: Release 4.60.2 In-Reply-To: References: <46503750.50401@ecs.soton.ac.uk> <4651B6B6.1010405@rogers.com> <4651C557.2050502@rogers.com> Message-ID: <4651DE40.9000607@rogers.com> Scott Silva wrote: > Gerry Doris spake the following on 5/21/2007 9:14 AM: >> Scott Silva wrote: >>> Gerry Doris spake the following on 5/21/2007 8:11 AM: >>>> Something appears to have happened to your ClamAV/SpamAssassin tarballs. >>>> I'm getting a "can't find the file" message when I click on the website >>>> link for them. >>>> >>>> >>> Seems to be working now. >>> >> Strange, it still isn't working for me??? I was able to download and >> install the new beta version of MailScanner but I can't find the tarball >> for the updated SpamAssassin and ClamAV. >> >> I'll try some different things and see what happens. > Is this the link you see? > http://www.mailscanner.info/files/4/install-Clam-0.90.2-SA-3.2.0.tar.gz > > > I have no idea why Firefox is having this problem. I've closed and restarted it. This is the message I'm getting... Firefox can't find the file at /files/4/install-Clam-0.90.2-SA-3.2.0.tar.gz. I'm logged onto www.mailscanner.info (clicked on the link in Julian's email) and have selected the tarball link. However, I tried the exact same thing with IE (I'm using my work laptop which only has XP on it) and had no problems downloading the file. I think it must be one of those "windows" things. I haven't rebooted since yesterday so I'm WAY overdue! From ssilva at sgvwater.com Mon May 21 19:11:57 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 21 19:12:19 2007 Subject: Release 4.60.2 In-Reply-To: <4651DE40.9000607@rogers.com> References: <46503750.50401@ecs.soton.ac.uk> <4651B6B6.1010405@rogers.com> <4651C557.2050502@rogers.com> <4651DE40.9000607@rogers.com> Message-ID: > I have no idea why Firefox is having this problem. I've closed and > restarted it. This is the message I'm getting... > > Firefox can't find the file at > /files/4/install-Clam-0.90.2-SA-3.2.0.tar.gz. > > > I'm logged onto www.mailscanner.info (clicked on the link in Julian's > email) and have selected the tarball link. > > However, I tried the exact same thing with IE (I'm using my work laptop > which only has XP on it) and had no problems downloading the file. I > think it must be one of those "windows" things. I haven't rebooted > since yesterday so I'm WAY overdue! I'm also using Firefox on an XP pc. I can see the link, and download most of it until my virus scanner sees the eicar test file in it and stops it. But I usually wget the files from an ssh session on the servers, so I don't usually care if my virus scanner catches it. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Mon May 21 19:13:26 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 21 19:15:14 2007 Subject: 2 recpientis with diferent spam.actions In-Reply-To: <7d9b3cf20705211045o7f7905das94d9abe8cf9dbf74@mail.gmail.com> References: <7d9b3cf20705210934v255ee625wab058bc28a29d4b5@mail.gmail.com> <7d9b3cf20705211045o7f7905das94d9abe8cf9dbf74@mail.gmail.com> Message-ID: Eduardo Casarero spake the following on 5/21/2007 10:45 AM: > > > 2007/5/21, Scott Silva >: > > Eduardo Casarero spake the following on 5/21/2007 9:34 AM: > > Hi, i need your advice, one of my users told me that a email with the > > spam tag did not stay in quarantine and was deliver to his inbox. > > Checking the email, it was a mail with 2 recpients one belongs to 1 > > domain that has an spam action 'store,deliver,header' and the other > > recipient just 'store,header'. > > > > Checking the Mailscanner.conf i found the parameter 'Use Default > Rules > > With Multiple Recipients' that is set to 'no' . The comments on > > mailscanner.conf says that if you set 'no' it will match the first > rule > > aviable and exit. is that correct? Should i put 'yes'?? > > > > Thanks!!! > > > > Eduardo. > > > You need to split messages for multiple recipients if you want it to > work > reliably. > > > the splitting is done at mta level? Yes. There are howto's on the wiki for sendmail and postfix AFAIR. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From uxbod at splatnix.net Mon May 21 19:18:17 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Mon May 21 19:18:21 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <4651D6A1.4000506@xplanation.com> References: <4651D6A1.4000506@xplanation.com> Message-ID: Even with just using one RBL I was getting non-spam items marked as SPAM. When I made the change it marked SPAM messages correctly. On Mon, 21 May 2007 19:28:01 +0200, Paul Bijnens wrote: > On 2007-05-21 17:10, Julian Field wrote: >> >> >> Paul Bijnens wrote: >>> On 2007-05-16 17:41, Julian Field wrote: >> >>>> I'll put it in the main codebase then. Perl has some very subtle bugs > in >>>> it... >>>> >>> I believe I don't need to teach perl to Julian (rather the other way >>> around :-) ), but anyway... >> >> >>>>>>> >>>>>>> >>>>>>>> # JKF 3/10/2005 >>>>>>>> my $temp = @HitList; >>>>>>>> $temp = $temp + 0; >>>>>>>> $temp = 0 unless $HitList[0] =~ /a-z/i; >>>>>>>> return ($temp, join(', ', @HitList)); >>>>>>>> } >>>>>>>> >>>>>>>> Let's see if that helps. According to the book, the 2 middle lines >>>>>>>> shouldn't be needed at all. >>>>>>>> >>> To me this seems like the array @HitList contains an empty or undef >>> value. The match against "/[a-z]/i" (or was that really intended >>> "/a-z/i"??) >> No, your version would match against any string that contained the >> string "a-z" in it (in upper or lower case). > > Excuse me :-) but "/a-z/i" is your version and that will search for > a string "a-z" lower or upper case. My version, "/[a-z]/i", will match > a name with at least one letter in it. Which is what you're trying to > do, I believe. > You're effectively removing any RBL hits now, which is the main reason > why no more FP's got hit by the current beta tester(-s? -- only one > person as far I see had the problem). > > http://lists.mailscanner.info/pipermail/mailscanner/2007-May/073331.html > > I'm still interested in the exact list of RBLs in his config. > Does it happen when 1 list is added? Two? Some particular list only? > > >>> just hides the source of the real error: getting an empty >>> value for RBL name. >> >> If I printed the string of @HitList it turned out to have no contents, > > How? Something like: > > @HitList = ( "" ); # somehow this ended up in the list > $temp = @HitList; > warn("HitList contains $temp entries: '@HitList'\n"); > > No (visible) contents, but still one element in the array. > > >> so the scalar of it should have been zero. I have seen the problem of >> "0" not always equaling zero a few other times, hence the addition of >> zero to it to try to fix it, which has normally fixed the problem > > You can have that problem with "" or undef, acting as 0 in calculations > but not showing up as a "0" when printed. Indeed fixed by explicitly > converting to number by adding "+ 0". > >> elsewhere. The new modification has only been recently needed, the code >> has worked perfectly well for years (the previous version was very old >> code). If it had been needed before, people would have been complaining >> loudly about this for the past few years, and they haven't been. So if >> the start of the list doesn't contain a letter (all RBL names must >> contain at least 1 letter or they wouldn't work) then the list must >> actually be empty, so I force it to return zero. > > So we have to find out where the list element comes from that does > not contain a letter, but is empty instead. Instead of covering up the > bug here. (Still not convinced it is a perl bug.) > Maybe most people use some RBLs at the MTA-level to block the incoming > mail completely and/or use other RBLs in SA for scoring, and let the > spam list entry in MailScanner empty. Or the bug happens only on > a timeout, like suggested in the OP problem, or only for certain > combinations of timeout values, etc, etc. > > >> >>> Now finding out where the empty value is coming from, is -- at my >>> current understanding of the code -- not yet successful. >> >> Yes. I have another demo of a Perl bug which I'll post for you if you >> like. Perl is not bug-free. > > Sure not. But, speaking for myself, it's usually in my own > programs, and not in the perl compiler, that I find the bugs. :-) > > > -- > Paul Bijnens, xplanation Technology Services Tel +32 16 397.511 > Technologielaan 21 bus 2, B-3001 Leuven, BELGIUM Fax +32 16 397.512 > http://www.xplanation.com/ email: Paul.Bijnens@xplanation.com > *********************************************************************** > * I think I've got the hang of it now: exit, ^D, ^C, ^\, ^Z, ^Q, ^^, * > * F6, quit, ZZ, :q, :q!, M-Z, ^X^C, logoff, logout, close, bye, /bye, * > * stop, end, F3, ~., ^]c, +++ ATH, disconnect, halt, abort, hangup, * > * PF4, F20, ^X^X, :D::D, KJOB, F14-f-e, F8-e, kill -1 $$, shutdown, * > * init 0, kill -9 1, Alt-F4, Ctrl-Alt-Del, AltGr-NumLock, Stop-A, ... * > * ... "Are you sure?" ... YES ... Phew ... I'm out * > *********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From Kevin_Miller at ci.juneau.ak.us Mon May 21 19:30:55 2007 From: Kevin_Miller at ci.juneau.ak.us (Kevin Miller) Date: Mon May 21 19:30:40 2007 Subject: Archiving non-spam In-Reply-To: References: Message-ID: Scott Silva wrote: > Using this setting will archive ALL mail (ham, spam, high spam). Nope, don't want that! > If you only want to store non spam you could add a "store" directive > to your non-spam actions. If you use Mailwatch, this works good, as > it will be stored along with any spam you archive. OK - did that and it's working a treat. > The store directive will store in quarantine, under a nonspam > directory. I'm seeing the non-spam turning up in the MailWatch quarantine page now. That's fine - I presume that the current processes to clean the quarantined spam directories will also do the non-spam directories? I've got that set to 30 days at the moment - be nice to be able to manage both spam and non-spam seperately but in this case it looks like I can't. Oh well. > You could forward all the nonspam to a separate account, and use an > IMAP client to move the mails from one place to another. Hmmm. Not sure I follow that. With hundreds of users the goal is to be able to just drop them into the MTA's queue and let it get them where they need to go. Thanks Scott... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 From paul.bijnens at xplanation.com Mon May 21 20:03:57 2007 From: paul.bijnens at xplanation.com (Paul Bijnens) Date: Mon May 21 20:04:11 2007 Subject: FPs and SA 3.2.0 In-Reply-To: References: <4651D6A1.4000506@xplanation.com> Message-ID: <4651ED1D.3080007@xplanation.com> --[ UxBoD ]-- wrote: > Even with just using one RBL I was getting non-spam items marked as SPAM. > When I made the change it marked SPAM messages correctly. Don't be silly. So you added this line; $temp = 0 unless $HitList[0] =~ /a-z/i; And you did NOT add this line: $temp = 0 unless $HitList[0] =~ /[a-z]/i; and afterwards you get a correct (non-empty, but no FP) list of RBLs? What RBL did such a "marked SPAM message" got hit on? The list "spamhaus-A-Z" maybe? Or you mean that the SPAM messages were no false positives anymore? (Answer: Because SA had marked it like that, not because MailScanner found it in a spam list added in MailScanner.conf having the string "a-z".) Read and understand before you reply! Please! > On Mon, 21 May 2007 19:28:01 +0200, Paul Bijnens > wrote: >> On 2007-05-21 17:10, Julian Field wrote: >>> >>> Paul Bijnens wrote: >>>> On 2007-05-16 17:41, Julian Field wrote: >>>>> I'll put it in the main codebase then. Perl has some very subtle bugs >> in >>>>> it... >>>>> >>>> I believe I don't need to teach perl to Julian (rather the other way >>>> around :-) ), but anyway... >>> >>>>>>>> >>>>>>>>> # JKF 3/10/2005 >>>>>>>>> my $temp = @HitList; >>>>>>>>> $temp = $temp + 0; >>>>>>>>> $temp = 0 unless $HitList[0] =~ /a-z/i; >>>>>>>>> return ($temp, join(', ', @HitList)); >>>>>>>>> } >>>>>>>>> >>>>>>>>> Let's see if that helps. According to the book, the 2 middle lines >>>>>>>>> shouldn't be needed at all. >>>>>>>>> >>>> To me this seems like the array @HitList contains an empty or undef >>>> value. The match against "/[a-z]/i" (or was that really intended >>>> "/a-z/i"??) >>> No, your version would match against any string that contained the >>> string "a-z" in it (in upper or lower case). >> Excuse me :-) but "/a-z/i" is your version and that will search for >> a string "a-z" lower or upper case. My version, "/[a-z]/i", will match >> a name with at least one letter in it. Which is what you're trying to >> do, I believe. >> You're effectively removing any RBL hits now, which is the main reason >> why no more FP's got hit by the current beta tester(-s? -- only one >> person as far I see had the problem). >> >> http://lists.mailscanner.info/pipermail/mailscanner/2007-May/073331.html >> >> I'm still interested in the exact list of RBLs in his config. >> Does it happen when 1 list is added? Two? Some particular list only? >> >> >>>> just hides the source of the real error: getting an empty >>>> value for RBL name. >>> If I printed the string of @HitList it turned out to have no contents, >> How? Something like: >> >> @HitList = ( "" ); # somehow this ended up in the list >> $temp = @HitList; >> warn("HitList contains $temp entries: '@HitList'\n"); >> >> No (visible) contents, but still one element in the array. >> >> >>> so the scalar of it should have been zero. I have seen the problem of >>> "0" not always equaling zero a few other times, hence the addition of >>> zero to it to try to fix it, which has normally fixed the problem >> You can have that problem with "" or undef, acting as 0 in calculations >> but not showing up as a "0" when printed. Indeed fixed by explicitly >> converting to number by adding "+ 0". >> >>> elsewhere. The new modification has only been recently needed, the code >>> has worked perfectly well for years (the previous version was very old >>> code). If it had been needed before, people would have been complaining >>> loudly about this for the past few years, and they haven't been. So if >>> the start of the list doesn't contain a letter (all RBL names must >>> contain at least 1 letter or they wouldn't work) then the list must >>> actually be empty, so I force it to return zero. >> So we have to find out where the list element comes from that does >> not contain a letter, but is empty instead. Instead of covering up the >> bug here. (Still not convinced it is a perl bug.) >> Maybe most people use some RBLs at the MTA-level to block the incoming >> mail completely and/or use other RBLs in SA for scoring, and let the >> spam list entry in MailScanner empty. Or the bug happens only on >> a timeout, like suggested in the OP problem, or only for certain >> combinations of timeout values, etc, etc. >> >> >>>> Now finding out where the empty value is coming from, is -- at my >>>> current understanding of the code -- not yet successful. >>> Yes. I have another demo of a Perl bug which I'll post for you if you >>> like. Perl is not bug-free. >> Sure not. But, speaking for myself, it's usually in my own >> programs, and not in the perl compiler, that I find the bugs. :-) -- Paul Bijnens, xplanation Technology Services Tel +32 16 397.511 Technologielaan 21 bus 2, B-3001 Leuven, BELGIUM Fax +32 16 397.512 http://www.xplanation.com/ email: Paul.Bijnens@xplanation.com *********************************************************************** * I think I've got the hang of it now: exit, ^D, ^C, ^\, ^Z, ^Q, ^^, * * F6, quit, ZZ, :q, :q!, M-Z, ^X^C, logoff, logout, close, bye, /bye, * * stop, end, F3, ~., ^]c, +++ ATH, disconnect, halt, abort, hangup, * * PF4, F20, ^X^X, :D::D, KJOB, F14-f-e, F8-e, kill -1 $$, shutdown, * * init 0, kill -9 1, Alt-F4, Ctrl-Alt-Del, AltGr-NumLock, Stop-A, ... * * ... "Are you sure?" ... YES ... Phew ... I'm out * *********************************************************************** From uxbod at splatnix.net Mon May 21 20:26:50 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Mon May 21 20:26:54 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <4651ED1D.3080007@xplanation.com> References: <4651ED1D.3080007@xplanation.com> Message-ID: Calm down Paul ;) Right lets go back to the beginning. I noticed that a huge amount of email was being marked within MailWatch as listed in RBL, yet in the rules summary no RBLs were actually being reported. At first I thought it was down to my list of RBLs I was using within MailScanner.conf. Therefore I tried one at a time and got the same result. Thinking back I even set Spam List = and got the same result. At this point I posted my question to the list, and Jules asked me to give the code change a try. As soon as I made the change and restarted MS I no longer saw this situation. I understand Perl to a degree myself, and have myself seen what can happen when using a undefined variable to compare against. At the end of the day it has resolved a issue for us. If I have misunderstood then so be it, but all I can do is report my personal findings. Regards, On Mon, 21 May 2007 21:03:57 +0200, Paul Bijnens wrote: > --[ UxBoD ]-- wrote: >> Even with just using one RBL I was getting non-spam items marked as > SPAM. >> When I made the change it marked SPAM messages correctly. > > Don't be silly. > > So you added this line; > $temp = 0 unless $HitList[0] =~ /a-z/i; > And you did NOT add this line: > $temp = 0 unless $HitList[0] =~ /[a-z]/i; > > and afterwards you get a correct (non-empty, but no FP) list of RBLs? > What RBL did such a "marked SPAM message" got hit on? > The list "spamhaus-A-Z" maybe? > > Or you mean that the SPAM messages were no false positives anymore? > (Answer: Because SA had marked it like that, not because MailScanner > found it in a spam list added in MailScanner.conf having the string > "a-z".) > > Read and understand before you reply! Please! > > > >> On Mon, 21 May 2007 19:28:01 +0200, Paul Bijnens >> wrote: >>> On 2007-05-21 17:10, Julian Field wrote: >>>> >>>> Paul Bijnens wrote: >>>>> On 2007-05-16 17:41, Julian Field wrote: >>>>>> I'll put it in the main codebase then. Perl has some very subtle > bugs >>> in >>>>>> it... >>>>>> >>>>> I believe I don't need to teach perl to Julian (rather the other way >>>>> around :-) ), but anyway... >>>> >>>>>>>>> >>>>>>>>>> # JKF 3/10/2005 >>>>>>>>>> my $temp = @HitList; >>>>>>>>>> $temp = $temp + 0; >>>>>>>>>> $temp = 0 unless $HitList[0] =~ /a-z/i; >>>>>>>>>> return ($temp, join(', ', @HitList)); >>>>>>>>>> } >>>>>>>>>> >>>>>>>>>> Let's see if that helps. According to the book, the 2 middle > lines >>>>>>>>>> shouldn't be needed at all. >>>>>>>>>> >>>>> To me this seems like the array @HitList contains an empty or undef >>>>> value. The match against "/[a-z]/i" (or was that really intended >>>>> "/a-z/i"??) >>>> No, your version would match against any string that contained the >>>> string "a-z" in it (in upper or lower case). >>> Excuse me :-) but "/a-z/i" is your version and that will search for >>> a string "a-z" lower or upper case. My version, "/[a-z]/i", will match >>> a name with at least one letter in it. Which is what you're trying to >>> do, I believe. >>> You're effectively removing any RBL hits now, which is the main reason >>> why no more FP's got hit by the current beta tester(-s? -- only one >>> person as far I see had the problem). >>> >>> > http://lists.mailscanner.info/pipermail/mailscanner/2007-May/073331.html >>> >>> I'm still interested in the exact list of RBLs in his config. >>> Does it happen when 1 list is added? Two? Some particular list only? >>> >>> >>>>> just hides the source of the real error: getting an empty >>>>> value for RBL name. >>>> If I printed the string of @HitList it turned out to have no contents, >>> How? Something like: >>> >>> @HitList = ( "" ); # somehow this ended up in the list >>> $temp = @HitList; >>> warn("HitList contains $temp entries: '@HitList'\n"); >>> >>> No (visible) contents, but still one element in the array. >>> >>> >>>> so the scalar of it should have been zero. I have seen the problem of >>>> "0" not always equaling zero a few other times, hence the addition of >>>> zero to it to try to fix it, which has normally fixed the problem >>> You can have that problem with "" or undef, acting as 0 in calculations >>> but not showing up as a "0" when printed. Indeed fixed by explicitly >>> converting to number by adding "+ 0". >>> >>>> elsewhere. The new modification has only been recently needed, the > code >>>> has worked perfectly well for years (the previous version was very old >>>> code). If it had been needed before, people would have been > complaining >>>> loudly about this for the past few years, and they haven't been. So if >>>> the start of the list doesn't contain a letter (all RBL names must >>>> contain at least 1 letter or they wouldn't work) then the list must >>>> actually be empty, so I force it to return zero. >>> So we have to find out where the list element comes from that does >>> not contain a letter, but is empty instead. Instead of covering up the >>> bug here. (Still not convinced it is a perl bug.) >>> Maybe most people use some RBLs at the MTA-level to block the incoming >>> mail completely and/or use other RBLs in SA for scoring, and let the >>> spam list entry in MailScanner empty. Or the bug happens only on >>> a timeout, like suggested in the OP problem, or only for certain >>> combinations of timeout values, etc, etc. >>> >>> >>>>> Now finding out where the empty value is coming from, is -- at my >>>>> current understanding of the code -- not yet successful. >>>> Yes. I have another demo of a Perl bug which I'll post for you if you >>>> like. Perl is not bug-free. >>> Sure not. But, speaking for myself, it's usually in my own >>> programs, and not in the perl compiler, that I find the bugs. :-) > > > -- > Paul Bijnens, xplanation Technology Services Tel +32 16 397.511 > Technologielaan 21 bus 2, B-3001 Leuven, BELGIUM Fax +32 16 397.512 > http://www.xplanation.com/ email: Paul.Bijnens@xplanation.com > *********************************************************************** > * I think I've got the hang of it now: exit, ^D, ^C, ^\, ^Z, ^Q, ^^, * > * F6, quit, ZZ, :q, :q!, M-Z, ^X^C, logoff, logout, close, bye, /bye, * > * stop, end, F3, ~., ^]c, +++ ATH, disconnect, halt, abort, hangup, * > * PF4, F20, ^X^X, :D::D, KJOB, F14-f-e, F8-e, kill -1 $$, shutdown, * > * init 0, kill -9 1, Alt-F4, Ctrl-Alt-Del, AltGr-NumLock, Stop-A, ... * > * ... "Are you sure?" ... YES ... Phew ... I'm out * > *********************************************************************** > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From sandrews at andrewscompanies.com Mon May 21 20:35:56 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Mon May 21 20:36:02 2007 Subject: Release 4.60.2 In-Reply-To: <4651B3A9.1000809@ecs.soton.ac.uk> References: <46503750.50401@ecs.soton.ac.uk> <46507BA0.2030206@ecs.soton.ac.uk><1964AAFBC212F742958F9275BF63DBB04B0A46@winchester.andrewscompanies.com> <4651B3A9.1000809@ecs.soton.ac.uk> Message-ID: <1964AAFBC212F742958F9275BF63DBB04B0A66@winchester.andrewscompanies.com> Is that beta list still active? I haven't had anything on it since February. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian Field Sent: Monday, May 21, 2007 10:59 AM To: MailScanner discussion Subject: Re: Release 4.60.2 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Yes, but I post announcements of betas to the beta list and the main list. The last thing I want to do is to restrict the number of people who try betas to only those on the beta list (there are only a few on it). If people feel like replying to both lists, then they can. Most of the discussion takes place on the beta list, I don't think a bit of overspill causes any problem. Steven Andrews wrote: > Didn't we have a beta list for this stuff specifically? > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of > Julian Field > Sent: Sunday, May 20, 2007 12:47 PM > To: MailScanner discussion > Subject: Re: Release 4.60.2 > > > * PGP Bad Signature, Signed by an unverified key: 05/20/07 at 17:47:33 > > > > Hugo van der Kooij wrote: > >> On Sun, 20 May 2007, Julian Field wrote: >> >> >>> I have just released another beta. >>> >> Just a thought. Could you indicate in the subject line this is a beta >> announcement? It would be easier to distinguish beta announcements >> from the main announcements. >> >> > The main announcements always have "MailScanner ANNOUNCE" in the > subject line. And they are (virtually) always at the start of the > month. But I agree with you, I should put "beta" in the subject line > somewhere. I will try to remember in future, > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For > all your IT requirements visit www.transtec.co.uk > > > > * Julian Field > * 0x1415B654 - Unverified(L) > > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGUbQmEfZZRxQVtlQRAv4RAKCGTILx06BZXrwrZ+3IwmuLmdvr8ACff3SL convnzJWeD0W/8YoUnxU2IE= =dxwG -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Mon May 21 21:23:40 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 21 21:26:45 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <4651D6A1.4000506@xplanation.com> References: <4649CA97.5050802@ecs.soton.ac.uk> <464B2631.4060202@ecs.soton.ac.uk> <465194D2.5060203@xplanation.com> <4651B64F.4070901@ecs.soton.ac.uk> <4651D6A1.4000506@xplanation.com> Message-ID: <4651FFCC.804@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Paul Bijnens wrote: > On 2007-05-21 17:10, Julian Field wrote: > >> Paul Bijnens wrote: >> >>> On 2007-05-16 17:41, Julian Field wrote: >>> >>>> I'll put it in the main codebase then. Perl has some very subtle bugs in >>>> it... >>>> >>>> >>> I believe I don't need to teach perl to Julian (rather the other way >>> around :-) ), but anyway... >>> >> >>>>>>> >>>>>>> >>>>>>> >>>>>>>> # JKF 3/10/2005 >>>>>>>> my $temp = @HitList; >>>>>>>> $temp = $temp + 0; >>>>>>>> $temp = 0 unless $HitList[0] =~ /a-z/i; >>>>>>>> return ($temp, join(', ', @HitList)); >>>>>>>> } >>>>>>>> >>>>>>>> Let's see if that helps. According to the book, the 2 middle lines >>>>>>>> shouldn't be needed at all. >>>>>>>> >>>>>>>> >>> To me this seems like the array @HitList contains an empty or undef >>> value. The match against "/[a-z]/i" (or was that really intended >>> "/a-z/i"??) >>> >> No, your version would match against any string that contained the >> string "a-z" in it (in upper or lower case). >> > > Excuse me :-) but "/a-z/i" is your version and that will search for > a string "a-z" lower or upper case. My version, "/[a-z]/i", will match > a name with at least one letter in it. Which is what you're trying to > do, I believe. > It appears I owe you a rather large apology :-( Sorry! Many thanks for pointing out the error in my code. I have fixed it and put out a new beta with it fixed. > You're effectively removing any RBL hits now, which is the main reason > why no more FP's got hit by the current beta tester(-s? -- only one > person as far I see had the problem). > > http://lists.mailscanner.info/pipermail/mailscanner/2007-May/073331.html > > I'm still interested in the exact list of RBLs in his config. > Does it happen when 1 list is added? Two? Some particular list only? > > > >>> just hides the source of the real error: getting an empty >>> value for RBL name. >>> >> If I printed the string of @HitList it turned out to have no contents, >> > > How? Something like: > > @HitList = ( "" ); # somehow this ended up in the list > $temp = @HitList; > warn("HitList contains $temp entries: '@HitList'\n"); > > No (visible) contents, but still one element in the array. > > > >> so the scalar of it should have been zero. I have seen the problem of >> "0" not always equaling zero a few other times, hence the addition of >> zero to it to try to fix it, which has normally fixed the problem >> > > You can have that problem with "" or undef, acting as 0 in calculations > but not showing up as a "0" when printed. Indeed fixed by explicitly > converting to number by adding "+ 0". > > >> elsewhere. The new modification has only been recently needed, the code >> has worked perfectly well for years (the previous version was very old >> code). If it had been needed before, people would have been complaining >> loudly about this for the past few years, and they haven't been. So if >> the start of the list doesn't contain a letter (all RBL names must >> contain at least 1 letter or they wouldn't work) then the list must >> actually be empty, so I force it to return zero. >> > > So we have to find out where the list element comes from that does > not contain a letter, but is empty instead. Instead of covering up the > bug here. (Still not convinced it is a perl bug.) > Maybe most people use some RBLs at the MTA-level to block the incoming > mail completely and/or use other RBLs in SA for scoring, and let the > spam list entry in MailScanner empty. Or the bug happens only on > a timeout, like suggested in the OP problem, or only for certain > combinations of timeout values, etc, etc. > > > >>> Now finding out where the empty value is coming from, is -- at my >>> current understanding of the code -- not yet successful. >>> >> Yes. I have another demo of a Perl bug which I'll post for you if you >> like. Perl is not bug-free. >> > > Sure not. But, speaking for myself, it's usually in my own > programs, and not in the perl compiler, that I find the bugs. :-) > Agreed. But I have found the '$n=$n+0' trick solve a few problems in the past. Bugs that appeared on 1 user's system that I could not reproduce on my own systems. Adding 0 fixed it. But yes, on the other hand, they have been rare (I think there's 2 in the whole of MailScanner, the most annoying was the spam score returned by SpamAssassin. It was generating 'not spam' reports where it clearly printed a spam score greater than the threshold. Add 0 to the number and then do the comparison again, and it produced the desired result.) Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGUgBVEfZZRxQVtlQRAuCSAKCPzzlzxJyUfJ1FqdtlwMQZhBKbwgCgphdD DHyakLVp1DOcumPj8mJk/rs= =5mpG -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From mkettler at evi-inc.com Mon May 21 21:27:53 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Mon May 21 21:28:06 2007 Subject: locking bayes? In-Reply-To: <4651CFEF.4010100@ecs.soton.ac.uk> References: <46516CA5.7040207@nerc.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBAB257E5@HC-MBX02.herefordshire.gov.uk> <46518742.6080105@nerc.ac.uk> <4651BA1D.1090603@evi-inc.com> <4651CFEF.4010100@ecs.soton.ac.uk> Message-ID: <465200C9.4010304@evi-inc.com> Julian Field wrote: > > "check_MailScanner" should do as a replacement for the "service > MailScanner start" command. Hi Julian! Would that get rid of /var/lock/subsys/MailScanner.off and create /var/lock/check_Mailscanner.lock ? Otherwise, that would start MailScanner, but the cron-job checker wouldn't function properly.. From MailScanner at ecs.soton.ac.uk Mon May 21 21:36:37 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 21 21:37:33 2007 Subject: Release 4.60.2 In-Reply-To: <1964AAFBC212F742958F9275BF63DBB04B0A66@winchester.andrewscompanies.com> References: <46503750.50401@ecs.soton.ac.uk> <46507BA0.2030206@ecs.soton.ac.uk><1964AAFBC212F742958F9275BF63DBB04B0A46@winchester.andrewscompanies.com> <4651B3A9.1000809@ecs.soton.ac.uk> <1964AAFBC212F742958F9275BF63DBB04B0A66@winchester.andrewscompanies.com> Message-ID: <465202D5.1020608@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Most definitely. There have been quite a few posts in the last few days. I have just checked, you are still subscribed. Problem is probably your end, I (and others) are getting the list postings okay. Steven Andrews wrote: > Is that beta list still active? I haven't had anything on it since > February. > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian > Field > Sent: Monday, May 21, 2007 10:59 AM > To: MailScanner discussion > Subject: Re: Release 4.60.2 > > > * PGP Bad Signature, Signed by an unverified key: 05/21/07 at 16:00:54 > > Yes, but I post announcements of betas to the beta list and the main > list. The last thing I want to do is to restrict the number of people > who try betas to only those on the beta list (there are only a few on > it). If people feel like replying to both lists, then they can. Most of > the discussion takes place on the beta list, I don't think a bit of > overspill causes any problem. > > Steven Andrews wrote: > >> Didn't we have a beta list for this stuff specifically? >> >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of >> Julian Field >> Sent: Sunday, May 20, 2007 12:47 PM >> To: MailScanner discussion >> Subject: Re: Release 4.60.2 >> >> >> >>> Old Bad Signature, Signed by an unverified key: 05/20/07 at 17:47:33 >>> >> >> Hugo van der Kooij wrote: >> >> >>> On Sun, 20 May 2007, Julian Field wrote: >>> >>> >>> >>>> I have just released another beta. >>>> >>>> >>> Just a thought. Could you indicate in the subject line this is a beta >>> > > >>> announcement? It would be easier to distinguish beta announcements >>> from the main announcements. >>> >>> >>> >> The main announcements always have "MailScanner ANNOUNCE" in the >> subject line. And they are (virtually) always at the start of the >> month. But I agree with you, I should put "beta" in the subject line >> somewhere. I will try to remember in future, >> >> Jules >> >> -- >> Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> MailScanner customisation, or any advanced system administration help? >> Contact me at Jules@Jules.FM >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For >> all your IT requirements visit www.transtec.co.uk >> >> >> >> * Julian Field >> * 0x1415B654 - Unverified(L) >> >> >> -- >> This message has been scanned for viruses and dangerous content by >> MailScanner, and is believed to be clean. >> For all your IT requirements visit www.transtec.co.uk >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all > your IT requirements visit www.transtec.co.uk > > > > * Julian Field > * 0x1415B654 - Unverified(L) > > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGUgLiEfZZRxQVtlQRAiWPAJkB4kVnAVlekxpz+yllx2koZBYJ6QCgjjyi L7H9+58EMuBA4IH56fLb2xE= =XGLA -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From res at ausics.net Mon May 21 22:12:12 2007 From: res at ausics.net (Res) Date: Tue May 22 00:41:12 2007 Subject: Release 4.60.2 In-Reply-To: <4651B3A9.1000809@ecs.soton.ac.uk> References: <46503750.50401@ecs.soton.ac.uk> <46507BA0.2030206@ecs.soton.ac.uk> <1964AAFBC212F742958F9275BF63DBB04B0A46@winchester.andrewscompanies.com> <4651B3A9.1000809@ecs.soton.ac.uk> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Mon, 21 May 2007, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Yes, but I post announcements of betas to the beta list and the main > list. The last thing I want to do is to restrict the number of people > who try betas to only those on the beta list (there are only a few on > it). If people feel like replying to both lists, then they can. Most of > the discussion takes place on the beta list, I don't think a bit of > overspill causes any problem. Agreed, the wider the testing of various installs/MTA's/OS's the better it is for everyone, all of the beta testers have a wide variety of OS's and MTA's, but we cant cover them all and theres bound to be those on this list who have unusual setups and no matter how small the issue, its still an issue Julian would rather not have in existance and they can help by bringing it up. > > Steven Andrews wrote: >> Didn't we have a beta list for this stuff specifically? >> - -- Cheers Res Vote for your favourite Operating System: http://polls.ausics.net/v1.php -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGUgsusWhAmSIQh7MRAsyxAJ4+7ru6xhDH5hqUy29kYSmuh0i9fQCcDH1t thmNBwi8hWXEx91t6gC4QMg= =rwR7 -----END PGP SIGNATURE----- From cparker at swatgear.com Tue May 22 00:45:18 2007 From: cparker at swatgear.com (Chris W. Parker) Date: Tue May 22 00:48:08 2007 Subject: MailScanner on Centos 5: updated References: Message-ID: <97FD54B5E57A1842AA1A4B232E47611773E3D8@ati-ex-02.ati.local> On Monday, May 21, 2007 5:52 AM Hugo van der Kooij <> said: > I am making some notes on how I am doing with the installation of > MailScanner on Centos 5. > > In the process I needed to make a slight change to the perl-Filesys-Df > package to make it work. > > There might be a better way to this but at least it got me a working > package. Hmm... sounds like a lot of trouble. If MS doesn't like CentOS very much, which distro does it work well with? (So I can experiment with a new distro on my next install.) Thanks, Chris. From mogens at fumlersoft.dk Tue May 22 01:14:50 2007 From: mogens at fumlersoft.dk (Mogens Melander) Date: Tue May 22 01:14:44 2007 Subject: SA not working in MS In-Reply-To: <46519488.7030204@slackadelic.com> References: <4698.90.184.17.152.1179734533.squirrel@mail.fumlersoft.dk> <46519488.7030204@slackadelic.com> Message-ID: <4443.90.184.17.152.1179792890.squirrel@mail.fumlersoft.dk> Matt, Nice doc. I looked it over. Well done. I'll take another look when i'm done upgrading MS to MailScanner-4.59.4-2. I'm running sendmail and cyrus-imap/sasl, and the MS/SA/ClamAV is originally from OpenProtect, so files are not located in the same places as Julian's install package, making it a "interesting" adventure to get everything in the right places. On Mon, May 21, 2007 14:46, Matt Hayes wrote: > Mogens Melander wrote: >> Hi, >> >> Running on i686, Slackware 10 (2.4.26), MS 4.58.9-1, SA 3.2.0 >> > *snip* > > Mogens, > > Have a look at http://wiki.slackadelic.com/doku.php/howto:mailserver > > > I wrote that tutorial using Slackware 11 and should be relevant to your > issue. > > -Matt > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by OpenProtect(http://www.openprotect.com), and is > believed to be clean. > -- Later Mogens Melander +45 40 85 71 38 +66 870 133 224 -- This message has been scanned for viruses and dangerous content by OpenProtect(http://www.openprotect.com), and is believed to be clean. From sandrews at andrewscompanies.com Tue May 22 01:54:46 2007 From: sandrews at andrewscompanies.com (Steven Andrews) Date: Tue May 22 01:54:57 2007 Subject: MailScanner on Centos 5: updated In-Reply-To: <97FD54B5E57A1842AA1A4B232E47611773E3D8@ati-ex-02.ati.local> References: <97FD54B5E57A1842AA1A4B232E47611773E3D8@ati-ex-02.ati.local> Message-ID: <1964AAFBC212F742958F9275BF63DBB04B0A72@winchester.andrewscompanies.com> Works just fine on centos 4. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Chris W. Parker Sent: Monday, May 21, 2007 7:45 PM To: MailScanner discussion Subject: RE: MailScanner on Centos 5: updated On Monday, May 21, 2007 5:52 AM Hugo van der Kooij <> said: > I am making some notes on how I am doing with the installation of > MailScanner on Centos 5. > > In the process I needed to make a slight change to the perl-Filesys-Df > package to make it work. > > There might be a better way to this but at least it got me a working > package. Hmm... sounds like a lot of trouble. If MS doesn't like CentOS very much, which distro does it work well with? (So I can experiment with a new distro on my next install.) Thanks, Chris. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From hvdkooij at vanderkooij.org Mon May 21 23:16:56 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue May 22 03:00:50 2007 Subject: Release 4.60.2 In-Reply-To: <4651D0C8.3040602@ecs.soton.ac.uk> References: <46503750.50401@ecs.soton.ac.uk> <4651B6B6.1010405@rogers.com> <4651D0C8.3040602@ecs.soton.ac.uk> Message-ID: On Mon, 21 May 2007, Julian Field wrote: > Hugo van der Kooij wrote: >> On Mon, 21 May 2007, Gerry Doris wrote: >> >>> Something appears to have happened to your ClamAV/SpamAssassin >>> tarballs. I'm getting a "can't find the file" message when I click >>> on the website link for them. >> >> Just for fun. Can you tell me which exact page (URL) you are on? >> >> It seems that google had some obsolete pages at the top of the list. >> It bit me just recently when I did follow google hits instead of going >> to the website and following the menu. > Google had its "Download" link pointing to downloads.shtml and not > .html. So I just deleted the .shtml and made it a soft link to the > .html. So any difference in the files you are seeing now is your web > browser's cache being old. Just checked. The old page is no longer in the google database or at least not rated very high. I guess they detected the link as duplicated. Putting an Eicar test file (or string) in a distribution file is getting people into trouble however. Some can not avoid having to download it through a scanner and the download will fail that way. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From vinay_poojary2000 at yahoo.co.in Tue May 22 05:35:13 2007 From: vinay_poojary2000 at yahoo.co.in (vinay poojary) Date: Tue May 22 05:35:16 2007 Subject: error with mails composed via rich text format Message-ID: <133701.58338.qm@web8324.mail.in.yahoo.com> Dear Sir, mailscanner is a lovely tool to work with, I have enjoyed the mailscanner for years now with no problems . presently i am facing a small problem , the mails sent via rich text format gets corrupted / reaches the users with headers information etc .The attachment sent via rich text format gets embedded in mail body . Thanking you in advance . Regards, vinay Poojary --------------------------------- Here?s a new way to find what you're looking for - Yahoo! Answers -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070522/14d407c5/attachment.html From hvdkooij at vanderkooij.org Tue May 22 07:33:24 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue May 22 07:34:11 2007 Subject: MailScanner on Centos 5: updated In-Reply-To: <97FD54B5E57A1842AA1A4B232E47611773E3D8@ati-ex-02.ati.local> References: <97FD54B5E57A1842AA1A4B232E47611773E3D8@ati-ex-02.ati.local> Message-ID: On Mon, 21 May 2007, Chris W. Parker wrote: > On Monday, May 21, 2007 5:52 AM Hugo van der Kooij <> said: > >> I am making some notes on how I am doing with the installation of >> MailScanner on Centos 5. >> >> In the process I needed to make a slight change to the perl-Filesys-Df >> package to make it work. >> >> There might be a better way to this but at least it got me a working >> package. > > Hmm... sounds like a lot of trouble. It's not. Not much more trouble then others as far as I can tell. And learning to be as fluent with anything else is much, much more work. > If MS doesn't like CentOS very much, which distro does it work well > with? (So I can experiment with a new distro on my next install.) Actually Filesys/Df is the only thing not yet present in centos + rpmforge. So installing MS is pretty much 1 command. It's just that I prefer to follow repositories and Jules seems more intend to keep a 'private'selection of perl tools in the installer. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From hvdkooij at vanderkooij.org Tue May 22 07:41:11 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue May 22 07:41:44 2007 Subject: MailScanner on Centos 5: updated In-Reply-To: <1964AAFBC212F742958F9275BF63DBB04B0A72@winchester.andrewscompanies.com> References: <97FD54B5E57A1842AA1A4B232E47611773E3D8@ati-ex-02.ati.local> <1964AAFBC212F742958F9275BF63DBB04B0A72@winchester.andrewscompanies.com> Message-ID: On Mon, 21 May 2007, Steven Andrews wrote: > Works just fine on centos 4. So if you fetch http://www.mailscanner.info/files/4/rpm/MailScanner-4.59.4-2.rpm.tar.gz Can you run the following without trouble: rpmbuild --rebuild perl-Filesys-Df-0.90-1.src.rpm As on Centos 4.5 I get at the end: RPM build errors: Installed (but unpackaged) file(s) found: /usr/lib/perl5/5.8.8/i386-linux-thread-multi/perllocal.pod /usr/lib/perl5/site_perl/5.8.8/i386-linux-thread-multi/auto/Filesys/Df/.packlist Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) Please, don't top post: A: Yes. >Q: Are you sure? >>A: Because it reverses the logical flow of conversation. >>>Q: Why is top posting frowned upon? From lawrence.oduor at gmail.com Tue May 22 07:45:19 2007 From: lawrence.oduor at gmail.com (Lawi) Date: Tue May 22 07:45:22 2007 Subject: MailScanner[9493]: New Batch: Found invalid queue files: Message-ID: <432baf410705212345h3e686814xcd25bb23aee00305@mail.gmail.com> I have installed exim 6.47 and Mailscanner 4.59 and now i seem to be getting the error "format error in spool" for a number of messages awaiting delivery by exim on the exim log while MailScanner Says "Found invalid queue files" as shown in the Maillog below May 22 09:36:52 proxy3 MailScanner[9602]: Batch (1 message) processed in 13.79 seconds May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Found invalid queue files: 1HqBRW-0005w6-9i 1HqCcH-0006Ti-Ez 1HqEav-0007Gi-OK 1HqFpu-0007lx-4O 1HqLRJ-0001Wy-JE 1HqM1O-0001l4-6x 1HqMMz-0001uu-00 1HqMwH-0002D5-Qc 1HqNRU-0002Ut-1O May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Found 10 messages waiting May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Scanning 1 messages, 3309 bytes May 22 09:37:28 proxy3 MailScanner[9493]: Spam Checks completed at 423 bytes per second May 22 09:37:28 proxy3 MailScanner[9493]: Virus and Content Scanning: Starting May 22 09:37:29 proxy3 MailScanner[9493]: WARNING: Can't parse the configuration file. what is causing this problem? exim or mailscanner? what is this configuration file Mailscanner cannot parse? how is is it solved? regards, -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070522/79ad35e4/attachment.html From hvdkooij at vanderkooij.org Tue May 22 07:44:59 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue May 22 07:45:33 2007 Subject: error with mails composed via rich text format In-Reply-To: <133701.58338.qm@web8324.mail.in.yahoo.com> References: <133701.58338.qm@web8324.mail.in.yahoo.com> Message-ID: On Tue, 22 May 2007, vinay poojary wrote: > mailscanner is a lovely tool to work with, I have enjoyed the mailscanner for years now with no problems . > > presently i am facing a small problem , the mails sent via rich text format gets corrupted / reaches the users with headers information etc .The attachment sent via rich text format gets embedded in mail body . Does this happen if you just let it pass and do not let MailScanner touch it? (But still use the same MTA) Can you check the original message to see it conforms to RFC's? I have seen quite a few messages with obscure endings in the headers at some lines which is going to mess up handling by strict interpreters. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From Q.G.Campbell at newcastle.ac.uk Tue May 22 07:44:32 2007 From: Q.G.Campbell at newcastle.ac.uk (Quentin Campbell) Date: Tue May 22 07:49:01 2007 Subject: 4.60.2 install errors on RH AS4 Message-ID: <4165CF7A7F12DE4B96622CCBB90586470A4D0E81@largo.campus.ncl.ac.uk> Julian Thought I would help out by installing and running 4.60.2-3 on a production server. However found some install problems. The box I used is a Red Hat Enterprise Linux AS release 4 (Nahant Update 4) system on a DL380 box. gcc -v gives: Reading specs from /usr/lib/gcc/i386-redhat-linux/3.4.6/specs Configured with: ../configure --prefix=/usr --mandir=/usr/share/man --infodir=/usr/share/info --enable-shared --enable-threads=posix --disable-checking --with-system-zlib --enable-__cxa_atexit --disable-libunwind-exceptions --enable-java-awt=gtk --host=i386-redhat-linux Thread model: posix gcc version 3.4.6 20060404 (Red Hat 3.4.6-3) I scripted the run of ./install.sh and then did my usual 'grep' of the script output. The gzipped file 'install.sh.log' file is attached. 'grep -i error install.sh.log' includes the following output: ... make: *** [test_dynamic] Error 255 error: Bad exit status from /var/tmp/rpm-tmp.31568 (%build) RPM build errors: t/tbt_06errormess.........ok make: *** [test_dynamic] Error 255 error: Bad exit status from /var/tmp/rpm-tmp.20682 (%build) RPM build errors: make: *** [test_dynamic] Error 255 error: Bad exit status from /var/tmp/rpm-tmp.80498 (%build) RPM build errors: make: *** [test_dynamic] Error 9 error: Bad exit status from /var/tmp/rpm-tmp.64696 (%build) RPM build errors: Execution of t/bigexp.t aborted due to compilation errors. Execution of t/option_l.t aborted due to compilation errors. make: *** [test_dynamic] Error 255 error: Bad exit status from /var/tmp/rpm-tmp.50980 (%build) RPM build errors: Do not worry too much about errors from the next command. NOTE: If you get lots of errors here, run the install.sh script 'grep -i warn install.sh.log' output includes: ... warning: Installed (but unpackaged) file(s) found: warning: Installed (but unpackaged) file(s) found: warning: Installed (but unpackaged) file(s) found: warning: Installed (but unpackaged) file(s) found: warning: Installed (but unpackaged) file(s) found: warning: Installed (but unpackaged) file(s) found: warning: Installed (but unpackaged) file(s) found: DBI.c:4265: warning: unused variable `ix' warning: Installed (but unpackaged) file(s) found: warning: Installed (but unpackaged) file(s) found: warning: Installed (but unpackaged) file(s) found: warning: Installed (but unpackaged) file(s) found: WARNING: LICENSE is not a known parameter. Warning: prerequisite Test::More 0.62 not found. We have 0.6. Warning: prerequisite Math::BigInt 1.83 not found. We have 1.70. Warning: prerequisite Math::BigInt 1.83 not found. We have 1.70. Warning: prerequisite Math::BigRat 0.19 not found. We have 0.12. warning: Installed (but unpackaged) file(s) found: 'grep -i miss install.sh.log' has output that includes: ... Missing file /usr/src/redhat/RPMS/noarch/perl-Test-Harness-2.64-1.noarch.rpm. t/missing.................ok Missing file /usr/src/redhat/RPMS/noarch/perl-Test-Simple-0.70-1.noarch.rpm. Missing file /usr/src/redhat/RPMS/noarch/perl-Math-BigInt-1.86-1.noarch.rpm. Missing file /usr/src/redhat/RPMS/noarch/perl-Math-BigRat-0.19-1.noarch.rpm. Missing file /usr/src/redhat/RPMS/noarch/perl-bignum-0.21-1.noarch.rpm 'grep -i cannot install.sh.log' outputs: 1/18 skipped: cannot write readonly files 1/34 skipped: cannot write readonly files 1/1 skipped: Module::Signature cannot verify I hope this info is of assistance. Quentin --- PHONE: +44 191 222 8209 Information Systems and Services (ISS), Newcastle University, Newcastle upon Tyne, FAX: +44 191 222 8765 United Kingdom, NE1 7RU. ------------------------------------------------------------------ -------------- next part -------------- A non-text attachment was scrubbed... Name: install.sh.log.gz Type: application/x-gzip Size: 36525 bytes Desc: install.sh.log.gz Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070522/48a2f597/install.sh.log.gz From Q.G.Campbell at newcastle.ac.uk Tue May 22 08:39:48 2007 From: Q.G.Campbell at newcastle.ac.uk (Quentin Campbell) Date: Tue May 22 08:44:01 2007 Subject: Scalability of 'spam.whitelist.rules' facility In-Reply-To: <4651AF3E.3030205@ecs.soton.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0CA0@largo.campus.ncl.ac.uk> <4651AF3E.3030205@ecs.soton.ac.uk> Message-ID: <4165CF7A7F12DE4B96622CCBB90586470A4D0E90@largo.campus.ncl.ac.uk> >-----Original Message----- >From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >bounces@lists.mailscanner.info] On Behalf Of Julian Field >Sent: 21 May 2007 15:40 >To: MailScanner discussion >Subject: Re: Scalability of 'spam.whitelist.rules' facility > >-----BEGIN PGP SIGNED MESSAGE----- >Hash: SHA1 > > >[snip] Julian wrote: >I would not advise more than about 1,000 entries in a ruleset. If you >are doing more, then far better to have a little Custom Function that >slurps in a db file at start time (and every "Restart Every" period) and >just does a quick hash table lookup for each message. This would be >hugely faster. If you set > Restart Every = 3600 >then it will re-read the whitelist every hour, which is probably >frequent enough for most people most of the time, and makes it dead easy >to implement. > >The only restriction would be that each whitelist entry was a complete >email address or complete domain name. Also, would they all be "From" >rules? Is that okay? > Julian Thanks for the helpful suggestion. I hope I have the skills to implement it! The bulk of the whitelist rules entries are 'From:' complete addresses. However there are some regular expressions and some To: addresses as well in the whitelist rules file. I suppose there is no reason why I cannot combine your Custom Function and db approach for the complete addresses _and_ leave a stub spam.whitelist.rules file containing the remaining handful of regular expressions and To: addresses? Quentin From uxbod at splatnix.net Tue May 22 09:22:12 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Tue May 22 09:22:20 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <4651FFCC.804@ecs.soton.ac.uk> References: <4651FFCC.804@ecs.soton.ac.uk> Message-ID: Yeah apologies Paul I was tired :( I am having a play around with the code at the moment. What would happen though if a RBL was purely numbers ie. 12345 ? On Mon, 21 May 2007 21:23:40 +0100, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Paul Bijnens wrote: >> On 2007-05-21 17:10, Julian Field wrote: >> >>> Paul Bijnens wrote: >>> >>>> On 2007-05-16 17:41, Julian Field wrote: >>>> >>>>> I'll put it in the main codebase then. Perl has some very subtle bugs > in >>>>> it... >>>>> >>>>> >>>> I believe I don't need to teach perl to Julian (rather the other way >>>> around :-) ), but anyway... >>>> >>> >>>>>>>> >>>>>>>> >>>>>>>> >>>>>>>>> # JKF 3/10/2005 >>>>>>>>> my $temp = @HitList; >>>>>>>>> $temp = $temp + 0; >>>>>>>>> $temp = 0 unless $HitList[0] =~ /a-z/i; >>>>>>>>> return ($temp, join(', ', @HitList)); >>>>>>>>> } >>>>>>>>> >>>>>>>>> Let's see if that helps. According to the book, the 2 middle > lines >>>>>>>>> shouldn't be needed at all. >>>>>>>>> >>>>>>>>> >>>> To me this seems like the array @HitList contains an empty or undef >>>> value. The match against "/[a-z]/i" (or was that really intended >>>> "/a-z/i"??) >>>> >>> No, your version would match against any string that contained the >>> string "a-z" in it (in upper or lower case). >>> >> >> Excuse me :-) but "/a-z/i" is your version and that will search for >> a string "a-z" lower or upper case. My version, "/[a-z]/i", will match >> a name with at least one letter in it. Which is what you're trying to >> do, I believe. >> > It appears I owe you a rather large apology :-( > Sorry! > Many thanks for pointing out the error in my code. I have fixed it and > put out a new beta with it fixed. > >> You're effectively removing any RBL hits now, which is the main reason >> why no more FP's got hit by the current beta tester(-s? -- only one >> person as far I see had the problem). >> >> http://lists.mailscanner.info/pipermail/mailscanner/2007-May/073331.html >> >> I'm still interested in the exact list of RBLs in his config. >> Does it happen when 1 list is added? Two? Some particular list only? >> >> >> >>>> just hides the source of the real error: getting an empty >>>> value for RBL name. >>>> >>> If I printed the string of @HitList it turned out to have no contents, >>> >> >> How? Something like: >> >> @HitList = ( "" ); # somehow this ended up in the list >> $temp = @HitList; >> warn("HitList contains $temp entries: '@HitList'\n"); >> >> No (visible) contents, but still one element in the array. >> >> >> >>> so the scalar of it should have been zero. I have seen the problem of >>> "0" not always equaling zero a few other times, hence the addition of >>> zero to it to try to fix it, which has normally fixed the problem >>> >> >> You can have that problem with "" or undef, acting as 0 in calculations >> but not showing up as a "0" when printed. Indeed fixed by explicitly >> converting to number by adding "+ 0". >> >> >>> elsewhere. The new modification has only been recently needed, the code > >>> has worked perfectly well for years (the previous version was very old >>> code). If it had been needed before, people would have been complaining > >>> loudly about this for the past few years, and they haven't been. So if >>> the start of the list doesn't contain a letter (all RBL names must >>> contain at least 1 letter or they wouldn't work) then the list must >>> actually be empty, so I force it to return zero. >>> >> >> So we have to find out where the list element comes from that does >> not contain a letter, but is empty instead. Instead of covering up the >> bug here. (Still not convinced it is a perl bug.) >> Maybe most people use some RBLs at the MTA-level to block the incoming >> mail completely and/or use other RBLs in SA for scoring, and let the >> spam list entry in MailScanner empty. Or the bug happens only on >> a timeout, like suggested in the OP problem, or only for certain >> combinations of timeout values, etc, etc. >> >> >> >>>> Now finding out where the empty value is coming from, is -- at my >>>> current understanding of the code -- not yet successful. >>>> >>> Yes. I have another demo of a Perl bug which I'll post for you if you >>> like. Perl is not bug-free. >>> >> >> Sure not. But, speaking for myself, it's usually in my own >> programs, and not in the perl compiler, that I find the bugs. :-) >> > Agreed. But I have found the '$n=$n+0' trick solve a few problems in the > past. Bugs that appeared on 1 user's system that I could not reproduce > on my own systems. Adding 0 fixed it. > > But yes, on the other hand, they have been rare (I think there's 2 in > the whole of MailScanner, the most annoying was the spam score returned > by SpamAssassin. It was generating 'not spam' reports where it clearly > printed a spam score greater than the threshold. Add 0 to the number and > then do the comparison again, and it produced the desired result.) > > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: UTF-8 > > wj8DBQFGUgBVEfZZRxQVtlQRAuCSAKCPzzlzxJyUfJ1FqdtlwMQZhBKbwgCgphdD > DHyakLVp1DOcumPj8mJk/rs= > =5mpG > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Tue May 22 09:33:35 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Tue May 22 09:33:41 2007 Subject: FPs and SA 3.2.0 In-Reply-To: References: Message-ID: <7a49a93e46da5980370793fd82f2d3d1@62.49.223.244> perhaps :- $temp = 0 unless ($HitList[0] =~ /[0-9|a-z]/i); to cover all eventualities? On Tue, 22 May 2007 09:22:12 +0100, "--[ UxBoD ]--" wrote: > Yeah apologies Paul I was tired :( I am having a play around with the code > at the moment. What would happen though if a RBL was purely numbers ie. > 12345 ? > > On Mon, 21 May 2007 21:23:40 +0100, Julian Field > wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> >> >> Paul Bijnens wrote: >>> On 2007-05-21 17:10, Julian Field wrote: >>> >>>> Paul Bijnens wrote: >>>> >>>>> On 2007-05-16 17:41, Julian Field wrote: >>>>> >>>>>> I'll put it in the main codebase then. Perl has some very subtle > bugs >> in >>>>>> it... >>>>>> >>>>>> >>>>> I believe I don't need to teach perl to Julian (rather the other way >>>>> around :-) ), but anyway... >>>>> >>>> >>>>>>>>> >>>>>>>>> >>>>>>>>> >>>>>>>>>> # JKF 3/10/2005 >>>>>>>>>> my $temp = @HitList; >>>>>>>>>> $temp = $temp + 0; >>>>>>>>>> $temp = 0 unless $HitList[0] =~ /a-z/i; >>>>>>>>>> return ($temp, join(', ', @HitList)); >>>>>>>>>> } >>>>>>>>>> >>>>>>>>>> Let's see if that helps. According to the book, the 2 middle >> lines >>>>>>>>>> shouldn't be needed at all. >>>>>>>>>> >>>>>>>>>> >>>>> To me this seems like the array @HitList contains an empty or undef >>>>> value. The match against "/[a-z]/i" (or was that really intended >>>>> "/a-z/i"??) >>>>> >>>> No, your version would match against any string that contained the >>>> string "a-z" in it (in upper or lower case). >>>> >>> >>> Excuse me :-) but "/a-z/i" is your version and that will search for >>> a string "a-z" lower or upper case. My version, "/[a-z]/i", will match >>> a name with at least one letter in it. Which is what you're trying to >>> do, I believe. >>> >> It appears I owe you a rather large apology :-( >> Sorry! >> Many thanks for pointing out the error in my code. I have fixed it and >> put out a new beta with it fixed. >> >>> You're effectively removing any RBL hits now, which is the main reason >>> why no more FP's got hit by the current beta tester(-s? -- only one >>> person as far I see had the problem). >>> >>> > http://lists.mailscanner.info/pipermail/mailscanner/2007-May/073331.html >>> >>> I'm still interested in the exact list of RBLs in his config. >>> Does it happen when 1 list is added? Two? Some particular list only? >>> >>> >>> >>>>> just hides the source of the real error: getting an empty >>>>> value for RBL name. >>>>> >>>> If I printed the string of @HitList it turned out to have no contents, > >>>> >>> >>> How? Something like: >>> >>> @HitList = ( "" ); # somehow this ended up in the list >>> $temp = @HitList; >>> warn("HitList contains $temp entries: '@HitList'\n"); >>> >>> No (visible) contents, but still one element in the array. >>> >>> >>> >>>> so the scalar of it should have been zero. I have seen the problem of >>>> "0" not always equaling zero a few other times, hence the addition of >>>> zero to it to try to fix it, which has normally fixed the problem >>>> >>> >>> You can have that problem with "" or undef, acting as 0 in calculations >>> but not showing up as a "0" when printed. Indeed fixed by explicitly >>> converting to number by adding "+ 0". >>> >>> >>>> elsewhere. The new modification has only been recently needed, the > code >> >>>> has worked perfectly well for years (the previous version was very old > >>>> code). If it had been needed before, people would have been > complaining >> >>>> loudly about this for the past few years, and they haven't been. So if > >>>> the start of the list doesn't contain a letter (all RBL names must >>>> contain at least 1 letter or they wouldn't work) then the list must >>>> actually be empty, so I force it to return zero. >>>> >>> >>> So we have to find out where the list element comes from that does >>> not contain a letter, but is empty instead. Instead of covering up the >>> bug here. (Still not convinced it is a perl bug.) >>> Maybe most people use some RBLs at the MTA-level to block the incoming >>> mail completely and/or use other RBLs in SA for scoring, and let the >>> spam list entry in MailScanner empty. Or the bug happens only on >>> a timeout, like suggested in the OP problem, or only for certain >>> combinations of timeout values, etc, etc. >>> >>> >>> >>>>> Now finding out where the empty value is coming from, is -- at my >>>>> current understanding of the code -- not yet successful. >>>>> >>>> Yes. I have another demo of a Perl bug which I'll post for you if you >>>> like. Perl is not bug-free. >>>> >>> >>> Sure not. But, speaking for myself, it's usually in my own >>> programs, and not in the perl compiler, that I find the bugs. :-) >>> >> Agreed. But I have found the '$n=$n+0' trick solve a few problems in the > >> past. Bugs that appeared on 1 user's system that I could not reproduce >> on my own systems. Adding 0 fixed it. >> >> But yes, on the other hand, they have been rare (I think there's 2 in >> the whole of MailScanner, the most annoying was the spam score returned >> by SpamAssassin. It was generating 'not spam' reports where it clearly >> printed a spam score greater than the threshold. Add 0 to the number and > >> then do the comparison again, and it produced the desired result.) >> >> >> Jules >> >> - -- >> Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> MailScanner customisation, or any advanced system administration help? >> Contact me at Jules@Jules.FM >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> For all your IT requirements visit www.transtec.co.uk >> >> >> >> -----BEGIN PGP SIGNATURE----- >> Version: PGP Desktop 9.6.1 (Build 1012) >> Charset: UTF-8 >> >> wj8DBQFGUgBVEfZZRxQVtlQRAuCSAKCPzzlzxJyUfJ1FqdtlwMQZhBKbwgCgphdD >> DHyakLVp1DOcumPj8mJk/rs= >> =5mpG >> -----END PGP SIGNATURE----- >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> For all your IT requirements visit www.transtec.co.uk >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> > -- > --[ UxBoD ]-- > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From Paul.Bijnens at xplanation.com Tue May 22 11:11:08 2007 From: Paul.Bijnens at xplanation.com (Paul Bijnens) Date: Tue May 22 11:11:16 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <7a49a93e46da5980370793fd82f2d3d1@62.49.223.244> References: <7a49a93e46da5980370793fd82f2d3d1@62.49.223.244> Message-ID: <4652C1BC.5020608@xplanation.com> On 2007-05-22 10:33, --[ UxBoD ]-- wrote: > perhaps :- > > $temp = 0 unless ($HitList[0] =~ /[0-9|a-z]/i); > > to cover all eventualities? > In real perl that would be ... =~ /\w/; The @HitList contains the "name" of the blacklist found as the first item on each line in spam.lists.conf, like: ORDB-RBL relays.ordb.org. So just make a name that contains a letter and the current test for "/[a-z]/i" succeeds. Actually my point is that this patch covers up a deeper bug (without known effects on other places, because we did not found it yet). The @HitList contains somehow an empty element. It got this by reading a pipe, where the uneven lines contain the RBL-name and the even lines contain the word "Hit", or "Dead", etc. Somehow a blank line got into that stream, followed by "Hit". We better find out how a blank line can get there... Could be a minor problem, or could be a problem on a deeper level that will show up in other circumstances too. -- Paul Bijnens, xplanation Technology Services Tel +32 16 397.511 Technologielaan 21 bus 2, B-3001 Leuven, BELGIUM Fax +32 16 397.512 http://www.xplanation.com/ email: Paul.Bijnens@xplanation.com *********************************************************************** * I think I've got the hang of it now: exit, ^D, ^C, ^\, ^Z, ^Q, ^^, * * F6, quit, ZZ, :q, :q!, M-Z, ^X^C, logoff, logout, close, bye, /bye, * * stop, end, F3, ~., ^]c, +++ ATH, disconnect, halt, abort, hangup, * * PF4, F20, ^X^X, :D::D, KJOB, F14-f-e, F8-e, kill -1 $$, shutdown, * * init 0, kill -9 1, Alt-F4, Ctrl-Alt-Del, AltGr-NumLock, Stop-A, ... * * ... "Are you sure?" ... YES ... Phew ... I'm out * *********************************************************************** From uxbod at splatnix.net Tue May 22 11:16:00 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Tue May 22 11:16:17 2007 Subject: FPs and SA 3.2.0 In-Reply-To: <4652C1BC.5020608@xplanation.com> References: <4652C1BC.5020608@xplanation.com> Message-ID: <41196a36a625b2626fd82a3847e4555c@62.49.223.244> Hmmm. If somebody could try setting up a dummy RBL (sorry don't have a test server here) and see what happens when that is added to Spam list. Perhaps it is a timeout issue ? On Tue, 22 May 2007 12:11:08 +0200, Paul Bijnens wrote: > On 2007-05-22 10:33, --[ UxBoD ]-- wrote: >> perhaps :- >> >> $temp = 0 unless ($HitList[0] =~ /[0-9|a-z]/i); >> >> to cover all eventualities? >> > > In real perl that would be ... =~ /\w/; > > The @HitList contains the "name" of the blacklist found as the > first item on each line in spam.lists.conf, like: > > ORDB-RBL relays.ordb.org. > > So just make a name that contains a letter and the current test > for "/[a-z]/i" succeeds. > > Actually my point is that this patch covers up a deeper bug (without > known effects on other places, because we did not found it yet). The > @HitList contains somehow an empty element. It got this by reading > a pipe, where the uneven lines contain the RBL-name and the even > lines contain the word "Hit", or "Dead", etc. Somehow a blank > line got into that stream, followed by "Hit". > We better find out how a blank line can get there... > Could be a minor problem, or could be a problem on a deeper level that > will show up in other circumstances too. > > > -- > Paul Bijnens, xplanation Technology Services Tel +32 16 397.511 > Technologielaan 21 bus 2, B-3001 Leuven, BELGIUM Fax +32 16 397.512 > http://www.xplanation.com/ email: Paul.Bijnens@xplanation.com > *********************************************************************** > * I think I've got the hang of it now: exit, ^D, ^C, ^\, ^Z, ^Q, ^^, * > * F6, quit, ZZ, :q, :q!, M-Z, ^X^C, logoff, logout, close, bye, /bye, * > * stop, end, F3, ~., ^]c, +++ ATH, disconnect, halt, abort, hangup, * > * PF4, F20, ^X^X, :D::D, KJOB, F14-f-e, F8-e, kill -1 $$, shutdown, * > * init 0, kill -9 1, Alt-F4, Ctrl-Alt-Del, AltGr-NumLock, Stop-A, ... * > * ... "Are you sure?" ... YES ... Phew ... I'm out * > *********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Tue May 22 11:52:00 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 22 11:53:15 2007 Subject: locking bayes? In-Reply-To: <465200C9.4010304@evi-inc.com> References: <46516CA5.7040207@nerc.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBAB257E5@HC-MBX02.herefordshire.gov.uk> <46518742.6080105@nerc.ac.uk> <4651BA1D.1090603@evi-inc.com> <4651CFEF.4010100@ecs.soton.ac.uk> <465200C9.4010304@evi-inc.com> Message-ID: <4652CB50.9010304@ecs.soton.ac.uk> Matt Kettler wrote: > Julian Field wrote: > >> "check_MailScanner" should do as a replacement for the "service >> MailScanner start" command. >> > > Hi Julian! > > Would that get rid of /var/lock/subsys/MailScanner.off and create > /var/lock/check_Mailscanner.lock ? > > Otherwise, that would start MailScanner, but the cron-job checker wouldn't > function properly.. > > > You're absolutely right, it wouldn't. I had completely forgotten about the cron-job lock files. I blame it on being asleep for 2 1/2 weeks :-) Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Tue May 22 11:55:21 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 22 11:56:28 2007 Subject: Release 4.60.2 In-Reply-To: References: <46503750.50401@ecs.soton.ac.uk> <4651B6B6.1010405@rogers.com> <4651D0C8.3040602@ecs.soton.ac.uk> Message-ID: <4652CC19.8000508@ecs.soton.ac.uk> Hugo van der Kooij wrote: > On Mon, 21 May 2007, Julian Field wrote: > >> Hugo van der Kooij wrote: >>> On Mon, 21 May 2007, Gerry Doris wrote: >>> >>>> Something appears to have happened to your ClamAV/SpamAssassin >>>> tarballs. I'm getting a "can't find the file" message when I click >>>> on the website link for them. >>> >>> Just for fun. Can you tell me which exact page (URL) you are on? >>> >>> It seems that google had some obsolete pages at the top of the list. >>> It bit me just recently when I did follow google hits instead of going >>> to the website and following the menu. >> Google had its "Download" link pointing to downloads.shtml and not >> .html. So I just deleted the .shtml and made it a soft link to the >> .html. So any difference in the files you are seeing now is your web >> browser's cache being old. > > Just checked. The old page is no longer in the google database or at > least not rated very high. I guess they detected the link as duplicated. > > Putting an Eicar test file (or string) in a distribution file is > getting people into trouble however. Some can not avoid having to > download it through a scanner and the download will fail that way. But isn't the Eicar file in the ClamAV download? I don't want to start shipping any different build of ClamAV from their supplied one. I suggest you take this up with the ClamAV guys. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Tue May 22 11:58:20 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 22 11:59:13 2007 Subject: MailScanner on Centos 5: updated In-Reply-To: References: <97FD54B5E57A1842AA1A4B232E47611773E3D8@ati-ex-02.ati.local> <1964AAFBC212F742958F9275BF63DBB04B0A72@winchester.andrewscompanies.com> Message-ID: <4652CCCC.8080806@ecs.soton.ac.uk> Hugo van der Kooij wrote: > On Mon, 21 May 2007, Steven Andrews wrote: > >> Works just fine on centos 4. > > So if you fetch > http://www.mailscanner.info/files/4/rpm/MailScanner-4.59.4-2.rpm.tar.gz > > Can you run the following without trouble: > > rpmbuild --rebuild perl-Filesys-Df-0.90-1.src.rpm > > As on Centos 4.5 I get at the end: > > RPM build errors: > Installed (but unpackaged) file(s) found: > /usr/lib/perl5/5.8.8/i386-linux-thread-multi/perllocal.pod > > /usr/lib/perl5/site_perl/5.8.8/i386-linux-thread-multi/auto/Filesys/Df/.packlist > > My install.sh script should stop it breaking when it finds this. It's common and totally harmless. If you do it by hand you will get this error, but running my install.sh script should stop it dying at this point. > Hugo. > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Tue May 22 11:59:27 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 22 12:00:20 2007 Subject: 4.60.2 install errors on RH AS4 In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470A4D0E81@largo.campus.ncl.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0E81@largo.campus.ncl.ac.uk> Message-ID: <4652CD0F.6060601@ecs.soton.ac.uk> Please try 4.60.3. Quentin Campbell wrote: > Julian > > Thought I would help out by installing and running 4.60.2-3 on a > production server. However found some install problems. > > The box I used is a Red Hat Enterprise Linux AS release 4 (Nahant Update > 4) system on a DL380 box. > > gcc -v gives: > > Reading specs from /usr/lib/gcc/i386-redhat-linux/3.4.6/specs > Configured with: ../configure --prefix=/usr --mandir=/usr/share/man > --infodir=/usr/share/info --enable-shared --enable-threads=posix > --disable-checking --with-system-zlib --enable-__cxa_atexit > --disable-libunwind-exceptions --enable-java-awt=gtk > --host=i386-redhat-linux > Thread model: posix > gcc version 3.4.6 20060404 (Red Hat 3.4.6-3) > > I scripted the run of ./install.sh and then did my usual 'grep' of the > script output. The gzipped file 'install.sh.log' file is attached. > > 'grep -i error install.sh.log' includes the following output: > > ... > make: *** [test_dynamic] Error 255 > error: Bad exit status from /var/tmp/rpm-tmp.31568 (%build) > RPM build errors: > t/tbt_06errormess.........ok > > make: *** [test_dynamic] Error 255 > error: Bad exit status from /var/tmp/rpm-tmp.20682 (%build) > RPM build errors: > make: *** [test_dynamic] Error 255 > error: Bad exit status from /var/tmp/rpm-tmp.80498 (%build) > RPM build errors: > make: *** [test_dynamic] Error 9 > error: Bad exit status from /var/tmp/rpm-tmp.64696 (%build) > RPM build errors: > Execution of t/bigexp.t aborted due to compilation errors. > Execution of t/option_l.t aborted due to compilation errors. > make: *** [test_dynamic] Error 255 > error: Bad exit status from /var/tmp/rpm-tmp.50980 (%build) > RPM build errors: > Do not worry too much about errors from the next command. > NOTE: If you get lots of errors here, run the install.sh script > > 'grep -i warn install.sh.log' output includes: > > ... > warning: Installed (but unpackaged) file(s) found: > warning: Installed (but unpackaged) file(s) found: > warning: Installed (but unpackaged) file(s) found: > warning: Installed (but unpackaged) file(s) found: > warning: Installed (but unpackaged) file(s) found: > warning: Installed (but unpackaged) file(s) found: > warning: Installed (but unpackaged) file(s) found: > DBI.c:4265: warning: unused variable `ix' > warning: Installed (but unpackaged) file(s) found: > warning: Installed (but unpackaged) file(s) found: > warning: Installed (but unpackaged) file(s) found: > warning: Installed (but unpackaged) file(s) found: > WARNING: LICENSE is not a known parameter. > Warning: prerequisite Test::More 0.62 not found. We have 0.6. > Warning: prerequisite Math::BigInt 1.83 not found. We have 1.70. > Warning: prerequisite Math::BigInt 1.83 not found. We have 1.70. > Warning: prerequisite Math::BigRat 0.19 not found. We have 0.12. > warning: Installed (but unpackaged) file(s) found: > > 'grep -i miss install.sh.log' has output that includes: > > ... > Missing file > /usr/src/redhat/RPMS/noarch/perl-Test-Harness-2.64-1.noarch.rpm. > t/missing.................ok > > Missing file > /usr/src/redhat/RPMS/noarch/perl-Test-Simple-0.70-1.noarch.rpm. > Missing file > /usr/src/redhat/RPMS/noarch/perl-Math-BigInt-1.86-1.noarch.rpm. > Missing file > /usr/src/redhat/RPMS/noarch/perl-Math-BigRat-0.19-1.noarch.rpm. > Missing file /usr/src/redhat/RPMS/noarch/perl-bignum-0.21-1.noarch.rpm > > 'grep -i cannot install.sh.log' outputs: > > 1/18 skipped: cannot write readonly files > 1/34 skipped: cannot write readonly files > 1/1 skipped: Module::Signature cannot verify > > > I hope this info is of assistance. > > Quentin > --- > PHONE: +44 191 222 8209 Information Systems and Services (ISS), > Newcastle University, > Newcastle upon Tyne, > FAX: +44 191 222 8765 United Kingdom, NE1 7RU. > ------------------------------------------------------------------ > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Tue May 22 12:00:59 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 22 12:02:04 2007 Subject: Scalability of 'spam.whitelist.rules' facility In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470A4D0E90@largo.campus.ncl.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0CA0@largo.campus.ncl.ac.uk> <4651AF3E.3030205@ecs.soton.ac.uk> <4165CF7A7F12DE4B96622CCBB90586470A4D0E90@largo.campus.ncl.ac.uk> Message-ID: <4652CD6B.8020709@ecs.soton.ac.uk> Quentin Campbell wrote: >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Julian Field >> Sent: 21 May 2007 15:40 >> To: MailScanner discussion >> Subject: Re: Scalability of 'spam.whitelist.rules' facility >> >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> >> [snip] >> > Julian wrote: > >> I would not advise more than about 1,000 entries in a ruleset. If you >> are doing more, then far better to have a little Custom Function that >> slurps in a db file at start time (and every "Restart Every" period) >> > and > >> just does a quick hash table lookup for each message. This would be >> hugely faster. If you set >> Restart Every = 3600 >> then it will re-read the whitelist every hour, which is probably >> frequent enough for most people most of the time, and makes it dead >> > easy > >> to implement. >> >> The only restriction would be that each whitelist entry was a complete >> email address or complete domain name. Also, would they all be "From" >> rules? Is that okay? >> >> > Julian > > Thanks for the helpful suggestion. I hope I have the skills to implement > it! > > The bulk of the whitelist rules entries are 'From:' complete addresses. > > However there are some regular expressions and some To: addresses as > well in the whitelist rules file. > > I suppose there is no reason why I cannot combine your Custom Function > and db approach for the complete addresses _and_ leave a stub > spam.whitelist.rules file containing the remaining handful of regular > expressions and To: addresses? > > You can call a ruleset from within a Custom Function. I documented how to do this in the mailing list archive, and there should now be an example of it in the CustomFunctions directory. > Quentin > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From amaclach at yahoo.co.uk Tue May 22 12:34:02 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Tue May 22 12:34:12 2007 Subject: Archiving non-spam Message-ID: <861707.81432.qm@web26311.mail.ukl.yahoo.com> I'm sure it wouldn't take long to write a script to parse the nonspam directories and pipe the messages through sendmail... ----- Original Message ---- From: Kevin Miller To: MailScanner discussion Sent: Monday, 21 May, 2007 7:30:55 PM Subject: RE: Archiving non-spam Scott Silva wrote: > Using this setting will archive ALL mail (ham, spam, high spam). Nope, don't want that! > If you only want to store non spam you could add a "store" directive > to your non-spam actions. If you use Mailwatch, this works good, as > it will be stored along with any spam you archive. OK - did that and it's working a treat. > The store directive will store in quarantine, under a nonspam > directory. I'm seeing the non-spam turning up in the MailWatch quarantine page now. That's fine - I presume that the current processes to clean the quarantined spam directories will also do the non-spam directories? I've got that set to 30 days at the moment - be nice to be able to manage both spam and non-spam seperately but in this case it looks like I can't. Oh well. > You could forward all the nonspam to a separate account, and use an > IMAP client to move the mails from one place to another. Hmmm. Not sure I follow that. With hundreds of users the goal is to be able to just drop them into the MTA's queue and let it get them where they need to go. Thanks Scott... ...Kevin -- Kevin Miller Registered Linux User No: 307357 CBJ MIS Dept. Network Systems Admin., Mail Admin. 155 South Seward Street ph: (907) 586-0242 Juneau, Alaska 99801 fax: (907 586-4500 -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From Q.G.Campbell at newcastle.ac.uk Tue May 22 13:40:29 2007 From: Q.G.Campbell at newcastle.ac.uk (Quentin Campbell) Date: Tue May 22 13:43:33 2007 Subject: 4.60.3-1 install errors on RH AS4 Message-ID: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk> Julian Tried an 'install.sh' with 4.60.3-1 on the same RH AS4 system and got similar compilation and RPM build errors as for 4.60.2. The gzipped 'install.sh.log' file is attached. This contains the scripted output of the 'install.sh' command again. Quentin --- PHONE: +44 191 222 8209 Information Systems and Services (ISS), Newcastle University, Newcastle upon Tyne, FAX: +44 191 222 8765 United Kingdom, NE1 7RU. ------------------------------------------------------------------ -------------- next part -------------- A non-text attachment was scrubbed... Name: install.sh.log.gz Type: application/x-gzip Size: 28661 bytes Desc: install.sh.log.gz Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070522/5681d989/install.sh.log.gz From hvdkooij at vanderkooij.org Tue May 22 14:07:31 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue May 22 14:08:10 2007 Subject: MailScanner on Centos 5: updated In-Reply-To: <4652CCCC.8080806@ecs.soton.ac.uk> References: <97FD54B5E57A1842AA1A4B232E47611773E3D8@ati-ex-02.ati.local> <1964AAFBC212F742958F9275BF63DBB04B0A72@winchester.andrewscompanies.com> <4652CCCC.8080806@ecs.soton.ac.uk> Message-ID: On Tue, 22 May 2007, Julian Field wrote: > Hugo van der Kooij wrote: >> On Mon, 21 May 2007, Steven Andrews wrote: >> >> > Works just fine on centos 4. >> >> So if you fetch >> http://www.mailscanner.info/files/4/rpm/MailScanner-4.59.4-2.rpm.tar.gz >> >> Can you run the following without trouble: >> >> rpmbuild --rebuild perl-Filesys-Df-0.90-1.src.rpm >> >> As on Centos 4.5 I get at the end: >> >> RPM build errors: >> Installed (but unpackaged) file(s) found: >> /usr/lib/perl5/5.8.8/i386-linux-thread-multi/perllocal.pod >> >> /usr/lib/perl5/site_perl/5.8.8/i386-linux-thread-multi/auto/Filesys/Df/.packlist >> >> > My install.sh script should stop it breaking when it finds this. It's common > and totally harmless. If you do it by hand you will get this error, but > running my install.sh script should stop it dying at this point. I would prefer to solve the issue and not work around them. At least that is my current impression of what the install script does. And I am rather seriously thinking of setting up a repository for those parts not yet covered by rpmforge so one can install mailscanner through yum once the proper repositories have been added. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From MailScanner at ecs.soton.ac.uk Tue May 22 14:51:00 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 22 14:52:05 2007 Subject: 4.60.3-1 install errors on RH AS4 In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk> Message-ID: <4652F544.5050007@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 But does MailScanner still work okay, despite the installation problems? Which update of AS4 are you using? Quentin Campbell wrote: > Julian > > Tried an 'install.sh' with 4.60.3-1 on the same RH AS4 system and got > similar compilation and RPM build errors as for 4.60.2. > > The gzipped 'install.sh.log' file is attached. This contains the > scripted output of the 'install.sh' command again. > > Quentin > --- > PHONE: +44 191 222 8209 Information Systems and Services (ISS), > Newcastle University, > Newcastle upon Tyne, > FAX: +44 191 222 8765 United Kingdom, NE1 7RU. > ------------------------------------------------------------------ > > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGUvVYEfZZRxQVtlQRAl03AJsEit1Etq2vL8v0Srx45KD2hRRNNgCfcSZW DWoanoAzzh+0Z6qJqd7H+XA= =5qeK -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From prandal at herefordshire.gov.uk Tue May 22 15:24:12 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Tue May 22 15:30:28 2007 Subject: MailScanner on Centos 5: updated In-Reply-To: References: <97FD54B5E57A1842AA1A4B232E47611773E3D8@ati-ex-02.ati.local><1964AAFBC212F742958F9275BF63DBB04B0A72@winchester.andrewscompanies.com><4652CCCC.8080806@ecs.soton.ac.uk> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBAB259BE@HC-MBX02.herefordshire.gov.uk> mailscanner-bounces@lists.mailscanner.info wrote: > On Tue, 22 May 2007, Julian Field wrote: > >> Hugo van der Kooij wrote: >>> On Mon, 21 May 2007, Steven Andrews wrote: >>> >>>> Works just fine on centos 4. >>> >>> So if you fetch >>> > http://www.mailscanner.info/files/4/rpm/MailScanner-4.59.4-2.r > pm.tar.gz >>> >>> Can you run the following without trouble: >>> >>> rpmbuild --rebuild perl-Filesys-Df-0.90-1.src.rpm >>> >>> As on Centos 4.5 I get at the end: >>> >>> RPM build errors: >>> Installed (but unpackaged) file(s) found: >>> /usr/lib/perl5/5.8.8/i386-linux-thread-multi/perllocal.pod >>> >>> > /usr/lib/perl5/site_perl/5.8.8/i386-linux-thread-multi/auto/Fi > lesys/Df/.packlist >>> >>> >> My install.sh script should stop it breaking when it finds this. >> It's common and totally harmless. If you do it by hand you will get >> this error, but running my install.sh script should stop it dying at >> this point. > > I would prefer to solve the issue and not work around them. At least > that is my current impression of what the install script does. > > And I am rather seriously thinking of setting up a repository for > those parts not yet covered by rpmforge so one can install > mailscanner through yum once the proper repositories have been added. > > Hugo. It might be worthwhile dropping a line to Dag Wieers asking that the module(s) in question be added to RPMForge. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK From hvdkooij at vanderkooij.org Tue May 22 15:49:19 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue May 22 15:49:59 2007 Subject: MailScanner on Centos 5: updated In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBAB259BE@HC-MBX02.herefordshire.gov.uk> References: <97FD54B5E57A1842AA1A4B232E47611773E3D8@ati-ex-02.ati.local><1964AAFBC212F742958F9275BF63DBB04B0A72@winchester.andrewscompanies.com><4652CCCC.8080806@ecs.soton.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBAB259BE@HC-MBX02.herefordshire.gov.uk> Message-ID: On Tue, 22 May 2007, Randal, Phil wrote: > It might be worthwhile dropping a line to Dag Wieers asking that the > module(s) in question be added to RPMForge. You are not supposed to look at the notes on my desk ;-) It is on my tasklist that slowly becomes smaller bit by bit. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From snifer_ at hotmail.com Tue May 22 17:01:34 2007 From: snifer_ at hotmail.com (Juan Pablo Salazar =?utf-8?b?QmVydMOtbg==?=) Date: Tue May 22 17:02:21 2007 Subject: fix: regex for removing tags inside links (phishing filter) Message-ID: The regexp for removing tags inside links is not very good. Currently, it's being done this way: $squashedtext =~ s/(\<\/?[^>]*\>)*//ig; # Remove tags So, html like this is not properly detected, and sometimes detected as phishing (not this example, but other cases): my image >>> I've found a better regexp in http://haacked.com/archive/2004/10/25/usingregularexpressionstomatchhtml.aspx so now I'm successfully using this: $squashedtext =~ s/(\<\/?\w+((\s+\w+(\s*=\s*(?:\".*?\"|\'.*?\'|[^\'\">\s]+))?)+\s*|\s*)\/?\>)* //ig; #Remove tags This has to be used before whitespaces are removed. From MailScanner at ecs.soton.ac.uk Tue May 22 17:08:01 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 22 17:09:00 2007 Subject: MailScanner on Centos 5: updated In-Reply-To: References: <97FD54B5E57A1842AA1A4B232E47611773E3D8@ati-ex-02.ati.local><1964AAFBC212F742958F9275BF63DBB04B0A72@winchester.andrewscompanies.com><4652CCCC.8080806@ecs.soton.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBAB259BE@HC-MBX02.herefordshire.gov.uk> Message-ID: <46531561.9020103@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hugo van der Kooij wrote: > On Tue, 22 May 2007, Randal, Phil wrote: > >> It might be worthwhile dropping a line to Dag Wieers asking that the >> module(s) in question be added to RPMForge. > > You are not supposed to look at the notes on my desk ;-) It is on my > tasklist that slowly becomes smaller bit by bit. > > Hugo. > I just installed 4.60.3 on CentOS 5.0 and it appears to have installed just fine. Now to install ClamAV and SpamAssaassin and test it again. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGUxVrEfZZRxQVtlQRArB9AKDaRynqJdwft1A6/UFjHwXw1npp3QCfTHIz LNi2wnP7kvjckksTS7FnehE= =t1BF -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Tue May 22 17:51:32 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 22 17:52:55 2007 Subject: fix: regex for removing tags inside links (phishing filter) In-Reply-To: References: Message-ID: <46531F94.7080107@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Can you give me a simple example of mine doing it wrong where yours does it better please? I need to see your patch in action before accepting it. Juan Pablo Salazar Bert?n wrote: > The regexp for removing tags inside links is not very good. Currently, it's > being done this way: > > $squashedtext =~ s/(\<\/?[^>]*\>)*//ig; # Remove tags > > So, html like this is not properly detected, and sometimes detected as phishing > (not this example, but other cases): > > my image >>> > > I've found a better regexp in > http://haacked.com/archive/2004/10/25/usingregularexpressionstomatchhtml.aspx so > now I'm successfully using this: > > $squashedtext =~ > s/(\<\/?\w+((\s+\w+(\s*=\s*(?:\".*?\"|\'.*?\'|[^\'\">\s]+))?)+\s*|\s*)\/?\>)* > //ig; #Remove tags > > This has to be used before whitespaces are removed. > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGUx+eEfZZRxQVtlQRAltOAKCnG00GKFWGVem5SMu8efmMWHlQLwCg7tQx kJ/f5muc5LPb7IZvqK119bk= =NEGM -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From pravin.rane at gmail.com Tue May 22 17:52:55 2007 From: pravin.rane at gmail.com (Pravin Rane) Date: Tue May 22 17:52:58 2007 Subject: error with mails composed via rich text format In-Reply-To: References: <133701.58338.qm@web8324.mail.in.yahoo.com> Message-ID: <13c021a90705220952sa1a848dw91c49e02ff545714@mail.gmail.com> Well this is not Mailscanner problem. The actual attachment and message gets embedded in winmail.dat file making unreadable for MUA's other than Microsoft Outlook 97/2000 See below link for more info http://www.gpc.edu/~jbenson/resource/winmail.htm and this one http://support.microsoft.com/kb/138053 On 5/22/07, Hugo van der Kooij wrote: > > On Tue, 22 May 2007, vinay poojary wrote: > > > mailscanner is a lovely tool to work with, I have enjoyed the > mailscanner for years now with no problems . > > > > presently i am facing a small problem , the mails sent via rich text > format gets corrupted / reaches the users with headers information etc .The > attachment sent via rich text format gets embedded in mail body . > > Does this happen if you just let it pass and do not let MailScanner touch > it? (But still use the same MTA) > > Can you check the original message to see it conforms to RFC's? I have > seen quite a few messages with obscure endings in the headers at some > lines which is going to mess up handling by strict interpreters. > > Hugo. > > -- > hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ > This message is using 100% recycled electrons. > > Some men see computers as they are and say "Windows" > I use computers with Linux and say "Why Windows?" > (Thanks JFK, for the insight.) > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- Regards Pravin -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070522/d1d30345/attachment.html From bpumphrey at woodmclaw.com Tue May 22 16:24:47 2007 From: bpumphrey at woodmclaw.com (Billy A. Pumphrey) Date: Tue May 22 18:07:13 2007 Subject: Connection Deferred In-Reply-To: <464D0E29.2050700@rheelweb.co.nz> Message-ID: <04D932B0071FE34FA63EBB1977B48D15029C5032@woodenex.woodmaclaw.local> Good suggestion. I am finally going through the emails here and see your response to mine. I will most defiantly check this option as I am getting tired of it happening. Thank you. Billy Pumphrey IT Manager Wooden & McLaughlin > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Seamus Allan > Sent: Thursday, May 17, 2007 10:24 PM > To: MailScanner discussion > Subject: Re: Connection Deffered > > I had a similar problem with my receiving mail server behind a > MailScanner gateway. Turned out I just needed to turn up the number of > connections per minute on the smtp on the mail server so that it didn't > think the Mailscanner machine was flooding it. > I don't know if this is the case with Exchange, but perhaps gives you > something to look at? > > Cheers > > Seamus. > > Billy A. Pumphrey wrote: > > I am hoping someone is willing to help me with this. I thought that I > > had the problem fixed but maybe not. I believe that current incoming > > email is coming through MailScanner and to the Exchange server. The > > problem is that ther are about 650 emails that will not go through. I > > get this: > > > > Command: > > sendmail -v -bp -OQueueDirectory=//var/spool/mqueue > > > > Result (about 650 of these): > > l4FL9c8I028182 998389 6606332+May 15 17:09 > > (Deferred: Connection refused by [10.1.1.22]) > > > > > > > > I have sendmail, Cent OS 4.4. > > > > I have not changed anything before this started happening. I restarted > > the Exchange server and that is allowing the new emails to come through > > ( I think, I will see for sure if this reaches the list during the > > problem phase). > > > > Please advise :) > > Thank you > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. From bpumphrey at woodmclaw.com Tue May 22 18:20:52 2007 From: bpumphrey at woodmclaw.com (Billy A. Pumphrey) Date: Tue May 22 18:20:55 2007 Subject: Connection Deferred In-Reply-To: <464D0E29.2050700@rheelweb.co.nz> Message-ID: <04D932B0071FE34FA63EBB1977B48D15029C50AF@woodenex.woodmaclaw.local> I looked and in exchange the "Limit number of connections to:" is not check marked. So if should not be limiting the number of connections. It just happened again too, where I had to restart the server to get the exchange server to accept connections again from MailScanner. Hhmm.. Billy Pumphrey IT Manager Wooden & McLaughlin > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Seamus Allan > Sent: Thursday, May 17, 2007 10:24 PM > To: MailScanner discussion > Subject: Re: Connection Deffered > > I had a similar problem with my receiving mail server behind a > MailScanner gateway. Turned out I just needed to turn up the number of > connections per minute on the smtp on the mail server so that it didn't > think the Mailscanner machine was flooding it. > I don't know if this is the case with Exchange, but perhaps gives you > something to look at? > > Cheers > > Seamus. > > Billy A. Pumphrey wrote: > > I am hoping someone is willing to help me with this. I thought that I > > had the problem fixed but maybe not. I believe that current incoming > > email is coming through MailScanner and to the Exchange server. The > > problem is that ther are about 650 emails that will not go through. I > > get this: > > > > Command: > > sendmail -v -bp -OQueueDirectory=//var/spool/mqueue > > > > Result (about 650 of these): > > l4FL9c8I028182 998389 6606332+May 15 17:09 > > (Deferred: Connection refused by [10.1.1.22]) > > > > > > > > I have sendmail, Cent OS 4.4. > > > > I have not changed anything before this started happening. I restarted > > the Exchange server and that is allowing the new emails to come through > > ( I think, I will see for sure if this reaches the list during the > > problem phase). > > > > Please advise :) > > Thank you > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. From bpumphrey at woodmclaw.com Tue May 22 18:23:27 2007 From: bpumphrey at woodmclaw.com (Billy A. Pumphrey) Date: Tue May 22 18:23:30 2007 Subject: Connection Deferred In-Reply-To: <04D932B0071FE34FA63EBB1977B48D15029C5032@woodenex.woodmaclaw.local> Message-ID: <04D932B0071FE34FA63EBB1977B48D15029C50B4@woodenex.woodmaclaw.local> Another update. I did find another setting in there "Limit number of messages per connection to:". That was set to 20, so I raised it to 200. Hopefully that will take care of it. Thank you a bunch as there is hope! Billy Pumphrey IT Manager Wooden & McLaughlin > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Billy A. Pumphrey > Sent: Tuesday, May 22, 2007 11:25 AM > To: MailScanner discussion > Subject: RE: Connection Deferred > > Good suggestion. I am finally going through the emails here and see > your response to mine. I will most defiantly check this option as I am > getting tired of it happening. Thank you. > > Billy Pumphrey > IT Manager > Wooden & McLaughlin > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > > bounces@lists.mailscanner.info] On Behalf Of Seamus Allan > > Sent: Thursday, May 17, 2007 10:24 PM > > To: MailScanner discussion > > Subject: Re: Connection Deffered > > > > I had a similar problem with my receiving mail server behind a > > MailScanner gateway. Turned out I just needed to turn up the number of > > connections per minute on the smtp on the mail server so that it > didn't > > think the Mailscanner machine was flooding it. > > I don't know if this is the case with Exchange, but perhaps gives you > > something to look at? > > > > Cheers > > > > Seamus. > > > > Billy A. Pumphrey wrote: > > > I am hoping someone is willing to help me with this. I thought that > I > > > had the problem fixed but maybe not. I believe that current > incoming > > > email is coming through MailScanner and to the Exchange server. The > > > problem is that ther are about 650 emails that will not go through. > I > > > get this: > > > > > > Command: > > > sendmail -v -bp -OQueueDirectory=//var/spool/mqueue > > > > > > Result (about 650 of these): > > > l4FL9c8I028182 998389 6606332+May 15 17:09 > > > (Deferred: Connection refused by [10.1.1.22]) > > > > > > > > > > > > I have sendmail, Cent OS 4.4. > > > > > > I have not changed anything before this started happening. I > restarted > > > the Exchange server and that is allowing the new emails to come > through > > > ( I think, I will see for sure if this reaches the list during the > > > problem phase). > > > > > > Please advise :) > > > Thank you > > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > -- > > This message has been scanned for viruses and > > dangerous content by MailScanner, and is > > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. From lmachite00 at yahoo.com.br Tue May 22 18:44:13 2007 From: lmachite00 at yahoo.com.br (Luis Marcelo Achite) Date: Tue May 22 18:44:27 2007 Subject: Strange scenario with Mailscanner + Sendmail Message-ID: <46532BED.3070706@yahoo.com.br> Hi, I?m using Mailscanner with Sendmail to block spam on my network. On the last days, some strange issue began to happen. Mailscanner is liberating spam and saying that the email is on the whitelist. The fact is that the message IS SPAM and the email IS NOT on the whitelist file. Looking on the log and following the processes, I can see that on the first reference of the message, it is showing the correct external email, but when Mailscanner acts, it is showing that the user is on the whitelist. Checking the header of the message, I can see that "X-IAIBR1-MailScanner-From" has the correct email, but "From" (and "X-Originating-Email" and "X-Sender") has an internal email, which is obviously on the whitelist. I suppose the spammer found a way to modify these fields and deceive Mailscanner. How can I protect my network from this kind of attack? Thanks in advance for any information on this. Regards. Marcelo -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ka at pacific.net Tue May 22 19:08:54 2007 From: ka at pacific.net (Ken A) Date: Tue May 22 19:08:54 2007 Subject: Strange scenario with Mailscanner + Sendmail In-Reply-To: <46532BED.3070706@yahoo.com.br> References: <46532BED.3070706@yahoo.com.br> Message-ID: <465331B6.7030701@pacific.net> Luis Marcelo Achite wrote: > Hi, > > I?m using Mailscanner with Sendmail to block spam on my network. On the > last days, some strange issue began to happen. Mailscanner is liberating > spam and saying that the email is on the whitelist. The fact is that the > message IS SPAM and the email IS NOT on the whitelist file. > > Looking on the log and following the processes, I can see that on the > first reference of the message, it is showing the correct external > email, but when Mailscanner acts, it is showing that the user is on the > whitelist. Checking the header of the message, I can see that > "X-IAIBR1-MailScanner-From" has the correct email, but "From" (and > "X-Originating-Email" and "X-Sender") has an internal email, which is > obviously on the whitelist. > > I suppose the spammer found a way to modify these fields and deceive > Mailscanner. > > How can I protect my network from this kind of attack? Are you splitting incoming email to one recipient per message before it reaches sendmail, using queue groups? If not, have you looked for this message ID in sendmail log and verified that there is not a whitelist entry for this "X-IAIBR1-MailScanner-From" for the envelope To: address? Ken Anderson Pacific.Net > > Thanks in advance for any information on this. > > Regards. > > Marcelo > -- Ken Anderson Pacific.Net From ssilva at sgvwater.com Tue May 22 19:16:51 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 22 19:17:18 2007 Subject: MailScanner on Centos 5: updated In-Reply-To: References: <97FD54B5E57A1842AA1A4B232E47611773E3D8@ati-ex-02.ati.local><1964AAFBC212F742958F9275BF63DBB04B0A72@winchester.andrewscompanies.com><4652CCCC.8080806@ecs.soton.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBAB259BE@HC-MBX02.herefordshire.gov.uk> Message-ID: Hugo van der Kooij spake the following on 5/22/2007 7:49 AM: > On Tue, 22 May 2007, Randal, Phil wrote: > >> It might be worthwhile dropping a line to Dag Wieers asking that the >> module(s) in question be added to RPMForge. > > You are not supposed to look at the notes on my desk ;-) It is on my > tasklist that slowly becomes smaller bit by bit. > > Hugo. > That must be nice. Mine todo list is just a big fifo stack. It never seems to get very much smaller, but it does change! -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From MailScanner at ecs.soton.ac.uk Tue May 22 19:16:07 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 22 19:18:01 2007 Subject: Strange scenario with Mailscanner + Sendmail In-Reply-To: <46532BED.3070706@yahoo.com.br> References: <46532BED.3070706@yahoo.com.br> Message-ID: <46533367.7090301@ecs.soton.ac.uk> A better way of using a whitelist entry to avoid spam-scanning mail coming from your own network is to use the IP addresses of your internal network rather than the email domain name. With Spam Checks = %rules-dir%/spam.checks.rules and then in /etc/MailScanner/rules/spam.checks.rules put this: From: 10.11.12. no FromOrTo; default yes where 10.11.12.* is the IP range of your internal network. You can use most formats of IP range in there. Luis Marcelo Achite wrote: > Hi, > > I?m using Mailscanner with Sendmail to block spam on my network. On > the last days, some strange issue began to happen. Mailscanner is > liberating spam and saying that the email is on the whitelist. The > fact is that the message IS SPAM and the email IS NOT on the whitelist > file. > > Looking on the log and following the processes, I can see that on the > first reference of the message, it is showing the correct external > email, but when Mailscanner acts, it is showing that the user is on > the whitelist. Checking the header of the message, I can see that > "X-IAIBR1-MailScanner-From" has the correct email, but "From" (and > "X-Originating-Email" and "X-Sender") has an internal email, which is > obviously on the whitelist. > > I suppose the spammer found a way to modify these fields and deceive > Mailscanner. > > How can I protect my network from this kind of attack? > > Thanks in advance for any information on this. > > Regards. > > Marcelo > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From rcooper at dwford.com Tue May 22 19:07:16 2007 From: rcooper at dwford.com (Rick Cooper) Date: Tue May 22 19:40:31 2007 Subject: Clamd Scanning Message-ID: <057d01c79c9c$080735f0$0301a8c0@SAHOMELT> This is directed mainly to Julian. I finally found the time to integrate the clamd scanning and I am currently testing. It appears to be quite fast and, of course, reduces the resource requirements quit a bit. I haven't installed a MS version that includes the clamdscan stuff yet and I was thinking that if one is using clamdscan one must have clamd installed and running so would it be ok to call the scanner clamd and make the changes to the virus scanners conf file to reflect that (/bin/false /tmp)? It will be a while before I can submit a patch because I will have to get the time to build a latest version MS that doesn't include any of my personal patches, run it for a bit and then make the patches... But I haven't forgotten just haven't had any time (again). Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From jorgeaaq at csags.com.mx Tue May 22 19:54:19 2007 From: jorgeaaq at csags.com.mx (Jorge Amador Arenas Quezada) Date: Tue May 22 19:58:14 2007 Subject: Rules for my boss In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk> Message-ID: <46533C5B.9040202@csags.com.mx> Hi: i have two questions to the experts, i hope someone point me in the right direction 1.- with mailscanner can make a rule to stop mails above 10Meg but only if is the number of recipients is more than 10 ? 2.- can someone point me in the direction or chpater in manual or book ( i have it, and read it , but i believe i do not have enough imagination to figure out how do this) thanks in advance Jorge From alex at nkpanama.com Tue May 22 20:21:19 2007 From: alex at nkpanama.com (Alex Neuman) Date: Tue May 22 20:22:02 2007 Subject: Strange scenario with Mailscanner + Sendmail In-Reply-To: <46533367.7090301@ecs.soton.ac.uk> References: <46532BED.3070706@yahoo.com.br> <46533367.7090301@ecs.soton.ac.uk> Message-ID: <465342AF.5030307@nkpanama.com> True. Nowadays you even have to (m|f)ilter out people purporting to be from your network using whatever you have on your 220 SMTP response. Julian Field wrote: > A better way of using a whitelist entry to avoid spam-scanning mail > coming from your own network is to use the IP addresses of your > internal network rather than the email domain name. > > With > Spam Checks = %rules-dir%/spam.checks.rules > and then in /etc/MailScanner/rules/spam.checks.rules put this: > > From: 10.11.12. no > FromOrTo; default yes > > where 10.11.12.* is the IP range of your internal network. > You can use most formats of IP range in there. > > Luis Marcelo Achite wrote: >> Hi, >> >> I?m using Mailscanner with Sendmail to block spam on my network. On >> the last days, some strange issue began to happen. Mailscanner is >> liberating spam and saying that the email is on the whitelist. The >> fact is that the message IS SPAM and the email IS NOT on the >> whitelist file. >> >> Looking on the log and following the processes, I can see that on the >> first reference of the message, it is showing the correct external >> email, but when Mailscanner acts, it is showing that the user is on >> the whitelist. Checking the header of the message, I can see that >> "X-IAIBR1-MailScanner-From" has the correct email, but "From" (and >> "X-Originating-Email" and "X-Sender") has an internal email, which is >> obviously on the whitelist. >> >> I suppose the spammer found a way to modify these fields and deceive >> Mailscanner. >> >> How can I protect my network from this kind of attack? >> >> Thanks in advance for any information on this. >> >> Regards. >> >> Marcelo >> > > Jules > From snifer_ at hotmail.com Tue May 22 21:23:19 2007 From: snifer_ at hotmail.com (Juan Pablo Salazar =?utf-8?b?QmVydMOtbg==?=) Date: Tue May 22 21:23:44 2007 Subject: fix: regex for removing tags inside links (phishing filter) References: <46531F94.7080107@ecs.soton.ac.uk> Message-ID: Julian Field ecs.soton.ac.uk> writes: > > > Can you give me a simple example of mine doing it wrong where yours does > it better please? > I need to see your patch in action before accepting it. > > Jules > Hi Julian, here's a sample of a link that is recognized as phishing:
3D"Net>" = hspace=3D10=20 = src=3D"https://www.aa.com/content/images/espanol/mailouts/pageNetSaaversC= L.jpg"=20 align=3Dtop border=3D0>
I recommend you to read the blog post, since the blogger's first approach is something very similar to yours. If you need more info, please let me know. Regards. From MailScanner at ecs.soton.ac.uk Tue May 22 21:34:56 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 22 21:40:09 2007 Subject: Clamd Scanning In-Reply-To: <057d01c79c9c$080735f0$0301a8c0@SAHOMELT> References: <057d01c79c9c$080735f0$0301a8c0@SAHOMELT> Message-ID: <465353F0.3010801@ecs.soton.ac.uk> Rick Cooper wrote: > > This is directed mainly to Julian. I finally found the time to integrate the > clamd scanning and I am currently testing. It appears to be quite fast and, > of course, reduces the resource requirements quit a bit. > > I haven't installed a MS version that includes the clamdscan stuff yet and I > was thinking that if one is using clamdscan one must have clamd installed > and running so would it be ok to call the scanner clamd and make the changes > to the virus scanners conf file to reflect that (/bin/false /tmp)? The installer will replace (or add a .rpmnew) your virus.scanners.conf file with the relevant info in it. I have implemented it using the clamdscan as the overhead of that is pretty small. The correct virus.scanners.conf like looks like this: clamd /opt/MailScanner/lib/clamd-wrapper /usr/local Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Tue May 22 21:36:33 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 22 21:40:48 2007 Subject: MailScanner on Centos 5: updated In-Reply-To: References: <97FD54B5E57A1842AA1A4B232E47611773E3D8@ati-ex-02.ati.local><1964AAFBC212F742958F9275BF63DBB04B0A72@winchester.andrewscompanies.com><4652CCCC.8080806@ecs.soton.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBAB259BE@HC-MBX02.herefordshire.gov.uk> Message-ID: <46535451.6050205@ecs.soton.ac.uk> Scott Silva wrote: > Hugo van der Kooij spake the following on 5/22/2007 7:49 AM: > >> On Tue, 22 May 2007, Randal, Phil wrote: >> >> >>> It might be worthwhile dropping a line to Dag Wieers asking that the >>> module(s) in question be added to RPMForge. >>> >> You are not supposed to look at the notes on my desk ;-) It is on my >> tasklist that slowly becomes smaller bit by bit. >> >> Hugo. >> >> > That must be nice. Mine todo list is just a big fifo stack. It never seems to > get very much smaller, but it does change! > I have installed the latest beta of MailScanner and the latest revision of my ClamAV+SA package on CentOS 5.0 and they both installed and ran just fine. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Tue May 22 21:39:47 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 22 21:41:40 2007 Subject: Rules for my boss In-Reply-To: <46533C5B.9040202@csags.com.mx> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk> <46533C5B.9040202@csags.com.mx> Message-ID: <46535513.6060200@ecs.soton.ac.uk> Jorge Amador Arenas Quezada wrote: > Hi: > > i have two questions to the experts, i hope someone point me in the > right direction > > 1.- with mailscanner can make a rule to stop mails above 10Meg but > only if is the number of recipients is more than 10 ? You would have to do this with a little Custom Function. Attach it to the Maximum Message Size, and make it check the size of the array @{$message->{to}}. Start from the example Custom Function in /usr/lib/MailScanner/MailScanner/CustomFunctions and work from there. Should be pretty straightforward to write. For a donation, I'll even write it for you :-) > > 2.- can someone point me in the direction or chpater in manual or book > ( i have it, and read it , but i believe i do not have enough > imagination to figure out how do this) > > thanks in advance > > Jorge > > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Tue May 22 21:59:27 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 22 22:00:31 2007 Subject: fix: regex for removing tags inside links (phishing filter) In-Reply-To: References: <46531F94.7080107@ecs.soton.ac.uk> Message-ID: <465359AF.2090101@ecs.soton.ac.uk> Juan Pablo Salazar Bert?n wrote: > Julian Field ecs.soton.ac.uk> writes: > > >> Can you give me a simple example of mine doing it wrong where yours does >> it better please? >> I need to see your patch in action before accepting it. >> >> Jules >> >> > > > Hi Julian, here's a sample of a link that is recognized as phishing: > > = > href=3D"https://www.aa.com/content/espanol/ofertasEspeciales/ofertas/netS= > AAversLatam.jhtml"=20 > target=3D_blank>
3D"Net>" = > hspace=3D10=20 > = > src=3D"https://www.aa.com/content/images/espanol/mailouts/pageNetSaaversC= > L.jpg"=20 > align=3Dtop border=3D0> > > I recommend you to read the blog post, since the blogger's first approach is > something very similar to yours. > > If you need more info, please let me know. Regards. > Okay, I understand now, the blog post at least attempts to explain it :-) Explaining big regexps never was very easy! It will be in the next release (4.60.4). Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From rcooper at dwford.com Tue May 22 22:31:55 2007 From: rcooper at dwford.com (Rick Cooper) Date: Tue May 22 22:32:00 2007 Subject: Clamd Scanning In-Reply-To: <465353F0.3010801@ecs.soton.ac.uk> References: <057d01c79c9c$080735f0$0301a8c0@SAHOMELT> <465353F0.3010801@ecs.soton.ac.uk> Message-ID: <05c701c79cb8$9eeb8860$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Julian Field > Sent: Tuesday, May 22, 2007 4:35 PM > To: MailScanner discussion > Subject: Re: Clamd Scanning > > > > Rick Cooper wrote: > > [...] > > to the virus scanners conf file to reflect that (/bin/false /tmp)? > The installer will replace (or add a .rpmnew) your > virus.scanners.conf > file with the relevant info in it. I have implemented it using the > clamdscan as the overhead of that is pretty small. The correct > virus.scanners.conf like looks like this: > clamd /opt/MailScanner/lib/clamd-wrapper /usr/local > > I am not sure I understand, I was referring to the conversation from a couple weeks ago about adding direct clamd support not clamdscan. Wouldn't have a wrapper, update, etc. Would talk directly to the daemon, at least as fast as clamavmodule and doesn't increase the memory overhead a bit. I was under the impression you were interested in that. Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From hvdkooij at vanderkooij.org Tue May 22 22:58:49 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue May 22 22:59:34 2007 Subject: Connection Deferred In-Reply-To: <04D932B0071FE34FA63EBB1977B48D15029C50B4@woodenex.woodmaclaw.local> References: <04D932B0071FE34FA63EBB1977B48D15029C50B4@woodenex.woodmaclaw.local> Message-ID: On Tue, 22 May 2007, Billy A. Pumphrey wrote: > Another update. I did find another setting in there "Limit number of > messages per connection to:". That was set to 20, so I raised it to > 200. Hopefully that will take care of it. Thank you a bunch as there > is hope! There is hope if you are willing to considere dumping exchange ;-) Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From hvdkooij at vanderkooij.org Tue May 22 23:10:26 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue May 22 23:11:02 2007 Subject: MailScanner on Centos 5: updated In-Reply-To: <46535451.6050205@ecs.soton.ac.uk> References: <97FD54B5E57A1842AA1A4B232E47611773E3D8@ati-ex-02.ati.local><1964AAFBC212F742958F9275BF63DBB04B0A72@winchester.andrewscompanies.com><4652CCCC.8080806@ecs.soton.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBAB259BE@HC-MBX02.herefordshire.gov.uk> <46535451.6050205@ecs.soton.ac.uk> Message-ID: On Tue, 22 May 2007, Julian Field wrote: > Scott Silva wrote: >> Hugo van der Kooij spake the following on 5/22/2007 7:49 AM: >> >> > On Tue, 22 May 2007, Randal, Phil wrote: >> > >> > > It might be worthwhile dropping a line to Dag Wieers asking that the >> > > module(s) in question be added to RPMForge. >> > > >> > You are not supposed to look at the notes on my desk ;-) It is on my >> > tasklist that slowly becomes smaller bit by bit. >> > >> That must be nice. Mine todo list is just a big fifo stack. It never seems >> to >> get very much smaller, but it does change! >> > I have installed the latest beta of MailScanner and the latest revision of my > ClamAV+SA package on CentOS 5.0 and they both installed and ran just fine. Can you redo it without your install script? And without customized clamav and SA installs? I get both of these from rpmforge as well: - spamassassin-3.2.0-1.el5.rf - clamav-db-0.90.2-1.el5.rf - clamd-0.90.2-1.el5.rf - clamav-0.90.2-1.el5.rf The only ones not available on rpmforge are: - perl-Filesys-Df-0.90-2 - mailscanner-4.59.4-2 I would have expected that these would have been sufficient: - perl-Filesys-DiskFree-0.06-1.2.el5.rf - perl-Filesys-DiskSpace-0.05-1.2.el5.rf But I still need perl-Filesys-Df-0.90-2 to satisfy mailscanner-4.59.4-2 Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From martinh at solidstatelogic.com Wed May 23 09:35:54 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 23 09:36:04 2007 Subject: feature request: compress attachments In-Reply-To: Message-ID: Jules Any thoughts on this? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Koopmann, Jan-Peter > Sent: 10 May 2007 11:12 > To: mailscanner@lists.mailscanner.info > Subject: feature request: compress attachments > > Hi, > > I just came across another product that offers automatic attachment > compression on mails passing the proxy/gateway. Since many people tend to > send their Powerpoint/Word/Excel files uncompressed due to lazyness this > might actually be a good contribution. There are several solutions for > this available at least for Exchange servers but it should be possible to > implement this within MailScanner. So e.g. with a ruleset I could force > all incoming mails with not compressed attachments to be zipped and save > quite some storage in the Exchange databases. > > > Kind regards, > JP ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From MailScanner at ecs.soton.ac.uk Wed May 23 10:49:29 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 23 10:55:07 2007 Subject: Clamd Scanning In-Reply-To: <05c701c79cb8$9eeb8860$0301a8c0@SAHOMELT> References: <057d01c79c9c$080735f0$0301a8c0@SAHOMELT> <465353F0.3010801@ecs.soton.ac.uk> <05c701c79cb8$9eeb8860$0301a8c0@SAHOMELT> Message-ID: <46540E29.2000007@ecs.soton.ac.uk> Rick Cooper wrote: > > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf >> Of Julian Field >> Sent: Tuesday, May 22, 2007 4:35 PM >> To: MailScanner discussion >> Subject: Re: Clamd Scanning >> >> >> >> Rick Cooper wrote: >> >>> >>> > > [...] > >>> to the virus scanners conf file to reflect that (/bin/false /tmp)? >>> >> The installer will replace (or add a .rpmnew) your >> virus.scanners.conf >> file with the relevant info in it. I have implemented it using the >> clamdscan as the overhead of that is pretty small. The correct >> virus.scanners.conf like looks like this: >> clamd /opt/MailScanner/lib/clamd-wrapper /usr/local >> >> >> > > I am not sure I understand, I was referring to the conversation from a > couple weeks ago about adding direct clamd support not clamdscan. Wouldn't > have a wrapper, update, etc. Would talk directly to the daemon, at least as > fast as clamavmodule and doesn't increase the memory overhead a bit. I was > under the impression you were interested in that. > Oh right,, okay. That sounds like a good idea. > Rick > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Wed May 23 10:55:30 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 23 10:57:47 2007 Subject: feature request: compress attachments In-Reply-To: References: Message-ID: <46540F92.5050108@ecs.soton.ac.uk> Not easy to do. I'll think about it, but no promises, sorry. Martin.Hepworth wrote: > Jules > > Any thoughts on this? > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Koopmann, Jan-Peter >> Sent: 10 May 2007 11:12 >> To: mailscanner@lists.mailscanner.info >> Subject: feature request: compress attachments >> >> Hi, >> >> I just came across another product that offers automatic attachment >> compression on mails passing the proxy/gateway. Since many people tend >> > to > >> send their Powerpoint/Word/Excel files uncompressed due to lazyness >> > this > >> might actually be a good contribution. There are several solutions for >> this available at least for Exchange servers but it should be possible >> > to > >> implement this within MailScanner. So e.g. with a ruleset I could >> > force > >> all incoming mails with not compressed attachments to be zipped and >> > save > >> quite some storage in the Exchange databases. >> >> >> Kind regards, >> JP >> > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From martinh at solidstatelogic.com Wed May 23 11:02:53 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 23 11:03:00 2007 Subject: feature request: compress attachments In-Reply-To: <46540F92.5050108@ecs.soton.ac.uk> Message-ID: <106f047568251e44a37a9ca53d199b41@solidstatelogic.com> Jules Yeah I know it's not easy, that's we thought "you" would be able to help out ;-) Talking of 'you', how's the health? Back to work yet, or just doing MailScanner stuff to get back to speed? -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Julian Field > Sent: 23 May 2007 10:56 > To: MailScanner discussion > Subject: Re: feature request: compress attachments > > Not easy to do. I'll think about it, but no promises, sorry. > > Martin.Hepworth wrote: > > Jules > > > > Any thoughts on this? > > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > > > >> -----Original Message----- > >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > >> bounces@lists.mailscanner.info] On Behalf Of Koopmann, Jan-Peter > >> Sent: 10 May 2007 11:12 > >> To: mailscanner@lists.mailscanner.info > >> Subject: feature request: compress attachments > >> > >> Hi, > >> > >> I just came across another product that offers automatic attachment > >> compression on mails passing the proxy/gateway. Since many people tend > >> > > to > > > >> send their Powerpoint/Word/Excel files uncompressed due to lazyness > >> > > this > > > >> might actually be a good contribution. There are several solutions for > >> this available at least for Exchange servers but it should be possible > >> > > to > > > >> implement this within MailScanner. So e.g. with a ruleset I could > >> > > force > > > >> all incoming mails with not compressed attachments to be zipped and > >> > > save > > > >> quite some storage in the Exchange databases. > >> > >> > >> Kind regards, > >> JP > >> > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are intended for the > > addressee only and may be confidential. If they come to you in error > > you must take no action based on them, nor must you copy or show them > > to anyone. Please advise the sender by replying to this e-mail > > immediately and then delete the original from your computer. > > > > Opinion : Any opinions expressed in this e-mail are entirely those of > > the author and unless specifically stated to the contrary, are not > > necessarily those of the author's employer. > > > > Security Warning : Internet e-mail is not necessarily a secure > > communications medium and can be subject to data corruption. We advise > > that you consider this fact when e-mailing us. > > > > Viruses : We have taken steps to ensure that this e-mail and any > > attachments are free from known viruses but in keeping with good > > computing practice, you should ensure that they are virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic > > Registered as a limited company in England and Wales > > (Company No:5362730) > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > United Kingdom > > ********************************************************************** > > > > > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From MailScanner at ecs.soton.ac.uk Wed May 23 11:15:03 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 23 11:15:55 2007 Subject: feature request: compress attachments In-Reply-To: <106f047568251e44a37a9ca53d199b41@solidstatelogic.com> References: <106f047568251e44a37a9ca53d199b41@solidstatelogic.com> Message-ID: <46541427.2060606@ecs.soton.ac.uk> Martin.Hepworth wrote: > Jules > > Yeah I know it's not easy, that's we thought "you" would be able to help > out ;-) > :-) > Talking of 'you', how's the health? Back to work yet, or just doing > MailScanner stuff to get back to speed? > My health is slowly improving. Unfortunately I'm not managing to put on any weight, which won't make the docs happy, but I am getting a lot stronger. I'm not back at work yet, and am signed off until the start of July. I'm doing MailScanner stuff to stop myself getting bored mostly. It also helps build up my mental stamina so that when I do go back to work, I'll be able to survive a full day. > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Julian Field >> Sent: 23 May 2007 10:56 >> To: MailScanner discussion >> Subject: Re: feature request: compress attachments >> >> Not easy to do. I'll think about it, but no promises, sorry. >> >> Martin.Hepworth wrote: >> >>> Jules >>> >>> Any thoughts on this? >>> >>> -- >>> Martin Hepworth >>> Snr Systems Administrator >>> Solid State Logic >>> Tel: +44 (0)1865 842300 >>> >>> >>> >>>> -----Original Message----- >>>> From: mailscanner-bounces@lists.mailscanner.info >>>> > [mailto:mailscanner- > >>>> bounces@lists.mailscanner.info] On Behalf Of Koopmann, Jan-Peter >>>> Sent: 10 May 2007 11:12 >>>> To: mailscanner@lists.mailscanner.info >>>> Subject: feature request: compress attachments >>>> >>>> Hi, >>>> >>>> I just came across another product that offers automatic attachment >>>> compression on mails passing the proxy/gateway. Since many people >>>> > tend > >>> to >>> >>> >>>> send their Powerpoint/Word/Excel files uncompressed due to lazyness >>>> >>>> >>> this >>> >>> >>>> might actually be a good contribution. There are several solutions >>>> > for > >>>> this available at least for Exchange servers but it should be >>>> > possible > >>> to >>> >>> >>>> implement this within MailScanner. So e.g. with a ruleset I could >>>> >>>> >>> force >>> >>> >>>> all incoming mails with not compressed attachments to be zipped and >>>> >>>> >>> save >>> >>> >>>> quite some storage in the Exchange databases. >>>> >>>> >>>> Kind regards, >>>> JP >>>> >>>> >>> >>> >>> >>> > ********************************************************************** > >>> Confidentiality : This e-mail and any attachments are intended for >>> > the > >>> addressee only and may be confidential. If they come to you in error >>> you must take no action based on them, nor must you copy or show >>> > them > >>> to anyone. Please advise the sender by replying to this e-mail >>> immediately and then delete the original from your computer. >>> >>> Opinion : Any opinions expressed in this e-mail are entirely those >>> > of > >>> the author and unless specifically stated to the contrary, are not >>> necessarily those of the author's employer. >>> >>> Security Warning : Internet e-mail is not necessarily a secure >>> communications medium and can be subject to data corruption. We >>> > advise > >>> that you consider this fact when e-mailing us. >>> >>> Viruses : We have taken steps to ensure that this e-mail and any >>> attachments are free from known viruses but in keeping with good >>> computing practice, you should ensure that they are virus free. >>> >>> Red Lion 49 Ltd T/A Solid State Logic >>> Registered as a limited company in England and Wales >>> (Company No:5362730) >>> Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, >>> United Kingdom >>> >>> > ********************************************************************** > >>> >> Jules >> >> -- >> Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> MailScanner customisation, or any advanced system administration help? >> Contact me at Jules@Jules.FM >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> For all your IT requirements visit www.transtec.co.uk >> >> >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> For all your IT requirements visit www.transtec.co.uk >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From martinh at solidstatelogic.com Wed May 23 11:22:51 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 23 11:22:53 2007 Subject: feature request: compress attachments In-Reply-To: <46541427.2060606@ecs.soton.ac.uk> Message-ID: <7a45998d63765a42803c316eb88d7b6d@solidstatelogic.com> Jules For putting on weight I'd normally recommend sitting in front of the TV eating lots of Chocolate digestives, but given you're general issues that might not be too good an idea ! Anyway take it easy and hopefully the bank holiday will give you an opportunity to get out - dunno what public transport is doing between S'ton and Milton Keynes, but Bletchley Park is a really geeky place to go to! -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Julian Field > Sent: 23 May 2007 11:15 > To: MailScanner discussion > Subject: Re: feature request: compress attachments > > > > Martin.Hepworth wrote: > > Jules > > > > Yeah I know it's not easy, that's we thought "you" would be able to help > > out ;-) > > > :-) > > Talking of 'you', how's the health? Back to work yet, or just doing > > MailScanner stuff to get back to speed? > > > My health is slowly improving. Unfortunately I'm not managing to put on > any weight, which won't make the docs happy, but I am getting a lot > stronger. I'm not back at work yet, and am signed off until the start of > July. I'm doing MailScanner stuff to stop myself getting bored mostly. > It also helps build up my mental stamina so that when I do go back to > work, I'll be able to survive a full day. > > > -- > > Martin Hepworth > > Snr Systems Administrator > > Solid State Logic > > Tel: +44 (0)1865 842300 > > > > > >> -----Original Message----- > >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > >> bounces@lists.mailscanner.info] On Behalf Of Julian Field > >> Sent: 23 May 2007 10:56 > >> To: MailScanner discussion > >> Subject: Re: feature request: compress attachments > >> > >> Not easy to do. I'll think about it, but no promises, sorry. > >> > >> Martin.Hepworth wrote: > >> > >>> Jules > >>> > >>> Any thoughts on this? > >>> > >>> -- > >>> Martin Hepworth > >>> Snr Systems Administrator > >>> Solid State Logic > >>> Tel: +44 (0)1865 842300 > >>> > >>> > >>> > >>>> -----Original Message----- > >>>> From: mailscanner-bounces@lists.mailscanner.info > >>>> > > [mailto:mailscanner- > > > >>>> bounces@lists.mailscanner.info] On Behalf Of Koopmann, Jan-Peter > >>>> Sent: 10 May 2007 11:12 > >>>> To: mailscanner@lists.mailscanner.info > >>>> Subject: feature request: compress attachments > >>>> > >>>> Hi, > >>>> > >>>> I just came across another product that offers automatic attachment > >>>> compression on mails passing the proxy/gateway. Since many people > >>>> > > tend > > > >>> to > >>> > >>> > >>>> send their Powerpoint/Word/Excel files uncompressed due to lazyness > >>>> > >>>> > >>> this > >>> > >>> > >>>> might actually be a good contribution. There are several solutions > >>>> > > for > > > >>>> this available at least for Exchange servers but it should be > >>>> > > possible > > > >>> to > >>> > >>> > >>>> implement this within MailScanner. So e.g. with a ruleset I could > >>>> > >>>> > >>> force > >>> > >>> > >>>> all incoming mails with not compressed attachments to be zipped and > >>>> > >>>> > >>> save > >>> > >>> > >>>> quite some storage in the Exchange databases. > >>>> > >>>> > >>>> Kind regards, > >>>> JP > >>>> > >>>> > >>> > >>> > >>> > >>> > > ********************************************************************** > > > >>> Confidentiality : This e-mail and any attachments are intended for > >>> > > the > > > >>> addressee only and may be confidential. If they come to you in error > >>> you must take no action based on them, nor must you copy or show > >>> > > them > > > >>> to anyone. Please advise the sender by replying to this e-mail > >>> immediately and then delete the original from your computer. > >>> > >>> Opinion : Any opinions expressed in this e-mail are entirely those > >>> > > of > > > >>> the author and unless specifically stated to the contrary, are not > >>> necessarily those of the author's employer. > >>> > >>> Security Warning : Internet e-mail is not necessarily a secure > >>> communications medium and can be subject to data corruption. We > >>> > > advise > > > >>> that you consider this fact when e-mailing us. > >>> > >>> Viruses : We have taken steps to ensure that this e-mail and any > >>> attachments are free from known viruses but in keeping with good > >>> computing practice, you should ensure that they are virus free. > >>> > >>> Red Lion 49 Ltd T/A Solid State Logic > >>> Registered as a limited company in England and Wales > >>> (Company No:5362730) > >>> Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > >>> United Kingdom > >>> > >>> > > ********************************************************************** > > > >>> > >> Jules > >> > >> -- > >> Julian Field MEng CITP > >> www.MailScanner.info > >> Buy the MailScanner book at www.MailScanner.info/store > >> > >> MailScanner customisation, or any advanced system administration help? > >> Contact me at Jules@Jules.FM > >> > >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > >> For all your IT requirements visit www.transtec.co.uk > >> > >> > >> > >> -- > >> This message has been scanned for viruses and > >> dangerous content by MailScanner, and is > >> believed to be clean. > >> For all your IT requirements visit www.transtec.co.uk > >> > >> -- > >> MailScanner mailing list > >> mailscanner@lists.mailscanner.info > >> http://lists.mailscanner.info/mailman/listinfo/mailscanner > >> > >> Before posting, read http://wiki.mailscanner.info/posting > >> > >> Support MailScanner development - buy the book off the website! > >> > > > > > > > > > > ********************************************************************** > > Confidentiality : This e-mail and any attachments are intended for the > > addressee only and may be confidential. If they come to you in error > > you must take no action based on them, nor must you copy or show them > > to anyone. Please advise the sender by replying to this e-mail > > immediately and then delete the original from your computer. > > > > Opinion : Any opinions expressed in this e-mail are entirely those of > > the author and unless specifically stated to the contrary, are not > > necessarily those of the author's employer. > > > > Security Warning : Internet e-mail is not necessarily a secure > > communications medium and can be subject to data corruption. We advise > > that you consider this fact when e-mailing us. > > > > Viruses : We have taken steps to ensure that this e-mail and any > > attachments are free from known viruses but in keeping with good > > computing practice, you should ensure that they are virus free. > > > > Red Lion 49 Ltd T/A Solid State Logic > > Registered as a limited company in England and Wales > > (Company No:5362730) > > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > > United Kingdom > > ********************************************************************** > > > > > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From glenn.steen at gmail.com Wed May 23 11:35:31 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed May 23 11:35:34 2007 Subject: feature request: compress attachments In-Reply-To: <46541427.2060606@ecs.soton.ac.uk> References: <106f047568251e44a37a9ca53d199b41@solidstatelogic.com> <46541427.2060606@ecs.soton.ac.uk> Message-ID: <223f97700705230335q1bc9f308tefd25a7c129505a@mail.gmail.com> On 23/05/07, Julian Field wrote: > > > Martin.Hepworth wrote: > > Jules > > > > Yeah I know it's not easy, that's we thought "you" would be able to help > > out ;-) > > > :-) > > Talking of 'you', how's the health? Back to work yet, or just doing > > MailScanner stuff to get back to speed? > > > My health is slowly improving. Unfortunately I'm not managing to put on > any weight, which won't make the docs happy, but I am getting a lot > stronger. I'm not back at work yet, and am signed off until the start of > July. I'm doing MailScanner stuff to stop myself getting bored mostly. > It also helps build up my mental stamina so that when I do go back to > work, I'll be able to survive a full day. > Glad to hear you're taking it relatively slowly... When you started putting out betas, I was a bit worried (mother hen mentality:-). Talking about betas, do you plan on putting one out with some form of "p record handling" for Postfix any time soon? I've been really bogged down lately, so haven't worked on the "PF2.4 version" ... yet:). If you need a new set of "PF2.3" patches, I think I can find them in the archives for you... Or wherever I put them:-). If you want to look at what I have for 2.4/full body edits, I'll liekly need do a new set... Provided I did get around to doing the ugly "spin through security check" in ReadQf... RALM striking again (I think you are familiar with the consept... Random Access Lossy Memory:), mostly since I've been very busy with other stuff. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From Q.G.Campbell at newcastle.ac.uk Wed May 23 13:32:31 2007 From: Q.G.Campbell at newcastle.ac.uk (Quentin Campbell) Date: Wed May 23 13:39:59 2007 Subject: 4.60.3-1 install errors on RH AS4 - error when it is run In-Reply-To: <4652F544.5050007@ecs.soton.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk> <4652F544.5050007@ecs.soton.ac.uk> Message-ID: <4165CF7A7F12DE4B96622CCBB90586470A4D11AE@largo.campus.ncl.ac.uk> >-----Original Message----- >From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >bounces@lists.mailscanner.info] On Behalf Of Julian Field >Sent: 22 May 2007 14:51 >To: MailScanner discussion >Subject: Re: 4.60.3-1 install errors on RH AS4 > >-----BEGIN PGP SIGNED MESSAGE----- >Hash: SHA1 > >But does MailScanner still work okay, despite the installation problems? > >Which update of AS4 are you using? > Julian A 'cat /etc/redhat-release' gives "Red Hat Enterprise Linux AS release 4 (Nahant Update 4)" Ran MailScanner 4.60.3-1 in debug mode and got (from two different invocations): [root@cheviot9 clamav]# service MailScanner start Starting MailScanner daemons: incoming sendmail: [ OK ] outgoing sendmail: [ OK ] MailScanner: In Debugging mode, not forking... Use of uninitialized value in concatenation (.) or string at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1087. Use of uninitialized value in concatenation (.) or string at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1089. check: no loaded plugin implements 'check_main': cannot scan! at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/PerMsgStatus.pm line 164. Ignore errors about failing to find EOCD signature format error: can't find EOCD signature at /usr/sbin/MailScanner line 832 Stopping now as you are debugging me. [ OK ] [root@cheviot9 clamav]# service MailScanner start Starting MailScanner daemons: incoming sendmail: [ OK ] outgoing sendmail: [ OK ] MailScanner: In Debugging mode, not forking... Use of uninitialized value in concatenation (.) or string at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1087. Use of uninitialized value in concatenation (.) or string at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1089. check: no loaded plugin implements 'check_main': cannot scan! at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/PerMsgStatus.pm line 164. Ignore errors about failing to find EOCD signature Stopping now as you are debugging me The /var/log/maillog for the last start shows: ... May 23 12:54:46 cheviot9 sendmail[5060]: alias database /etc/mail/aliases rebuilt by root May 23 12:54:46 cheviot9 sendmail[5060]: /etc/mail/aliases: 408 aliases, longest 83 bytes, 21885 bytes total May 23 12:54:46 cheviot9 sendmail[5069]: starting daemon (8.13.1): SMTP May 23 12:54:46 cheviot9 sendmail[5069]: STARTTLS: ServerCertFile missing May 23 12:54:46 cheviot9 sendmail[5069]: started as: /usr/sbin/sendmail -bd -OPrivacyOptions=noetrn -ODeliveryMode=queueonly -OQueueDirectory=/var/spool/mqueue.in -OPidFile=/var/run/sendmail.in.pid May 23 12:54:46 cheviot9 sm-msp-queue[5073]: starting daemon (8.13.1): queueing@00:15:00 May 23 12:54:46 cheviot9 sendmail[5078]: starting daemon (8.13.1): queueing@00:15:00 May 23 12:54:46 cheviot9 sendmail[5078]: started as: /usr/sbin/sendmail -q15m -OPidFile=/var/run/sendmail.out.pid May 23 12:54:47 cheviot9 MailScanner[5094]: MailScanner E-Mail Virus Scanner version 4.60.3 starting... May 23 12:54:48 cheviot9 MailScanner[5094]: Read 764 hostnames from the phishing whitelist May 23 12:54:48 cheviot9 MailScanner[5094]: Using SpamAssassin results cache May 23 12:54:48 cheviot9 MailScanner[5094]: Connected to SpamAssassin cache database May 23 12:54:48 cheviot9 MailScanner[5094]: lock.pl sees Config LockType = posix May 23 12:54:48 cheviot9 MailScanner[5094]: lock.pl sees have_module = 0 May 23 12:54:48 cheviot9 MailScanner[5094]: Using locktype = posix May 23 12:54:48 cheviot9 MailScanner[5094]: Creating hardcoded struct_flock subroutine for linux (Linux-type) May 23 12:54:48 cheviot9 MailScanner[5094]: New Batch: Scanning 1 messages, 1597 bytes May 23 12:54:48 cheviot9 MailScanner[5094]: Created attachment dirs for 1 messages May 23 12:54:48 cheviot9 MailScanner[5094]: MCP Checks: Starting May 23 12:54:48 cheviot9 MailScanner[5094]: Message Content Protection SpamAssassin returned 65280 May 23 12:54:48 cheviot9 MailScanner[5094]: MCP Checks completed at 17428 bytes per second May 23 12:54:48 cheviot9 MailScanner[5094]: Spam Checks: Starting May 23 12:54:49 cheviot9 MailScanner[5094]: Virus and Content Scanning: Starting May 23 12:54:49 cheviot9 MailScanner[5094]: Commencing scanning by clamav... May 23 12:54:58 cheviot9 MailScanner[5094]: Completed scanning by clamav May 23 12:54:58 cheviot9 MailScanner[5094]: Commencing scanning by mcafee... May 23 12:54:58 cheviot9 MailScanner[5094]: Completed scanning by mcafee May 23 12:54:58 cheviot9 MailScanner[5094]: Completed checking by /usr/bin/file May 23 12:54:58 cheviot9 MailScanner[5094]: Virus Scanning completed at 161 bytes per second May 23 12:54:58 cheviot9 MailScanner[5094]: About to deliver 1 messages May 23 12:54:58 cheviot9 MailScanner[5094]: Uninfected: Delivered 1 messages May 23 12:54:58 cheviot9 MailScanner[5094]: Virus Processing completed at 191303 bytes per second May 23 12:54:58 cheviot9 MailScanner[5094]: Batch completed at 159 bytes per second (1597 / 9) May 23 12:54:58 cheviot9 MailScanner[5094]: Batch (1 message) processed in 9.99 seconds May 23 12:54:58 cheviot9 MailScanner[5094]: MailScanner child dying of old age May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: ClientCertFile missing May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: ClientKeyFile missing May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: CACertPath missing May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: CACertFile missing May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: CRLFile missing May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS=client, init=1 May 23 12:54:58 cheviot9 sendmail[5107]: l4NBpfpt004809: SMTP outgoing connect on cheviot9.ncl.ac.uk May 23 12:55:01 cheviot9 sendmail[5107]: l4NBpfpt004809: to=, delay=00:03:20, xdelay=00:00:03, mailer=esmtp, pri=121128, relay=burnmoor.ncl.ac.uk. [128.240.233.53], dsn=2.0.0, stat=Sent (MAA29651 Message accepted for delivery) May 23 12:55:01 cheviot9 sendmail[5107]: l4NBpfpt004809: done; delay=00:03:20, ntries=1 ... I hope that provides the info you need? Quentin --- PHONE: +44 191 222 8209 Information Systems and Services (ISS), Newcastle University, Newcastle upon Tyne, FAX: +44 191 222 8765 United Kingdom, NE1 7RU. ------------------------------------------------------------------ From MailScanner at ecs.soton.ac.uk Wed May 23 15:18:07 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 23 15:18:53 2007 Subject: 4.60.3-1 install errors on RH AS4 - error when it is run In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470A4D11AE@largo.campus.ncl.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk> <4652F544.5050007@ecs.soton.ac.uk> <4165CF7A7F12DE4B96622CCBB90586470A4D11AE@largo.campus.ncl.ac.uk> Message-ID: <46544D1F.7000900@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 This would imply an error in your /etc/mail/spamassassin/*.pre files. Some important plugin isn't being loaded. If you wipe SpamAssassin and reinstall it, does that help? If you're using an RPM of SA, then just rpm -e it. Otherwise wipe /etc/mail/spamassassin and SpamAssassin.pm (wherever that is under /usr/lib/perl5), then reinstall SpamAssassin. Quentin Campbell wrote: >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Julian Field >> Sent: 22 May 2007 14:51 >> To: MailScanner discussion >> Subject: Re: 4.60.3-1 install errors on RH AS4 >> >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> But does MailScanner still work okay, despite the installation >> > problems? > >> Which update of AS4 are you using? >> >> > > Julian > > A 'cat /etc/redhat-release' gives "Red Hat Enterprise Linux AS release 4 > (Nahant Update 4)" > > Ran MailScanner 4.60.3-1 in debug mode and got (from two different > invocations): > > [root@cheviot9 clamav]# service MailScanner start > Starting MailScanner daemons: > incoming sendmail: [ OK ] > outgoing sendmail: [ OK ] > MailScanner: In Debugging mode, not forking... > Use of uninitialized value in concatenation (.) or string at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1087. > Use of uninitialized value in concatenation (.) or string at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1089. > check: no loaded plugin implements 'check_main': cannot scan! at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/PerMsgStatus.pm line > 164. > Ignore errors about failing to find EOCD signature > format error: can't find EOCD signature > at /usr/sbin/MailScanner line 832 > Stopping now as you are debugging me. > [ OK ] > [root@cheviot9 clamav]# service MailScanner start > Starting MailScanner daemons: > incoming sendmail: [ OK ] > outgoing sendmail: [ OK ] > MailScanner: In Debugging mode, not forking... > Use of uninitialized value in concatenation (.) or string at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1087. > Use of uninitialized value in concatenation (.) or string at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1089. > check: no loaded plugin implements 'check_main': cannot scan! at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/PerMsgStatus.pm line > 164. > Ignore errors about failing to find EOCD signature > Stopping now as you are debugging me > > > The /var/log/maillog for the last start shows: > > ... > May 23 12:54:46 cheviot9 sendmail[5060]: alias database > /etc/mail/aliases rebuilt by root > May 23 12:54:46 cheviot9 sendmail[5060]: /etc/mail/aliases: 408 aliases, > longest 83 bytes, 21885 bytes total > May 23 12:54:46 cheviot9 sendmail[5069]: starting daemon (8.13.1): SMTP > May 23 12:54:46 cheviot9 sendmail[5069]: STARTTLS: ServerCertFile > missing > May 23 12:54:46 cheviot9 sendmail[5069]: started as: /usr/sbin/sendmail > -bd -OPrivacyOptions=noetrn -ODeliveryMode=queueonly > -OQueueDirectory=/var/spool/mqueue.in -OPidFile=/var/run/sendmail.in.pid > May 23 12:54:46 cheviot9 sm-msp-queue[5073]: starting daemon (8.13.1): > queueing@00:15:00 > May 23 12:54:46 cheviot9 sendmail[5078]: starting daemon (8.13.1): > queueing@00:15:00 > May 23 12:54:46 cheviot9 sendmail[5078]: started as: /usr/sbin/sendmail > -q15m -OPidFile=/var/run/sendmail.out.pid > May 23 12:54:47 cheviot9 MailScanner[5094]: MailScanner E-Mail Virus > Scanner version 4.60.3 starting... > May 23 12:54:48 cheviot9 MailScanner[5094]: Read 764 hostnames from the > phishing whitelist > May 23 12:54:48 cheviot9 MailScanner[5094]: Using SpamAssassin results > cache > May 23 12:54:48 cheviot9 MailScanner[5094]: Connected to SpamAssassin > cache database > May 23 12:54:48 cheviot9 MailScanner[5094]: lock.pl sees Config > LockType = posix > May 23 12:54:48 cheviot9 MailScanner[5094]: lock.pl sees have_module = > 0 > May 23 12:54:48 cheviot9 MailScanner[5094]: Using locktype = posix > May 23 12:54:48 cheviot9 MailScanner[5094]: Creating hardcoded > struct_flock subroutine for linux (Linux-type) > May 23 12:54:48 cheviot9 MailScanner[5094]: New Batch: Scanning 1 > messages, 1597 bytes > May 23 12:54:48 cheviot9 MailScanner[5094]: Created attachment dirs for > 1 messages > May 23 12:54:48 cheviot9 MailScanner[5094]: MCP Checks: Starting > May 23 12:54:48 cheviot9 MailScanner[5094]: Message Content Protection > SpamAssassin returned 65280 > May 23 12:54:48 cheviot9 MailScanner[5094]: MCP Checks completed at > 17428 bytes per second > May 23 12:54:48 cheviot9 MailScanner[5094]: Spam Checks: Starting > May 23 12:54:49 cheviot9 MailScanner[5094]: Virus and Content Scanning: > Starting > May 23 12:54:49 cheviot9 MailScanner[5094]: Commencing scanning by > clamav... > May 23 12:54:58 cheviot9 MailScanner[5094]: Completed scanning by clamav > > May 23 12:54:58 cheviot9 MailScanner[5094]: Commencing scanning by > mcafee... > May 23 12:54:58 cheviot9 MailScanner[5094]: Completed scanning by mcafee > > May 23 12:54:58 cheviot9 MailScanner[5094]: Completed checking by > /usr/bin/file > May 23 12:54:58 cheviot9 MailScanner[5094]: Virus Scanning completed at > 161 bytes per second > May 23 12:54:58 cheviot9 MailScanner[5094]: About to deliver 1 messages > May 23 12:54:58 cheviot9 MailScanner[5094]: Uninfected: Delivered 1 > messages > May 23 12:54:58 cheviot9 MailScanner[5094]: Virus Processing completed > at 191303 bytes per second > May 23 12:54:58 cheviot9 MailScanner[5094]: Batch completed at 159 bytes > per second (1597 / 9) > May 23 12:54:58 cheviot9 MailScanner[5094]: Batch (1 message) processed > in 9.99 seconds > May 23 12:54:58 cheviot9 MailScanner[5094]: MailScanner child dying of > old age > May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: ClientCertFile > missing > May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: ClientKeyFile missing > May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: CACertPath missing > May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: CACertFile missing > May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: CRLFile missing > May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS=client, init=1 > May 23 12:54:58 cheviot9 sendmail[5107]: l4NBpfpt004809: SMTP outgoing > connect on cheviot9.ncl.ac.uk > May 23 12:55:01 cheviot9 sendmail[5107]: l4NBpfpt004809: > to=, delay=00:03:20, xdelay=00:00:03, > mailer=esmtp, pri=121128, relay=burnmoor.ncl.ac.uk. [128.240.233.53], > dsn=2.0.0, stat=Sent (MAA29651 Message accepted for delivery) > May 23 12:55:01 cheviot9 sendmail[5107]: l4NBpfpt004809: done; > delay=00:03:20, ntries=1 > ... > > > I hope that provides the info you need? > > Quentin > --- > PHONE: +44 191 222 8209 Information Systems and Services (ISS), > Newcastle University, > Newcastle upon Tyne, > FAX: +44 191 222 8765 United Kingdom, NE1 7RU. > ------------------------------------------------------------------ > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGVE0lEfZZRxQVtlQRAuHDAJ9H7C/oI91zZCPnhwlTh96vGb3USgCgyT7O x771DyI3vw2w2hDZVuQqp2U= =Ixb3 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From alex at nkpanama.com Wed May 23 15:32:07 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Wed May 23 15:32:53 2007 Subject: feature request: compress attachments In-Reply-To: <46541427.2060606@ecs.soton.ac.uk> References: <106f047568251e44a37a9ca53d199b41@solidstatelogic.com> <46541427.2060606@ecs.soton.ac.uk> Message-ID: <46545067.6030902@nkpanama.com> Julian Field wrote: > > > Martin.Hepworth wrote: >> Jules >> >> Yeah I know it's not easy, that's we thought "you" would be able to help >> out ;-) >> > :-) >> Talking of 'you', how's the health? Back to work yet, or just doing >> MailScanner stuff to get back to speed? >> > My health is slowly improving. Unfortunately I'm not managing to put > on any weight, which won't make the docs happy, but I am getting a lot > stronger. I'm not back at work yet, and am signed off until the start > of July. I'm doing MailScanner stuff to stop myself getting bored > mostly. It also helps build up my mental stamina so that when I do go > back to work, I'll be able to survive a full day. > I can give you my near-foolproof way of putting on weight in a few "two words..." phrases: * Haagen Dazs * Sara Lee * Baskin Robbins ... thank you, I'll be here all week! :-) >> -- >> Martin Hepworth >> Snr Systems Administrator >> Solid State Logic >> Tel: +44 (0)1865 842300 >> >> >>> -----Original Message----- >>> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >>> bounces@lists.mailscanner.info] On Behalf Of Julian Field >>> Sent: 23 May 2007 10:56 >>> To: MailScanner discussion >>> Subject: Re: feature request: compress attachments >>> >>> Not easy to do. I'll think about it, but no promises, sorry. >>> >>> Martin.Hepworth wrote: >>> >>>> Jules >>>> >>>> Any thoughts on this? >>>> >>>> -- >>>> Martin Hepworth >>>> Snr Systems Administrator >>>> Solid State Logic >>>> Tel: +44 (0)1865 842300 >>>> >>>> >>>> >>>>> -----Original Message----- >>>>> From: mailscanner-bounces@lists.mailscanner.info >>>>> >> [mailto:mailscanner- >> >>>>> bounces@lists.mailscanner.info] On Behalf Of Koopmann, Jan-Peter >>>>> Sent: 10 May 2007 11:12 >>>>> To: mailscanner@lists.mailscanner.info >>>>> Subject: feature request: compress attachments >>>>> >>>>> Hi, >>>>> >>>>> I just came across another product that offers automatic attachment >>>>> compression on mails passing the proxy/gateway. Since many people >>>>> >> tend >> >>>> to >>>> >>>> >>>>> send their Powerpoint/Word/Excel files uncompressed due to lazyness >>>>> >>>>> >>>> this >>>> >>>> >>>>> might actually be a good contribution. There are several solutions >>>>> >> for >> >>>>> this available at least for Exchange servers but it should be >>>>> >> possible >> >>>> to >>>> >>>> >>>>> implement this within MailScanner. So e.g. with a ruleset I could >>>>> >>>>> >>>> force >>>> >>>> >>>>> all incoming mails with not compressed attachments to be zipped and >>>>> >>>>> >>>> save >>>> >>>> >>>>> quite some storage in the Exchange databases. >>>>> >>>>> >>>>> Kind regards, >>>>> JP >>>>> >>>>> >>>> >>>> >>>> >>>> >> ********************************************************************** >> >>>> Confidentiality : This e-mail and any attachments are intended for >>>> >> the >> >>>> addressee only and may be confidential. If they come to you in error >>>> you must take no action based on them, nor must you copy or show >>>> >> them >> >>>> to anyone. Please advise the sender by replying to this e-mail >>>> immediately and then delete the original from your computer. >>>> >>>> Opinion : Any opinions expressed in this e-mail are entirely those >>>> >> of >> >>>> the author and unless specifically stated to the contrary, are not >>>> necessarily those of the author's employer. >>>> >>>> Security Warning : Internet e-mail is not necessarily a secure >>>> communications medium and can be subject to data corruption. We >>>> >> advise >> >>>> that you consider this fact when e-mailing us. >>>> >>>> Viruses : We have taken steps to ensure that this e-mail and any >>>> attachments are free from known viruses but in keeping with good >>>> computing practice, you should ensure that they are virus free. >>>> >>>> Red Lion 49 Ltd T/A Solid State Logic >>>> Registered as a limited company in England and Wales >>>> (Company No:5362730) >>>> Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, >>>> United Kingdom >>>> >>>> >> ********************************************************************** >> >>>> >>> Jules >>> >>> -- >>> Julian Field MEng CITP >>> www.MailScanner.info >>> Buy the MailScanner book at www.MailScanner.info/store >>> >>> MailScanner customisation, or any advanced system administration help? >>> Contact me at Jules@Jules.FM >>> >>> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >>> For all your IT requirements visit www.transtec.co.uk >>> >>> >>> >>> -- >>> This message has been scanned for viruses and >>> dangerous content by MailScanner, and is >>> believed to be clean. >>> For all your IT requirements visit www.transtec.co.uk >>> >>> -- >>> MailScanner mailing list >>> mailscanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! >>> >> >> >> >> >> ********************************************************************** >> Confidentiality : This e-mail and any attachments are intended for >> the addressee only and may be confidential. If they come to you in >> error you must take no action based on them, nor must you copy or >> show them to anyone. Please advise the sender by replying to this >> e-mail immediately and then delete the original from your computer. >> >> Opinion : Any opinions expressed in this e-mail are entirely those of >> the author and unless specifically stated to the contrary, are not >> necessarily those of the author's employer. >> >> Security Warning : Internet e-mail is not necessarily a secure >> communications medium and can be subject to data corruption. We >> advise that you consider this fact when e-mailing us. >> Viruses : We have taken steps to ensure that this e-mail and any >> attachments are free from known viruses but in keeping with good >> computing practice, you should ensure that they are virus free. >> >> Red Lion 49 Ltd T/A Solid State Logic >> Registered as a limited company in England and Wales (Company >> No:5362730) >> Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, >> United Kingdom >> ********************************************************************** >> >> > > Jules > From alex at nkpanama.com Wed May 23 15:33:20 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Wed May 23 15:34:15 2007 Subject: feature request: compress attachments In-Reply-To: <223f97700705230335q1bc9f308tefd25a7c129505a@mail.gmail.com> References: <106f047568251e44a37a9ca53d199b41@solidstatelogic.com> <46541427.2060606@ecs.soton.ac.uk> <223f97700705230335q1bc9f308tefd25a7c129505a@mail.gmail.com> Message-ID: <465450B0.3030405@nkpanama.com> Glenn Steen wrote: > Talking about betas, do you plan on putting one out with some form of > "p record handling" for Postfix any time soon? I think it's on hold pending the acquisition of a new pedal-driven perforator! :-) > > > Cheers From martinh at solidstatelogic.com Wed May 23 15:43:27 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Wed May 23 15:43:32 2007 Subject: feature request: compress attachments In-Reply-To: <46545067.6030902@nkpanama.com> Message-ID: No Ben & Jerry's - Haagan Dazs is rubbish in comparison... -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Alex Neuman van der Hans > Sent: 23 May 2007 15:32 > To: MailScanner discussion > Subject: Re: feature request: compress attachments > > Julian Field wrote: > > > > > > Martin.Hepworth wrote: > >> Jules > >> > >> Yeah I know it's not easy, that's we thought "you" would be able to > help > >> out ;-) > >> > > :-) > >> Talking of 'you', how's the health? Back to work yet, or just doing > >> MailScanner stuff to get back to speed? > >> > > My health is slowly improving. Unfortunately I'm not managing to put > > on any weight, which won't make the docs happy, but I am getting a lot > > stronger. I'm not back at work yet, and am signed off until the start > > of July. I'm doing MailScanner stuff to stop myself getting bored > > mostly. It also helps build up my mental stamina so that when I do go > > back to work, I'll be able to survive a full day. > > > I can give you my near-foolproof way of putting on weight in a few "two > words..." phrases: > * Haagen Dazs > * Sara Lee > * Baskin Robbins > ... thank you, I'll be here all week! :-) > >> -- > >> Martin Hepworth > >> Snr Systems Administrator > >> Solid State Logic > >> Tel: +44 (0)1865 842300 > >> > >> > >>> -----Original Message----- > >>> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > >>> bounces@lists.mailscanner.info] On Behalf Of Julian Field > >>> Sent: 23 May 2007 10:56 > >>> To: MailScanner discussion > >>> Subject: Re: feature request: compress attachments > >>> > >>> Not easy to do. I'll think about it, but no promises, sorry. > >>> > >>> Martin.Hepworth wrote: > >>> > >>>> Jules > >>>> > >>>> Any thoughts on this? > >>>> > >>>> -- > >>>> Martin Hepworth > >>>> Snr Systems Administrator > >>>> Solid State Logic > >>>> Tel: +44 (0)1865 842300 > >>>> > >>>> > >>>> > >>>>> -----Original Message----- > >>>>> From: mailscanner-bounces@lists.mailscanner.info > >>>>> > >> [mailto:mailscanner- > >> > >>>>> bounces@lists.mailscanner.info] On Behalf Of Koopmann, Jan-Peter > >>>>> Sent: 10 May 2007 11:12 > >>>>> To: mailscanner@lists.mailscanner.info > >>>>> Subject: feature request: compress attachments > >>>>> > >>>>> Hi, > >>>>> > >>>>> I just came across another product that offers automatic attachment > >>>>> compression on mails passing the proxy/gateway. Since many people > >>>>> > >> tend > >> > >>>> to > >>>> > >>>> > >>>>> send their Powerpoint/Word/Excel files uncompressed due to lazyness > >>>>> > >>>>> > >>>> this > >>>> > >>>> > >>>>> might actually be a good contribution. There are several solutions > >>>>> > >> for > >> > >>>>> this available at least for Exchange servers but it should be > >>>>> > >> possible > >> > >>>> to > >>>> > >>>> > >>>>> implement this within MailScanner. So e.g. with a ruleset I could > >>>>> > >>>>> > >>>> force > >>>> > >>>> > >>>>> all incoming mails with not compressed attachments to be zipped and > >>>>> > >>>>> > >>>> save > >>>> > >>>> > >>>>> quite some storage in the Exchange databases. > >>>>> > >>>>> > >>>>> Kind regards, > >>>>> JP > >>>>> > >>>>> > >>>> > >>>> > >>>> > >>>> > >> ********************************************************************** > >> > >>>> Confidentiality : This e-mail and any attachments are intended for > >>>> > >> the > >> > >>>> addressee only and may be confidential. If they come to you in error > >>>> you must take no action based on them, nor must you copy or show > >>>> > >> them > >> > >>>> to anyone. Please advise the sender by replying to this e-mail > >>>> immediately and then delete the original from your computer. > >>>> > >>>> Opinion : Any opinions expressed in this e-mail are entirely those > >>>> > >> of > >> > >>>> the author and unless specifically stated to the contrary, are not > >>>> necessarily those of the author's employer. > >>>> > >>>> Security Warning : Internet e-mail is not necessarily a secure > >>>> communications medium and can be subject to data corruption. We > >>>> > >> advise > >> > >>>> that you consider this fact when e-mailing us. > >>>> > >>>> Viruses : We have taken steps to ensure that this e-mail and any > >>>> attachments are free from known viruses but in keeping with good > >>>> computing practice, you should ensure that they are virus free. > >>>> > >>>> Red Lion 49 Ltd T/A Solid State Logic > >>>> Registered as a limited company in England and Wales > >>>> (Company No:5362730) > >>>> Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > >>>> United Kingdom > >>>> > >>>> > >> ********************************************************************** > >> > >>>> > >>> Jules > >>> > >>> -- > >>> Julian Field MEng CITP > >>> www.MailScanner.info > >>> Buy the MailScanner book at www.MailScanner.info/store > >>> > >>> MailScanner customisation, or any advanced system administration help? > >>> Contact me at Jules@Jules.FM > >>> > >>> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > >>> For all your IT requirements visit www.transtec.co.uk > >>> > >>> > >>> > >>> -- > >>> This message has been scanned for viruses and > >>> dangerous content by MailScanner, and is > >>> believed to be clean. > >>> For all your IT requirements visit www.transtec.co.uk > >>> > >>> -- > >>> MailScanner mailing list > >>> mailscanner@lists.mailscanner.info > >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner > >>> > >>> Before posting, read http://wiki.mailscanner.info/posting > >>> > >>> Support MailScanner development - buy the book off the website! > >>> > >> > >> > >> > >> > >> ********************************************************************** > >> Confidentiality : This e-mail and any attachments are intended for > >> the addressee only and may be confidential. If they come to you in > >> error you must take no action based on them, nor must you copy or > >> show them to anyone. Please advise the sender by replying to this > >> e-mail immediately and then delete the original from your computer. > >> > >> Opinion : Any opinions expressed in this e-mail are entirely those of > >> the author and unless specifically stated to the contrary, are not > >> necessarily those of the author's employer. > >> > >> Security Warning : Internet e-mail is not necessarily a secure > >> communications medium and can be subject to data corruption. We > >> advise that you consider this fact when e-mailing us. > >> Viruses : We have taken steps to ensure that this e-mail and any > >> attachments are free from known viruses but in keeping with good > >> computing practice, you should ensure that they are virus free. > >> > >> Red Lion 49 Ltd T/A Solid State Logic > >> Registered as a limited company in England and Wales (Company > >> No:5362730) > >> Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > >> United Kingdom > >> ********************************************************************** > >> > >> > > > > Jules > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From MailScanner at ecs.soton.ac.uk Wed May 23 15:43:22 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 23 15:44:18 2007 Subject: feature request: compress attachments In-Reply-To: <223f97700705230335q1bc9f308tefd25a7c129505a@mail.gmail.com> References: <106f047568251e44a37a9ca53d199b41@solidstatelogic.com> <46541427.2060606@ecs.soton.ac.uk> <223f97700705230335q1bc9f308tefd25a7c129505a@mail.gmail.com> Message-ID: <4654530A.2020503@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Glenn Steen wrote: > Talking about betas, do you plan on putting one out with some form of > "p record handling" for Postfix any time soon? I've been really bogged > down lately, so haven't worked on the "PF2.4 version" ... yet:). > If you need a new set of "PF2.3" patches, I think I can find them in > the archives for you... Or wherever I put them:-). If you want to look > at what I have for 2.4/full body edits, I'll liekly need do a new > set... Provided I did get around to doing the ugly "spin through > security check" in ReadQf... RALM striking again (I think you are > familiar with the consept... Random Access Lossy Memory:), mostly > since I've been very busy with other stuff. How do I make PF generate these "p records"? As they can only be generated locally, they shouldn't contain malicious content so I probably don't need to merge them into the main text, I just need to handle them and be able to put them back in at the end. Does that sound likely? What can p records actually do? I would be very interested in a set of PF2.3 patches. What is the difference between 2.3 and 2.4? Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGVFMQEfZZRxQVtlQRAs1/AJ4kwqlJdl+bWb9jbtAEp1Hh8I96TgCg2Jag gx+wcjnL92/GIXoPidhVxJ0= =ffmX -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From amaclach at yahoo.co.uk Wed May 23 17:20:21 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Wed May 23 17:20:24 2007 Subject: feature request: compress attachments Message-ID: <55537.40454.qm@web26311.mail.ukl.yahoo.com> Guinness & kebabs - works (too well) for me... ----- Original Message ---- From: Martin.Hepworth To: MailScanner discussion Sent: Wednesday, 23 May, 2007 3:43:27 PM Subject: RE: feature request: compress attachments No Ben & Jerry's - Haagan Dazs is rubbish in comparison... -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Alex Neuman van der Hans > Sent: 23 May 2007 15:32 > To: MailScanner discussion > Subject: Re: feature request: compress attachments > > Julian Field wrote: > > > > > > Martin.Hepworth wrote: > >> Jules > >> > >> Yeah I know it's not easy, that's we thought "you" would be able to > help > >> out ;-) > >> > > :-) > >> Talking of 'you', how's the health? Back to work yet, or just doing > >> MailScanner stuff to get back to speed? > >> > > My health is slowly improving. Unfortunately I'm not managing to put > > on any weight, which won't make the docs happy, but I am getting a lot > > stronger. I'm not back at work yet, and am signed off until the start > > of July. I'm doing MailScanner stuff to stop myself getting bored > > mostly. It also helps build up my mental stamina so that when I do go > > back to work, I'll be able to survive a full day. > > > I can give you my near-foolproof way of putting on weight in a few "two > words..." phrases: > * Haagen Dazs > * Sara Lee > * Baskin Robbins > ... thank you, I'll be here all week! :-) > >> -- > >> Martin Hepworth > >> Snr Systems Administrator > >> Solid State Logic > >> Tel: +44 (0)1865 842300 > >> > >> > >>> -----Original Message----- > >>> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > >>> bounces@lists.mailscanner.info] On Behalf Of Julian Field > >>> Sent: 23 May 2007 10:56 > >>> To: MailScanner discussion > >>> Subject: Re: feature request: compress attachments > >>> > >>> Not easy to do. I'll think about it, but no promises, sorry. > >>> > >>> Martin.Hepworth wrote: > >>> > >>>> Jules > >>>> > >>>> Any thoughts on this? > >>>> > >>>> -- > >>>> Martin Hepworth > >>>> Snr Systems Administrator > >>>> Solid State Logic > >>>> Tel: +44 (0)1865 842300 > >>>> > >>>> > >>>> > >>>>> -----Original Message----- > >>>>> From: mailscanner-bounces@lists.mailscanner.info > >>>>> > >> [mailto:mailscanner- > >> > >>>>> bounces@lists.mailscanner.info] On Behalf Of Koopmann, Jan-Peter > >>>>> Sent: 10 May 2007 11:12 > >>>>> To: mailscanner@lists.mailscanner.info > >>>>> Subject: feature request: compress attachments > >>>>> > >>>>> Hi, > >>>>> > >>>>> I just came across another product that offers automatic attachment > >>>>> compression on mails passing the proxy/gateway. Since many people > >>>>> > >> tend > >> > >>>> to > >>>> > >>>> > >>>>> send their Powerpoint/Word/Excel files uncompressed due to lazyness > >>>>> > >>>>> > >>>> this > >>>> > >>>> > >>>>> might actually be a good contribution. There are several solutions > >>>>> > >> for > >> > >>>>> this available at least for Exchange servers but it should be > >>>>> > >> possible > >> > >>>> to > >>>> > >>>> > >>>>> implement this within MailScanner. So e.g. with a ruleset I could > >>>>> > >>>>> > >>>> force > >>>> > >>>> > >>>>> all incoming mails with not compressed attachments to be zipped and > >>>>> > >>>>> > >>>> save > >>>> > >>>> > >>>>> quite some storage in the Exchange databases. > >>>>> > >>>>> > >>>>> Kind regards, > >>>>> JP > >>>>> > >>>>> > >>>> > >>>> > >>>> > >>>> > >> ********************************************************************** > >> > >>>> Confidentiality : This e-mail and any attachments are intended for > >>>> > >> the > >> > >>>> addressee only and may be confidential. If they come to you in error > >>>> you must take no action based on them, nor must you copy or show > >>>> > >> them > >> > >>>> to anyone. Please advise the sender by replying to this e-mail > >>>> immediately and then delete the original from your computer. > >>>> > >>>> Opinion : Any opinions expressed in this e-mail are entirely those > >>>> > >> of > >> > >>>> the author and unless specifically stated to the contrary, are not > >>>> necessarily those of the author's employer. > >>>> > >>>> Security Warning : Internet e-mail is not necessarily a secure > >>>> communications medium and can be subject to data corruption. We > >>>> > >> advise > >> > >>>> that you consider this fact when e-mailing us. > >>>> > >>>> Viruses : We have taken steps to ensure that this e-mail and any > >>>> attachments are free from known viruses but in keeping with good > >>>> computing practice, you should ensure that they are virus free. > >>>> > >>>> Red Lion 49 Ltd T/A Solid State Logic > >>>> Registered as a limited company in England and Wales > >>>> (Company No:5362730) > >>>> Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > >>>> United Kingdom > >>>> > >>>> > >> ********************************************************************** > >> > >>>> > >>> Jules > >>> > >>> -- > >>> Julian Field MEng CITP > >>> www.MailScanner.info > >>> Buy the MailScanner book at www.MailScanner.info/store > >>> > >>> MailScanner customisation, or any advanced system administration help? > >>> Contact me at Jules@Jules.FM > >>> > >>> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > >>> For all your IT requirements visit www.transtec.co.uk > >>> > >>> > >>> > >>> -- > >>> This message has been scanned for viruses and > >>> dangerous content by MailScanner, and is > >>> believed to be clean. > >>> For all your IT requirements visit www.transtec.co.uk > >>> > >>> -- > >>> MailScanner mailing list > >>> mailscanner@lists.mailscanner.info > >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner > >>> > >>> Before posting, read http://wiki.mailscanner.info/posting > >>> > >>> Support MailScanner development - buy the book off the website! > >>> > >> > >> > >> > >> > >> ********************************************************************** > >> Confidentiality : This e-mail and any attachments are intended for > >> the addressee only and may be confidential. If they come to you in > >> error you must take no action based on them, nor must you copy or > >> show them to anyone. Please advise the sender by replying to this > >> e-mail immediately and then delete the original from your computer. > >> > >> Opinion : Any opinions expressed in this e-mail are entirely those of > >> the author and unless specifically stated to the contrary, are not > >> necessarily those of the author's employer. > >> > >> Security Warning : Internet e-mail is not necessarily a secure > >> communications medium and can be subject to data corruption. We > >> advise that you consider this fact when e-mailing us. > >> Viruses : We have taken steps to ensure that this e-mail and any > >> attachments are free from known viruses but in keeping with good > >> computing practice, you should ensure that they are virus free. > >> > >> Red Lion 49 Ltd T/A Solid State Logic > >> Registered as a limited company in England and Wales (Company > >> No:5362730) > >> Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > >> United Kingdom > >> ********************************************************************** > >> > >> > > > > Jules > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From alex at nkpanama.com Wed May 23 19:55:51 2007 From: alex at nkpanama.com (Alex Neuman) Date: Wed May 23 19:56:45 2007 Subject: feature request: compress attachments In-Reply-To: References: Message-ID: <46548E37.8010207@nkpanama.com> True... but that would be three words, right? :-) Martin.Hepworth wrote: > No > > Ben & Jerry's - Haagan Dazs is rubbish in comparison... > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Alex Neuman van der Hans >> Sent: 23 May 2007 15:32 >> To: MailScanner discussion >> Subject: Re: feature request: compress attachments >> >> Julian Field wrote: >> >>> Martin.Hepworth wrote: >>> >>>> Jules >>>> >>>> Yeah I know it's not easy, that's we thought "you" would be able to >>>> >> help >> >>>> out ;-) >>>> >>>> >>> :-) >>> >>>> Talking of 'you', how's the health? Back to work yet, or just doing >>>> MailScanner stuff to get back to speed? >>>> >>>> >>> My health is slowly improving. Unfortunately I'm not managing to put >>> on any weight, which won't make the docs happy, but I am getting a >>> > lot > >>> stronger. I'm not back at work yet, and am signed off until the >>> > start > >>> of July. I'm doing MailScanner stuff to stop myself getting bored >>> mostly. It also helps build up my mental stamina so that when I do >>> > go > >>> back to work, I'll be able to survive a full day. >>> >>> >> I can give you my near-foolproof way of putting on weight in a few >> > "two > >> words..." phrases: >> * Haagen Dazs >> * Sara Lee >> * Baskin Robbins >> ... thank you, I'll be here all week! :-) >> >>>> -- >>>> Martin Hepworth >>>> Snr Systems Administrator >>>> Solid State Logic >>>> Tel: +44 (0)1865 842300 >>>> >>>> >>>> >>>>> -----Original Message----- >>>>> From: mailscanner-bounces@lists.mailscanner.info >>>>> > [mailto:mailscanner- > >>>>> bounces@lists.mailscanner.info] On Behalf Of Julian Field >>>>> Sent: 23 May 2007 10:56 >>>>> To: MailScanner discussion >>>>> Subject: Re: feature request: compress attachments >>>>> >>>>> Not easy to do. I'll think about it, but no promises, sorry. >>>>> >>>>> Martin.Hepworth wrote: >>>>> >>>>> >>>>>> Jules >>>>>> >>>>>> Any thoughts on this? >>>>>> >>>>>> -- >>>>>> Martin Hepworth >>>>>> Snr Systems Administrator >>>>>> Solid State Logic >>>>>> Tel: +44 (0)1865 842300 >>>>>> >>>>>> >>>>>> >>>>>> >>>>>>> -----Original Message----- >>>>>>> From: mailscanner-bounces@lists.mailscanner.info >>>>>>> >>>>>>> >>>> [mailto:mailscanner- >>>> >>>> >>>>>>> bounces@lists.mailscanner.info] On Behalf Of Koopmann, Jan-Peter >>>>>>> Sent: 10 May 2007 11:12 >>>>>>> To: mailscanner@lists.mailscanner.info >>>>>>> Subject: feature request: compress attachments >>>>>>> >>>>>>> Hi, >>>>>>> >>>>>>> I just came across another product that offers automatic >>>>>>> > attachment > >>>>>>> compression on mails passing the proxy/gateway. Since many >>>>>>> > people > >>>> tend >>>> >>>> >>>>>> to >>>>>> >>>>>> >>>>>> >>>>>>> send their Powerpoint/Word/Excel files uncompressed due to >>>>>>> > lazyness > >>>>>>> >>>>>> this >>>>>> >>>>>> >>>>>> >>>>>>> might actually be a good contribution. There are several >>>>>>> > solutions > >>>> for >>>> >>>> >>>>>>> this available at least for Exchange servers but it should be >>>>>>> >>>>>>> >>>> possible >>>> >>>> >>>>>> to >>>>>> >>>>>> >>>>>> >>>>>>> implement this within MailScanner. So e.g. with a ruleset I >>>>>>> > could > >>>>>>> >>>>>> force >>>>>> >>>>>> >>>>>> >>>>>>> all incoming mails with not compressed attachments to be zipped >>>>>>> > and > >>>>>>> >>>>>> save >>>>>> >>>>>> >>>>>> >>>>>>> quite some storage in the Exchange databases. >>>>>>> >>>>>>> >>>>>>> Kind regards, >>>>>>> JP >>>>>>> >>>>>>> >>>>>>> >>>>>> >>>>>> >>>>>> > ********************************************************************** > >>>>>> Confidentiality : This e-mail and any attachments are intended >>>>>> > for > >>>> the >>>> >>>> >>>>>> addressee only and may be confidential. If they come to you in >>>>>> > error > >>>>>> you must take no action based on them, nor must you copy or show >>>>>> >>>>>> >>>> them >>>> >>>> >>>>>> to anyone. Please advise the sender by replying to this e-mail >>>>>> immediately and then delete the original from your computer. >>>>>> >>>>>> Opinion : Any opinions expressed in this e-mail are entirely >>>>>> > those > >>>> of >>>> >>>> >>>>>> the author and unless specifically stated to the contrary, are >>>>>> > not > >>>>>> necessarily those of the author's employer. >>>>>> >>>>>> Security Warning : Internet e-mail is not necessarily a secure >>>>>> communications medium and can be subject to data corruption. We >>>>>> >>>>>> >>>> advise >>>> >>>> >>>>>> that you consider this fact when e-mailing us. >>>>>> >>>>>> Viruses : We have taken steps to ensure that this e-mail and any >>>>>> attachments are free from known viruses but in keeping with good >>>>>> computing practice, you should ensure that they are virus free. >>>>>> >>>>>> Red Lion 49 Ltd T/A Solid State Logic >>>>>> Registered as a limited company in England and Wales >>>>>> (Company No:5362730) >>>>>> Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, >>>>>> United Kingdom >>>>>> >>>>>> >>>>>> > ********************************************************************** > >>>>> Jules >>>>> >>>>> -- >>>>> Julian Field MEng CITP >>>>> www.MailScanner.info >>>>> Buy the MailScanner book at www.MailScanner.info/store >>>>> >>>>> MailScanner customisation, or any advanced system administration >>>>> > help? > >>>>> Contact me at Jules@Jules.FM >>>>> >>>>> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >>>>> For all your IT requirements visit www.transtec.co.uk >>>>> >>>>> >>>>> >>>>> -- >>>>> This message has been scanned for viruses and >>>>> dangerous content by MailScanner, and is >>>>> believed to be clean. >>>>> For all your IT requirements visit www.transtec.co.uk >>>>> >>>>> -- >>>>> MailScanner mailing list >>>>> mailscanner@lists.mailscanner.info >>>>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>>>> >>>>> Before posting, read http://wiki.mailscanner.info/posting >>>>> >>>>> Support MailScanner development - buy the book off the website! >>>>> >>>>> >>>> >>>> >>>> >>>> > ********************************************************************** > >>>> Confidentiality : This e-mail and any attachments are intended for >>>> the addressee only and may be confidential. If they come to you in >>>> error you must take no action based on them, nor must you copy or >>>> show them to anyone. Please advise the sender by replying to this >>>> e-mail immediately and then delete the original from your computer. >>>> >>>> Opinion : Any opinions expressed in this e-mail are entirely those >>>> > of > >>>> the author and unless specifically stated to the contrary, are not >>>> necessarily those of the author's employer. >>>> >>>> Security Warning : Internet e-mail is not necessarily a secure >>>> communications medium and can be subject to data corruption. We >>>> advise that you consider this fact when e-mailing us. >>>> Viruses : We have taken steps to ensure that this e-mail and any >>>> attachments are free from known viruses but in keeping with good >>>> computing practice, you should ensure that they are virus free. >>>> >>>> Red Lion 49 Ltd T/A Solid State Logic >>>> Registered as a limited company in England and Wales (Company >>>> No:5362730) >>>> Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, >>>> United Kingdom >>>> >>>> > ********************************************************************** > >>>> >>> Jules >>> >>> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > From ssilva at sgvwater.com Wed May 23 20:01:20 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed May 23 20:05:12 2007 Subject: feature request: compress attachments In-Reply-To: <46541427.2060606@ecs.soton.ac.uk> References: <106f047568251e44a37a9ca53d199b41@solidstatelogic.com> <46541427.2060606@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 5/23/2007 3:15 AM: > > > Martin.Hepworth wrote: >> Jules >> >> Yeah I know it's not easy, that's we thought "you" would be able to help >> out ;-) >> > :-) >> Talking of 'you', how's the health? Back to work yet, or just doing >> MailScanner stuff to get back to speed? >> > My health is slowly improving. Unfortunately I'm not managing to put on > any weight, which won't make the docs happy, but I am getting a lot > stronger. I'm not back at work yet, and am signed off until the start of > July. I'm doing MailScanner stuff to stop myself getting bored mostly. > It also helps build up my mental stamina so that when I do go back to > work, I'll be able to survive a full day. > Hopefully they don't dump another big project on you for a while! -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Wed May 23 20:04:59 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed May 23 20:10:16 2007 Subject: feature request: compress attachments In-Reply-To: <46548E37.8010207@nkpanama.com> References: <46548E37.8010207@nkpanama.com> Message-ID: Alex Neuman spake the following on 5/23/2007 11:55 AM: > True... but that would be three words, right? :-) > > Martin.Hepworth wrote: Two words and and a symbol! ;-P -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Wed May 23 20:05:51 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed May 23 20:15:15 2007 Subject: feature request: compress attachments In-Reply-To: <55537.40454.qm@web26311.mail.ukl.yahoo.com> References: <55537.40454.qm@web26311.mail.ukl.yahoo.com> Message-ID: Andrew MacLachlan spake the following on 5/23/2007 9:20 AM: > Guinness & kebabs - works (too well) for me... > Bangers & mash! -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From mkettler at evi-inc.com Wed May 23 21:01:49 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Wed May 23 21:02:04 2007 Subject: feature request: compress attachments In-Reply-To: References: <55537.40454.qm@web26311.mail.ukl.yahoo.com> Message-ID: <46549DAD.7050708@evi-inc.com> Scott Silva wrote: > Andrew MacLachlan spake the following on 5/23/2007 9:20 AM: >> Guinness & kebabs - works (too well) for me... >> > Bangers & mash! Especially if appropriately paired with a suitable pint. But then again, IIRC, Julian isn't a beer/ale drinker, he's a wine drinker.. From MailScanner at ecs.soton.ac.uk Wed May 23 21:31:48 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 23 21:32:30 2007 Subject: feature request: compress attachments In-Reply-To: <46549DAD.7050708@evi-inc.com> References: <55537.40454.qm@web26311.mail.ukl.yahoo.com> <46549DAD.7050708@evi-inc.com> Message-ID: <4654A4B4.7090409@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Matt Kettler wrote: > Scott Silva wrote: > >> Andrew MacLachlan spake the following on 5/23/2007 9:20 AM: >> >>> Guinness & kebabs - works (too well) for me... >>> >>> >> Bangers & mash! >> > > Especially if appropriately paired with a suitable pint. > > But then again, IIRC, Julian isn't a beer/ale drinker, he's a wine drinker.. > Unfortunately only half my liver works at the moment, so I'm not really supposed to be an anything drinker :-( Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGVKS4EfZZRxQVtlQRAiobAJsEWuYuR5jghPp5NnKv/f+QN9DEcQCfWbfC S8nHj0/BgFsssgwYA/xv5gY= =Ph7t -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Wed May 23 21:45:19 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed May 23 21:45:45 2007 Subject: feature request: compress attachments In-Reply-To: <4654A4B4.7090409@ecs.soton.ac.uk> References: <55537.40454.qm@web26311.mail.ukl.yahoo.com> <46549DAD.7050708@evi-inc.com> <4654A4B4.7090409@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 5/23/2007 1:31 PM: > > > Matt Kettler wrote: >> Scott Silva wrote: > >>> Andrew MacLachlan spake the following on 5/23/2007 9:20 AM: >>> >>>> Guinness & kebabs - works (too well) for me... >>>> >>>> >>> Bangers & mash! >>> >> Especially if appropriately paired with a suitable pint. > >> But then again, IIRC, Julian isn't a beer/ale drinker, he's a wine drinker.. > > Unfortunately only half my liver works at the moment, so I'm not really > supposed to be an anything drinker :-( > > Jules > Double :-( -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From mkettler at evi-inc.com Wed May 23 21:51:35 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Wed May 23 21:51:52 2007 Subject: feature request: compress attachments In-Reply-To: <4654A4B4.7090409@ecs.soton.ac.uk> References: <55537.40454.qm@web26311.mail.ukl.yahoo.com> <46549DAD.7050708@evi-inc.com> <4654A4B4.7090409@ecs.soton.ac.uk> Message-ID: <4654A957.3050003@evi-inc.com> Julian Field wrote: > > > Matt Kettler wrote: >> Scott Silva wrote: > >>> Andrew MacLachlan spake the following on 5/23/2007 9:20 AM: >>> >>>> Guinness & kebabs - works (too well) for me... >>>> >>>> >>> Bangers & mash! >>> >> Especially if appropriately paired with a suitable pint. > >> But then again, IIRC, Julian isn't a beer/ale drinker, he's a wine drinker.. > > Unfortunately only half my liver works at the moment, so I'm not really > supposed to be an anything drinker :-( Good point.. Well, enjoy a nice healthy pint of water anyway :) From amaclach at yahoo.co.uk Wed May 23 23:16:14 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Wed May 23 23:16:16 2007 Subject: feature request: compress attachments Message-ID: <115762.74969.qm@web26310.mail.ukl.yahoo.com> Nothing better than a kebab with a nice big mug of tea! ----- Original Message ---- From: Matt Kettler To: MailScanner discussion Sent: Wednesday, 23 May, 2007 9:51:35 PM Subject: Re: feature request: compress attachments Julian Field wrote: > > > Matt Kettler wrote: >> Scott Silva wrote: > >>> Andrew MacLachlan spake the following on 5/23/2007 9:20 AM: >>> >>>> Guinness & kebabs - works (too well) for me... >>>> >>>> >>> Bangers & mash! >>> >> Especially if appropriately paired with a suitable pint. > >> But then again, IIRC, Julian isn't a beer/ale drinker, he's a wine drinker.. > > Unfortunately only half my liver works at the moment, so I'm not really > supposed to be an anything drinker :-( Good point.. Well, enjoy a nice healthy pint of water anyway :) -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From glenn.steen at gmail.com Thu May 24 10:15:56 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu May 24 10:16:04 2007 Subject: feature request: compress attachments In-Reply-To: <4654530A.2020503@ecs.soton.ac.uk> References: <106f047568251e44a37a9ca53d199b41@solidstatelogic.com> <46541427.2060606@ecs.soton.ac.uk> <223f97700705230335q1bc9f308tefd25a7c129505a@mail.gmail.com> <4654530A.2020503@ecs.soton.ac.uk> Message-ID: <223f97700705240215t192baa3ew7390643786dfd60c@mail.gmail.com> On 23/05/07, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Glenn Steen wrote: > > Talking about betas, do you plan on putting one out with some form of > > "p record handling" for Postfix any time soon? I've been really bogged > > down lately, so haven't worked on the "PF2.4 version" ... yet:). > > If you need a new set of "PF2.3" patches, I think I can find them in > > the archives for you... Or wherever I put them:-). If you want to look > > at what I have for 2.4/full body edits, I'll liekly need do a new > > set... Provided I did get around to doing the ugly "spin through > > security check" in ReadQf... RALM striking again (I think you are > > familiar with the consept... Random Access Lossy Memory:), mostly > > since I've been very busy with other stuff. > How do I make PF generate these "p records"? By using a milter. The whole construct is to facilitate milters editing/adding headers (PF2.3) and body content (PF2.4). > As they can only be generated locally, they shouldn't contain malicious > content so I probably don't need to merge them into the main text, I > just need to handle them and be able to put them back in at the end. > Does that sound likely? Nope, that will not work. Since they contain fix file offsets (just like a trusty ol' GOTO statement:) you would have to recalculate them, and this (although doable) is really _not_ as trivial as one might think. > What can p records actually do? As said they are to facilitate milters editing/adding things (there's a d record for marking records as deleted too... More on this below). Now what is done is that when you configure postfix to use a milter, the queue files will be "prepared" by the insertion of a p record in each of the three distinct sections of the queue file. These (fixed size) records of type "p" will have a record value of "0", which basically means "ignore me". If a milter adds a header, this will be written to the end of the queue file, _after_ the "E" record, and the appropriate "p" record will be updated with the file offset of the beginning of that header. after the header(s) there will be another "p" record with the offset just "behind" the "forward pointing" "p" record. If another header is added (say another milter wants to do that) the second "p" record, the one pointing "backward", will be updated with a "forward" offset, to the end of the file, and the header will be added there along with a new "backward" "p" record pointing to the original jump-off point. So you can have several "forward-pointing" "p" records, in a chain, but only one "backward", making it conceptually a curcular linked list kind of thing. In PF2.4, you have this implemented for full body editing (by milters) too. This means that a) there is no real sequentiality in the file any more. To read it all you need to seek to the offsets, read the records and seek on/back. b) headers and body segments can be interfoliated c) one simply cannot preserve the records _as is_, and still keep doing the additions/editing "the MailScanner way" too. d) Since these edits/additions are done before MailScanner, we cannot just ignore them. If (for example) someone is to use a greylisting milter (as Nerijus Baliunas does;-), the queue files generated by MailScanner will be corrupted. e) You can not rely on the "E" record to determine that a queue file is fully written, when full body edits are possible (PF2.4). For the headers, ReadQf will detect (in a way) that something is up, with my patches, which covers PF2.3... For the body edits of 2.4, we need do a little more. To handle these GOTO-like thingies we have to do one of three possible things: 1) Use them to do the edits/additions that MailScanner needs done. This would need some changes to PFDiskStore.pm (the Body class) and probably something for Postfix.pm (ReadQf) to correctly preserve them... And some major changes (I think) to actually use them for manipulating the queue files... I haven't looked much at this possibility, since last we went over this, you liked option #3 (below) better. 2) Keep doing the MailScanner edits/additions the way we always have, and try preserve/update the preserved "p" records offsets. This would probably work too, but would be a PITA logic-wise... 3) Acknowledging the fact that the queue file we actually pass _out_ from ailScanner isn't the same that is passed _into_ MailScanner, that it in fact is a completely new file (as per Mr V's stipulations some time ago:-), generated from the message object created from the incoming queue file, one could as well just remove the "p" records and add the records pointed to by the "p" record chain into the message object. So when we generate the new queue file, it'll be a normal queue file _without_ "p" or "d" records (at least no "d" records in the body;-). I've aimed (rather successfully, if I might say so:-) at implementing #3. My patches (that certainly are too well commented, clutsy here and there and not final in any way:-) implement this "whizzing around" and leaves the normal record handling functions to actually read out the records and put them where they belong. Since the Body class will now need handle deletions and jumps correctly (as is now, the deleted chucks will magically reappear when you transform the "d" records to "N" records, and there will be a spurious line with a number from where "p"->"N"....), I handle that... with minimal error checking... I simply have to trust that ReadQf has validated the _whole_ file... So to make these patches safe for PF2.4, one would have to add a loop to (as quicjly as possible) read through the body in search of the "p" record(s) and whatever they may point too. This last bit is what is lacking, from the current patches, and I (unfortunately) have had no time at all to spend on implementing/testing that part. I started on that, but then two things happened... You nearly fell off the planet, and my most esteemed colleague (my Oracle guru:) decided to take early retirement ... Dumping all his work in my lap. So the "2.4 patch" was never finished/tested:-(. It should be fairly easy to do though, just one more loop instead of the "jump to after body" you do now. > I would be very interested in a set of PF2.3 patches. I'll find you a link...: http://article.gmane.org/gmane.mail.virus.mailscanner/51465 Please be gentle, I know it's far from perfect. But it does work. > What is the difference between 2.3 and 2.4? See above;) > Jules > Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Thu May 24 10:20:45 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu May 24 10:20:47 2007 Subject: feature request: compress attachments In-Reply-To: <223f97700705240215t192baa3ew7390643786dfd60c@mail.gmail.com> References: <106f047568251e44a37a9ca53d199b41@solidstatelogic.com> <46541427.2060606@ecs.soton.ac.uk> <223f97700705230335q1bc9f308tefd25a7c129505a@mail.gmail.com> <4654530A.2020503@ecs.soton.ac.uk> <223f97700705240215t192baa3ew7390643786dfd60c@mail.gmail.com> Message-ID: <223f97700705240220w78019c7dq9f927ea569f5069a@mail.gmail.com> On 24/05/07, Glenn Steen wrote: > On 23/05/07, Julian Field wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: SHA1 (snip) > > What can p records actually do? > As said they are to facilitate milters editing/adding things (there's > a d record for marking records as deleted too... More on this below). (snip) Argh. Not "d" record.... The "delete this" record is the "w" record... The patch is correct, so everytime I say "d record" just imagine it said "w record"... Sigh. -- -- Glenn (a.k.a. Le grand Typo) email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From hvdkooij at vanderkooij.org Thu May 24 11:16:13 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Thu May 24 11:16:56 2007 Subject: yum based install Message-ID: Hi, It seems rpmforge will have (or does have by now ;-) a perl-Filesys-Df package. So the only thing one would need to use yum to install MS would be a repository with the mailscanner RPM in then for the usual distro's. There is an issue however that needs to be addressed in the MS rpm file to make it work. There is no dependency for perl-Filesys-Df in the MS RPM. I noticed the dependency only when I started MS that it needed Filesys/Df.pm to run. I understand Julian is no fan of packagers adding MS to their repositories. If keeping it up-to-date and getting some usage figures is the main issue then I think it would be almost trivial to setup a repository so yum can fetch MS from the right site and Julian will still have an up-to-date repository and the download statistics. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From prandal at herefordshire.gov.uk Thu May 24 11:42:56 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Thu May 24 11:45:51 2007 Subject: yum based install In-Reply-To: References: Message-ID: <7EF0EE5CB3B263488C8C18823239BEBAB25C08@HC-MBX02.herefordshire.gov.uk> Any chance of adding a page to the Wiki detailing which pre-requisites you can get from rpmforge and how to get them? Preferably assuming that the person installing MailScanner has no prior knowledge of rpmforge. Cheers, Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Hugo van der Kooij > Sent: 24 May 2007 11:16 > To: MailScanner discussion > Subject: yum based install > > Hi, > > It seems rpmforge will have (or does have by now ;-) a > perl-Filesys-Df > package. > > So the only thing one would need to use yum to install MS would be a > repository with the mailscanner RPM in then for the usual distro's. > > There is an issue however that needs to be addressed in the > MS rpm file to > make it work. There is no dependency for perl-Filesys-Df in > the MS RPM. I > noticed the dependency only when I started MS that it needed > Filesys/Df.pm > to run. > > I understand Julian is no fan of packagers adding MS to their > repositories. If keeping it up-to-date and getting some usage > figures is > the main issue then I think it would be almost trivial to setup a > repository so yum can fetch MS from the right site and Julian > will still > have an up-to-date repository and the download statistics. > > Hugo. > > -- > hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ > This message is using 100% recycled electrons. > > Some men see computers as they are and say "Windows" > I use computers with Linux and say "Why Windows?" > (Thanks JFK, for the insight.) > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From hvdkooij at vanderkooij.org Thu May 24 11:55:53 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Thu May 24 11:56:28 2007 Subject: yum based install In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBAB25C08@HC-MBX02.herefordshire.gov.uk> References: <7EF0EE5CB3B263488C8C18823239BEBAB25C08@HC-MBX02.herefordshire.gov.uk> Message-ID: On Thu, 24 May 2007, Randal, Phil wrote: > Any chance of adding a page to the Wiki detailing which pre-requisites > you can get from rpmforge and how to get them? > > Preferably assuming that the person installing MailScanner has no prior > knowledge of rpmforge. The notes are on my desk. But the weather is way to good now ;-) But they will find their way to my homepage one of these days (evenings I presume). Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) Please, don't top post: A: Yes. >Q: Are you sure? >>A: Because it reverses the logical flow of conversation. >>>Q: Why is top posting frowned upon? From maillists at conactive.com Thu May 24 12:31:18 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu May 24 12:33:26 2007 Subject: Enabling bounces Message-ID: I want to enable bouncing spam to one particular sender server, but apparently the bounce doesn't occur. I changed the "Enable Spam Bounce" rule to point to the ruleset file and added one rule. But the bounce doesn't happen. Do I also need to add "bounce" as a spam action? I'm vary to do this since I don't want to accidentally enable bouncing to everyone. If so, I don't understand the reasoning behind this. It looks like an unnecessary duplication to me. If the only reason is to enable rulesets for this action it should better be named "spam bouncing rules" or some such. I have another question on bouncing. Where does MailScanner bounce back to? I assume the envelope-from? What does it do in case of <> senders? Does it then use the header-from or does it fail? Thanks. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From john at tradoc.fr Thu May 24 12:52:52 2007 From: john at tradoc.fr (John Wilcock) Date: Thu May 24 12:52:58 2007 Subject: Enabling bounces In-Reply-To: References: Message-ID: <46557C94.8010304@tradoc.fr> Kai Schaetzl wrote: > I want to enable bouncing spam to one particular sender server, but > apparently the bounce doesn't occur. > I changed the "Enable Spam Bounce" rule to point to the ruleset file and > added one rule. But the bounce doesn't happen. Do I also need to add > "bounce" as a spam action? Yes, you need to add a corresponding ruleset for the spam actions, with bounce set as an action for the offending sender. > If so, I don't understand the reasoning behind this. It looks like an > unnecessary duplication to me. If the only reason is to enable rulesets > for this action it should better be named "spam bouncing rules" or some > such. It is unnecessary in theory, but bouncing spam is such a bad idea in most cases that I suspect Julian set things this way to provide a double layer of idiot-proofness to help ensure that you only bounce spam if you know *exactly* what you're doing. FWIW I use this very function to bounce any outbound spam sent by my own users, with the aim of alerting them to potential false positives at the receiving end. Likewise, MailScanner won't bounce high scoring spam even if you tell it to via the Enable Spam Bounce rule (as I found out when I tried to send a GTUBE to test my setup!) John. -- -- Over 3000 webcams from ski resorts around the world - www.snoweye.com -- Translate your technical documents and web pages - www.tradoc.fr From Q.G.Campbell at newcastle.ac.uk Thu May 24 13:13:01 2007 From: Q.G.Campbell at newcastle.ac.uk (Quentin Campbell) Date: Thu May 24 13:17:03 2007 Subject: Recognising and flagging 'foreign' language e-mails in MCP Message-ID: <4165CF7A7F12DE4B96622CCBB90586470A4D1400@largo.campus.ncl.ac.uk> I use a small group of SpamAssassin rules in MCP to add a header to any message that looks like it is in Russian. The added header will look something like: X-Newcastle-MailScanner-MCPCheck: MCP-Clean, MCP-Checker (score=0.01, required 1, MCP_RUSSIAN 0.01 This allows anyone who expects to receive messages in Russian to set up a personal mail filter rule to look for the string "MCP_RUSSIAN" in the message headers and move such messages into a "Russian" folder. The reason they need to do this is that most messages in Russian that are received here are tagged as spam. Most are spam! If this "MCP_RUSSIAN" rule precedes the personal mail filter rules that recipients use for dealing with tagged spam then they don't miss (possibly) important messages in Russian. I want to do similar tagging in MCP for messages in German, Chinese and Japanese and perhaps other languages if the need arises. I am probably re-inventing the wheel here. Does anyone have, or know of, sets of SpamAssassin rules that reliably recognise e-mail in various foreign languages, the three languages above in particular? The SA ok_languages and ok_locales options don't quite work in the way that is needed to achieve the above. Quentin --- PHONE: +44 191 222 8209 Information Systems and Services (ISS), Newcastle University, Newcastle upon Tyne, FAX: +44 191 222 8765 United Kingdom, NE1 7RU. ------------------------------------------------------------------ From amaclach at yahoo.co.uk Thu May 24 14:25:00 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Thu May 24 14:25:04 2007 Subject: sending a copy of all inbound messages to two MTAs Message-ID: <820823.95684.qm@web26315.mail.ukl.yahoo.com> This is a strange request, and I suspect that it's probably a PostFix question: can a copy of each inbound message be sent to an alternate MTA? This is so a new mailserver can be tested with real inbound mail flows... --Asbestos suit zipped up... Andy From MailScanner at ecs.soton.ac.uk Thu May 24 14:23:38 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 24 14:28:51 2007 Subject: PF2.4 support - was Re: feature request: compress attachments In-Reply-To: <223f97700705240220w78019c7dq9f927ea569f5069a@mail.gmail.com> References: <106f047568251e44a37a9ca53d199b41@solidstatelogic.com> <46541427.2060606@ecs.soton.ac.uk> <223f97700705230335q1bc9f308tefd25a7c129505a@mail.gmail.com> <4654530A.2020503@ecs.soton.ac.uk> <223f97700705240215t192baa3ew7390643786dfd60c@mail.gmail.com> <223f97700705240220w78019c7dq9f927ea569f5069a@mail.gmail.com> Message-ID: <465591DA.10207@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Glen, My brain is not well enough to get my head round this stuff. It's all washing in through my eyes and straight out of my ears unfortunately. Is there any chance you could find time to implement the 2.4 support as you say you already have an idea how to do it anyway please? Once you're convinced it works, I'll then just adopt your patches. Sorry, I'm just not up to doing this myself, but would very much like to get full PF support in as soon as possible. If you can generate a few test messages for me, I'll then test your code and hopefully start to gain a bit of insight into how it works. Many thanks, Jules. Glenn Steen wrote: > On 24/05/07, Glenn Steen wrote: >> On 23/05/07, Julian Field wrote: >> > -----BEGIN PGP SIGNED MESSAGE----- >> > Hash: SHA1 > (snip) >> > What can p records actually do? >> As said they are to facilitate milters editing/adding things (there's >> a d record for marking records as deleted too... More on this below). > (snip) > Argh. Not "d" record.... The "delete this" record is the "w" record... > The patch is correct, so everytime I say "d record" just imagine it > said "w record"... Sigh. > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGVZLSEfZZRxQVtlQRAnEHAJ9RruvevcCb2eR2KRx9jwabxWjmsACgiqNJ 2ur6J9NJkyknmx1ftF/rTeQ= =3/NV -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From mkercher at nfsmith.com Thu May 24 14:25:25 2007 From: mkercher at nfsmith.com (Mike Kercher) Date: Thu May 24 14:29:35 2007 Subject: sending a copy of all inbound messages to two MTAs References: <820823.95684.qm@web26315.mail.ukl.yahoo.com> Message-ID: <6DEF8ABC1767C045B91F42066D36358E93C6@HOUPEX01.nfsmith.info> Andrew MacLachlan <> wrote on Thursday, May 24, 2007 8:25 AM: : This is a strange request, and I suspect that it's probably a PostFix : question: can a copy of each inbound message be sent to an alternate : MTA? : This is so a new mailserver can be tested with real inbound mail : flows... : : --Asbestos suit zipped up... : : Andy You could probably setup a ficticious domain on the new server and then use an Archive ruleset to archive all emails to user@fakedomain.tld -Mike From MailScanner at ecs.soton.ac.uk Thu May 24 14:28:16 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 24 14:29:41 2007 Subject: Recognising and flagging 'foreign' language e-mails in MCP In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470A4D1400@largo.campus.ncl.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D1400@largo.campus.ncl.ac.uk> Message-ID: <465592F0.9050809@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Quentin Campbell wrote: > I use a small group of SpamAssassin rules in MCP to add a header to any > message that looks like it is in Russian. The added header will look > something like: > > X-Newcastle-MailScanner-MCPCheck: MCP-Clean, MCP-Checker (score=0.01, > required 1, MCP_RUSSIAN 0.01 > > This allows anyone who expects to receive messages in Russian to set up > a personal mail filter rule to look for the string "MCP_RUSSIAN" in the > message headers and move such messages into a "Russian" folder. > > The reason they need to do this is that most messages in Russian that > are received here are tagged as spam. Most are spam! > I have done this too, but I didn't see any need to do it in MCP (as MCP has a very high speed overhead). Just a normal SA rule with a small score will do fine, just put your initials or something similar at the start of the rule name. > If this "MCP_RUSSIAN" rule precedes the personal mail filter rules that > recipients use for dealing with tagged spam then they don't miss > (possibly) important messages in Russian. > > I want to do similar tagging in MCP for messages in German, Chinese and > Japanese and perhaps other languages if the need arises. > > I am probably re-inventing the wheel here. Does anyone have, or know of, > sets of SpamAssassin rules that reliably recognise e-mail in various > foreign languages, the three languages above in particular? The SA > ok_languages and ok_locales options don't quite work in the way that is > needed to achieve the above. > I found the same problem. I just look for the windows-1251 character set string appearing in the Subject: line. There are similar character set strings for the other character sets you are interested in. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGVZMfEfZZRxQVtlQRAhv9AKC/UiOWHkgRqIlMR6m1kleByXkvtgCgxRSY gjaYKwfRPIV2HF33aLBbl4k= =4DG+ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From dhawal at netmagicsolutions.com Thu May 24 14:37:35 2007 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Thu May 24 14:37:50 2007 Subject: sending a copy of all inbound messages to two MTAs In-Reply-To: <820823.95684.qm@web26315.mail.ukl.yahoo.com> References: <820823.95684.qm@web26315.mail.ukl.yahoo.com> Message-ID: <4655951F.7010108@netmagicsolutions.com> Andrew MacLachlan wrote: > This is a strange request, and I suspect that it's probably a PostFix question: > can a copy of each inbound message be sent to an alternate MTA? > This is so a new mailserver can be tested with real inbound mail flows... This is not a strange request, actually an often asked question.. the answer for postfix is using the always_bcc OR recipient_bcc_maps configuration parameter.. http://www.postfix.org/postconf.5.html#always_bcc http://www.postfix.org/postconf.5.html#recipient_bcc_maps Be careful though, since if a mail to the BCC address bounces it will be bounced to the sender. From drew at technologytiger.net Thu May 24 14:44:50 2007 From: drew at technologytiger.net (Drew Marshall) Date: Thu May 24 14:45:01 2007 Subject: sending a copy of all inbound messages to two MTAs In-Reply-To: <820823.95684.qm@web26315.mail.ukl.yahoo.com> References: <820823.95684.qm@web26315.mail.ukl.yahoo.com> Message-ID: <44302.194.70.180.170.1180014290.squirrel@www.technologytiger.net> On Thu, May 24, 2007 14:25, Andrew MacLachlan wrote: > This is a strange request, and I suspect that it's probably a PostFix > question: > can a copy of each inbound message be sent to an alternate MTA? > This is so a new mailserver can be tested with real inbound mail flows... > > --Asbestos suit zipped up... It is a Postfix question but the answer is always_bcc http://www.postfix.org/postconf.5.html#always_bcc alternatively if you need to preserve the original sender details, you could play around with your relay_recipients_map creating duplicate aliases to the second box. Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by the Technology Tiger MailScanner. Further information can be found at www.technologytiger.net/policy Technology Tiger Limited is registered in Scotland with registration number: 310997 Registered Office 55-57 West High Street Inverurie AB51 3QQ From glenn.steen at gmail.com Thu May 24 15:24:48 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu May 24 15:24:52 2007 Subject: PF2.4 support - was Re: feature request: compress attachments In-Reply-To: <465591DA.10207@ecs.soton.ac.uk> References: <106f047568251e44a37a9ca53d199b41@solidstatelogic.com> <46541427.2060606@ecs.soton.ac.uk> <223f97700705230335q1bc9f308tefd25a7c129505a@mail.gmail.com> <4654530A.2020503@ecs.soton.ac.uk> <223f97700705240215t192baa3ew7390643786dfd60c@mail.gmail.com> <223f97700705240220w78019c7dq9f927ea569f5069a@mail.gmail.com> <465591DA.10207@ecs.soton.ac.uk> Message-ID: <223f97700705240724m29f91775n552eb10ca0363e8d@mail.gmail.com> On 24/05/07, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Glen, > > My brain is not well enough to get my head round this stuff. It's all > washing in through my eyes and straight out of my ears unfortunately. > > Is there any chance you could find time to implement the 2.4 support as > you say you already have an idea how to do it anyway please? > > Once you're convinced it works, I'll then just adopt your patches. > > Sorry, I'm just not up to doing this myself, but would very much like to > get full PF support in as soon as possible. > > If you can generate a few test messages for me, I'll then test your code > and hopefully start to gain a bit of insight into how it works. > > Many thanks, > Jules. I'll see what I can do... The problem is testing it all... Very timeconsuming. I found the first draft for 2.4 support, but ... it needs testing... I'll see what I can do, perhaps this weekend. > Glenn Steen wrote: > > On 24/05/07, Glenn Steen wrote: > >> On 23/05/07, Julian Field wrote: > >> > -----BEGIN PGP SIGNED MESSAGE----- > >> > Hash: SHA1 > > (snip) > >> > What can p records actually do? > >> As said they are to facilitate milters editing/adding things (there's > >> a d record for marking records as deleted too... More on this below). > > (snip) > > Argh. Not "d" record.... The "delete this" record is the "w" record... > > The patch is correct, so everytime I say "d record" just imagine it > > said "w record"... Sigh. > > > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: ISO-8859-1 > > wj8DBQFGVZLSEfZZRxQVtlQRAnEHAJ9RruvevcCb2eR2KRx9jwabxWjmsACgiqNJ > 2ur6J9NJkyknmx1ftF/rTeQ= > =3/NV > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From maillists at conactive.com Thu May 24 15:31:52 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu May 24 15:32:29 2007 Subject: Enabling bounces In-Reply-To: <46557C94.8010304@tradoc.fr> References: <46557C94.8010304@tradoc.fr> Message-ID: John Wilcock wrote on Thu, 24 May 2007 13:52:52 +0200: > Yes, you need to add a corresponding ruleset for the spam actions, with > bounce set as an action for the offending sender. But then I do not understand the whole thing at all. If I put bounce in the Spam Score Actions, then it will apply for everyone. If I make it a ruleset, then I don't see how or why the other ruleset is necessary/works. Example: Spam Actions = %rules-dir%/spam.actions.rules -> From: IP bounce FromOrTo: default default store notify header "X-Spam-Status: Yes" what for do I then need Enable Spam Bounce = %rules-dir%/bounce.rules for? > Likewise, MailScanner won't bounce high scoring spam even if you tell it > to via the Enable Spam Bounce rule (as I found out when I tried to send > a GTUBE to test my setup!) Oh, I think I now understand, bummer. It's high-scoring spam that I want to bounce back. So, using *only* Enable Spam Bounce = %rules-dir%/bounce.rules (and not Spam Actions) would work if it is low-scoring spam? Hm. What I want to do is bounce spam (or other messages) back that I get from a specific customer who moved to his own in-house poorly maintained mailserver (Exchange). Instead of having a decent spam detection he bounces all non-deliverable mail back via his smarthost - which happens to be me. If I just stop him dead I'm gonna sure loose him. If I try to explain and convince him (already tried) that he should "bounce" during the SMTP connection it takes me a year. So, I wanted to boost all the messages that come from postmaster@hisdomain via Spamassassin to 20 or so, detect them as spam and bounce back to him until he understands. As the sender envelope is empty I can only rely on methods that look at the mail headers. And I don't want to add another milter to the mix. Any ideas how I can do it with MailScanner (as obviously what I had in mind won't work). Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From john at tradoc.fr Thu May 24 15:53:12 2007 From: john at tradoc.fr (John Wilcock) Date: Thu May 24 15:53:21 2007 Subject: Enabling bounces In-Reply-To: References: <46557C94.8010304@tradoc.fr> Message-ID: <4655A6D8.4030201@tradoc.fr> Kai Schaetzl wrote: > what for do I then need > Enable Spam Bounce = %rules-dir%/bounce.rules Because bouncing spam is not generally recommended and this is Julian's way of making it harder to enable it. > Hm. What I want to do is bounce spam (or other messages) back that I get > from a specific customer who moved to his own in-house poorly maintained > mailserver (Exchange). Instead of having a decent spam detection he bounces > all non-deliverable mail back via his smarthost - which happens to be > me. If > I just stop him dead I'm gonna sure loose him. If I try to explain and > convince him (already tried) that he should "bounce" during the SMTP > connection it takes me a year. So, I wanted to boost all the messages that > come from postmaster@hisdomain via Spamassassin to 20 or so, detect them as > spam and bounce back to him until he understands. > As the sender envelope is empty I can only rely on methods that look at the > mail headers. And I don't want to add another milter to the mix. > Any ideas how I can do it with MailScanner (as obviously what I had in mind > won't work). How about: ? a ruleset to set "Is Definitely Spam" to yes for his messages (make sure you also have "Definite Spam Is High Scoring = no" ? a ruleset to set "Spam Actions" to bounce for him only ? and a ruleset on Enable Spam Bounce to enable bounces for his IP only John. -- -- Over 3000 webcams from ski resorts around the world - www.snoweye.com -- Translate your technical documents and web pages - www.tradoc.fr From MailScanner at ecs.soton.ac.uk Thu May 24 16:06:03 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 24 16:09:19 2007 Subject: Enabling bounces In-Reply-To: References: <46557C94.8010304@tradoc.fr> Message-ID: <4655A9DB.4050000@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Kai Schaetzl wrote: > John Wilcock wrote on Thu, 24 May 2007 13:52:52 +0200: > > >> Yes, you need to add a corresponding ruleset for the spam actions, with >> bounce set as an action for the offending sender. >> > > But then I do not understand the whole thing at all. If I put bounce in the > Spam Score Actions, then it will apply for everyone. If I make it a ruleset, > then I don't see how or why the other ruleset is necessary/works. > Because it is necessary. If you want to bounce spam, you have to jump through some hoops. For a given message, spam actions has to evaluate to a result including "bounce", and enable spam bounce has to evaluate to "yes". The ruleset is necessary because I say it is :-) > Example: > > Spam Actions = %rules-dir%/spam.actions.rules > -> > From: IP bounce > FromOrTo: default default store notify header "X-Spam-Status: Yes" > > what for do I then need > Enable Spam Bounce = %rules-dir%/bounce.rules > for? > > >> Likewise, MailScanner won't bounce high scoring spam even if you tell it >> to via the Enable Spam Bounce rule (as I found out when I tried to send >> a GTUBE to test my setup!) >> > > Oh, I think I now understand, bummer. It's high-scoring spam that I want to > bounce back. So, using *only* > Enable Spam Bounce = %rules-dir%/bounce.rules > (and not Spam Actions) > would work if it is low-scoring spam? > You can't bounce high-scoring spam at all. Sorry, fully intentional. But after all, you have the source code so there's nothing actually stopping you changing it. > Hm. What I want to do is bounce spam (or other messages) back that I get > from a specific customer who moved to his own in-house poorly maintained > mailserver (Exchange). Instead of having a decent spam detection he bounces > all non-deliverable mail back via his smarthost - which happens to be me. If > I just stop him dead I'm gonna sure loose him. If I try to explain and > convince him (already tried) that he should "bounce" during the SMTP > connection it takes me a year. So, I wanted to boost all the messages that > come from postmaster@hisdomain via Spamassassin to 20 or so, detect them as > spam and bounce back to him until he understands. > As the sender envelope is empty I can only rely on methods that look at the > mail headers. And I don't want to add another milter to the mix. > MailScanner doesn't use the From: address in the headers at all, it only uses the envelope sender address. > Any ideas how I can do it with MailScanner (as obviously what I had in mind > won't work). > You could do it with a Custom Function tied to "Enable Spam Bounce" probably. I would need to think a bit about exactly what you would want to do. You want to spot spam coming from postmaster@hisdomain (in the From: header) and switch off its $message->{ishigh} flag so it gets treated as normal scoring spam, at which point you can bounce it. It's just a problem of working out which config option to attach the Custom Function to. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGVapCEfZZRxQVtlQRArjvAKC3RNJBC0rCgjomF7wqeVuBmjVXHwCgwT+Y jviv3vrT/l2yhbI2wLTpOAo= =m+kT -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From Q.G.Campbell at newcastle.ac.uk Thu May 24 16:08:22 2007 From: Q.G.Campbell at newcastle.ac.uk (Quentin Campbell) Date: Thu May 24 16:11:43 2007 Subject: 4.60.3-1 install errors on RH AS4 - error when it is run In-Reply-To: <46544D1F.7000900@ecs.soton.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk> <4652F544.5050007@ecs.soton.ac.uk><4165CF7A7F12DE4B96622CCBB90586470A4D11AE@largo.campus.ncl.ac.uk> <46544D1F.7000900@ecs.soton.ac.uk> Message-ID: <4165CF7A7F12DE4B96622CCBB90586470A4D1496@largo.campus.ncl.ac.uk> Julian I renamed /etc/mail/spamassassin/v320.pre -> v320.pre+, removed /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm and installed SA-3.1.7. I had been running this before the upgrade to MS-4.60.3 and SA-3.2.0. Service MailScanner start now gives: [root@cheviot9 Mail-SpamAssassin-3.1.7]# service MailScanner start Starting MailScanner daemons: incoming sendmail: [ OK ] outgoing sendmail: [ OK ] MailScanner: In Debugging mode, not forking... Use of uninitialized value in concatenation (.) or string at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1044. Use of uninitialized value in concatenation (.) or string at /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1046. Ignore errors about failing to find EOCD signature format error: can't find EOCD signature at /usr/sbin/MailScanner line 832 Stopping now as you are debugging me. [ OK ] Quentin PS I am away from work now until Tuesday so will pursue this again then. >-----Original Message----- >From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >bounces@lists.mailscanner.info] On Behalf Of Julian Field >Sent: 23 May 2007 15:18 >To: MailScanner discussion >Subject: Re: 4.60.3-1 install errors on RH AS4 - error when it is run > >-----BEGIN PGP SIGNED MESSAGE----- >Hash: SHA1 > >This would imply an error in your /etc/mail/spamassassin/*.pre files. >Some important plugin isn't being loaded. If you wipe SpamAssassin and >reinstall it, does that help? If you're using an RPM of SA, then just >rpm -e it. Otherwise wipe /etc/mail/spamassassin and SpamAssassin.pm >(wherever that is under /usr/lib/perl5), then reinstall SpamAssassin. > >Quentin Campbell wrote: >>> -----Original Message----- >>> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >>> bounces@lists.mailscanner.info] On Behalf Of Julian Field >>> Sent: 22 May 2007 14:51 >>> To: MailScanner discussion >>> Subject: Re: 4.60.3-1 install errors on RH AS4 >>> >>> -----BEGIN PGP SIGNED MESSAGE----- >>> Hash: SHA1 >>> >>> But does MailScanner still work okay, despite the installation >>> >> problems? >> >>> Which update of AS4 are you using? >>> >>> >> >> Julian >> >> A 'cat /etc/redhat-release' gives "Red Hat Enterprise Linux AS release >4 >> (Nahant Update 4)" >> >> Ran MailScanner 4.60.3-1 in debug mode and got (from two different >> invocations): >> >> [root@cheviot9 clamav]# service MailScanner start >> Starting MailScanner daemons: >> incoming sendmail: [ OK ] >> outgoing sendmail: [ OK ] >> MailScanner: In Debugging mode, not forking... >> Use of uninitialized value in concatenation (.) or string at >> /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1087. >> Use of uninitialized value in concatenation (.) or string at >> /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1089. >> check: no loaded plugin implements 'check_main': cannot scan! at >> /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/PerMsgStatus.pm line >> 164. >> Ignore errors about failing to find EOCD signature >> format error: can't find EOCD signature >> at /usr/sbin/MailScanner line 832 >> Stopping now as you are debugging me. >> [ OK ] >> [root@cheviot9 clamav]# service MailScanner start >> Starting MailScanner daemons: >> incoming sendmail: [ OK ] >> outgoing sendmail: [ OK ] >> MailScanner: In Debugging mode, not forking... >> Use of uninitialized value in concatenation (.) or string at >> /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1087. >> Use of uninitialized value in concatenation (.) or string at >> /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1089. >> check: no loaded plugin implements 'check_main': cannot scan! at >> /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/PerMsgStatus.pm line >> 164. >> Ignore errors about failing to find EOCD signature >> Stopping now as you are debugging me >> >> >> The /var/log/maillog for the last start shows: >> >> ... >> May 23 12:54:46 cheviot9 sendmail[5060]: alias database >> /etc/mail/aliases rebuilt by root >> May 23 12:54:46 cheviot9 sendmail[5060]: /etc/mail/aliases: 408 >aliases, >> longest 83 bytes, 21885 bytes total >> May 23 12:54:46 cheviot9 sendmail[5069]: starting daemon (8.13.1): >SMTP >> May 23 12:54:46 cheviot9 sendmail[5069]: STARTTLS: ServerCertFile >> missing >> May 23 12:54:46 cheviot9 sendmail[5069]: started as: >/usr/sbin/sendmail >> -bd -OPrivacyOptions=noetrn -ODeliveryMode=queueonly >> -OQueueDirectory=/var/spool/mqueue.in - >OPidFile=/var/run/sendmail.in.pid >> May 23 12:54:46 cheviot9 sm-msp-queue[5073]: starting daemon (8.13.1): >> queueing@00:15:00 >> May 23 12:54:46 cheviot9 sendmail[5078]: starting daemon (8.13.1): >> queueing@00:15:00 >> May 23 12:54:46 cheviot9 sendmail[5078]: started as: >/usr/sbin/sendmail >> -q15m -OPidFile=/var/run/sendmail.out.pid >> May 23 12:54:47 cheviot9 MailScanner[5094]: MailScanner E-Mail Virus >> Scanner version 4.60.3 starting... >> May 23 12:54:48 cheviot9 MailScanner[5094]: Read 764 hostnames from >the >> phishing whitelist >> May 23 12:54:48 cheviot9 MailScanner[5094]: Using SpamAssassin results >> cache >> May 23 12:54:48 cheviot9 MailScanner[5094]: Connected to SpamAssassin >> cache database >> May 23 12:54:48 cheviot9 MailScanner[5094]: lock.pl sees Config >> LockType = posix >> May 23 12:54:48 cheviot9 MailScanner[5094]: lock.pl sees have_module = >> 0 >> May 23 12:54:48 cheviot9 MailScanner[5094]: Using locktype = posix >> May 23 12:54:48 cheviot9 MailScanner[5094]: Creating hardcoded >> struct_flock subroutine for linux (Linux-type) >> May 23 12:54:48 cheviot9 MailScanner[5094]: New Batch: Scanning 1 >> messages, 1597 bytes >> May 23 12:54:48 cheviot9 MailScanner[5094]: Created attachment dirs >for >> 1 messages >> May 23 12:54:48 cheviot9 MailScanner[5094]: MCP Checks: Starting >> May 23 12:54:48 cheviot9 MailScanner[5094]: Message Content Protection >> SpamAssassin returned 65280 >> May 23 12:54:48 cheviot9 MailScanner[5094]: MCP Checks completed at >> 17428 bytes per second >> May 23 12:54:48 cheviot9 MailScanner[5094]: Spam Checks: Starting >> May 23 12:54:49 cheviot9 MailScanner[5094]: Virus and Content >Scanning: >> Starting >> May 23 12:54:49 cheviot9 MailScanner[5094]: Commencing scanning by >> clamav... >> May 23 12:54:58 cheviot9 MailScanner[5094]: Completed scanning by >clamav >> >> May 23 12:54:58 cheviot9 MailScanner[5094]: Commencing scanning by >> mcafee... >> May 23 12:54:58 cheviot9 MailScanner[5094]: Completed scanning by >mcafee >> >> May 23 12:54:58 cheviot9 MailScanner[5094]: Completed checking by >> /usr/bin/file >> May 23 12:54:58 cheviot9 MailScanner[5094]: Virus Scanning completed >at >> 161 bytes per second >> May 23 12:54:58 cheviot9 MailScanner[5094]: About to deliver 1 >messages >> May 23 12:54:58 cheviot9 MailScanner[5094]: Uninfected: Delivered 1 >> messages >> May 23 12:54:58 cheviot9 MailScanner[5094]: Virus Processing completed >> at 191303 bytes per second >> May 23 12:54:58 cheviot9 MailScanner[5094]: Batch completed at 159 >bytes >> per second (1597 / 9) >> May 23 12:54:58 cheviot9 MailScanner[5094]: Batch (1 message) >processed >> in 9.99 seconds >> May 23 12:54:58 cheviot9 MailScanner[5094]: MailScanner child dying of >> old age >> May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: ClientCertFile >> missing >> May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: ClientKeyFile >missing >> May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: CACertPath missing >> May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: CACertFile missing >> May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: CRLFile missing >> May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS=client, init=1 >> May 23 12:54:58 cheviot9 sendmail[5107]: l4NBpfpt004809: SMTP outgoing >> connect on cheviot9.ncl.ac.uk >> May 23 12:55:01 cheviot9 sendmail[5107]: l4NBpfpt004809: >> to=, delay=00:03:20, >xdelay=00:00:03, >> mailer=esmtp, pri=121128, relay=burnmoor.ncl.ac.uk. [128.240.233.53], >> dsn=2.0.0, stat=Sent (MAA29651 Message accepted for delivery) >> May 23 12:55:01 cheviot9 sendmail[5107]: l4NBpfpt004809: done; >> delay=00:03:20, ntries=1 >> ... >> >> >> I hope that provides the info you need? >> >> Quentin >> --- >> PHONE: +44 191 222 8209 Information Systems and Services (ISS), >> Newcastle University, >> Newcastle upon Tyne, >> FAX: +44 191 222 8765 United Kingdom, NE1 7RU. >> ------------------------------------------------------------------ >> >> >> > >Jules > >- -- >Julian Field MEng CITP >www.MailScanner.info >Buy the MailScanner book at www.MailScanner.info/store > >MailScanner customisation, or any advanced system administration help? >Contact me at Jules@Jules.FM > >PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >For all your IT requirements visit www.transtec.co.uk > > > >-----BEGIN PGP SIGNATURE----- >Version: PGP Desktop 9.6.1 (Build 1012) >Charset: ISO-8859-1 > >wj8DBQFGVE0lEfZZRxQVtlQRAuHDAJ9H7C/oI91zZCPnhwlTh96vGb3USgCgyT7O >x771DyI3vw2w2hDZVuQqp2U= >=Ixb3 >-----END PGP SIGNATURE----- > >-- >This message has been scanned for viruses and >dangerous content by MailScanner, and is >believed to be clean. >For all your IT requirements visit www.transtec.co.uk > >-- >MailScanner mailing list >mailscanner@lists.mailscanner.info >http://lists.mailscanner.info/mailman/listinfo/mailscanner > >Before posting, read http://wiki.mailscanner.info/posting > >Support MailScanner development - buy the book off the website! From amaclach at yahoo.co.uk Thu May 24 16:13:18 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Thu May 24 16:13:23 2007 Subject: sending a copy of all inbound messages to two MTAs Message-ID: <668080.79708.qm@web26312.mail.ukl.yahoo.com> I'll give this one a try... I need to preserve the sender/recipient details ----- Original Message ---- From: Drew Marshall To: MailScanner discussion Sent: Thursday, 24 May, 2007 2:44:50 PM Subject: Re: sending a copy of all inbound messages to two MTAs On Thu, May 24, 2007 14:25, Andrew MacLachlan wrote: > This is a strange request, and I suspect that it's probably a PostFix > question: > can a copy of each inbound message be sent to an alternate MTA? > This is so a new mailserver can be tested with real inbound mail flows... > > --Asbestos suit zipped up... It is a Postfix question but the answer is always_bcc http://www.postfix.org/postconf.5.html#always_bcc alternatively if you need to preserve the original sender details, you could play around with your relay_recipients_map creating duplicate aliases to the second box. Drew -- In line with our policy, this message has been scanned for viruses and dangerous content by the Technology Tiger MailScanner. Further information can be found at www.technologytiger.net/policy Technology Tiger Limited is registered in Scotland with registration number: 310997 Registered Office 55-57 West High Street Inverurie AB51 3QQ -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From uxbod at splatnix.net Thu May 24 16:27:09 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Thu May 24 16:27:38 2007 Subject: sending a copy of all inbound messages to two MTAs In-Reply-To: <668080.79708.qm@web26312.mail.ukl.yahoo.com> References: <668080.79708.qm@web26312.mail.ukl.yahoo.com> Message-ID: Easier solution :- http://www.snertsoft.com/sendmail/roundhouse/ On Thu, 24 May 2007 15:13:18 +0000 (GMT), Andrew MacLachlan wrote: > I'll give this one a try... > I need to preserve the sender/recipient details > > ----- Original Message ---- > From: Drew Marshall > To: MailScanner discussion > Sent: Thursday, 24 May, 2007 2:44:50 PM > Subject: Re: sending a copy of all inbound messages to two MTAs > > On Thu, May 24, 2007 14:25, Andrew MacLachlan wrote: >> This is a strange request, and I suspect that it's probably a PostFix >> question: >> can a copy of each inbound message be sent to an alternate MTA? >> This is so a new mailserver can be tested with real inbound mail > flows... >> >> --Asbestos suit zipped up... > > It is a Postfix question but the answer is always_bcc > http://www.postfix.org/postconf.5.html#always_bcc alternatively if you > need to preserve the original sender details, you could play around with > your relay_recipients_map creating duplicate aliases to the second box. > > Drew > > > -- > In line with our policy, this message has been scanned > for viruses and dangerous content by the Technology Tiger MailScanner. > Further information can be found at www.technologytiger.net/policy > > Technology Tiger Limited is registered in Scotland with registration > number: 310997 > Registered Office 55-57 West High Street Inverurie AB51 3QQ > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Thu May 24 16:49:42 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 24 16:50:48 2007 Subject: 4.60.3-1 install errors on RH AS4 - error when it is run In-Reply-To: <4165CF7A7F12DE4B96622CCBB90586470A4D1496@largo.campus.ncl.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk> <4652F544.5050007@ecs.soton.ac.uk><4165CF7A7F12DE4B96622CCBB90586470A4D11AE@largo.campus.ncl.ac.uk> <46544D1F.7000900@ecs.soton.ac.uk> <4165CF7A7F12DE4B96622CCBB90586470A4D1496@largo.campus.ncl.ac.uk> Message-ID: <4655B416.9040202@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I would advise moving all the *.pre files out of the way. SA installation will re-create them. Quentin Campbell wrote: > Julian > > I renamed /etc/mail/spamassassin/v320.pre -> v320.pre+, removed > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm and installed > SA-3.1.7. > > I had been running this before the upgrade to MS-4.60.3 and SA-3.2.0. > > Service MailScanner start now gives: > > [root@cheviot9 Mail-SpamAssassin-3.1.7]# service MailScanner start > Starting MailScanner daemons: > incoming sendmail: [ OK ] > outgoing sendmail: [ OK ] > MailScanner: In Debugging mode, not forking... > Use of uninitialized value in concatenation (.) or string at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1044. > Use of uninitialized value in concatenation (.) or string at > /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1046. > Ignore errors about failing to find EOCD signature > format error: can't find EOCD signature > at /usr/sbin/MailScanner line 832 > Stopping now as you are debugging me. > [ OK ] > > Quentin > > PS I am away from work now until Tuesday so will pursue this again then. > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Julian Field >> Sent: 23 May 2007 15:18 >> To: MailScanner discussion >> Subject: Re: 4.60.3-1 install errors on RH AS4 - error when it is run >> >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> This would imply an error in your /etc/mail/spamassassin/*.pre files. >> Some important plugin isn't being loaded. If you wipe SpamAssassin and >> reinstall it, does that help? If you're using an RPM of SA, then just >> rpm -e it. Otherwise wipe /etc/mail/spamassassin and SpamAssassin.pm >> (wherever that is under /usr/lib/perl5), then reinstall SpamAssassin. >> >> Quentin Campbell wrote: >> >>>> -----Original Message----- >>>> From: mailscanner-bounces@lists.mailscanner.info >>>> > [mailto:mailscanner- > >>>> bounces@lists.mailscanner.info] On Behalf Of Julian Field >>>> Sent: 22 May 2007 14:51 >>>> To: MailScanner discussion >>>> Subject: Re: 4.60.3-1 install errors on RH AS4 >>>> >>>> -----BEGIN PGP SIGNED MESSAGE----- >>>> Hash: SHA1 >>>> >>>> But does MailScanner still work okay, despite the installation >>>> >>>> >>> problems? >>> >>> >>>> Which update of AS4 are you using? >>>> >>>> >>>> >>> Julian >>> >>> A 'cat /etc/redhat-release' gives "Red Hat Enterprise Linux AS >>> > release > >> 4 >> >>> (Nahant Update 4)" >>> >>> Ran MailScanner 4.60.3-1 in debug mode and got (from two different >>> invocations): >>> >>> [root@cheviot9 clamav]# service MailScanner start >>> Starting MailScanner daemons: >>> incoming sendmail: [ OK ] >>> outgoing sendmail: [ OK ] >>> MailScanner: In Debugging mode, not forking... >>> Use of uninitialized value in concatenation (.) or string at >>> /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1087. >>> Use of uninitialized value in concatenation (.) or string at >>> /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1089. >>> check: no loaded plugin implements 'check_main': cannot scan! at >>> /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/PerMsgStatus.pm line >>> 164. >>> Ignore errors about failing to find EOCD signature >>> format error: can't find EOCD signature >>> at /usr/sbin/MailScanner line 832 >>> Stopping now as you are debugging me. >>> [ OK ] >>> [root@cheviot9 clamav]# service MailScanner start >>> Starting MailScanner daemons: >>> incoming sendmail: [ OK ] >>> outgoing sendmail: [ OK ] >>> MailScanner: In Debugging mode, not forking... >>> Use of uninitialized value in concatenation (.) or string at >>> /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1087. >>> Use of uninitialized value in concatenation (.) or string at >>> /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin.pm line 1089. >>> check: no loaded plugin implements 'check_main': cannot scan! at >>> /usr/lib/perl5/site_perl/5.8.5/Mail/SpamAssassin/PerMsgStatus.pm line >>> 164. >>> Ignore errors about failing to find EOCD signature >>> Stopping now as you are debugging me >>> >>> >>> The /var/log/maillog for the last start shows: >>> >>> ... >>> May 23 12:54:46 cheviot9 sendmail[5060]: alias database >>> /etc/mail/aliases rebuilt by root >>> May 23 12:54:46 cheviot9 sendmail[5060]: /etc/mail/aliases: 408 >>> >> aliases, >> >>> longest 83 bytes, 21885 bytes total >>> May 23 12:54:46 cheviot9 sendmail[5069]: starting daemon (8.13.1): >>> >> SMTP >> >>> May 23 12:54:46 cheviot9 sendmail[5069]: STARTTLS: ServerCertFile >>> missing >>> May 23 12:54:46 cheviot9 sendmail[5069]: started as: >>> >> /usr/sbin/sendmail >> >>> -bd -OPrivacyOptions=noetrn -ODeliveryMode=queueonly >>> -OQueueDirectory=/var/spool/mqueue.in - >>> >> OPidFile=/var/run/sendmail.in.pid >> >>> May 23 12:54:46 cheviot9 sm-msp-queue[5073]: starting daemon >>> > (8.13.1): > >>> queueing@00:15:00 >>> May 23 12:54:46 cheviot9 sendmail[5078]: starting daemon (8.13.1): >>> queueing@00:15:00 >>> May 23 12:54:46 cheviot9 sendmail[5078]: started as: >>> >> /usr/sbin/sendmail >> >>> -q15m -OPidFile=/var/run/sendmail.out.pid >>> May 23 12:54:47 cheviot9 MailScanner[5094]: MailScanner E-Mail Virus >>> Scanner version 4.60.3 starting... >>> May 23 12:54:48 cheviot9 MailScanner[5094]: Read 764 hostnames from >>> >> the >> >>> phishing whitelist >>> May 23 12:54:48 cheviot9 MailScanner[5094]: Using SpamAssassin >>> > results > >>> cache >>> May 23 12:54:48 cheviot9 MailScanner[5094]: Connected to SpamAssassin >>> cache database >>> May 23 12:54:48 cheviot9 MailScanner[5094]: lock.pl sees Config >>> LockType = posix >>> May 23 12:54:48 cheviot9 MailScanner[5094]: lock.pl sees have_module >>> > = > >>> 0 >>> May 23 12:54:48 cheviot9 MailScanner[5094]: Using locktype = posix >>> May 23 12:54:48 cheviot9 MailScanner[5094]: Creating hardcoded >>> struct_flock subroutine for linux (Linux-type) >>> May 23 12:54:48 cheviot9 MailScanner[5094]: New Batch: Scanning 1 >>> messages, 1597 bytes >>> May 23 12:54:48 cheviot9 MailScanner[5094]: Created attachment dirs >>> >> for >> >>> 1 messages >>> May 23 12:54:48 cheviot9 MailScanner[5094]: MCP Checks: Starting >>> May 23 12:54:48 cheviot9 MailScanner[5094]: Message Content >>> > Protection > >>> SpamAssassin returned 65280 >>> May 23 12:54:48 cheviot9 MailScanner[5094]: MCP Checks completed at >>> 17428 bytes per second >>> May 23 12:54:48 cheviot9 MailScanner[5094]: Spam Checks: Starting >>> May 23 12:54:49 cheviot9 MailScanner[5094]: Virus and Content >>> >> Scanning: >> >>> Starting >>> May 23 12:54:49 cheviot9 MailScanner[5094]: Commencing scanning by >>> clamav... >>> May 23 12:54:58 cheviot9 MailScanner[5094]: Completed scanning by >>> >> clamav >> >>> May 23 12:54:58 cheviot9 MailScanner[5094]: Commencing scanning by >>> mcafee... >>> May 23 12:54:58 cheviot9 MailScanner[5094]: Completed scanning by >>> >> mcafee >> >>> May 23 12:54:58 cheviot9 MailScanner[5094]: Completed checking by >>> /usr/bin/file >>> May 23 12:54:58 cheviot9 MailScanner[5094]: Virus Scanning completed >>> >> at >> >>> 161 bytes per second >>> May 23 12:54:58 cheviot9 MailScanner[5094]: About to deliver 1 >>> >> messages >> >>> May 23 12:54:58 cheviot9 MailScanner[5094]: Uninfected: Delivered 1 >>> messages >>> May 23 12:54:58 cheviot9 MailScanner[5094]: Virus Processing >>> > completed > >>> at 191303 bytes per second >>> May 23 12:54:58 cheviot9 MailScanner[5094]: Batch completed at 159 >>> >> bytes >> >>> per second (1597 / 9) >>> May 23 12:54:58 cheviot9 MailScanner[5094]: Batch (1 message) >>> >> processed >> >>> in 9.99 seconds >>> May 23 12:54:58 cheviot9 MailScanner[5094]: MailScanner child dying >>> > of > >>> old age >>> May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: ClientCertFile >>> missing >>> May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: ClientKeyFile >>> >> missing >> >>> May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: CACertPath missing >>> May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: CACertFile missing >>> May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS: CRLFile missing >>> May 23 12:54:58 cheviot9 sendmail[5106]: STARTTLS=client, init=1 >>> May 23 12:54:58 cheviot9 sendmail[5107]: l4NBpfpt004809: SMTP >>> > outgoing > >>> connect on cheviot9.ncl.ac.uk >>> May 23 12:55:01 cheviot9 sendmail[5107]: l4NBpfpt004809: >>> to=, delay=00:03:20, >>> >> xdelay=00:00:03, >> >>> mailer=esmtp, pri=121128, relay=burnmoor.ncl.ac.uk. [128.240.233.53], >>> dsn=2.0.0, stat=Sent (MAA29651 Message accepted for delivery) >>> May 23 12:55:01 cheviot9 sendmail[5107]: l4NBpfpt004809: done; >>> delay=00:03:20, ntries=1 >>> ... >>> >>> >>> I hope that provides the info you need? >>> >>> Quentin >>> --- >>> PHONE: +44 191 222 8209 Information Systems and Services (ISS), >>> Newcastle University, >>> Newcastle upon Tyne, >>> FAX: +44 191 222 8765 United Kingdom, NE1 7RU. >>> ------------------------------------------------------------------ >>> >>> >>> >>> >> Jules >> >> - -- >> Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> MailScanner customisation, or any advanced system administration help? >> Contact me at Jules@Jules.FM >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> For all your IT requirements visit www.transtec.co.uk >> >> >> >> -----BEGIN PGP SIGNATURE----- >> Version: PGP Desktop 9.6.1 (Build 1012) >> Charset: ISO-8859-1 >> >> wj8DBQFGVE0lEfZZRxQVtlQRAuHDAJ9H7C/oI91zZCPnhwlTh96vGb3USgCgyT7O >> x771DyI3vw2w2hDZVuQqp2U= >> =Ixb3 >> -----END PGP SIGNATURE----- >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> For all your IT requirements visit www.transtec.co.uk >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGVbQxEfZZRxQVtlQRAnJ+AJ0T7hRYjEvZ8+o54O3hElR81DPk9ACgtB9M q8sHrsXfA6fjiqn87aWXJM0= =7LHq -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From maillists at conactive.com Thu May 24 17:06:42 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu May 24 17:06:46 2007 Subject: Enabling bounces In-Reply-To: <4655A9DB.4050000@ecs.soton.ac.uk> References: <46557C94.8010304@tradoc.fr> <4655A9DB.4050000@ecs.soton.ac.uk> Message-ID: Julian Field wrote on Thu, 24 May 2007 16:06:03 +0100: > Because it is necessary. If you want to bounce spam, you have to jump > through some hoops. I'm not questioning the hoops, I'm wondering if I really understand it right that *two* rulesets are necessary. For a given message, spam actions has to evaluate to > a result including "bounce", and enable spam bounce has to evaluate to > "yes". The ruleset is necessary because I say it is :-) But I don't see how *two* rulesets are supposed to work or are necessary. I think it's not clear what my confusion is about: spam.actions.rules: From: IP bounce FromOrTo: default store notify header "X-Spam-Status: Yes" *and* bounce.rules; From: IP yes From: default no is that really what I have to do if I wanted to bounce? > MailScanner doesn't use the From: address in the headers at all, it only > uses the envelope sender address. That's why I wanted to boost spamminess of the messages with Spamassassin which would then enable MailScanner to bounce the messages by detecting them as spam (for sure), but with high scoring spam excluded it's very unreliable as most messages would score high probably even without boosting them up. I think I could also just forward all messages to a specific address, as the forward action is available for spam and non-spam. But the problem still is the detection. Can I create a rule that detects messages from <> *and* IP? I know that I can "and" rules, but can I detect an empty sender? > > Any ideas how I can do it with MailScanner (as obviously what I had in mind > > won't work). > > > You could do it with a Custom Function tied to "Enable Spam Bounce" > probably. I would need to think a bit about exactly what you would want > to do. You want to spot spam coming from postmaster@hisdomain (in the > From: header) and switch off its $message->{ishigh} flag so it gets > treated as normal scoring spam, at which point you can bounce it. It's > just a problem of working out which config option to attach the Custom > Function to. Frankly, it's then probably easier to compile milter-regex as I think it can use header parts as well. I hoped I could do it somehow with MailScanner as I just need the blockage for this one thing. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Thu May 24 17:06:42 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu May 24 17:06:47 2007 Subject: Enabling bounces In-Reply-To: <4655A6D8.4030201@tradoc.fr> References: <46557C94.8010304@tradoc.fr> <4655A6D8.4030201@tradoc.fr> Message-ID: John Wilcock wrote on Thu, 24 May 2007 16:53:12 +0200: > ? a ruleset to set "Is Definitely Spam" to yes for his messages (make > sure you also have "Definite Spam Is High Scoring = no" This won't work because it needs an IP or a From envelope. I can only work on the mail header from. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From dhawal at netmagicsolutions.com Thu May 24 17:17:00 2007 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Thu May 24 17:17:19 2007 Subject: sending a copy of all inbound messages to two MTAs In-Reply-To: References: <668080.79708.qm@web26312.mail.ukl.yahoo.com> Message-ID: <4655BA7C.6060601@netmagicsolutions.com> --[ UxBoD ]-- wrote: > Easier solution :- > > http://www.snertsoft.com/sendmail/roundhouse/ The OP mentioned postfix.. though postfix has milter support now, setting up roundhouse for a task which can be done by inbuilt options is overkill IMO. > On Thu, 24 May 2007 15:13:18 +0000 (GMT), Andrew MacLachlan > wrote: >> I'll give this one a try... >> I need to preserve the sender/recipient details >> >> ----- Original Message ---- >> From: Drew Marshall >> To: MailScanner discussion >> Sent: Thursday, 24 May, 2007 2:44:50 PM >> Subject: Re: sending a copy of all inbound messages to two MTAs >> >> On Thu, May 24, 2007 14:25, Andrew MacLachlan wrote: >>> This is a strange request, and I suspect that it's probably a PostFix >>> question: >>> can a copy of each inbound message be sent to an alternate MTA? >>> This is so a new mailserver can be tested with real inbound mail >> flows... >>> --Asbestos suit zipped up... >> It is a Postfix question but the answer is always_bcc >> http://www.postfix.org/postconf.5.html#always_bcc alternatively if you >> need to preserve the original sender details, you could play around with >> your relay_recipients_map creating duplicate aliases to the second box. >> >> Drew From ssilva at sgvwater.com Thu May 24 17:21:35 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 24 17:22:05 2007 Subject: yum based install In-Reply-To: References: Message-ID: Hugo van der Kooij spake the following on 5/24/2007 3:16 AM: > Hi, > > It seems rpmforge will have (or does have by now ;-) a perl-Filesys-Df > package. > > So the only thing one would need to use yum to install MS would be a > repository with the mailscanner RPM in then for the usual distro's. > > There is an issue however that needs to be addressed in the MS rpm file > to make it work. There is no dependency for perl-Filesys-Df in the MS > RPM. I noticed the dependency only when I started MS that it needed > Filesys/Df.pm to run. > > I understand Julian is no fan of packagers adding MS to their > repositories. If keeping it up-to-date and getting some usage figures is > the main issue then I think it would be almost trivial to setup a > repository so yum can fetch MS from the right site and Julian will still > have an up-to-date repository and the download statistics. > > Hugo. > If Julian doesn't want the MailScanner rpm on a repo, you could always do a yum localinstall with proper repo info in place. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From MailScanner at ecs.soton.ac.uk Thu May 24 17:31:39 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 24 17:32:53 2007 Subject: Enabling bounces In-Reply-To: References: <46557C94.8010304@tradoc.fr> <4655A9DB.4050000@ecs.soton.ac.uk> Message-ID: <4655BDEB.7000401@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Kai Schaetzl wrote: > Julian Field wrote on Thu, 24 May 2007 16:06:03 +0100: > > >> Because it is necessary. If you want to bounce spam, you have to jump >> through some hoops. >> > > I'm not questioning the hoops, I'm wondering if I really understand it right that > *two* rulesets are necessary. > Yes. > For a given message, spam actions has to evaluate to > >> a result including "bounce", and enable spam bounce has to evaluate to >> "yes". The ruleset is necessary because I say it is :-) >> > > But I don't see how *two* rulesets are supposed to work or are necessary. > I think it's not clear what my confusion is about: > > spam.actions.rules: > From: IP bounce > FromOrTo: default store notify header "X-Spam-Status: Yes" > > *and* > > bounce.rules; > From: IP yes > From: default no > > is that really what I have to do if I wanted to bounce? > Yes. > >> MailScanner doesn't use the From: address in the headers at all, it only >> uses the envelope sender address. >> > > That's why I wanted to boost spamminess of the messages with Spamassassin which > would then enable MailScanner to bounce the messages by detecting them as spam > (for sure), but with high scoring spam excluded it's very unreliable as most > messages would score high probably even without boosting them up. > A little Custom Function could set '$message->{ishigh} = 0;' if the IP address matches, to stop it being treated as high-scoring spam, so you could then bounce it. > I think I could also just forward all messages to a specific address, as the > forward action is available for spam and non-spam. But the problem still is the > detection. Can I create a rule that detects messages from <> *and* IP? I know > that I can "and" rules, but can I detect an empty sender? > I seem to remember you can set the address to /^$/ and it will treat that as an empty address. That is a regular expression that will match an empty address. So you can say From: /^$/ and From: IP yes in a ruleset and that should do what you want. > >>> Any ideas how I can do it with MailScanner (as obviously what I had in mind >>> won't work). >>> >>> >> You could do it with a Custom Function tied to "Enable Spam Bounce" >> probably. I would need to think a bit about exactly what you would want >> to do. You want to spot spam coming from postmaster@hisdomain (in the >> From: header) and switch off its $message->{ishigh} flag so it gets >> treated as normal scoring spam, at which point you can bounce it. It's >> just a problem of working out which config option to attach the Custom >> Function to. >> > > Frankly, it's then probably easier to compile milter-regex as I think it can use > header parts as well. I hoped I could do it somehow with MailScanner as I just > need the blockage for this one thing. > > Kai > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGVb4PEfZZRxQVtlQRAmW5AJ41Z6ZH9M5aMJDlZ7ghkYTYGQEBJQCg6oiO uad6qK3lhlnpiF+7dfXE7MQ= =eg63 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Thu May 24 17:36:16 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 24 17:37:07 2007 Subject: yum based install In-Reply-To: References: Message-ID: <4655BF00.6030801@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Scott Silva wrote: > Hugo van der Kooij spake the following on 5/24/2007 3:16 AM: > >> Hi, >> >> It seems rpmforge will have (or does have by now ;-) a perl-Filesys-Df >> package. >> >> So the only thing one would need to use yum to install MS would be a >> repository with the mailscanner RPM in then for the usual distro's. >> >> There is an issue however that needs to be addressed in the MS rpm file >> to make it work. There is no dependency for perl-Filesys-Df in the MS >> RPM. I noticed the dependency only when I started MS that it needed >> Filesys/Df.pm to run. >> >> I understand Julian is no fan of packagers adding MS to their >> repositories. If keeping it up-to-date and getting some usage figures is >> the main issue then I think it would be almost trivial to setup a >> repository so yum can fetch MS from the right site and Julian will still >> have an up-to-date repository and the download statistics. >> >> Hugo. >> >> > If Julian doesn't want the MailScanner rpm on a repo, you could always do a > yum localinstall with proper repo info in place. > Do I need to do anything to make yum installs work more easily? Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGVb8PEfZZRxQVtlQRAonXAJ9BbppPMzD55K6bkhkaHlstWwTOHwCdH/tZ szh2VZ4nhZpUFim2vOgIcbM= =acsL -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Thu May 24 17:54:22 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 24 17:54:41 2007 Subject: Enabling bounces In-Reply-To: References: <46557C94.8010304@tradoc.fr> Message-ID: Kai Schaetzl spake the following on 5/24/2007 7:31 AM: > John Wilcock wrote on Thu, 24 May 2007 13:52:52 +0200: > >> Yes, you need to add a corresponding ruleset for the spam actions, with >> bounce set as an action for the offending sender. > > But then I do not understand the whole thing at all. If I put bounce in the > Spam Score Actions, then it will apply for everyone. If I make it a ruleset, > then I don't see how or why the other ruleset is necessary/works. > > Example: > > Spam Actions = %rules-dir%/spam.actions.rules > -> > From: IP bounce > FromOrTo: default default store notify header "X-Spam-Status: Yes" > > what for do I then need > Enable Spam Bounce = %rules-dir%/bounce.rules > for? > >> Likewise, MailScanner won't bounce high scoring spam even if you tell it >> to via the Enable Spam Bounce rule (as I found out when I tried to send >> a GTUBE to test my setup!) > > Oh, I think I now understand, bummer. It's high-scoring spam that I want to > bounce back. So, using *only* > Enable Spam Bounce = %rules-dir%/bounce.rules > (and not Spam Actions) > would work if it is low-scoring spam? > > Hm. What I want to do is bounce spam (or other messages) back that I get > from a specific customer who moved to his own in-house poorly maintained > mailserver (Exchange). Instead of having a decent spam detection he bounces > all non-deliverable mail back via his smarthost - which happens to be me. If > I just stop him dead I'm gonna sure loose him. If I try to explain and > convince him (already tried) that he should "bounce" during the SMTP > connection it takes me a year. So, I wanted to boost all the messages that > come from postmaster@hisdomain via Spamassassin to 20 or so, detect them as > spam and bounce back to him until he understands. > As the sender envelope is empty I can only rely on methods that look at the > mail headers. And I don't want to add another milter to the mix. > Any ideas how I can do it with MailScanner (as obviously what I had in mind > won't work). > > Kai > Maybe if you "volunteered" some time to help him fix his setup, it might go easier for both of you. You get to stop the flood, and build some points with a customer. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From clacroix at cegep-ste-foy.qc.ca Thu May 24 18:01:31 2007 From: clacroix at cegep-ste-foy.qc.ca (Charles Lacroix) Date: Thu May 24 18:01:40 2007 Subject: yum based install In-Reply-To: <4655BF00.6030801@ecs.soton.ac.uk> References: <4655BF00.6030801@ecs.soton.ac.uk> Message-ID: <200705241301.31918.clacroix@cegep-ste-foy.qc.ca> On Thursday 24 May 2007 12:36, Julian Field wrote: > Scott Silva wrote: > > Hugo van der Kooij spake the following on 5/24/2007 3:16 AM: > >> Hi, > >> > >> It seems rpmforge will have (or does have by now ;-) a perl-Filesys-Df > >> package. > >> > >> So the only thing one would need to use yum to install MS would be a > >> repository with the mailscanner RPM in then for the usual distro's. > >> > >> There is an issue however that needs to be addressed in the MS rpm file > >> to make it work. There is no dependency for perl-Filesys-Df in the MS > >> RPM. I noticed the dependency only when I started MS that it needed > >> Filesys/Df.pm to run. > >> > >> I understand Julian is no fan of packagers adding MS to their > >> repositories. If keeping it up-to-date and getting some usage figures is > >> the main issue then I think it would be almost trivial to setup a > >> repository so yum can fetch MS from the right site and Julian will still > >> have an up-to-date repository and the download statistics. > >> > >> Hugo. > > > > If Julian doesn't want the MailScanner rpm on a repo, you could always do > > a yum localinstall with proper repo info in place. > > Do I need to do anything to make yum installs work more easily? Basicly, you need to make sure your requirements are in the yum repository and yum does the rest :) > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk -- Charles Lacroix, Administrateur UNIX. Service des t?l?communications et des technologies C?gep de Sainte-Foy (418) 659-6600 # 4266 From H.de.Vries at philos.rug.nl Thu May 24 18:01:22 2007 From: H.de.Vries at philos.rug.nl (Hauke de Vries) Date: Thu May 24 18:01:48 2007 Subject: Add header In-Reply-To: <4655B416.9040202@ecs.soton.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk>, <4165CF7A7F12DE4B96622CCBB90586470A4D1496@largo.campus.ncl.ac.uk>, <4655B416.9040202@ecs.soton.ac.uk> Message-ID: <4655E102.6212.10542213@H.de.Vries.philos.rug.nl> I've enabled Plugin:RelayCountry in SA3.2 If I perform spamassassin -D < spam.eml > spam.dbg an header X-Spam-Relay-Country: IT is appended. But it doesn't show up if it goes thru MailScanner? From ugob at lubik.ca Thu May 24 18:07:04 2007 From: ugob at lubik.ca (Ugo Bellavance) Date: Thu May 24 18:07:24 2007 Subject: SpamAssassin 3.2.0 with 4.54.6 Message-ID: Hi, Anyone running MS 4.54.6 with SA 3.2.0? We'd like to wait for the next release to upgrade MS, but we'd like to upgrade SA... Thanks, Ugo From MailScanner at ecs.soton.ac.uk Thu May 24 18:17:33 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 24 18:18:16 2007 Subject: SpamAssassin 3.2.0 with 4.54.6 In-Reply-To: References: Message-ID: <4655C8AD.2060600@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I'll probably release 4.60 at the start of June, so you've only got a week to wait. I can't see any major problems of running 4.54.6 with SA 3.2.0. I'll test it out on a VM for you if you like. What VM would you prefer me to try it on? CentOS 4.4, CentOS 5.0 or Solaris 9? Ugo Bellavance wrote: > Hi, > > Anyone running MS 4.54.6 with SA 3.2.0? We'd like to wait for the > next release to upgrade MS, but we'd like to upgrade SA... > > Thanks, > > Ugo > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGVciyEfZZRxQVtlQRAkuEAJkB33lf6DbywwMWpp3G5OARf1gpfACfTuev q2Lqj1+qX2wndaLmbsmNnzs= =10sn -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Thu May 24 18:15:10 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 24 18:19:10 2007 Subject: yum based install In-Reply-To: <200705241301.31918.clacroix@cegep-ste-foy.qc.ca> References: <4655BF00.6030801@ecs.soton.ac.uk> <200705241301.31918.clacroix@cegep-ste-foy.qc.ca> Message-ID: <4655C81E.3050001@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Charles Lacroix wrote: > On Thursday 24 May 2007 12:36, Julian Field wrote: > >> Scott Silva wrote: >> >>> Hugo van der Kooij spake the following on 5/24/2007 3:16 AM: >>> >>>> Hi, >>>> >>>> It seems rpmforge will have (or does have by now ;-) a perl-Filesys-Df >>>> package. >>>> >>>> So the only thing one would need to use yum to install MS would be a >>>> repository with the mailscanner RPM in then for the usual distro's. >>>> >>>> There is an issue however that needs to be addressed in the MS rpm file >>>> to make it work. There is no dependency for perl-Filesys-Df in the MS >>>> RPM. I noticed the dependency only when I started MS that it needed >>>> Filesys/Df.pm to run. >>>> >>>> I understand Julian is no fan of packagers adding MS to their >>>> repositories. If keeping it up-to-date and getting some usage figures is >>>> the main issue then I think it would be almost trivial to setup a >>>> repository so yum can fetch MS from the right site and Julian will still >>>> have an up-to-date repository and the download statistics. >>>> >>>> Hugo. >>>> >>> If Julian doesn't want the MailScanner rpm on a repo, you could always do >>> a yum localinstall with proper repo info in place. >>> >> Do I need to do anything to make yum installs work more easily? >> > > Basicly, you need to make sure your requirements are in the yum repository and > yum does the rest :) > Tell me more... Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGVciwEfZZRxQVtlQRAqyXAJ9S9x0vbDMUkXLhFCAtEujP61uJggCg+DSm e0eROEZflKBdNgDb3VpqLzQ= =+6J7 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Thu May 24 18:33:10 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 24 18:33:37 2007 Subject: yum based install In-Reply-To: <4655BF00.6030801@ecs.soton.ac.uk> References: <4655BF00.6030801@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 5/24/2007 9:36 AM: > > > Scott Silva wrote: >> Hugo van der Kooij spake the following on 5/24/2007 3:16 AM: > >>> Hi, >>> >>> It seems rpmforge will have (or does have by now ;-) a perl-Filesys-Df >>> package. >>> >>> So the only thing one would need to use yum to install MS would be a >>> repository with the mailscanner RPM in then for the usual distro's. >>> >>> There is an issue however that needs to be addressed in the MS rpm file >>> to make it work. There is no dependency for perl-Filesys-Df in the MS >>> RPM. I noticed the dependency only when I started MS that it needed >>> Filesys/Df.pm to run. >>> >>> I understand Julian is no fan of packagers adding MS to their >>> repositories. If keeping it up-to-date and getting some usage figures is >>> the main issue then I think it would be almost trivial to setup a >>> repository so yum can fetch MS from the right site and Julian will still >>> have an up-to-date repository and the download statistics. >>> >>> Hugo. >>> >>> >> If Julian doesn't want the MailScanner rpm on a repo, you could always do a >> yum localinstall with proper repo info in place. > > Do I need to do anything to make yum installs work more easily? > > Jules > I think it was mentioned near the top of this message about adding the dependency for perl-Filesys-Df. If the rpm has the proper requires, it should be just a matter of adding rpmforge as a yum repo, and doing "yum localinstall --enablerepo=rpmforge mailscanner.xxx.noarch.rpm. If you feel so inclined, maybe Dag can mirror the MailScanner rpm and then it would be a "one-stop" shop. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From mkettler at evi-inc.com Thu May 24 18:44:55 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Thu May 24 18:45:12 2007 Subject: Add header In-Reply-To: <4655E102.6212.10542213@H.de.Vries.philos.rug.nl> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk>, <4165CF7A7F12DE4B96622CCBB90586470A4D1496@largo.campus.ncl.ac.uk>, <4655B416.9040202@ecs.soton.ac.uk> <4655E102.6212.10542213@H.de.Vries.philos.rug.nl> Message-ID: <4655CF17.5050909@evi-inc.com> Hauke de Vries wrote: > I've enabled Plugin:RelayCountry in SA3.2 > If I perform spamassassin -D < spam.eml > spam.dbg > an header X-Spam-Relay-Country: IT > is appended. Ok, so you set up SA to do that with an add_header command? (I gather such from the subject line) > > But it doesn't show up if it goes thru MailScanner? > Nope. MailScanner does it's own markups. Nothing SA generates or adds to the message will be reflected when using MailScanner. MailScanner runs SA, takes the results, and makes its own headers containing the results. Nothing else from SpamAssassin is preserved. Therefore all "add_header" and other markup related directives in SA are irrelevant. That said, the X-Spam-Relay-Country header WILL be present as metadata when SA processes the message, so rules based on it will still work. The only part that's not going to work is any modifications to the delivered message. And while we're at it, what does this message have to do with "4.60.3-1 install errors on RH AS4"? ie: why'd you reply to that thread instead of creating a new one? There are those of us who use threaded mailreaders, that keep track of the "references" and "in-reply-to" headers. Those readers will bury your message inside whatever thread you replied to, even if you change the subject. Do yourself a favor and make a new post instead of replying to an existing one if you want to make a new thread. Otherwise, those of us using threaded mailreaders might overlook your posts as a part of some thread that does not interest us. From hvdkooij at vanderkooij.org Thu May 24 18:46:05 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Thu May 24 18:46:45 2007 Subject: yum based install In-Reply-To: <200705241301.31918.clacroix@cegep-ste-foy.qc.ca> References: <4655BF00.6030801@ecs.soton.ac.uk> <200705241301.31918.clacroix@cegep-ste-foy.qc.ca> Message-ID: On Thu, 24 May 2007, Charles Lacroix wrote: > On Thursday 24 May 2007 12:36, Julian Field wrote: >> Scott Silva wrote: >>> Hugo van der Kooij spake the following on 5/24/2007 3:16 AM: >>>> Hi, >>>> >>>> It seems rpmforge will have (or does have by now ;-) a perl-Filesys-Df >>>> package. >>>> >>>> So the only thing one would need to use yum to install MS would be a >>>> repository with the mailscanner RPM in then for the usual distro's. >>>> >>>> There is an issue however that needs to be addressed in the MS rpm file >>>> to make it work. There is no dependency for perl-Filesys-Df in the MS >>>> RPM. I noticed the dependency only when I started MS that it needed >>>> Filesys/Df.pm to run. >>>> >>>> I understand Julian is no fan of packagers adding MS to their >>>> repositories. If keeping it up-to-date and getting some usage figures is >>>> the main issue then I think it would be almost trivial to setup a >>>> repository so yum can fetch MS from the right site and Julian will still >>>> have an up-to-date repository and the download statistics. >>> >>> If Julian doesn't want the MailScanner rpm on a repo, you could always do >>> a yum localinstall with proper repo info in place. >> >> Do I need to do anything to make yum installs work more easily? > > Basicly, you need to make sure your requirements are in the yum repository and > yum does the rest :) In effect you need to explicitly define perl-Filesys-Df a requirement in the spec file. Then store the mailscanner rpm in the right web tree and setup the yum repository. For this I found the description on http://www.phy.duke.edu/~rgb/General/yum_article/yum_article/node14.html rather usefull. As I think MailScanner will work with most distro's that use yum you could propably do with just one part instead of adding one per distro. If you need any assistence I would be glad to lend a hand but you may want to do this off-list. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From MailScanner at ecs.soton.ac.uk Thu May 24 19:01:16 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 24 19:02:17 2007 Subject: yum based install In-Reply-To: References: <4655BF00.6030801@ecs.soton.ac.uk> Message-ID: <4655D2EC.6000804@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Scott Silva wrote: > Julian Field spake the following on 5/24/2007 9:36 AM: > >> Scott Silva wrote: >> >>> Hugo van der Kooij spake the following on 5/24/2007 3:16 AM: >>> >>>> Hi, >>>> >>>> It seems rpmforge will have (or does have by now ;-) a perl-Filesys-Df >>>> package. >>>> >>>> So the only thing one would need to use yum to install MS would be a >>>> repository with the mailscanner RPM in then for the usual distro's. >>>> >>>> There is an issue however that needs to be addressed in the MS rpm file >>>> to make it work. There is no dependency for perl-Filesys-Df in the MS >>>> RPM. I noticed the dependency only when I started MS that it needed >>>> Filesys/Df.pm to run. >>>> >>>> I understand Julian is no fan of packagers adding MS to their >>>> repositories. If keeping it up-to-date and getting some usage figures is >>>> the main issue then I think it would be almost trivial to setup a >>>> repository so yum can fetch MS from the right site and Julian will still >>>> have an up-to-date repository and the download statistics. >>>> >>>> Hugo. >>>> >>>> >>>> >>> If Julian doesn't want the MailScanner rpm on a repo, you could always do a >>> yum localinstall with proper repo info in place. >>> >> Do I need to do anything to make yum installs work more easily? >> >> Jules >> >> > I think it was mentioned near the top of this message about adding the > dependency for perl-Filesys-Df. If the rpm has the proper requires, The problem with that is it doesn't help you if you have installed any of the Perl modules using CPAN. This is why the MailScanner rpm file doesn't have a long "requires" list containing all the Perl modules it needs. If you have any of the Perl modules installed via CPAN, you have the module but don't have the RPM for it. Some people (and there are quite of few of them) prefer to use CPAN to manage their Perl modules as it avoids the problem where I have to 'force' the installation of an RPM because the Perl module builds into the same location as that used by the main perl rpm itself. Quite a few of the Perl modules I use do this. You will notice the 'clashes' error messages when the Perl rpms attempt to install during my install.sh script. A Perl module can choose to live in one of 3 places: (1) the main perl library tree (these are the troublemakers) (2) the 'vendor_perl' tree (3) the 'site_perl' tree If a module chooses (1) then the RPM built from it won't install without being forced. And if you force it, it will overwrite any later version that may be installed already. So people use CPAN instead as it happily installs into (1) without any trickery that they don't know about, and it won't overwrite newer versions. Unfortunately, the whole concept of RPMs doesn't work very well with how the Perl library structure works. And I can't fix that. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGVdL1EfZZRxQVtlQRAjLZAJ4r70hEBBWWFnoJ6An3Zyabl0NfVwCg9akU z0y+Ta+XJ36hR8AP819kRp0= =P1ot -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Thu May 24 19:16:01 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 24 19:16:30 2007 Subject: yum based install In-Reply-To: <4655D2EC.6000804@ecs.soton.ac.uk> References: <4655BF00.6030801@ecs.soton.ac.uk> <4655D2EC.6000804@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 5/24/2007 11:01 AM: > > > Scott Silva wrote: >> Julian Field spake the following on 5/24/2007 9:36 AM: > >>> Scott Silva wrote: >>> >>>> Hugo van der Kooij spake the following on 5/24/2007 3:16 AM: >>>> >>>>> Hi, >>>>> >>>>> It seems rpmforge will have (or does have by now ;-) a perl-Filesys-Df >>>>> package. >>>>> >>>>> So the only thing one would need to use yum to install MS would be a >>>>> repository with the mailscanner RPM in then for the usual distro's. >>>>> >>>>> There is an issue however that needs to be addressed in the MS rpm file >>>>> to make it work. There is no dependency for perl-Filesys-Df in the MS >>>>> RPM. I noticed the dependency only when I started MS that it needed >>>>> Filesys/Df.pm to run. >>>>> >>>>> I understand Julian is no fan of packagers adding MS to their >>>>> repositories. If keeping it up-to-date and getting some usage figures is >>>>> the main issue then I think it would be almost trivial to setup a >>>>> repository so yum can fetch MS from the right site and Julian will still >>>>> have an up-to-date repository and the download statistics. >>>>> >>>>> Hugo. >>>>> >>>>> >>>>> >>>> If Julian doesn't want the MailScanner rpm on a repo, you could always do a >>>> yum localinstall with proper repo info in place. >>>> >>> Do I need to do anything to make yum installs work more easily? >>> >>> Jules >>> >>> >> I think it was mentioned near the top of this message about adding the >> dependency for perl-Filesys-Df. If the rpm has the proper requires, > The problem with that is it doesn't help you if you have installed any > of the Perl modules using CPAN. This is why the MailScanner rpm file > doesn't have a long "requires" list containing all the Perl modules it > needs. If you have any of the Perl modules installed via CPAN, you have > the module but don't have the RPM for it. > > Some people (and there are quite of few of them) prefer to use CPAN to > manage their Perl modules as it avoids the problem where I have to > 'force' the installation of an RPM because the Perl module builds into > the same location as that used by the main perl rpm itself. Quite a few > of the Perl modules I use do this. You will notice the 'clashes' error > messages when the Perl rpms attempt to install during my install.sh script. > > A Perl module can choose to live in one of 3 places: > (1) the main perl library tree (these are the troublemakers) > (2) the 'vendor_perl' tree > (3) the 'site_perl' tree > > If a module chooses (1) then the RPM built from it won't install without > being forced. And if you force it, it will overwrite any later version > that may be installed already. > > So people use CPAN instead as it happily installs into (1) without any > trickery that they don't know about, and it won't overwrite newer versions. > > Unfortunately, the whole concept of RPMs doesn't work very well with how > the Perl library structure works. And I can't fix that. > > > Jules > I personally don't have a problem with your installer. I use it at every upgrade "just because". Since I already have to beat them with a stick to install things I also like such as Vispan and mailwatch, I don't mind a little extra work occasionally. That is what I make the "big bucks" for. MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From richard.siddall at elirion.net Thu May 24 19:16:11 2007 From: richard.siddall at elirion.net (Richard Siddall) Date: Thu May 24 19:16:57 2007 Subject: yum based install In-Reply-To: <4655D2EC.6000804@ecs.soton.ac.uk> References: <4655BF00.6030801@ecs.soton.ac.uk> <4655D2EC.6000804@ecs.soton.ac.uk> Message-ID: <4655D66B.10800@elirion.net> Julian Field wrote: > The problem with that is it doesn't help you if you have installed any > of the Perl modules using CPAN. This is why the MailScanner rpm file > doesn't have a long "requires" list containing all the Perl modules it > needs. If you have any of the Perl modules installed via CPAN, you have > the module but don't have the RPM for it. > Julian, Could you put out a meta-RPM with the full list of Requires? It would contain no files, just a list of requires that would cause yum/apt/whatever to pull in the MailScanner RPM and all the Perl modules. Regards, Richard Siddall From prandal at herefordshire.gov.uk Thu May 24 19:02:44 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Thu May 24 19:48:07 2007 Subject: yum based install In-Reply-To: <4655BF00.6030801@ecs.soton.ac.uk> References: <4655BF00.6030801@ecs.soton.ac.uk> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBAB25CCF@HC-MBX02.herefordshire.gov.uk> Yum localinstall is explained here: http://fedoranews.org/mediawiki/index.php/Using_yum_localinstall_package name I guess specifying dependencies in your RPM would help in that case, but that in itself is a can of worms. Phil -- Phil Randal Network Engineer Herefordshire Council Hereford, UK > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Julian Field > Sent: 24 May 2007 17:36 > To: MailScanner discussion > Subject: Re: yum based install > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Scott Silva wrote: > > Hugo van der Kooij spake the following on 5/24/2007 3:16 AM: > > > >> Hi, > >> > >> It seems rpmforge will have (or does have by now ;-) a > perl-Filesys-Df > >> package. > >> > >> So the only thing one would need to use yum to install MS > would be a > >> repository with the mailscanner RPM in then for the usual distro's. > >> > >> There is an issue however that needs to be addressed in > the MS rpm file > >> to make it work. There is no dependency for > perl-Filesys-Df in the MS > >> RPM. I noticed the dependency only when I started MS that it needed > >> Filesys/Df.pm to run. > >> > >> I understand Julian is no fan of packagers adding MS to their > >> repositories. If keeping it up-to-date and getting some > usage figures is > >> the main issue then I think it would be almost trivial to setup a > >> repository so yum can fetch MS from the right site and > Julian will still > >> have an up-to-date repository and the download statistics. > >> > >> Hugo. > >> > >> > > If Julian doesn't want the MailScanner rpm on a repo, you > could always do a > > yum localinstall with proper repo info in place. > > > Do I need to do anything to make yum installs work more easily? > > Jules > > - -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -----BEGIN PGP SIGNATURE----- > Version: PGP Desktop 9.6.1 (Build 1012) > Charset: UTF-8 > > wj8DBQFGVb8PEfZZRxQVtlQRAonXAJ9BbppPMzD55K6bkhkaHlstWwTOHwCdH/tZ > szh2VZ4nhZpUFim2vOgIcbM= > =acsL > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From ugob at lubik.ca Thu May 24 20:04:02 2007 From: ugob at lubik.ca (Ugo Bellavance) Date: Thu May 24 20:04:34 2007 Subject: SpamAssassin 3.2.0 with 4.54.6 In-Reply-To: <4655C8AD.2060600@ecs.soton.ac.uk> References: <4655C8AD.2060600@ecs.soton.ac.uk> Message-ID: Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > I'll probably release 4.60 at the start of June, so you've only got a > week to wait. I can't see any major problems of running 4.54.6 with SA > 3.2.0. > I'll test it out on a VM for you if you like. > What VM would you prefer me to try it on? > CentOS 4.4, CentOS 5.0 or Solaris 9? CentOS 4.4 please (.5 is released fyi). Thanks, Ugo From hvdkooij at vanderkooij.org Thu May 24 20:06:32 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Thu May 24 20:07:10 2007 Subject: yum based install In-Reply-To: <4655D2EC.6000804@ecs.soton.ac.uk> References: <4655BF00.6030801@ecs.soton.ac.uk> <4655D2EC.6000804@ecs.soton.ac.uk> Message-ID: On Thu, 24 May 2007, Julian Field wrote: >>> Do I need to do anything to make yum installs work more easily? >>> >> I think it was mentioned near the top of this message about adding the >> dependency for perl-Filesys-Df. If the rpm has the proper requires, > The problem with that is it doesn't help you if you have installed any > of the Perl modules using CPAN. This is why the MailScanner rpm file > doesn't have a long "requires" list containing all the Perl modules it > needs. If you have any of the Perl modules installed via CPAN, you have > the module but don't have the RPM for it. Well this requirement is only for the package in the repository. If one installs perl from CPAN then one is unlikely to use yum just to install mailscanner. But for those that perfer to let the package manager take care of it the package. Dag also expressed his interrest in adding mailscanner to rpmforge if you feel uncomfortable with maintaing a repository. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From ugob at lubik.ca Thu May 24 20:06:13 2007 From: ugob at lubik.ca (Ugo Bellavance) Date: Thu May 24 20:10:16 2007 Subject: HOWTO: Use re2c and compiled SpamAssassin rules In-Reply-To: <463DCE75.7090905@alexb.ch> References: <463DB32E.5070702@ecs.soton.ac.uk> <463DCE75.7090905@alexb.ch> Message-ID: ... currently writing it in the wiki... From cparker at swatgear.com Thu May 24 20:11:03 2007 From: cparker at swatgear.com (Chris W. Parker) Date: Thu May 24 20:11:06 2007 Subject: OT: Modified access and relay-domains file, still get 550 5.7.1 Message-ID: <97FD54B5E57A1842AA1A4B232E47611773EBA8@ati-ex-02.ati.local> Hello, I avoided sending this question here since it's off topic but I can't find a solution after about a week so here goes. :) I'm trying to set up Swiftmailer (an SMTP library for PHP) to send email from my web machine through my MS box and then on to wherever it's going. I have a few remote users that send email through their cellular phones. The way I got the phones to send successfully was by adding the carrier's sending mail server to /etc/mail/relay-domains. Now that I'm trying to relay mail from one of my own servers I thought I'd just add that servers host name to relay-domains (and restart) and everything would be fine. But alas... Here is what my log says: May 18 12:58:22 filter sendmail[16033]: l4IJwMD4016033: ruleset=check_mail, arg1=, relay=hachiroku.swatgear.com [67.17.248.232], reject=550 5.7.1 ... Access denied I did some research (and asked a question in another forum) and thought that maybe I needed to add the IP address of the sending server to /etc/mail/access and then 'make'. Still no good. At this point I have both the FQDN and external IP address of the sending server (as seen in the above log line) in both /etc/mail/access and /etc/mail/relay-domains. What am I missing? Thanks! Chris. From ugob at lubik.ca Thu May 24 20:11:32 2007 From: ugob at lubik.ca (Ugo Bellavance) Date: Thu May 24 20:15:13 2007 Subject: HOWTO: Use re2c and compiled SpamAssassin rules In-Reply-To: <463DB32E.5070702@ecs.soton.ac.uk> References: <463DB32E.5070702@ecs.soton.ac.uk> Message-ID: Done, using the original text from Julian: http://wiki.mailscanner.info/doku.php?id=documentation:anti_spam:spamassassin:pre_compiling_re2c Please edit the wiki entry if you feel it is not correct. Ugo From hvdkooij at vanderkooij.org Thu May 24 20:15:43 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Thu May 24 20:16:21 2007 Subject: yum based install In-Reply-To: <4655D66B.10800@elirion.net> References: <4655BF00.6030801@ecs.soton.ac.uk> <4655D2EC.6000804@ecs.soton.ac.uk> <4655D66B.10800@elirion.net> Message-ID: On Thu, 24 May 2007, Richard Siddall wrote: > Julian Field wrote: >> The problem with that is it doesn't help you if you have installed any of >> the Perl modules using CPAN. This is why the MailScanner rpm file doesn't >> have a long "requires" list containing all the Perl modules it needs. If >> you have any of the Perl modules installed via CPAN, you have the module >> but don't have the RPM for it. > > Could you put out a meta-RPM with the full list of Requires? It would > contain no files, just a list of requires that would cause yum/apt/whatever > to pull in the MailScanner RPM and all the Perl modules. Silly I did not think of it. I know the trick work for complex setups like mythtv with over 20 packages to install. That way there is no need to change the current package either. A rather lengty example can be seen on http://dl.atrpms.net/all/mythtv-suite.spec In our case it could be something like: Summary: Meta-package dragging in all of MailScanner Name: mailscanner-suite Version: 1 Release: 1 Requires: mailscanner Requires: perl-Filesys-Df ..... Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From lists at jfworks.net Thu May 24 20:31:57 2007 From: lists at jfworks.net (James) Date: Thu May 24 20:31:11 2007 Subject: OT: Modified access and relay-domains file, still get 550 5.7.1 In-Reply-To: <97FD54B5E57A1842AA1A4B232E47611773EBA8@ati-ex-02.ati.local> References: <97FD54B5E57A1842AA1A4B232E47611773EBA8@ati-ex-02.ati.local> Message-ID: <4655E82D.1010500@jfworks.net> Chris W. Parker wrote: > Hello, > > I avoided sending this question here since it's off topic but I can't > find a solution after about a week so here goes. :) > > I'm trying to set up Swiftmailer (an SMTP library for PHP) to send email > from my web machine through my MS box and then on to wherever it's > going. > > I have a few remote users that send email through their cellular phones. > The way I got the phones to send successfully was by adding the > carrier's sending mail server to /etc/mail/relay-domains. Now that I'm > trying to relay mail from one of my own servers I thought I'd just add > that servers host name to relay-domains (and restart) and everything > would be fine. But alas... > > Here is what my log says: > > May 18 12:58:22 filter sendmail[16033]: l4IJwMD4016033: > ruleset=check_mail, arg1=, > relay=hachiroku.swatgear.com [67.17.248.232], reject=550 5.7.1 > ... Access denied > > I did some research (and asked a question in another forum) and thought > that maybe I needed to add the IP address of the sending server to > /etc/mail/access and then 'make'. Still no good. > > At this point I have both the FQDN and external IP address of the > sending server (as seen in the above log line) in both /etc/mail/access > and /etc/mail/relay-domains. > > What am I missing? > > > > Thanks! > Chris. > Can you post your /etc/mail/access file ? From steve.swaney at fsl.com Thu May 24 20:41:51 2007 From: steve.swaney at fsl.com (Stephen Swaney) Date: Thu May 24 20:40:02 2007 Subject: HOWTO: Use re2c and compiled SpamAssassin rules In-Reply-To: References: <463DB32E.5070702@ecs.soton.ac.uk> Message-ID: <2e4301c79e3b$93775980$ba660c80$@swaney@fsl.com> Thanks! Steve Steve Swaney steve@fsl.com > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Ugo Bellavance > Sent: Thursday, May 24, 2007 3:12 PM > To: mailscanner@lists.mailscanner.info > Subject: Re: HOWTO: Use re2c and compiled SpamAssassin rules > > Done, using the original text from Julian: > > http://wiki.mailscanner.info/doku.php?id=documentation:anti_spam:spamas > sassin:pre_compiling_re2c > > Please edit the wiki entry if you feel it is not correct. > > Ugo > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Thu May 24 20:47:31 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 24 20:48:48 2007 Subject: yum based install In-Reply-To: <4655D66B.10800@elirion.net> References: <4655BF00.6030801@ecs.soton.ac.uk> <4655D2EC.6000804@ecs.soton.ac.uk> <4655D66B.10800@elirion.net> Message-ID: <4655EBD3.60303@ecs.soton.ac.uk> Skipped content of type multipart/mixed-------------- next part -------------- A non-text attachment was scrubbed... Name: PGP.sig Type: application/pgp-signature Size: 195 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070524/a78267d9/PGP.bin From hvdkooij at vanderkooij.org Thu May 24 21:14:31 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Thu May 24 21:15:06 2007 Subject: yum based install In-Reply-To: <4655EBD3.60303@ecs.soton.ac.uk> References: <4655BF00.6030801@ecs.soton.ac.uk> <4655D2EC.6000804@ecs.soton.ac.uk> <4655D66B.10800@elirion.net> <4655EBD3.60303@ecs.soton.ac.uk> Message-ID: On Thu, 24 May 2007, Julian Field wrote: > Try the attached RPM. I have attached the spec file too for you. > Am I going to have to update this for every single beta version? Or just > every stable version? Actually you do not have to update it untill the requirements change. It might be wise to update it for the major ones. But I would not put the beta versions in the repository. Anyone willing to do the beta's is propably willing to put in just little extra effort to fetch them manually. But once installed a `yum update` command will update mailscanner. Even if one removes the meta package afterwards. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From ugob at lubik.ca Thu May 24 21:27:16 2007 From: ugob at lubik.ca (Ugo Bellavance) Date: Thu May 24 21:27:52 2007 Subject: OT: Modified access and relay-domains file, still get 550 5.7.1 In-Reply-To: <97FD54B5E57A1842AA1A4B232E47611773EBA8@ati-ex-02.ati.local> References: <97FD54B5E57A1842AA1A4B232E47611773EBA8@ati-ex-02.ati.local> Message-ID: Chris W. Parker wrote: > Hello, > > I avoided sending this question here since it's off topic but I can't > find a solution after about a week so here goes. :) > > I'm trying to set up Swiftmailer (an SMTP library for PHP) to send email > from my web machine through my MS box and then on to wherever it's > going. > > I have a few remote users that send email through their cellular phones. > The way I got the phones to send successfully was by adding the > carrier's sending mail server to /etc/mail/relay-domains. Now that I'm > trying to relay mail from one of my own servers I thought I'd just add > that servers host name to relay-domains (and restart) and everything > would be fine. But alas... > > Here is what my log says: > > May 18 12:58:22 filter sendmail[16033]: l4IJwMD4016033: > ruleset=check_mail, arg1=, > relay=hachiroku.swatgear.com [67.17.248.232], reject=550 5.7.1 > ... Access denied > > I did some research (and asked a question in another forum) and thought > that maybe I needed to add the IP address of the sending server to > /etc/mail/access and then 'make'. Still no good. This command helps you see the content of access.db: strings /etc/mail/access You can pipe the output to grep or less if needed. From richard.siddall at elirion.net Thu May 24 21:27:36 2007 From: richard.siddall at elirion.net (Richard Siddall) Date: Thu May 24 21:28:30 2007 Subject: yum based install In-Reply-To: <4655EBD3.60303@ecs.soton.ac.uk> References: <4655BF00.6030801@ecs.soton.ac.uk> <4655D2EC.6000804@ecs.soton.ac.uk> <4655D66B.10800@elirion.net> <4655EBD3.60303@ecs.soton.ac.uk> Message-ID: <4655F538.6050407@elirion.net> Julian Field wrote: > Try the attached RPM. I have attached the spec file too for you. > Am I going to have to update this for every single beta version? Or just > every stable version? > Thanks. The VPS I tried it on doesn't have yum, but it looks like the RPM doesn't actually require mailscanner, despite being listed in the Requires section in the .spec file. The other problem is that four of the required Perl modules are provided by the main Perl RPM on that distro (CentOS 5); I think that will cause yum to complain. Not sure what that /tmp/motd is doing... As far as version numbers go, I don't know whether the meta-RPM should have the same number as the main MailScanner RPM and require at least that version of the main RPM, or whether you can just do a new version of the meta-RPM whenever the requirements change. There are probably pros and cons to both approaches. Regards, Richard Siddall From MailScanner at ecs.soton.ac.uk Thu May 24 21:37:22 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 24 21:38:21 2007 Subject: SpamAssassin 3.2.0 with 4.54.6 In-Reply-To: References: <4655C8AD.2060600@ecs.soton.ac.uk> Message-ID: <4655F782.40304@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Ugo Bellavance wrote: > Julian Field wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> I'll probably release 4.60 at the start of June, so you've only got a >> week to wait. I can't see any major problems of running 4.54.6 with >> SA 3.2.0. >> I'll test it out on a VM for you if you like. >> What VM would you prefer me to try it on? >> CentOS 4.4, CentOS 5.0 or Solaris 9? > > CentOS 4.4 please (.5 is released fyi). Works just fine. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGVfecEfZZRxQVtlQRAh/+AKDIsE6BgFDhZeeAjN3a0Ewuo0A08ACg0imo vXNBzr80ttfsJkdekg0dM2c= =lHCn -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Thu May 24 21:42:20 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 24 21:43:30 2007 Subject: yum based install In-Reply-To: <4655F538.6050407@elirion.net> References: <4655BF00.6030801@ecs.soton.ac.uk> <4655D2EC.6000804@ecs.soton.ac.uk> <4655D66B.10800@elirion.net> <4655EBD3.60303@ecs.soton.ac.uk> <4655F538.6050407@elirion.net> Message-ID: <4655F8AC.9090706@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Richard Siddall wrote: > Julian Field wrote: >> Try the attached RPM. I have attached the spec file too for you. >> Am I going to have to update this for every single beta version? Or >> just every stable version? >> > > Thanks. The VPS I tried it on doesn't have yum, but it looks like the > RPM doesn't actually require mailscanner, despite being listed in the > Requires section in the .spec file. The other problem is that four of > the required Perl modules are provided by the main Perl RPM on that > distro (CentOS 5); I think that will cause yum to complain. In which case you have a problem. CentOS 4's main Perl RPM will provide a different list of modules from that in CentOS 5. > > Not sure what that /tmp/motd is doing... It insisted on having a file to play with, so I gave it one. It wouldn't generate an RPM that didn't have a file in it. > > As far as version numbers go, I don't know whether the meta-RPM should > have the same number as the main MailScanner RPM and require at least > that version of the main RPM, or whether you can just do a new version > of the meta-RPM whenever the requirements change. There are probably > pros and cons to both approaches. > > Regards, > > Richard Siddall Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGVfjGEfZZRxQVtlQRAqM1AKCPdGYUs8HJCq1kTm2qo+vZTTHOigCfXtML pQwPO1IwAk/QhyUU3Da4Dp4= =ESUT -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ugob at lubik.ca Thu May 24 21:40:27 2007 From: ugob at lubik.ca (Ugo Bellavance) Date: Thu May 24 21:46:51 2007 Subject: SpamAssassin 3.2.0 with 4.54.6 In-Reply-To: <4655F782.40304@ecs.soton.ac.uk> References: <4655C8AD.2060600@ecs.soton.ac.uk> <4655F782.40304@ecs.soton.ac.uk> Message-ID: Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > Ugo Bellavance wrote: >> Julian Field wrote: >>> -----BEGIN PGP SIGNED MESSAGE----- >>> Hash: SHA1 >>> >>> I'll probably release 4.60 at the start of June, so you've only got a >>> week to wait. I can't see any major problems of running 4.54.6 with >>> SA 3.2.0. >>> I'll test it out on a VM for you if you like. >>> What VM would you prefer me to try it on? >>> CentOS 4.4, CentOS 5.0 or Solaris 9? >> CentOS 4.4 please (.5 is released fyi). > Works just fine. So the bug where it was considered as spam when a DNSBL timed out in SA doesn't affect 4.54.6? Ugo From richard.siddall at elirion.net Thu May 24 21:52:08 2007 From: richard.siddall at elirion.net (Richard Siddall) Date: Thu May 24 21:52:58 2007 Subject: yum based install In-Reply-To: <4655EBD3.60303@ecs.soton.ac.uk> References: <4655BF00.6030801@ecs.soton.ac.uk> <4655D2EC.6000804@ecs.soton.ac.uk> <4655D66B.10800@elirion.net> <4655EBD3.60303@ecs.soton.ac.uk> Message-ID: <4655FAF8.6010906@elirion.net> Julian Field wrote: > Try the attached RPM. I have attached the spec file too for you. > Am I going to have to update this for every single beta version? Or just > every stable version? > I installed yum on the VPS I had tried the RPM on, and followed the instructions at http://wiki.centos.org/Repositories/RPMForge for installing RPMForge as a yum repo. Then using Scott Silva's suggestion: yum localinstall --enablerepo=rpmforge \ mailscanner-requires-4.60.3-1.noarch.rpm I get > Error: Missing Dependency: perl-MIME-Base64 is needed by package mailscanner-requires > Error: Missing Dependency: perl-File-Temp is needed by package mailscanner-requires > Error: Missing Dependency: perl-Time-HiRes is needed by package mailscanner-requires MIME::Base64, File::Temp and Time::HiRes are provided by the core Perl installation, but not listed in the Provides list for that RPM. Not sure how to fix that so the RPM installs cleanly. And, as noted before, the RPM posted to the list doesn't require the actual MailScanner RPM, so yum doesn't figure out the RPM is not on any of the repos. Regards, Richard. From richard.siddall at elirion.net Thu May 24 22:04:24 2007 From: richard.siddall at elirion.net (Richard Siddall) Date: Thu May 24 22:05:40 2007 Subject: yum based install In-Reply-To: <4655F8AC.9090706@ecs.soton.ac.uk> References: <4655BF00.6030801@ecs.soton.ac.uk> <4655D2EC.6000804@ecs.soton.ac.uk> <4655D66B.10800@elirion.net> <4655EBD3.60303@ecs.soton.ac.uk> <4655F538.6050407@elirion.net> <4655F8AC.9090706@ecs.soton.ac.uk> Message-ID: <4655FDD8.3030303@elirion.net> Julian Field wrote: > In which case you have a problem. CentOS 4's main Perl RPM will provide > a different list of modules from that in CentOS 5. Unfortunately true. And the list will be different with older/other distros. The elegant way of fixing this would be to have an accurate list of provides for the core Perl RPM, but that's not going to happen. I haven't tested it with a repo that has those modules available. I suspect yum won't like overwriting part of the core Perl RPM. Regards, Richard. From cparker at swatgear.com Thu May 24 22:08:02 2007 From: cparker at swatgear.com (Chris W. Parker) Date: Thu May 24 22:08:05 2007 Subject: OT: Modified access and relay-domains file, still get 550 5.7.1 References: <97FD54B5E57A1842AA1A4B232E47611773EBA8@ati-ex-02.ati.local> <4655E82D.1010500@jfworks.net> Message-ID: <97FD54B5E57A1842AA1A4B232E47611773E3F5@ati-ex-02.ati.local> On Thursday, May 24, 2007 12:32 PM James <> said: > Can you post your /etc/mail/access file ? Here is part of it: # default entries # to change this default list see: /etc/cron.daily/get_adsmtp.pl localhost.localdomain RELAY localhost RELAY 127.0.0.1 RELAY hachiroku.swatgear.com RELAY 67.17.248.232 RELAY swatgear.com REJECT nonlethal.com REJECT aardvarktactical.com REJECT postmaster@filter.swatgear.com OK root@filter.swatgear.com OK The rest of it is all the email addresses in Active Directory built automatically, daily. To prevent dictionary attacks(?) from reaching the Exchange server. Internet -> MailScanner -> Exchange -> Internet Looks like hachiroku.swatgear.com is redundant because of swatgear.com but that wouldn't be causing the problem would it? Thanks, Chris. From prandal at herefordshire.gov.uk Thu May 24 22:12:53 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Thu May 24 22:13:04 2007 Subject: HOWTO: Use re2c and compiled SpamAssassin rules In-Reply-To: References: <463DB32E.5070702@ecs.soton.ac.uk> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA03CED8@HC-MBX02.herefordshire.gov.uk> The easier way is to use the rpmforge repo and yum install re2c Cheers, Phil -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Ugo Bellavance Sent: 24 May 2007 20:12 To: mailscanner@lists.mailscanner.info Subject: Re: HOWTO: Use re2c and compiled SpamAssassin rules Done, using the original text from Julian: http://wiki.mailscanner.info/doku.php?id=documentation:anti_spam:spamass assin:pre_compiling_re2c Please edit the wiki entry if you feel it is not correct. Ugo -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From hvdkooij at vanderkooij.org Thu May 24 22:33:26 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Thu May 24 22:34:11 2007 Subject: yum based install In-Reply-To: <4655FDD8.3030303@elirion.net> References: <4655BF00.6030801@ecs.soton.ac.uk> <4655D2EC.6000804@ecs.soton.ac.uk> <4655D66B.10800@elirion.net> <4655EBD3.60303@ecs.soton.ac.uk> <4655F538.6050407@elirion.net> <4655F8AC.9090706@ecs.soton.ac.uk> <4655FDD8.3030303@elirion.net> Message-ID: On Thu, 24 May 2007, Richard Siddall wrote: > Julian Field wrote: >> In which case you have a problem. CentOS 4's main Perl RPM will provide a >> different list of modules from that in CentOS 5. > > Unfortunately true. And the list will be different with older/other distros. > > The elegant way of fixing this would be to have an accurate list of provides > for the core Perl RPM, but that's not going to happen. > > I haven't tested it with a repo that has those modules available. I suspect > yum won't like overwriting part of the core Perl RPM. Ok. There are multiple ways to do this. If Julian is willing to build a repository with mailscanner and the meta package I would more or less think of .... Build a list of requirements per distro. I think there might be people around who might have made notes. Building the spec file per distro can be done by some smart usage of if then constructs that the spec files allow. I need to dig into this to provide exact details as it was a while ago I did a trick like this. If Julian is willing to allow rpmforge to package mailscanner to fit into rpmforge I know there are several peple trampling to go ahead with it. (Dag Wiers added perl-Filesys-Df to rpmforge very very shortly after I mentioned I needed to do this manually.) I think someone like Dag might also help you setup your own repository if you are addemend you want to keep the repository on mailscanner.info. This would allow people more familiar with building repositories do what they do well and allow Juliad to concentrate on MS itself. I for one do not care who runs the repository. But having the ability to install mailscanner with yum would be more then fun. It would greatly simplify the process of keeping up-to-date and duplicating MS installations. Well perhaps we should sleep on it for now. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From maillists at conactive.com Thu May 24 23:14:47 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Thu May 24 23:14:51 2007 Subject: OT: Modified access and relay-domains file, still get 550 5.7.1 In-Reply-To: <97FD54B5E57A1842AA1A4B232E47611773EBA8@ati-ex-02.ati.local> References: <97FD54B5E57A1842AA1A4B232E47611773EBA8@ati-ex-02.ati.local> Message-ID: Chris W. Parker wrote on Thu, 24 May 2007 12:11:03 -0700: > The way I got the phones to send successfully was by adding the > carrier's sending mail server to /etc/mail/relay-domains. most mobiles that can send email support SMTP AUTH, better use that. > I did some research (and asked a question in another forum) and thought > that maybe I needed to add the IP address of the sending server to > /etc/mail/access and then 'make'. Still no good. You either add it to relay-domains *or* to access.db. With access.db you have to recompile access, with relay-domains you don't. And the syntax is slightly different. I personally prefer to use relay-domains. It's somewhat "cleaner". I reserve access.db for reject/acceptance of mail. As you have proven to yourself that relay-domains *works* (with your mobile phone users) it's obvious that you did something wrong when adding this new entry. And I think it's this: > swatgear.com REJECT > ruleset=check_mail, arg1=, Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From cparker at swatgear.com Thu May 24 23:41:10 2007 From: cparker at swatgear.com (Chris W. Parker) Date: Thu May 24 23:41:13 2007 Subject: OT: Modified access and relay-domains file, still get 550 5.7.1 References: <97FD54B5E57A1842AA1A4B232E47611773EBA8@ati-ex-02.ati.local> Message-ID: <97FD54B5E57A1842AA1A4B232E47611773EBAA@ati-ex-02.ati.local> On Thursday, May 24, 2007 3:15 PM Kai Schaetzl <> said: > As you have proven to yourself that > relay-domains *works* (with your mobile phone users) it's obvious > that you did something wrong when adding this new entry. And I think > it's this: > >> swatgear.com REJECT >> ruleset=check_mail, arg1=, Turns out you're right. However, I'm a bit nervous about this change because I added it several years ago when I configured my first MS box. It had something to do with the way my mail is setup. We have three domains that, although they have different websites, they are all aliases of the main domain, swatgear.com, when it comes to email addresses. user@domainA.com = user@domainB.com = user@domainC.com All this is funneled through the MS box to my Exchange machine. Having said all that, email appears to be flowing normally even though I commented the swatgear.com REJECT line. I guess there's something to be said about my documentation practices but for now is there anything that you can think of that might have been messed up by me commenting that line in /etc/mail/access? I know it might be too difficult to tell. But any thoughts might be useful. Thanks for your help! Chris. From res at ausics.net Fri May 25 00:00:48 2007 From: res at ausics.net (Res) Date: Fri May 25 00:00:58 2007 Subject: OT: Modified access and relay-domains file, still get 550 5.7.1 In-Reply-To: <97FD54B5E57A1842AA1A4B232E47611773E3F5@ati-ex-02.ati.local> References: <97FD54B5E57A1842AA1A4B232E47611773EBA8@ati-ex-02.ati.local> <4655E82D.1010500@jfworks.net> <97FD54B5E57A1842AA1A4B232E47611773E3F5@ati-ex-02.ati.local> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Thu, 24 May 2007, Chris W. Parker wrote: > localhost.localdomain RELAY > localhost RELAY > 127.0.0.1 RELAY > hachiroku.swatgear.com RELAY > 67.17.248.232 RELAY > swatgear.com REJECT > nonlethal.com REJECT > aardvarktactical.com REJECT > postmaster@filter.swatgear.com OK > root@filter.swatgear.com OK Not commenting any further on your problem as it seems you have fixed it, however you need to make changes in this file, you should never ever ever use the format of: domain.name ACTION You should use the format of Connect:domain.name ACTION If you ommit a leading action, anyone who forges domain.name can relay, eg: connecting from, to blah@domain to@domain. Using Connect:domain.name ensures they can't forge, and if using email address use From: , To: etc... - -- Cheers Res -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGVhkjsWhAmSIQh7MRAqUtAJ48JB74MthWaiDjANuDvl5UeFbAIQCfTo/C LaBSK7edl7CDNSZEFqRTPik= =8cYR -----END PGP SIGNATURE----- From james at gray.net.au Thu May 24 10:02:09 2007 From: james at gray.net.au (James Gray) Date: Fri May 25 00:25:22 2007 Subject: Rules for my boss In-Reply-To: <46535513.6060200@ecs.soton.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk> <46533C5B.9040202@csags.com.mx> <46535513.6060200@ecs.soton.ac.uk> Message-ID: <6A345D5E-5225-4151-8727-0D9DF91CE33F@gray.net.au> On 23/05/2007, at 6:39 AM, Julian Field wrote: > Jorge Amador Arenas Quezada wrote: >> 1.- with mailscanner can make a rule to stop mails above 10Meg but >> only if is the number of recipients is more than 10 ? > You would have to do this with a little Custom Function. Attach it > to the Maximum Message Size, and make it check the size of the > array @{$message->{to}}. Start from the example Custom Function in / > usr/lib/MailScanner/MailScanner/CustomFunctions and work from > there. Should be pretty straightforward to write. > > For a donation, I'll even write it for you :-) Just out of curiosity, if the MTA splits a multi-recipient message into individual messages for delivery, does that that have any effect on the @{message->{to}} array? Or does MailScanner still get the full list of recipients? Cheers, James -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/pkcs7-signature Size: 2417 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070524/6472f0ff/smime.bin From maillists at conactive.com Fri May 25 00:31:17 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Fri May 25 00:31:20 2007 Subject: Enabling bounces In-Reply-To: <4655BDEB.7000401@ecs.soton.ac.uk> References: <46557C94.8010304@tradoc.fr> <4655A9DB.4050000@ecs.soton.ac.uk> <4655BDEB.7000401@ecs.soton.ac.uk> Message-ID: Julian Field wrote on Thu, 24 May 2007 17:31:39 +0100: > I seem to remember you can set the address to /^$/ and it will treat > that as an empty address. That is a regular expression that will match > an empty address. > So you can say > From: /^$/ and From: IP yes > in a ruleset and that should do what you want. I remember that a regexp for a null sender got mentioned looong ago on the list, but couldn't find any hint on the wiki. I was about to try //. I have it now like your example in a ruleset file for high spam actions. This works, Jules, thanks. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Fri May 25 00:31:17 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Fri May 25 00:31:22 2007 Subject: yum based install In-Reply-To: References: <4655BF00.6030801@ecs.soton.ac.uk> <4655D2EC.6000804@ecs.soton.ac.uk> Message-ID: Hugo van der Kooij wrote on Thu, 24 May 2007 21:06:32 +0200 (CEST): > If one installs perl from CPAN then one is unlikely to use yum just to > install mailscanner. But for those that perfer to let the package manager > take care of it the package. > > Dag also expressed his interrest in adding mailscanner to rpmforge if you > feel uncomfortable with maintaing a repository. General problem is that usually not all required Perl rpms are available from a "well known" repo. So, you are likely going to miss a few and have to install these manually (for instance by unpacking Jules' rpm), anyway. If Dag is going to make sure that all the necessary Perl rpms are also available this would be great and you could indeed use yum for MailScanner updates in the future. Quite welcome. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From maillists at conactive.com Fri May 25 00:31:17 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Fri May 25 00:31:25 2007 Subject: Enabling bounces In-Reply-To: References: <46557C94.8010304@tradoc.fr> Message-ID: Scott Silva wrote on Thu, 24 May 2007 09:54:22 -0700: > Maybe if you "volunteered" some time to help him fix his setup, it might go > easier for both of you. You get to stop the flood, and build some points with > a customer. Good idea, if I had any idea about managing Exchange :-( Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From cparker at swatgear.com Fri May 25 00:49:44 2007 From: cparker at swatgear.com (Chris W. Parker) Date: Fri May 25 00:49:47 2007 Subject: OT: Modified access and relay-domains file, still get 550 5.7.1 References: <97FD54B5E57A1842AA1A4B232E47611773EBA8@ati-ex-02.ati.local><4655E82D.1010500@jfworks.net><97FD54B5E57A1842AA1A4B232E47611773E3F5@ati-ex-02.ati.local> Message-ID: <97FD54B5E57A1842AA1A4B232E47611773E3FA@ati-ex-02.ati.local> On Thursday, May 24, 2007 4:01 PM Res <> said: > Not commenting any further on your problem as it seems you have fixed > it, however you need to make changes in this file, you should never > ever ever use the format of: domain.name ACTION > You should use the format of Connect:domain.name ACTION > If you ommit a leading action, anyone who forges domain.name can > relay, eg: connecting from, to blah@domain to@domain. Thanks for the heads up. From wilson.galafassi at gmail.com Fri May 25 01:47:52 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Fri May 25 01:48:43 2007 Subject: mcp patch for 3.002000 Message-ID: Hello. Can someone send me the MCP patch por spamassassin version 3.002000? Thanks Wilson From hvdkooij at vanderkooij.org Fri May 25 08:18:24 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Fri May 25 08:19:02 2007 Subject: yum based install In-Reply-To: References: <4655BF00.6030801@ecs.soton.ac.uk> <4655D2EC.6000804@ecs.soton.ac.uk> Message-ID: On Fri, 25 May 2007, Kai Schaetzl wrote: > Hugo van der Kooij wrote on Thu, 24 May 2007 21:06:32 +0200 (CEST): > >> If one installs perl from CPAN then one is unlikely to use yum just to >> install mailscanner. But for those that perfer to let the package manager >> take care of it the package. >> >> Dag also expressed his interrest in adding mailscanner to rpmforge if you >> feel uncomfortable with maintaing a repository. > > General problem is that usually not all required Perl rpms are available > from a "well known" repo. So, you are likely going to miss a few and have to > install these manually (for instance by unpacking Jules' rpm), anyway. > If Dag is going to make sure that all the necessary Perl rpms are also > available this would be great and you could indeed use yum for MailScanner > updates in the future. Quite welcome. I think you missed my message where I stated they are allready part of rpmforge. The last missing one was added yesterday. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From x72m35 at gmail.com Fri May 25 08:23:21 2007 From: x72m35 at gmail.com (Lasantha Marian) Date: Fri May 25 08:20:36 2007 Subject: mcp patch for 3.002000 In-Reply-To: References: Message-ID: <46568EE9.5010604@gmail.com> Dear Wilson, Curious to know. What are you planning to patch in MCP ? I have been experiencing some strange behaviors in my MCP setup (SA 3.2.0/MS 4.59.4), i.e. MCP setup works very fine when tested from command line so does SpamAssassin setup (from both ends; command line and from MailScanner), but would not work properly from MailScanner. It would happily scan but does not check against customized MCP rules. MCP rules are properly applied and correct scores are shown when run from command line. The very same MCP rules set works fine with earlier versions (SA 3.1.1/MS 4.53.8). Is it the same kind of problem that you are experiencing in MCP ? Thanks and regards, Lasantha. *-------- Original Message --------* *Subject: * mcp patch for 3.002000 *Date: * Fri, 25/May/2007 6:17:52 AM +0550 *From: * "Wilson A. Galafassi Jr." *To: * "'MailScanner discussion'" > Hello. > > Can someone send me the MCP patch por spamassassin version 3.002000? > > Thanks > Wilson > > > > > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070525/afb92bc1/attachment.html From martinh at solidstatelogic.com Fri May 25 09:45:31 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Fri May 25 09:45:39 2007 Subject: semi [OT] IEFT moves DK to draft standard Message-ID: http://news.bbc.co.uk/1/hi/technology/6688675.stm looks like the digital signature people's (Verisign etc) shares will be going up soon ;-) -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From maillists at conactive.com Fri May 25 10:31:34 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Fri May 25 10:31:39 2007 Subject: yum based install In-Reply-To: References: <4655BF00.6030801@ecs.soton.ac.uk> <4655D2EC.6000804@ecs.soton.ac.uk> Message-ID: Hugo van der Kooij wrote on Fri, 25 May 2007 09:18:24 +0200 (CEST): > I think you missed my message where I stated they are allready part of > rpmforge. Yes, I did. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From MailScanner at ecs.soton.ac.uk Fri May 25 11:00:38 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri May 25 11:03:50 2007 Subject: yum based install In-Reply-To: <4655FAF8.6010906@elirion.net> References: <4655BF00.6030801@ecs.soton.ac.uk> <4655D2EC.6000804@ecs.soton.ac.uk> <4655D66B.10800@elirion.net> <4655EBD3.60303@ecs.soton.ac.uk> <4655FAF8.6010906@elirion.net> Message-ID: <4656B3C6.6070209@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Richard Siddall wrote: > Julian Field wrote: >> Try the attached RPM. I have attached the spec file too for you. >> Am I going to have to update this for every single beta version? Or >> just every stable version? >> > > I installed yum on the VPS I had tried the RPM on, and followed the > instructions at http://wiki.centos.org/Repositories/RPMForge for > installing RPMForge as a yum repo. Then using Scott Silva's suggestion: > yum localinstall --enablerepo=rpmforge \ > mailscanner-requires-4.60.3-1.noarch.rpm > > I get > >> Error: Missing Dependency: perl-MIME-Base64 is needed by package >> mailscanner-requires >> Error: Missing Dependency: perl-File-Temp is needed by package >> mailscanner-requires >> Error: Missing Dependency: perl-Time-HiRes is needed by package >> mailscanner-requires > > MIME::Base64, File::Temp and Time::HiRes are provided by the core Perl > installation, but not listed in the Provides list for that RPM. > > Not sure how to fix that so the RPM installs cleanly. > > And, as noted before, the RPM posted to the list doesn't require the > actual MailScanner RPM, so yum doesn't figure out the RPM is not on > any of the repos. Yes it does, or it certainly should do. Look at the spec file which I also posted. > > Regards, > > Richard. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: UTF-8 wj8DBQFGVrRdEfZZRxQVtlQRAiChAJsHET/SOHED72UjfESbb8YwdyhVxQCfRpoe tGPr9EQ2Yo0zmnCm6PsaC+4= =0k50 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Fri May 25 10:58:40 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri May 25 11:03:54 2007 Subject: SpamAssassin 3.2.0 with 4.54.6 In-Reply-To: References: <4655C8AD.2060600@ecs.soton.ac.uk> <4655F782.40304@ecs.soton.ac.uk> Message-ID: <4656B350.1010908@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 If it's a bug in SA, then that bug will be present. I haven't changed the SA support in a stable release in a long time. Ugo Bellavance wrote: > Julian Field wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> >> >> Ugo Bellavance wrote: >>> Julian Field wrote: >>>> -----BEGIN PGP SIGNED MESSAGE----- >>>> Hash: SHA1 >>>> >>>> I'll probably release 4.60 at the start of June, so you've only got >>>> a week to wait. I can't see any major problems of running 4.54.6 >>>> with SA 3.2.0. >>>> I'll test it out on a VM for you if you like. >>>> What VM would you prefer me to try it on? >>>> CentOS 4.4, CentOS 5.0 or Solaris 9? >>> CentOS 4.4 please (.5 is released fyi). >> Works just fine. > > So the bug where it was considered as spam when a DNSBL timed out in > SA doesn't affect 4.54.6? > > Ugo > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGVrRcEfZZRxQVtlQRAtJ/AKC/AREsXiYxDgySaCUYOqLEO8ULcACfZSUA EwZ4AKbV2D3wmiTVZKRlV+c= =3c8B -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From rabellino at di.unito.it Fri May 25 11:04:59 2007 From: rabellino at di.unito.it (Sergio Rabellino) Date: Fri May 25 11:05:17 2007 Subject: semi [OT] IEFT moves DK to draft standard References: Message-ID: <002001c79eb4$2a395210$6389a8c0@di.unito.it> For me it sounds like the Email Big Brother... Who will be the worldwide "honest" Authority for the email service ? Verisign ? maybe lesser OT than you think. Bye. ----- Original Message ----- From: "Martin.Hepworth" To: "MailScanner discussion" Sent: Friday, May 25, 2007 10:45 AM Subject: semi [OT] IEFT moves DK to draft standard http://news.bbc.co.uk/1/hi/technology/6688675.stm looks like the digital signature people's (Verisign etc) shares will be going up soon ;-) -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From martinh at solidstatelogic.com Fri May 25 11:16:36 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Fri May 25 11:16:41 2007 Subject: semi [OT] IEFT moves DK to draft standard In-Reply-To: <002001c79eb4$2a395210$6389a8c0@di.unito.it> Message-ID: <562461be9f4f23459f6b718bb29ecc18@solidstatelogic.com> Sergio The way it works it you place your public key in your DNS records, so no overall 'trust' path. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Sergio Rabellino > Sent: 25 May 2007 11:05 > To: MailScanner discussion > Subject: Re: semi [OT] IEFT moves DK to draft standard > > For me it sounds like the Email Big Brother... > Who will be the worldwide "honest" Authority for the email service ? > Verisign ? > > maybe lesser OT than you think. > Bye. > ----- Original Message ----- > From: "Martin.Hepworth" > To: "MailScanner discussion" > Sent: Friday, May 25, 2007 10:45 AM > Subject: semi [OT] IEFT moves DK to draft standard > > > > http://news.bbc.co.uk/1/hi/technology/6688675.stm > > looks like the digital signature people's (Verisign etc) shares will be > going up soon ;-) > > > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From MailScanner at ecs.soton.ac.uk Fri May 25 11:17:50 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri May 25 11:18:48 2007 Subject: Rules for my boss In-Reply-To: <6A345D5E-5225-4151-8727-0D9DF91CE33F@gray.net.au> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk> <46533C5B.9040202@csags.com.mx> <46535513.6060200@ecs.soton.ac.uk> <6A345D5E-5225-4151-8727-0D9DF91CE33F@gray.net.au> Message-ID: <4656B7CE.7070001@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 James Gray wrote: > On 23/05/2007, at 6:39 AM, Julian Field wrote: >> Jorge Amador Arenas Quezada wrote: >>> 1.- with mailscanner can make a rule to stop mails above 10Meg but >>> only if is the number of recipients is more than 10 ? > >> You would have to do this with a little Custom Function. Attach it to >> the Maximum Message Size, and make it check the size of the array >> @{$message->{to}}. Start from the example Custom Function in >> /usr/lib/MailScanner/MailScanner/CustomFunctions and work from there. >> Should be pretty straightforward to write. >> >> For a donation, I'll even write it for you :-) > > Just out of curiosity, if the MTA splits a multi-recipient message > into individual messages for delivery, does that that have any effect > on the @{message->{to}} array? Or does MailScanner still get the full > list of recipients? It does this splitting after MailScanner has done all its work. So it wouldn't have any effect on the to array as it hasn't happened yet. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGVrfVEfZZRxQVtlQRAsvHAJ9xOOwbZMfCNOgRxfTlEQuvj+TNWgCcDwJy BzEq+25iQ6jKlXLVDACkI4I= =hDY0 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Fri May 25 11:14:41 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri May 25 11:18:51 2007 Subject: HOWTO: Use re2c and compiled SpamAssassin rules In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA03CED8@HC-MBX02.herefordshire.gov.uk> References: <463DB32E.5070702@ecs.soton.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBA03CED8@HC-MBX02.herefordshire.gov.uk> Message-ID: <4656B711.5070005@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Please remember that not everyone runs yum. It is another possibility, but not necessarily always "the easier way". Randal, Phil wrote: > The easier way is to use the rpmforge repo and > > yum install re2c > > Cheers, > > Phil > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Ugo > Bellavance > Sent: 24 May 2007 20:12 > To: mailscanner@lists.mailscanner.info > Subject: Re: HOWTO: Use re2c and compiled SpamAssassin rules > > Done, using the original text from Julian: > > http://wiki.mailscanner.info/doku.php?id=documentation:anti_spam:spamass > assin:pre_compiling_re2c > > Please edit the wiki entry if you feel it is not correct. > > Ugo > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGVrfUEfZZRxQVtlQRAmn7AKCGlTAYnV9tLh7qHhWiBw8YlkU0wwCdEtMV vQWmMsfapS0wl//5bE/huBk= =xIXA -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From maillists at conactive.com Fri May 25 11:31:15 2007 From: maillists at conactive.com (Kai Schaetzl) Date: Fri May 25 11:31:18 2007 Subject: OT: Modified access and relay-domains file, still get 550 5.7.1 In-Reply-To: <97FD54B5E57A1842AA1A4B232E47611773EBAA@ati-ex-02.ati.local> References: <97FD54B5E57A1842AA1A4B232E47611773EBA8@ati-ex-02.ati.local> <97FD54B5E57A1842AA1A4B232E47611773EBAA@ati-ex-02.ati.local> Message-ID: Chris W. Parker wrote on Thu, 24 May 2007 15:41:10 -0700: > Having said all that, email appears to be flowing normally even though I > commented the swatgear.com REJECT line. I guess there's something to be > said about my documentation practices but for now is there anything that > you can think of that might have been messed up by me commenting that > line in /etc/mail/access? Looking a second time at your list I now understand why you did that. You want to reject mail to non-existing users @swatgear.com and REJECT all mail to it and then build an OK list from AD. I didn't really notice that part of your message the first time. *Now* there's obviously a chance that you get mail for existing local users that should not get mail as the general blockage is gone. Probably there was no OK for swiftmail@swatgear.com and so it got rejected at the check_mail (from) stage. I'm not sure if the way you do it is optimal and works in all cases. I may be wrong but I believe that using a construct like somedomain.com REJECT someaddress@swatgear.com OK will likely *reject* mail from somedomain.com to someaddress@swatgear.com as there is no way for sendmail to know which of the two should have priority. Using swatgear.com REJECT someaddress@swatgear.com OK as you do should encounter the same problem. It may work because usually the swatgear.com address will be in the rcpt to *only* and sendmail then overrides the REJECT with the OK. But you were getting *mail from* swiftmail@swatgear.com to swatgear.com and then the priority problem hits. There are extensions to the access.db like "Spam: Friend" that assure that mail gets always delivered. Kai -- Kai Sch?tzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com From rabellino at di.unito.it Fri May 25 11:48:34 2007 From: rabellino at di.unito.it (Sergio Rabellino) Date: Fri May 25 11:48:51 2007 Subject: semi [OT] IEFT moves DK to draft standard References: <562461be9f4f23459f6b718bb29ecc18@solidstatelogic.com> Message-ID: <000b01c79eba$412ad420$6389a8c0@di.unito.it> Probably I misunderstand/missing some technical details, but placing a pubkey anywhere isn't a trust model, the MTA's will trust the DNS ? They're only moving the problem from MTA trust to DNS trust. Maybe it's the solution or maybe not. sorry for the pingpong. ----- Original Message ----- From: "Martin.Hepworth" To: "MailScanner discussion" Sent: Friday, May 25, 2007 12:16 PM Subject: RE: semi [OT] IEFT moves DK to draft standard Sergio The way it works it you place your public key in your DNS records, so no overall 'trust' path. -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Sergio Rabellino > Sent: 25 May 2007 11:05 > To: MailScanner discussion > Subject: Re: semi [OT] IEFT moves DK to draft standard > > For me it sounds like the Email Big Brother... > Who will be the worldwide "honest" Authority for the email service ? > Verisign ? > > maybe lesser OT than you think. > Bye. > ----- Original Message ----- > From: "Martin.Hepworth" > To: "MailScanner discussion" > Sent: Friday, May 25, 2007 10:45 AM > Subject: semi [OT] IEFT moves DK to draft standard > > > > http://news.bbc.co.uk/1/hi/technology/6688675.stm > > looks like the digital signature people's (Verisign etc) shares will be > going up soon ;-) > > > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > > > > > > ********************************************************************** > Confidentiality : This e-mail and any attachments are intended for the > addressee only and may be confidential. If they come to you in error > you must take no action based on them, nor must you copy or show them > to anyone. Please advise the sender by replying to this e-mail > immediately and then delete the original from your computer. > > Opinion : Any opinions expressed in this e-mail are entirely those of > the author and unless specifically stated to the contrary, are not > necessarily those of the author's employer. > > Security Warning : Internet e-mail is not necessarily a secure > communications medium and can be subject to data corruption. We advise > that you consider this fact when e-mailing us. > > Viruses : We have taken steps to ensure that this e-mail and any > attachments are free from known viruses but in keeping with good > computing practice, you should ensure that they are virus free. > > Red Lion 49 Ltd T/A Solid State Logic > Registered as a limited company in England and Wales > (Company No:5362730) > Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, > United Kingdom > ********************************************************************** > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From ms-list at alexb.ch Fri May 25 11:55:21 2007 From: ms-list at alexb.ch (Alex Broens) Date: Fri May 25 11:55:32 2007 Subject: semi [OT] IEFT moves DK to draft standard In-Reply-To: References: Message-ID: <4656C099.9070703@alexb.ch> On 5/25/2007 10:45 AM, Martin.Hepworth wrote: > http://news.bbc.co.uk/1/hi/technology/6688675.stm > > looks like the digital signature people's (Verisign etc) shares will be > going up soon ;-) ????? You create your own signature and publish it via DNS. Where does something like Verisign come it? Alex From hvdkooij at vanderkooij.org Fri May 25 11:56:37 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Fri May 25 11:57:38 2007 Subject: semi [OT] IEFT moves DK to draft standard In-Reply-To: <002001c79eb4$2a395210$6389a8c0@di.unito.it> References: <002001c79eb4$2a395210$6389a8c0@di.unito.it> Message-ID: On Fri, 25 May 2007, Sergio Rabellino wrote: > For me it sounds like the Email Big Brother... > Who will be the worldwide "honest" Authority for the email service ? Verisign > ? I will not do business with Verisign. Without my concent my address details ended up on places I would not expect them. Lucky for me I did recognize the typo in the address details I had with Verisign. I use typos a lot to track my details. There was not enough proof to make a case but to me Verisign in on the untrusted list. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From res at ausics.net Fri May 25 11:58:10 2007 From: res at ausics.net (Res) Date: Fri May 25 11:58:42 2007 Subject: semi [OT] IEFT moves DK to draft standard In-Reply-To: <002001c79eb4$2a395210$6389a8c0@di.unito.it> References: <002001c79eb4$2a395210$6389a8c0@di.unito.it> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Fri, 25 May 2007, Sergio Rabellino wrote: > For me it sounds like the Email Big Brother... > Who will be the worldwide "honest" Authority for the email service ? Verisign veri$ign? god help us all! I'd never trust those bastards ever, the way they always tried to f#!K over many and extort the rest in recent years says it all. - -- Cheers Res -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGVsFGsWhAmSIQh7MRAlVTAJ4hkVeeE6LAi4N2uNg1+MiOpx/pmQCfUaRk 1yvOzOUPl9gyro2GIV/i1nI= =jCR2 -----END PGP SIGNATURE----- From martinh at solidstatelogic.com Fri May 25 12:01:19 2007 From: martinh at solidstatelogic.com (Martin.Hepworth) Date: Fri May 25 12:01:48 2007 Subject: semi [OT] IEFT moves DK to draft standard In-Reply-To: <4656C099.9070703@alexb.ch> Message-ID: <3abb4d8b6610964cad498e381c76e521@solidstatelogic.com> Someone's got to sign the keypair. Veri$ign/geotrust etc etc -- Martin Hepworth Snr Systems Administrator Solid State Logic Tel: +44 (0)1865 842300 > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Alex Broens > Sent: 25 May 2007 11:55 > To: MailScanner discussion > Subject: Re: semi [OT] IEFT moves DK to draft standard > > On 5/25/2007 10:45 AM, Martin.Hepworth wrote: > > http://news.bbc.co.uk/1/hi/technology/6688675.stm > > > > looks like the digital signature people's (Verisign etc) shares will be > > going up soon ;-) > > ????? > > You create your own signature and publish it via DNS. > > Where does something like Verisign come it? > > Alex > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ********************************************************************** Confidentiality : This e-mail and any attachments are intended for the addressee only and may be confidential. If they come to you in error you must take no action based on them, nor must you copy or show them to anyone. Please advise the sender by replying to this e-mail immediately and then delete the original from your computer. Opinion : Any opinions expressed in this e-mail are entirely those of the author and unless specifically stated to the contrary, are not necessarily those of the author's employer. Security Warning : Internet e-mail is not necessarily a secure communications medium and can be subject to data corruption. We advise that you consider this fact when e-mailing us. Viruses : We have taken steps to ensure that this e-mail and any attachments are free from known viruses but in keeping with good computing practice, you should ensure that they are virus free. Red Lion 49 Ltd T/A Solid State Logic Registered as a limited company in England and Wales (Company No:5362730) Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, United Kingdom ********************************************************************** From res at ausics.net Fri May 25 12:05:08 2007 From: res at ausics.net (Res) Date: Fri May 25 12:05:14 2007 Subject: semi [OT] IEFT moves DK to draft standard In-Reply-To: References: <002001c79eb4$2a395210$6389a8c0@di.unito.it> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Fri, 25 May 2007, Hugo van der Kooij wrote: > I will not do business with Verisign. Without my concent my address details > ended up on places I would not expect them. Lucky for me I did recognize the > typo in the address details I had with Verisign. and they are assholes who tried to lock domains long BEFORE expiry, also refused to change contact details when approaching expiry and promise it would be changed WHEN WE RENEWED WITH THEM, (knowing we needed them changed to move the domains AWAy from them) f'ing a$$wipes, OK this was 6/7 years ago, however I seriously doubt those pricks have changed. I have always publicly warned people never to deal with those $#$@#$#'s at verisign and I will continue to do so until the very day I die! - -- Cheers Res -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGVsLmsWhAmSIQh7MRAhOvAJ0bG0C8A/lAVAUbkfZycuYhc3MZPwCeKAuK 6Ewq9pHxROqPyxD+6auhO3c= =wLES -----END PGP SIGNATURE----- From dhawal at netmagicsolutions.com Fri May 25 12:18:08 2007 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Fri May 25 12:18:27 2007 Subject: semi [OT] IEFT moves DK to draft standard In-Reply-To: <3abb4d8b6610964cad498e381c76e521@solidstatelogic.com> References: <3abb4d8b6610964cad498e381c76e521@solidstatelogic.com> Message-ID: <4656C5F0.7040209@netmagicsolutions.com> Martin.Hepworth wrote: > Someone's got to sign the keypair. Veri$ign/geotrust etc etc From what i understand you make your own public/private keys and use them to: a. Publish the public key as a TXT record in your zone file for receiving MTAs to verify via a lookup. b. Sign messages on your outgoing mail server with your private key. See http://www.dkim.org/info/dkim-faq.html > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Alex Broens >> Sent: 25 May 2007 11:55 >> To: MailScanner discussion >> Subject: Re: semi [OT] IEFT moves DK to draft standard >> >> On 5/25/2007 10:45 AM, Martin.Hepworth wrote: >>> http://news.bbc.co.uk/1/hi/technology/6688675.stm >>> >>> looks like the digital signature people's (Verisign etc) shares will > be >>> going up soon ;-) >> ????? >> >> You create your own signature and publish it via DNS. >> >> Where does something like Verisign come it? >> >> Alex From john at tradoc.fr Fri May 25 12:18:45 2007 From: john at tradoc.fr (John Wilcock) Date: Fri May 25 12:18:49 2007 Subject: HOWTO: Use re2c and compiled SpamAssassin rules In-Reply-To: <4656B711.5070005@ecs.soton.ac.uk> References: <463DB32E.5070702@ecs.soton.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBA03CED8@HC-MBX02.herefordshire.gov.uk> <4656B711.5070005@ecs.soton.ac.uk> Message-ID: <4656C615.5030206@tradoc.fr> Julian Field wrote: > Please remember that not everyone runs yum. It is another possibility, > but not necessarily always "the easier way". For that matter, not everyone uses redhat-like systems that support yum. I'm a gentoo convert, for example, and I'm using the latest MailScanner beta installed via a homebrew ebuild (adapted from the slightly outdated one in sunrise). All the dependencies are available as gentoo ebuilds except for Filesys::Df which needs to be installed via g-cpan. John. -- -- Over 3000 webcams from ski resorts around the world - www.snoweye.com -- Translate your technical documents and web pages - www.tradoc.fr From res at ausics.net Fri May 25 12:23:17 2007 From: res at ausics.net (Res) Date: Fri May 25 12:23:25 2007 Subject: HOWTO: Use re2c and compiled SpamAssassin rules In-Reply-To: <4656C615.5030206@tradoc.fr> References: <463DB32E.5070702@ecs.soton.ac.uk> <7EF0EE5CB3B263488C8C18823239BEBA03CED8@HC-MBX02.herefordshire.gov.uk> <4656B711.5070005@ecs.soton.ac.uk> <4656C615.5030206@tradoc.fr> Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Fri, 25 May 2007, John Wilcock wrote: > Julian Field wrote: >> Please remember that not everyone runs yum. It is another possibility, but >> not necessarily always "the easier way". > > For that matter, not everyone uses redhat-like systems that support yum. > > I'm a gentoo convert, for example, and I'm using the latest MailScanner beta > installed via a homebrew ebuild (adapted from the slightly outdated one in > sunrise). All the dependencies are available as gentoo ebuilds except for > Filesys::Df which needs to be installed via g-cpan. Just use the tarball, its simple and easy to upgrade, all being on in place under /opt also makes it all nice and tidy, and 2 seconds to revert to an old version if an upgrade goes pear shaped. - -- Cheers Res -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGVscosWhAmSIQh7MRAnaKAJwNdq8vvnyJ2elFsy0rwnH9Ws5bYgCgtSGY BR7sAm8EYOro81vDI5aqTnc= =v4/t -----END PGP SIGNATURE----- From bilias at edu.physics.uoc.gr Fri May 25 12:29:20 2007 From: bilias at edu.physics.uoc.gr (Kapetanakis Giannis) Date: Fri May 25 12:29:35 2007 Subject: semi [OT] IEFT moves DK to draft standard In-Reply-To: <3abb4d8b6610964cad498e381c76e521@solidstatelogic.com> References: <3abb4d8b6610964cad498e381c76e521@solidstatelogic.com> Message-ID: On Fri, 25 May 2007, Martin.Hepworth wrote: > Someone's got to sign the keypair. Veri$ign/geotrust etc etc > > -- > Martin Hepworth > Snr Systems Administrator > Solid State Logic > Tel: +44 (0)1865 842300 According to my limited knowledge on the subject you present a self signed public key in your DNS zone files. Giannis ps. Trust is based on the authenticity of the dns records From richard.siddall at elirion.net Fri May 25 12:41:07 2007 From: richard.siddall at elirion.net (Richard Siddall) Date: Fri May 25 12:42:18 2007 Subject: yum based install In-Reply-To: <4656B3C6.6070209@ecs.soton.ac.uk> References: <4655BF00.6030801@ecs.soton.ac.uk> <4655D2EC.6000804@ecs.soton.ac.uk> <4655D66B.10800@elirion.net> <4655EBD3.60303@ecs.soton.ac.uk> <4655FAF8.6010906@elirion.net> <4656B3C6.6070209@ecs.soton.ac.uk> Message-ID: <4656CB53.10404@elirion.net> Julian Field wrote: >> And, as noted before, the RPM posted to the list doesn't require the >> actual MailScanner RPM, so yum doesn't figure out the RPM is not on >> any of the repos. > Yes it does, or it certainly should do. Look at the spec file which I > also posted. It certainly should do, but it doesn't: > [root@shearwater ~]# rpm -qp --requires mailscanner-requires-4.60.3-1.noarch.rpm > perl >= 5.6.1 > perl-Archive-Zip > perl-Compress-Zlib > perl-Convert-BinHex > perl-Convert-TNEF > perl-DBD-SQLite > perl-DBI > perl-File-Temp > perl-Filesys-Df > perl-Getopt-Long > perl-HTML-Parser > perl-HTML-Tagset > perl-IO-stringy > perl-MIME-Base64 > perl-MIME-tools >= 5.412 > perl-MailTools > perl-Net-CIDR > perl-Net-IP > perl-Sys-Hostname-Long > perl-Sys-Syslog > perl-Time-HiRes > perl-TimeDate > rpmlib(CompressedFileNames) <= 3.0.4-1 > rpmlib(PayloadFilesHavePrefix) <= 4.0-1 > tnef >= 1.1.1 > [root@shearwater ~]# I haven't tried rebuilding from the .spec file to see if I get different results. Regards, Richard. From richard.siddall at elirion.net Fri May 25 12:51:26 2007 From: richard.siddall at elirion.net (Richard Siddall) Date: Fri May 25 12:53:22 2007 Subject: yum based install In-Reply-To: <4656CB53.10404@elirion.net> References: <4655BF00.6030801@ecs.soton.ac.uk> <4655D2EC.6000804@ecs.soton.ac.uk> <4655D66B.10800@elirion.net> <4655EBD3.60303@ecs.soton.ac.uk> <4655FAF8.6010906@elirion.net> <4656B3C6.6070209@ecs.soton.ac.uk> <4656CB53.10404@elirion.net> Message-ID: <4656CDBE.6090404@elirion.net> Richard Siddall wrote: > I haven't tried rebuilding from the .spec file to see if I get different > results. > Just tried that, and after changing the Copyright tag to License, it gives the right set of dependencies: [root@shearwater ~]# rpm -qp --requires /usr/src/redhat/RPMS/noarch/mailscanner-requires-4.60.1-1.noarch.rpm mailscanner >= 4.60.1 perl >= 5.6.1 perl-Archive-Zip perl-Compress-Zlib perl-Convert-BinHex perl-Convert-TNEF perl-DBD-SQLite perl-DBI perl-File-Temp perl-Filesys-Df perl-Getopt-Long perl-HTML-Parser perl-HTML-Tagset perl-IO-stringy perl-MIME-Base64 perl-MIME-tools >= 5.412 perl-MailTools perl-Net-CIDR perl-Net-IP perl-Sys-Hostname-Long perl-Sys-Syslog perl-Time-HiRes perl-TimeDate rpmlib(CompressedFileNames) <= 3.0.4-1 rpmlib(PayloadFilesHavePrefix) <= 4.0-1 tnef >= 1.1.1 [root@shearwater ~]# So, it looks like a problem with the version of RPM Jules is using. Regards, Richard. From jaearick at colby.edu Fri May 25 13:25:29 2007 From: jaearick at colby.edu (Jeff A. Earickson) Date: Fri May 25 13:25:37 2007 Subject: semi [OT] IEFT moves DK to draft standard In-Reply-To: References: <002001c79eb4$2a395210$6389a8c0@di.unito.it> Message-ID: On Fri, 25 May 2007, Hugo van der Kooij wrote: > Date: Fri, 25 May 2007 12:56:37 +0200 (CEST) > From: Hugo van der Kooij > Reply-To: MailScanner discussion > To: MailScanner discussion > Subject: Re: semi [OT] IEFT moves DK to draft standard > > On Fri, 25 May 2007, Sergio Rabellino wrote: > >> For me it sounds like the Email Big Brother... >> Who will be the worldwide "honest" Authority for the email service ? >> Verisign ? > > I will not do business with Verisign. Without my concent my address details > ended up on places I would not expect them. Lucky for me I did recognize the > typo in the address details I had with Verisign. > > I use typos a lot to track my details. > > There was not enough proof to make a case but to me Verisign in on the > untrusted list. > > Hugo. I also will not do business with Verisign. Their attempted hijack of all unclaimed domains via DNS in September 2003 and the grief they caused every email sysadmin on the planet remains fresh in my memory. I moved all of my SSL cert business to Entrust after that disaster. Res described them very well in his rant. BTW, I have not installed 4.60.3 yet. Screwing up our mail system right before commencement would be an RGE (Resume Generating Event). I'll get to it next week. Jeff Earickson Colby College From glenn.steen at gmail.com Fri May 25 14:31:45 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri May 25 14:31:50 2007 Subject: PF2.4 support - was Re: feature request: compress attachments In-Reply-To: <223f97700705240724m29f91775n552eb10ca0363e8d@mail.gmail.com> References: <106f047568251e44a37a9ca53d199b41@solidstatelogic.com> <46541427.2060606@ecs.soton.ac.uk> <223f97700705230335q1bc9f308tefd25a7c129505a@mail.gmail.com> <4654530A.2020503@ecs.soton.ac.uk> <223f97700705240215t192baa3ew7390643786dfd60c@mail.gmail.com> <223f97700705240220w78019c7dq9f927ea569f5069a@mail.gmail.com> <465591DA.10207@ecs.soton.ac.uk> <223f97700705240724m29f91775n552eb10ca0363e8d@mail.gmail.com> Message-ID: <223f97700705250631r1635a36aw1c5ca4c6a247dc14@mail.gmail.com> On 24/05/07, Glenn Steen wrote: > On 24/05/07, Julian Field wrote: > > -----BEGIN PGP SIGNED MESSAGE----- > > Hash: SHA1 > > > > Glen, > > > > My brain is not well enough to get my head round this stuff. It's all > > washing in through my eyes and straight out of my ears unfortunately. > > > > Is there any chance you could find time to implement the 2.4 support as > > you say you already have an idea how to do it anyway please? > > > > Once you're convinced it works, I'll then just adopt your patches. > > > > Sorry, I'm just not up to doing this myself, but would very much like to > > get full PF support in as soon as possible. > > > > If you can generate a few test messages for me, I'll then test your code > > and hopefully start to gain a bit of insight into how it works. > > > > Many thanks, > > Jules. > > I'll see what I can do... The problem is testing it all... Very timeconsuming. > I found the first draft for 2.4 support, but ... it needs testing... > I'll see what I can do, perhaps this weekend. > Ok, found some time right now... I've tested this mainly with handcrafted queue files, and in my production (which does not use a body editing/replacing milter...), without any discernible bad effect. There is a price though, since we exchange a nice/fast seek with a semi-convoluted loop. The code is ugly, and could well bear with some constructive critisism... and if some sharp (postmix-friendly:-) minds like Dhawal, Drew, Joshua, Phil (Uxbod) or Gerhard could find some time to test/read/verify both the thinking and code, that would be much appreciated. Even some non-postfix-liking minds would be very much appreciated (That means you, oh evil bunny;-). It should be good enough for a beta:-). So if you feel up to it, and don't think it too massive a thing Jules...:-) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se -------------- next part -------------- A non-text attachment was scrubbed... Name: Postfix.pm.prec_final.patch Type: application/octet-stream Size: 11657 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070525/009abf0d/Postfix.pm.prec_final.obj -------------- next part -------------- A non-text attachment was scrubbed... Name: PFDiskStore.pm.prec_final.patch Type: application/octet-stream Size: 800 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070525/009abf0d/PFDiskStore.pm.prec_final.obj From glenn.steen at gmail.com Fri May 25 14:46:50 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri May 25 14:46:54 2007 Subject: Rules for my boss In-Reply-To: <4656B7CE.7070001@ecs.soton.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk> <46533C5B.9040202@csags.com.mx> <46535513.6060200@ecs.soton.ac.uk> <6A345D5E-5225-4151-8727-0D9DF91CE33F@gray.net.au> <4656B7CE.7070001@ecs.soton.ac.uk> Message-ID: <223f97700705250646j62702d39v56a80515b608c906@mail.gmail.com> On 25/05/07, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > > > James Gray wrote: > > On 23/05/2007, at 6:39 AM, Julian Field wrote: > >> Jorge Amador Arenas Quezada wrote: > >>> 1.- with mailscanner can make a rule to stop mails above 10Meg but > >>> only if is the number of recipients is more than 10 ? > > > >> You would have to do this with a little Custom Function. Attach it to > >> the Maximum Message Size, and make it check the size of the array > >> @{$message->{to}}. Start from the example Custom Function in > >> /usr/lib/MailScanner/MailScanner/CustomFunctions and work from there. > >> Should be pretty straightforward to write. > >> > >> For a donation, I'll even write it for you :-) > > > > Just out of curiosity, if the MTA splits a multi-recipient message > > into individual messages for delivery, does that that have any effect > > on the @{message->{to}} array? Or does MailScanner still get the full > > list of recipients? > It does this splitting after MailScanner has done all its work. So it > wouldn't have any effect on the to array as it hasn't happened yet. > > Jules > If one uses Postfix and _one_ instance to do this, why yes. But if one has done something like what I documented in the wiki... then MailScanner would see one message/recipient -> Only one recipient in the array;). How Rendmaul ... er, Sendmail would handle this, I have no clue. -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From MailScanner at ecs.soton.ac.uk Fri May 25 14:55:15 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri May 25 14:56:14 2007 Subject: PF2.4 support - was Re: feature request: compress attachments In-Reply-To: <223f97700705250631r1635a36aw1c5ca4c6a247dc14@mail.gmail.com> References: <106f047568251e44a37a9ca53d199b41@solidstatelogic.com> <46541427.2060606@ecs.soton.ac.uk> <223f97700705230335q1bc9f308tefd25a7c129505a@mail.gmail.com> <4654530A.2020503@ecs.soton.ac.uk> <223f97700705240215t192baa3ew7390643786dfd60c@mail.gmail.com> <223f97700705240220w78019c7dq9f927ea569f5069a@mail.gmail.com> <465591DA.10207@ecs.soton.ac.uk> <223f97700705240724m29f91775n552eb10ca0363e8d@mail.gmail.com> <223f97700705250631r1635a36aw1c5ca4c6a247dc14@mail.gmail.com> Message-ID: <4656EAC3.2070204@ecs.soton.ac.uk> Glenn Steen wrote: > On 24/05/07, Glenn Steen wrote: >> On 24/05/07, Julian Field wrote: >> > -----BEGIN PGP SIGNED MESSAGE----- >> > Hash: SHA1 >> > >> > Glen, >> > >> > My brain is not well enough to get my head round this stuff. It's all >> > washing in through my eyes and straight out of my ears unfortunately. >> > >> > Is there any chance you could find time to implement the 2.4 >> support as >> > you say you already have an idea how to do it anyway please? >> > >> > Once you're convinced it works, I'll then just adopt your patches. >> > >> > Sorry, I'm just not up to doing this myself, but would very much >> like to >> > get full PF support in as soon as possible. >> > >> > If you can generate a few test messages for me, I'll then test your >> code >> > and hopefully start to gain a bit of insight into how it works. >> > >> > Many thanks, >> > Jules. >> >> I'll see what I can do... The problem is testing it all... Very >> timeconsuming. >> I found the first draft for 2.4 support, but ... it needs testing... >> I'll see what I can do, perhaps this weekend. >> > > Ok, found some time right now... I've tested this mainly with > handcrafted queue files, and in my production (which does not use a > body editing/replacing milter...), without any discernible bad effect. > There is a price though, since we exchange a nice/fast seek with a > semi-convoluted loop. > > The code is ugly, and could well bear with some constructive > critisism... and if some sharp (postmix-friendly:-) minds like Dhawal, > Drew, Joshua, Phil (Uxbod) or Gerhard could find some time to > test/read/verify both the thinking and code, that would be much > appreciated. Even some non-postfix-liking minds would be very much > appreciated (That means you, oh evil bunny;-). > It should be good enough for a beta:-). So if you feel up to it, and > don't think it too massive a thing Jules...:-) That's just what I wanted, many thanks. I'll put out a beta in a bit with this in it. I assume this patch includes your previous patch, and is directly applicable to the main MailScanner source. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store Need help customising MailScanner? Contact me! Need help fixing or optimising your systems? Contact me! Need help getting you started solving new requirements from your boss? Contact me! PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From uxbod at splatnix.net Fri May 25 15:00:57 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Fri May 25 15:01:04 2007 Subject: PF2.4 support - was Re: feature request: compress attachments In-Reply-To: <4656EAC3.2070204@ecs.soton.ac.uk> References: <4656EAC3.2070204@ecs.soton.ac.uk> Message-ID: It will give me something todo this Bank Holiday weekend instead of mowing the lawn :) On Fri, 25 May 2007 14:55:15 +0100, Julian Field wrote: > > > Glenn Steen wrote: >> On 24/05/07, Glenn Steen wrote: >>> On 24/05/07, Julian Field wrote: >>> > -----BEGIN PGP SIGNED MESSAGE----- >>> > Hash: SHA1 >>> > >>> > Glen, >>> > >>> > My brain is not well enough to get my head round this stuff. It's all >>> > washing in through my eyes and straight out of my ears unfortunately. >>> > >>> > Is there any chance you could find time to implement the 2.4 >>> support as >>> > you say you already have an idea how to do it anyway please? >>> > >>> > Once you're convinced it works, I'll then just adopt your patches. >>> > >>> > Sorry, I'm just not up to doing this myself, but would very much >>> like to >>> > get full PF support in as soon as possible. >>> > >>> > If you can generate a few test messages for me, I'll then test your >>> code >>> > and hopefully start to gain a bit of insight into how it works. >>> > >>> > Many thanks, >>> > Jules. >>> >>> I'll see what I can do... The problem is testing it all... Very >>> timeconsuming. >>> I found the first draft for 2.4 support, but ... it needs testing... >>> I'll see what I can do, perhaps this weekend. >>> >> >> Ok, found some time right now... I've tested this mainly with >> handcrafted queue files, and in my production (which does not use a >> body editing/replacing milter...), without any discernible bad effect. >> There is a price though, since we exchange a nice/fast seek with a >> semi-convoluted loop. >> >> The code is ugly, and could well bear with some constructive >> critisism... and if some sharp (postmix-friendly:-) minds like Dhawal, >> Drew, Joshua, Phil (Uxbod) or Gerhard could find some time to >> test/read/verify both the thinking and code, that would be much >> appreciated. Even some non-postfix-liking minds would be very much >> appreciated (That means you, oh evil bunny;-). >> It should be good enough for a beta:-). So if you feel up to it, and >> don't think it too massive a thing Jules...:-) > That's just what I wanted, many thanks. > I'll put out a beta in a bit with this in it. > I assume this patch includes your previous patch, and is directly > applicable to the main MailScanner source. > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > Need help customising MailScanner? > Contact me! > Need help fixing or optimising your systems? > Contact me! > Need help getting you started solving new requirements from your boss? > Contact me! > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Fri May 25 15:05:37 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Fri May 25 15:06:09 2007 Subject: Enhancement Request ? Message-ID: <95170654daea8e8f4a71f7064bce9a06@62.49.223.244> I was thinking about a question which was asked the other day about maximum size for a rules file. How about implementing something similar to the Postfix configuration where you could specify :- Maximum Message Size = hash:%rules-dir%/max.message.size.rules and store the rules within a hashed database. What do you think ? -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From glenn.steen at gmail.com Fri May 25 15:08:31 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri May 25 15:08:42 2007 Subject: PF2.4 support - was Re: feature request: compress attachments In-Reply-To: References: <4656EAC3.2070204@ecs.soton.ac.uk> Message-ID: <223f97700705250708j2d4d4fbeke33b5e644ca6de6e@mail.gmail.com> On 25/05/07, --[ UxBoD ]-- wrote: > It will give me something todo this Bank Holiday weekend instead of mowing > the lawn :) :-) Thanks Phil Cheers -- Glenn > On Fri, 25 May 2007 14:55:15 +0100, Julian Field > wrote: > > > > > > Glenn Steen wrote: > >> On 24/05/07, Glenn Steen wrote: > >>> On 24/05/07, Julian Field wrote: > >>> > -----BEGIN PGP SIGNED MESSAGE----- > >>> > Hash: SHA1 > >>> > > >>> > Glen, > >>> > > >>> > My brain is not well enough to get my head round this stuff. It's all > >>> > washing in through my eyes and straight out of my ears unfortunately. > >>> > > >>> > Is there any chance you could find time to implement the 2.4 > >>> support as > >>> > you say you already have an idea how to do it anyway please? > >>> > > >>> > Once you're convinced it works, I'll then just adopt your patches. > >>> > > >>> > Sorry, I'm just not up to doing this myself, but would very much > >>> like to > >>> > get full PF support in as soon as possible. > >>> > > >>> > If you can generate a few test messages for me, I'll then test your > >>> code > >>> > and hopefully start to gain a bit of insight into how it works. > >>> > > >>> > Many thanks, > >>> > Jules. > >>> > >>> I'll see what I can do... The problem is testing it all... Very > >>> timeconsuming. > >>> I found the first draft for 2.4 support, but ... it needs testing... > >>> I'll see what I can do, perhaps this weekend. > >>> > >> > >> Ok, found some time right now... I've tested this mainly with > >> handcrafted queue files, and in my production (which does not use a > >> body editing/replacing milter...), without any discernible bad effect. > >> There is a price though, since we exchange a nice/fast seek with a > >> semi-convoluted loop. > >> > >> The code is ugly, and could well bear with some constructive > >> critisism... and if some sharp (postmix-friendly:-) minds like Dhawal, > >> Drew, Joshua, Phil (Uxbod) or Gerhard could find some time to > >> test/read/verify both the thinking and code, that would be much > >> appreciated. Even some non-postfix-liking minds would be very much > >> appreciated (That means you, oh evil bunny;-). > >> It should be good enough for a beta:-). So if you feel up to it, and > >> don't think it too massive a thing Jules...:-) > > That's just what I wanted, many thanks. > > I'll put out a beta in a bit with this in it. > > I assume this patch includes your previous patch, and is directly > > applicable to the main MailScanner source. > > > > Jules > > > > -- > > Julian Field MEng CITP > > www.MailScanner.info > > Buy the MailScanner book at www.MailScanner.info/store > > > > Need help customising MailScanner? > > Contact me! > > Need help fixing or optimising your systems? > > Contact me! > > Need help getting you started solving new requirements from your boss? > > Contact me! > > > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > > > > > > -- > > This message has been scanned for viruses and > > dangerous content by MailScanner, and is > > believed to be clean. > > For all your IT requirements visit www.transtec.co.uk > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > -- > > This message has been scanned for viruses and dangerous content by > > MailScanner, and is > > believed to be clean. > -- > --[ UxBoD ]-- > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > > > -- > This message has been scanned for viruses and dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From wilson.galafassi at gmail.com Fri May 25 15:09:05 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Fri May 25 15:09:22 2007 Subject: SpamAssassin patch Message-ID: Hello. I want the patch for SpamAssassin version 3.002000. Can you send me? Very thanks Wilson Galafassi From glenn.steen at gmail.com Fri May 25 15:07:48 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri May 25 15:15:09 2007 Subject: PF2.4 support - was Re: feature request: compress attachments In-Reply-To: <4656EAC3.2070204@ecs.soton.ac.uk> References: <106f047568251e44a37a9ca53d199b41@solidstatelogic.com> <46541427.2060606@ecs.soton.ac.uk> <223f97700705230335q1bc9f308tefd25a7c129505a@mail.gmail.com> <4654530A.2020503@ecs.soton.ac.uk> <223f97700705240215t192baa3ew7390643786dfd60c@mail.gmail.com> <223f97700705240220w78019c7dq9f927ea569f5069a@mail.gmail.com> <465591DA.10207@ecs.soton.ac.uk> <223f97700705240724m29f91775n552eb10ca0363e8d@mail.gmail.com> <223f97700705250631r1635a36aw1c5ca4c6a247dc14@mail.gmail.com> <4656EAC3.2070204@ecs.soton.ac.uk> Message-ID: <223f97700705250707s2fa2a13bs48b1c49847dc4ad4@mail.gmail.com> On 25/05/07, Julian Field wrote: > > > Glenn Steen wrote: > > On 24/05/07, Glenn Steen wrote: > >> On 24/05/07, Julian Field wrote: > >> > -----BEGIN PGP SIGNED MESSAGE----- > >> > Hash: SHA1 > >> > > >> > Glen, > >> > > >> > My brain is not well enough to get my head round this stuff. It's all > >> > washing in through my eyes and straight out of my ears unfortunately. > >> > > >> > Is there any chance you could find time to implement the 2.4 > >> support as > >> > you say you already have an idea how to do it anyway please? > >> > > >> > Once you're convinced it works, I'll then just adopt your patches. > >> > > >> > Sorry, I'm just not up to doing this myself, but would very much > >> like to > >> > get full PF support in as soon as possible. > >> > > >> > If you can generate a few test messages for me, I'll then test your > >> code > >> > and hopefully start to gain a bit of insight into how it works. > >> > > >> > Many thanks, > >> > Jules. > >> > >> I'll see what I can do... The problem is testing it all... Very > >> timeconsuming. > >> I found the first draft for 2.4 support, but ... it needs testing... > >> I'll see what I can do, perhaps this weekend. > >> > > > > Ok, found some time right now... I've tested this mainly with > > handcrafted queue files, and in my production (which does not use a > > body editing/replacing milter...), without any discernible bad effect. > > There is a price though, since we exchange a nice/fast seek with a > > semi-convoluted loop. > > > > The code is ugly, and could well bear with some constructive > > critisism... and if some sharp (postmix-friendly:-) minds like Dhawal, > > Drew, Joshua, Phil (Uxbod) or Gerhard could find some time to > > test/read/verify both the thinking and code, that would be much > > appreciated. Even some non-postfix-liking minds would be very much > > appreciated (That means you, oh evil bunny;-). > > It should be good enough for a beta:-). So if you feel up to it, and > > don't think it too massive a thing Jules...:-) > That's just what I wanted, many thanks. > I'll put out a beta in a bit with this in it. > I assume this patch includes your previous patch, and is directly > applicable to the main MailScanner source. Yes. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From jan-peter at koopmann.eu Fri May 25 15:15:54 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Fri May 25 15:16:05 2007 Subject: SpamAssassin patch In-Reply-To: References: Message-ID: On Friday, May 25, 2007 4:09 PM Wilson A. Galafassi Jr. wrote: > I want the patch for SpamAssassin version 3.002000. Can you send me? What patch? From uxbod at splatnix.net Fri May 25 15:16:44 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Fri May 25 15:16:53 2007 Subject: Enhancement Request ? In-Reply-To: <95170654daea8e8f4a71f7064bce9a06@62.49.223.244> References: <95170654daea8e8f4a71f7064bce9a06@62.49.223.244> Message-ID: Im stupid! It was mentioned that this was read into memory at daemon startup. But perhaps on large rulesets it would speed up this process ? On Fri, 25 May 2007 15:05:37 +0100, "--[ UxBoD ]--" wrote: > I was thinking about a question which was asked the other day about maximum > size for a rules file. How about implementing something similar to the > Postfix configuration where you could specify :- > > Maximum Message Size = hash:%rules-dir%/max.message.size.rules > > and store the rules within a hashed database. What do you think ? > > -- > --[ UxBoD ]-- > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From mkettler at evi-inc.com Fri May 25 15:17:25 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Fri May 25 15:17:42 2007 Subject: SpamAssassin patch In-Reply-To: References: Message-ID: <4656EFF5.3010607@evi-inc.com> Wilson A. Galafassi Jr. wrote: > Hello. > > I want the patch for SpamAssassin version 3.002000. Can you send me? > > Very thanks What patch? To quote Julian: -------------------- I have done some basic tests with my SpamAssassin 3.2.0 package and MailScanner 4.59 and it is working fine. -------------------- From campbell at cnpapers.com Fri May 25 15:19:10 2007 From: campbell at cnpapers.com (Steve Campbell) Date: Fri May 25 15:19:28 2007 Subject: semi [OT] IEFT moves DK to draft standard References: <002001c79eb4$2a395210$6389a8c0@di.unito.it> Message-ID: <010601c79ed7$a9d033e0$0705000a@ddf5dw71> > Res described them very well in his rant. How do you tell when Res is ranting or not? It all sounds the same :-) But I like what he says. Steve From wilson.galafassi at gmail.com Fri May 25 15:31:21 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Fri May 25 15:31:42 2007 Subject: RES: SpamAssassin patch In-Reply-To: <4656EFF5.3010607@evi-inc.com> References: <4656EFF5.3010607@evi-inc.com> Message-ID: The patch to use MCP. Is necessary or not? -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Matt Kettler Enviada em: sexta-feira, 25 de maio de 2007 11:17 Para: MailScanner discussion Assunto: Re: SpamAssassin patch Wilson A. Galafassi Jr. wrote: > Hello. > > I want the patch for SpamAssassin version 3.002000. Can you send me? > > Very thanks What patch? To quote Julian: -------------------- I have done some basic tests with my SpamAssassin 3.2.0 package and MailScanner 4.59 and it is working fine. -------------------- -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From glenn.steen at gmail.com Fri May 25 15:36:52 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri May 25 15:36:55 2007 Subject: Enhancement Request ? In-Reply-To: References: <95170654daea8e8f4a71f7064bce9a06@62.49.223.244> Message-ID: <223f97700705250736p344a4cccu56d2774e96bd41f1@mail.gmail.com> On 25/05/07, --[ UxBoD ]-- wrote: > Im stupid! It was mentioned that this was read into memory at daemon > startup. But perhaps on large rulesets it would speed up this process ? It probably would... Should the hashes be able to be REs too? But then... I'd consider a ruleset that needs to be more than 1000 lines to be somehow broken. IIRC the OP was using domains/email addresses to whitelist in MS, which is plainly not that smart. That OP said something about the risk of spoofing being negligible. Sigh. Well, I used to do that too. Not as big a set as 4000 entries, just a few hundred domains... Guess what: That was enough for all sort of badness to slip through as W/L.... solidly undermining the reputation/trust for the MailScanner system. Today I use a very limited spamassassin whitelist instead (less than 10 domains... actually less than 5:-), and that is it (apart from 127.0.0.1, of course:). Oh well, everyone to their own...:-). > On Fri, 25 May 2007 15:05:37 +0100, "--[ UxBoD ]--" > wrote: > > I was thinking about a question which was asked the other day about > maximum > > size for a rules file. How about implementing something similar to the > > Postfix configuration where you could specify :- > > > > Maximum Message Size = hash:%rules-dir%/max.message.size.rules > > > > and store the rules within a hashed database. What do you think ? > > > > -- > > --[ UxBoD ]-- > > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > > > > > > > -- > --[ UxBoD ]-- > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > > > -- > This message has been scanned for viruses and dangerous content by MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From dhawal at netmagicsolutions.com Fri May 25 15:36:47 2007 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Fri May 25 15:37:03 2007 Subject: RES: SpamAssassin patch In-Reply-To: References: <4656EFF5.3010607@evi-inc.com> Message-ID: <4656F47F.6050307@netmagicsolutions.com> Wilson A. Galafassi Jr. wrote: > The patch to use MCP. Is necessary or not? Are you talking about this? http://www.mailscanner.info/mcp.html#patches methinks, Julian hasn't updated it for SA 3.2.0 > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Matt Kettler > Enviada em: sexta-feira, 25 de maio de 2007 11:17 > Para: MailScanner discussion > Assunto: Re: SpamAssassin patch > > Wilson A. Galafassi Jr. wrote: >> Hello. >> >> I want the patch for SpamAssassin version 3.002000. Can you send me? >> >> Very thanks > > What patch? > > To quote Julian: > -------------------- > I have done some basic tests with my SpamAssassin 3.2.0 package and > MailScanner 4.59 and it is working fine. > -------------------- From glenn.steen at gmail.com Fri May 25 15:42:22 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Fri May 25 15:42:25 2007 Subject: semi [OT] IEFT moves DK to draft standard In-Reply-To: <010601c79ed7$a9d033e0$0705000a@ddf5dw71> References: <002001c79eb4$2a395210$6389a8c0@di.unito.it> <010601c79ed7$a9d033e0$0705000a@ddf5dw71> Message-ID: <223f97700705250742r32b75962rf3588366f2718ab0@mail.gmail.com> On 25/05/07, Steve Campbell wrote: > > Res described them very well in his rant. > How do you tell when Res is ranting or not? It all sounds the same :-) You mean he has ever _not_ ranted here?;-) (Sorry, oh Evil Bunny, couldn't help myself:) > But I like what he says. To be fair to Noel (and chime in with the man with the long-standing grudge, a.k.a. Jeff), so do I. > Steve > Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From uxbod at splatnix.net Fri May 25 15:54:41 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Fri May 25 15:55:53 2007 Subject: Enhancement Request ? In-Reply-To: <223f97700705250736p344a4cccu56d2774e96bd41f1@mail.gmail.com> References: <223f97700705250736p344a4cccu56d2774e96bd41f1@mail.gmail.com> Message-ID: Hi Glenn, Really was just seeing how we could speed up MS, though it is darn quick already :) especially on the side where it is having to query files for config details. Cheers, On Fri, 25 May 2007 16:36:52 +0200, "Glenn Steen" wrote: > On 25/05/07, --[ UxBoD ]-- wrote: >> Im stupid! It was mentioned that this was read into memory at daemon >> startup. But perhaps on large rulesets it would speed up this process ? > > It probably would... Should the hashes be able to be REs too? > > But then... I'd consider a ruleset that needs to be more than 1000 > lines to be somehow broken. > IIRC the OP was using domains/email addresses to whitelist in MS, > which is plainly not that smart. That OP said something about the risk > of spoofing being negligible. Sigh. > Well, I used to do that too. Not as big a set as 4000 entries, just a > few hundred domains... Guess what: That was enough for all sort of > badness to slip through as W/L.... solidly undermining the > reputation/trust for the MailScanner system. Today I use a very > limited spamassassin whitelist instead (less than 10 domains... > actually less than 5:-), and that is it (apart from 127.0.0.1, of > course:). > Oh well, everyone to their own...:-). > >> On Fri, 25 May 2007 15:05:37 +0100, "--[ UxBoD ]--" >> wrote: >> > I was thinking about a question which was asked the other day about >> maximum >> > size for a rules file. How about implementing something similar to the >> > Postfix configuration where you could specify :- >> > >> > Maximum Message Size = hash:%rules-dir%/max.message.size.rules >> > >> > and store the rules within a hashed database. What do you think ? >> > >> > -- >> > --[ UxBoD ]-- >> > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" >> > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >> > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >> > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >> > >> > >> > >> -- >> --[ UxBoD ]-- >> // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" >> // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 >> // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 >> // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net >> >> >> -- >> This message has been scanned for viruses and dangerous content by > MailScanner, and is >> believed to be clean. >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> > > Cheers > -- > -- Glenn > email: glenn < dot > steen < at > gmail < dot > com > work: glenn < dot > steen < at > ap1 < dot > se > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From wilson.galafassi at gmail.com Fri May 25 16:06:01 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Fri May 25 16:06:14 2007 Subject: RES: RES: SpamAssassin patch In-Reply-To: <4656F47F.6050307@netmagicsolutions.com> References: <4656EFF5.3010607@evi-inc.com> <4656F47F.6050307@netmagicsolutions.com> Message-ID: Yes. But i need the version for SpamAssassin version 3.002000. -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Dhawal Doshy Enviada em: sexta-feira, 25 de maio de 2007 11:37 Para: MailScanner discussion Assunto: Re: RES: SpamAssassin patch Wilson A. Galafassi Jr. wrote: > The patch to use MCP. Is necessary or not? Are you talking about this? http://www.mailscanner.info/mcp.html#patches methinks, Julian hasn't updated it for SA 3.2.0 > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Matt Kettler > Enviada em: sexta-feira, 25 de maio de 2007 11:17 > Para: MailScanner discussion > Assunto: Re: SpamAssassin patch > > Wilson A. Galafassi Jr. wrote: >> Hello. >> >> I want the patch for SpamAssassin version 3.002000. Can you send me? >> >> Very thanks > > What patch? > > To quote Julian: > -------------------- > I have done some basic tests with my SpamAssassin 3.2.0 package and > MailScanner 4.59 and it is working fine. > -------------------- -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From ka at pacific.net Fri May 25 16:09:50 2007 From: ka at pacific.net (Ken A) Date: Fri May 25 16:09:53 2007 Subject: Rules for my boss In-Reply-To: <223f97700705250646j62702d39v56a80515b608c906@mail.gmail.com> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk> <46533C5B.9040202@csags.com.mx> <46535513.6060200@ecs.soton.ac.uk> <6A345D5E-5225-4151-8727-0D9DF91CE33F@gray.net.au> <4656B7CE.7070001@ecs.soton.ac.uk> <223f97700705250646j62702d39v56a80515b608c906@mail.gmail.com> Message-ID: <4656FC3E.9070900@pacific.net> Glenn Steen wrote: > On 25/05/07, Julian Field wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> >> >> James Gray wrote: >> > On 23/05/2007, at 6:39 AM, Julian Field wrote: >> >> Jorge Amador Arenas Quezada wrote: >> >>> 1.- with mailscanner can make a rule to stop mails above 10Meg but >> >>> only if is the number of recipients is more than 10 ? >> > >> >> You would have to do this with a little Custom Function. Attach it to >> >> the Maximum Message Size, and make it check the size of the array >> >> @{$message->{to}}. Start from the example Custom Function in >> >> /usr/lib/MailScanner/MailScanner/CustomFunctions and work from there. >> >> Should be pretty straightforward to write. >> >> >> >> For a donation, I'll even write it for you :-) >> > >> > Just out of curiosity, if the MTA splits a multi-recipient message >> > into individual messages for delivery, does that that have any effect >> > on the @{message->{to}} array? Or does MailScanner still get the full >> > list of recipients? >> It does this splitting after MailScanner has done all its work. So it >> wouldn't have any effect on the to array as it hasn't happened yet. >> >> Jules >> > If one uses Postfix and _one_ instance to do this, why yes. But if one > has done something like what I documented in the wiki... then > MailScanner would see one message/recipient -> Only one recipient in > the array;). > How Rendmaul ... er, Sendmail would handle this, I have no clue. > sendmail splits before MailScanner too. that's the whole point of splitting. :-) -- Ken Anderson Pacific.Net From MailScanner at ecs.soton.ac.uk Fri May 25 16:35:29 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri May 25 16:38:12 2007 Subject: SpamAssassin patch In-Reply-To: <4656EFF5.3010607@evi-inc.com> References: <4656EFF5.3010607@evi-inc.com> Message-ID: <46570241.4000005@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Matt Kettler wrote: > Wilson A. Galafassi Jr. wrote: > >> Hello. >> >> I want the patch for SpamAssassin version 3.002000. Can you send me? >> >> Very thanks >> > > What patch? > He means that patch I have for SpamAssassin that makes it apply SA rules to binary files (e.g. Word docs) as well as text files. This lets MCP work on text within Word docs and Excel files. > To quote Julian: > -------------------- > I have done some basic tests with my SpamAssassin 3.2.0 package and > MailScanner 4.59 and it is working fine. > -------------------- > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGVwK8EfZZRxQVtlQRAjIqAKDSgIDE6lnZ4C85myjzI8ecPI2p8QCg2eZd TdD1lk1IMh6trcKA9utCi1A= =N5cY -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From H.de.Vries at philos.rug.nl Fri May 25 16:43:42 2007 From: H.de.Vries at philos.rug.nl (Hauke de Vries) Date: Fri May 25 16:44:09 2007 Subject: Add header In-Reply-To: <4655CF17.5050909@evi-inc.com> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk>, <4655E102.6212.10542213@H.de.Vries.philos.rug.nl>, <4655CF17.5050909@evi-inc.com> Message-ID: <4657204E.10194.15336295@H.de.Vries.philos.rug.nl> X-mailer: Pegasus Mail for Windows (4.41) Content-type: text/plain; charset=US-ASCII Content-transfer-encoding: 7BIT Content-description: Mail message body On 24 May 2007 at 13:44 Matt Kettler wrote: > Hauke de Vries wrote: > > I've enabled Plugin:RelayCountry in SA3.2 > > If I perform spamassassin -D < spam.eml > spam.dbg > > an header X-Spam-Relay-Country: IT > > is appended. > > Ok, so you set up SA to do that with an add_header command? (I gather > such from the subject line) Yep: add_header all Relay-Country _RELAYCOUNTRY_ > > > > But it doesn't show up if it goes thru MailScanner? > > > > Nope. MailScanner does it's own markups. Nothing SA generates or adds > to the message will be reflected when using MailScanner. > > MailScanner runs SA, takes the results, and makes its own headers > containing the results. Nothing else from SpamAssassin is preserved. > > Therefore all "add_header" and other markup related directives in SA > are irrelevant. > > That said, the X-Spam-Relay-Country header WILL be present as metadata > when SA processes the message, so rules based on it will still work. > > The only part that's not going to work is any modifications to the > delivered message. Understood and I should have tested. > And while we're at it, what does this message have to do with > "4.60.3-1 install errors on RH AS4"? ie: why'd you reply to that > thread instead of creating a new one? First, and you know the answer Mr Dunno, nothing. Second, I took the lazy route and forgot about the thread implications. > There are those of us who use threaded mailreaders, that keep track of > the "references" and "in-reply-to" headers. Those readers will bury > your message inside whatever thread you replied to, even if you change > the subject. > > Do yourself a favor and make a new post instead of replying to an > existing one if you want to make a new thread. Otherwise, those of us > using threaded mailreaders might overlook your posts as a part of some > thread that does not interest us. Mea culpa, mea maxima culpa Sir, I will honour your request and do you and others a favor. Thread closed ;-) From wilson.galafassi at gmail.com Fri May 25 16:50:37 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Fri May 25 16:51:34 2007 Subject: RES: SpamAssassin patch In-Reply-To: <46570241.4000005@ecs.soton.ac.uk> References: <4656EFF5.3010607@evi-inc.com> <46570241.4000005@ecs.soton.ac.uk> Message-ID: Is necessary to pach the version 3.002000? The patch exist? The mcp works withou this patch? -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field Enviada em: sexta-feira, 25 de maio de 2007 12:35 Para: MailScanner discussion Assunto: Re: SpamAssassin patch -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Matt Kettler wrote: > Wilson A. Galafassi Jr. wrote: > >> Hello. >> >> I want the patch for SpamAssassin version 3.002000. Can you send me? >> >> Very thanks >> > > What patch? > He means that patch I have for SpamAssassin that makes it apply SA rules to binary files (e.g. Word docs) as well as text files. This lets MCP work on text within Word docs and Excel files. > To quote Julian: > -------------------- > I have done some basic tests with my SpamAssassin 3.2.0 package and > MailScanner 4.59 and it is working fine. > -------------------- > > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGVwK8EfZZRxQVtlQRAjIqAKDSgIDE6lnZ4C85myjzI8ecPI2p8QCg2eZd TdD1lk1IMh6trcKA9utCi1A= =N5cY -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From mkettler at evi-inc.com Fri May 25 16:54:54 2007 From: mkettler at evi-inc.com (Matt Kettler) Date: Fri May 25 16:55:17 2007 Subject: Add header In-Reply-To: <4657204E.10194.15336295@H.de.Vries.philos.rug.nl> References: <4165CF7A7F12DE4B96622CCBB90586470A4D0FA5@largo.campus.ncl.ac.uk>, <4655E102.6212.10542213@H.de.Vries.philos.rug.nl>, <4655CF17.5050909@evi-inc.com> <4657204E.10194.15336295@H.de.Vries.philos.rug.nl> Message-ID: <465706CE.60202@evi-inc.com> Hauke de Vries wrote: >> >> Do yourself a favor and make a new post instead of replying to an >> existing one if you want to make a new thread. Otherwise, those of us >> using threaded mailreaders might overlook your posts as a part of some >> thread that does not interest us. > > Mea culpa, mea maxima culpa Sir, I will honour your > request and do you and others a favor. Well, really I didn't mean that as a bash on you.. mostly I was trying to point out how creating new threads helps your posts get noticed. Mea culpa if my tone sounded harsher than intended. > Thread closed ;-) From MailScanner at ecs.soton.ac.uk Fri May 25 16:59:39 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri May 25 17:03:31 2007 Subject: Beta release 4.60.4 Message-ID: <465707EB.4000805@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I have just released a new beta, 4.60.4, which includes the Postfix 2.3 and 2.4 patches provided by Glenn Steen. Download as usual from www.mailscanner.info. The full Change Log is: * New Features and Improvements * 1 Improved Sophos.install script so that it sets up /etc/ld.so.conf ready for installation of Perl-SAVI module required for "sophossavi" virus scanner. 1 Custom Functions can now receive parameters not only to their Init and End functions, but also to their run-time calculation functions (i.e. the real custom function itself used when processing each message). The Custom Function is now passed not only the message, but also a ref to a list of parameters specified in the MailScanner.conf file. 1 Improvement to phishing net. 1 'clamavmodule' scanner no longer detects encrypted zips/rars as viruses, leaving MailScanner to do the check later in the dangerous content scanning. The consequence is that MailWatch will allow them to be released from quarantine. 2 Updated a whole load of Perl modules in the pre-requisites lists for both MailScanner and SpamAssassin. 2 Added a "--nomodules" command-line option to the MailScanner install.sh script to skip installing required Perl modules. 2-2 Fixed bugs introduced by 4.60.2 in generic installer. Only affects 'other Linux and non-Linux' installer. 2-4 Fixed more non-Linux installer problems. 4 Added more modules to the list output by "MailScanner --version". 4 Improved phishing net detection of HTML tags, courtesy of snifer_@hotmail.com. 4 Added patches to provide full "p record" support in Postfix 2.3 and 2.4, courtesy of Glenn Steen . * Fixes * 1 Phishing net now correctly handles HTML tags inside links. 1 Deprecated clamscan flag replaced with supported one to stop it printing the summary. 1 Added '-b' to nod32-1.99 command-line options in SweepViruses.pm to stop scanner producing licensing details. Thanks to UxBoD. 1 Removed test in RPM distribution's test for RedHat 6 as it will clash with RHEL 6 and Fedora. Anyone still running RedHat 6 has bigger problems! :-) 1 Worked round Perl bug in returning number of RBLs hit by a message. 1 Fixed problem causing some password-protected RAR archives to be missed. 3 Fixed bug introduced in earlier beta in RBL code. Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGVwitEfZZRxQVtlQRAh5lAJ9+jXdkisKds85ya/cB4nfactX9DQCg3QJ5 yaR6O/fimQTO8JOe0t50vsY= =Hh95 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ms-list at alexb.ch Fri May 25 17:22:18 2007 From: ms-list at alexb.ch (Alex Broens) Date: Fri May 25 17:22:22 2007 Subject: Beta release 4.60.4 In-Reply-To: <465707EB.4000805@ecs.soton.ac.uk> References: <465707EB.4000805@ecs.soton.ac.uk> Message-ID: <46570D3A.8030802@alexb.ch> On 5/25/2007 5:59 PM, Julian Field wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > I have just released a new beta, 4.60.4, which includes the Postfix 2.3 > and 2.4 patches provided by Glenn Steen. > > 1 Removed test in RPM distribution's test for RedHat 6 as it will clash with > RHEL 6 and Fedora. Anyone still running RedHat 6 has bigger problems! :-) Do you mean RHEL 5? or are my clocks way off? Alex From daniel.maher at ubisoft.com Fri May 25 18:43:44 2007 From: daniel.maher at ubisoft.com (Daniel Maher) Date: Fri May 25 18:43:48 2007 Subject: examples of "free image host" spam Message-ID: <1E293D3FF63A3740B10AD5AAD88535D204F6DDCE@UBIMAIL1.ubisoft.org> Hello all, While I might be "asking for it" with this request, I would appreciate some examples of image spams which use free image hosting. Thanks! -- _ ?v? Daniel Maher /(_)\ Administrateur Syst?me Unix ^ ^ Unix System Administrator "The most incomprehensible thing about the world is that it is comprehensible." -- Albert Einstein. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070525/8cc9ce6d/attachment.html From wilson.galafassi at gmail.com Fri May 25 19:55:07 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Fri May 25 19:55:18 2007 Subject: increase load by store Message-ID: Hello. In my Server i?m using store option for all emails (about 10000/15000 per Day). This can increase the load of the Server? How much? Thanks Wilson From alex at nkpanama.com Fri May 25 20:03:40 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Fri May 25 20:04:27 2007 Subject: increase load by store In-Reply-To: References: Message-ID: <4657330C.6080403@nkpanama.com> I don't think it can increase the load on the server, unless you then want to read the messages using IMAP, for example. It will increase your disk usage, so you should be backing up and clearing the space before it becomes an issue. Wilson A. Galafassi Jr. wrote: > Hello. > > In my Server i?m using store option for all emails (about 10000/15000 per > Day). > > This can increase the load of the Server? How much? > > Thanks > > Wilson > > > > From MailScanner at ecs.soton.ac.uk Fri May 25 20:38:41 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Fri May 25 20:40:24 2007 Subject: Beta release 4.60.4 In-Reply-To: <46570D3A.8030802@alexb.ch> References: <465707EB.4000805@ecs.soton.ac.uk> <46570D3A.8030802@alexb.ch> Message-ID: <46573B41.1090704@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Alex Broens wrote: > On 5/25/2007 5:59 PM, Julian Field wrote: >> -----BEGIN PGP SIGNED MESSAGE----- >> Hash: SHA1 >> >> I have just released a new beta, 4.60.4, which includes the Postfix >> 2.3 and 2.4 patches provided by Glenn Steen. >> >> 1 Removed test in RPM distribution's test for RedHat 6 as it will >> clash with >> RHEL 6 and Fedora. Anyone still running RedHat 6 has bigger >> problems! :-) > > Do you mean RHEL 5? No, 6. I'm just fixing the bug in plenty of time :-) Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGVzuGEfZZRxQVtlQRAsnsAKCXrphIjH8f1Xji6tttycgG0EjpnQCg6wNM gUKQwr4HLbgEIYEwOpygaag= =axMx -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ka at pacific.net Fri May 25 20:46:24 2007 From: ka at pacific.net (Ken A) Date: Fri May 25 20:46:27 2007 Subject: increase load by store In-Reply-To: References: Message-ID: <46573D10.1060703@pacific.net> Wilson A. Galafassi Jr. wrote: > Hello. > > In my Server i?m using store option for all emails (about 10000/15000 per > Day). > > This can increase the load of the Server? Can adding i/o increase the load avg? yes. > How much? Depends on your system. How much is too much? > > Thanks > > Wilson > > > -- Ken Anderson Pacific.Net From rabellino at di.unito.it Fri May 25 22:57:26 2007 From: rabellino at di.unito.it (Sergio Rabellino) Date: Fri May 25 22:57:38 2007 Subject: semi [OT] IEFT moves DK to draft standard References: <3abb4d8b6610964cad498e381c76e521@solidstatelogic.com> Message-ID: <005501c79f17$af69f710$6389a8c0@di.unito.it> You're right, as i say, we're moving the trust from a service (SMTP) to another (DNS). The DNS lobbies will let us to manage emails at no costs ? Maybe, or maybe there will be an addendum fee to pay to install the TXT record. Are we sure that this is the best solution ? I'm not happy at all. ----- Original Message ----- From: "Kapetanakis Giannis" To: "MailScanner discussion" Sent: Friday, May 25, 2007 1:29 PM Subject: RE: semi [OT] IEFT moves DK to draft standard > On Fri, 25 May 2007, Martin.Hepworth wrote: > >> Someone's got to sign the keypair. Veri$ign/geotrust etc etc >> >> -- >> Martin Hepworth >> Snr Systems Administrator >> Solid State Logic >> Tel: +44 (0)1865 842300 > > According to my limited knowledge on the subject > you present a self signed public key in your DNS zone files. > > Giannis > ps. Trust is based on the authenticity of the dns records > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From jan-peter at koopmann.eu Sat May 26 09:17:35 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Sat May 26 09:17:53 2007 Subject: better blocking at MTA level (off-topic) Message-ID: Hi, looking at todays 88% High Scoring Spam ratio I would like to block more at the MTA level. What are relyable RBL services (commercial is fine) that can be used? Or other methods besides tarpitting, pipelining tricks etc. at MTA level (which we all do) that would reduce the load? Or am I the only one suffering from massive attacks the past few days? What are you guys using? Kind regards Jan-Peter Koopmann From hvdkooij at vanderkooij.org Sat May 26 09:24:12 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sat May 26 09:24:48 2007 Subject: semi [OT] IEFT moves DK to draft standard In-Reply-To: <005501c79f17$af69f710$6389a8c0@di.unito.it> References: <3abb4d8b6610964cad498e381c76e521@solidstatelogic.com> <005501c79f17$af69f710$6389a8c0@di.unito.it> Message-ID: On Fri, 25 May 2007, Sergio Rabellino wrote: > You're right, as i say, we're moving the trust from a service (SMTP) to > another (DNS). > The DNS lobbies will let us to manage emails at no costs ? > Maybe, or maybe there will be an addendum fee to pay to install the TXT > record. > > Are we sure that this is the best solution ? > I'm not happy at all. No. Say hotmail will follow this. I can still use an anonymous proxy. setup an account with hotmail and spam with signed emails untill they shutdown the account. To the best of my knowledge this is allready automated if I take the amount of spam from hotmail into account. I have just given up and added hotmail to my SMTP blacklist. I no longer see in a point in supporting free email providers. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From hvdkooij at vanderkooij.org Sat May 26 09:40:29 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sat May 26 09:41:05 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: References: Message-ID: On Sat, 26 May 2007, Koopmann, Jan-Peter wrote: > looking at todays 88% High Scoring Spam ratio I would like to block more > at the MTA level. What are relyable RBL services (commercial is fine) > that can be used? Or other methods besides tarpitting, pipelining tricks > etc. at MTA level (which we all do) that would reduce the load? > > Or am I the only one suffering from massive attacks the past few days? > What are you guys using? >From my postfix config: smtpd_client_restrictions = check_client_access hash:/etc/postfix/whitelist, check_sender_access hash:/etc/postfix/whitelist, check_recipient_access hash:/etc/postfix/recipients, permit_mynetworks, check_client_access hash:/etc/postfix/blacklist, check_sender_access hash:/etc/postfix/blacklist, check_client_access cidr:/etc/postfix/ipblacklist, regexp:/etc/postfix/dynamic_networks, reject_invalid_hostname, reject_non_fqdn_hostname, reject_unknown_hostname reject_non_fqdn_sender, reject_unknown_sender_domain reject_non_fqdn_recipient, reject_unknown_recipient_domain, reject_unauth_destination check_policy_service unix:/var/spool/postfix/postgrey/socket I have tested with Trend Micro RBL and you can take it yourself for a spin for 30 days: http://us.trendmicro.com/us/products/enterprise/network-reputation-services/index.html I am not sure you will like the pricetag but they are pretty good for a RBL. My blacklist contains domain name parts like: abo.wanadoo.fr (no point in allowing these DSL/CABLE spammers) And the regular expressions like: /^host-.*\.argeweb\.nl$/ /^softbank.*\.bbtec\.net$/ .... Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From prandal at herefordshire.gov.uk Sat May 26 10:05:05 2007 From: prandal at herefordshire.gov.uk (Randal, Phil) Date: Sat May 26 10:05:53 2007 Subject: semi [OT] IEFT moves DK to draft standard In-Reply-To: <005501c79f17$af69f710$6389a8c0@di.unito.it> References: <3abb4d8b6610964cad498e381c76e521@solidstatelogic.com> <005501c79f17$af69f710$6389a8c0@di.unito.it> Message-ID: <7EF0EE5CB3B263488C8C18823239BEBA03CEDB@HC-MBX02.herefordshire.gov.uk> For what it's worth, I've already seen DomainKeys signed spam here. All DKIM is going to do is tell you that the sender is in charge of the DNS for that domain. It could help blocking stuff from spambots if enough people adopt it, I guess. Cheers, Phil -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Sergio Rabellino Sent: 25 May 2007 22:57 To: MailScanner discussion Subject: Re: semi [OT] IEFT moves DK to draft standard You're right, as i say, we're moving the trust from a service (SMTP) to another (DNS). The DNS lobbies will let us to manage emails at no costs ? Maybe, or maybe there will be an addendum fee to pay to install the TXT record. Are we sure that this is the best solution ? I'm not happy at all. ----- Original Message ----- From: "Kapetanakis Giannis" To: "MailScanner discussion" Sent: Friday, May 25, 2007 1:29 PM Subject: RE: semi [OT] IEFT moves DK to draft standard > On Fri, 25 May 2007, Martin.Hepworth wrote: > >> Someone's got to sign the keypair. Veri$ign/geotrust etc etc >> >> -- >> Martin Hepworth >> Snr Systems Administrator >> Solid State Logic >> Tel: +44 (0)1865 842300 > > According to my limited knowledge on the subject > you present a self signed public key in your DNS zone files. > > Giannis > ps. Trust is based on the authenticity of the dns records > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From res at ausics.net Sat May 26 10:25:47 2007 From: res at ausics.net (Res) Date: Sat May 26 10:26:08 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: References: Message-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sat, 26 May 2007, Koopmann, Jan-Peter wrote: > Or am I the only one suffering from massive attacks the past few days? > What are you guys using? zen.spamhaus.org dnsbl.sorbs.net bl.spamcop.net rejecting no rDNS, forged hostnames, badmx, bad helo (and a beta broadband hostname block on one of the servers) -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGV/0dsWhAmSIQh7MRAtijAJwLJLYgbW+ysBPbuxhfrXPojMJkhgCeK6r+ 3FnWYcxqoUNCEEVI41wLTQo= =rGp7 -----END PGP SIGNATURE----- From jan-peter at koopmann.eu Sat May 26 10:26:13 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Sat May 26 10:26:24 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: References: Message-ID: On Saturday, May 26, 2007 10:40 AM Hugo van der Kooij wrote: > reject_invalid_hostname, > reject_non_fqdn_hostname, > reject_unknown_hostname > reject_non_fqdn_sender, > reject_unknown_sender_domain > reject_non_fqdn_recipient, > reject_unknown_recipient_domain, > reject_unauth_destination > check_policy_service unix:/var/spool/postfix/postgrey/socket I wish I could use all of those for strict testing. Unfortunatly too many legit senders of our clients are too stupid to setup their mail-servers correctly. > I have tested with Trend Micro RBL and you can take it yourself for a > spin for 30 days: > http://us.trendmicro.com/us/products/enterprise/network-reputation-servi ces/index.html > > I am not sure you will like the pricetag but they are pretty good for > a RBL. Just requested an eval. Thanks for the hint. Do you have an appr. price for the two RBLs? I cannot find any on their web-page. What about false-positives and a comparison to spamhouse etc.? Is TM that much better and worth the price? Kind regards Jan-Peter Koopmann From MailScanner at ecs.soton.ac.uk Sat May 26 10:42:43 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sat May 26 10:45:26 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: References: Message-ID: <46580113.10806@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Look out very soon for the announcement of a new product from Fort Systems. This will do exactly what you're looking for. All the beta sites have been raving about it, the test results from them have been fantastic! Keep an eye open on the -announce list, should appear in the next few weeks. Koopmann, Jan-Peter wrote: > Hi, > > looking at todays 88% High Scoring Spam ratio I would like to block more > at the MTA level. What are relyable RBL services (commercial is fine) > that can be used? Or other methods besides tarpitting, pipelining tricks > etc. at MTA level (which we all do) that would reduce the load? > > Or am I the only one suffering from massive attacks the past few days? > What are you guys using? > > > > Kind regards > > Jan-Peter Koopmann > > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGWAGbEfZZRxQVtlQRAnBPAJ9e1k6m7hjm2m9y+IvxoHufQkoqngCdHXjE hwB+Wx4QKZ9cc2p80YqCcpQ= =xTpj -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From dhawal at netmagicsolutions.com Sat May 26 11:14:13 2007 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Sat May 26 11:14:32 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: References: Message-ID: <46580875.5090505@netmagicsolutions.com> Koopmann, Jan-Peter wrote: > On Saturday, May 26, 2007 10:40 AM Hugo van der Kooij wrote: > >> reject_invalid_hostname, >> reject_non_fqdn_hostname, >> reject_unknown_hostname >> reject_non_fqdn_sender, >> reject_unknown_sender_domain >> reject_non_fqdn_recipient, >> reject_unknown_recipient_domain, >> reject_unauth_destination >> check_policy_service unix:/var/spool/postfix/postgrey/socket > > I wish I could use all of those for strict testing. Unfortunatly too > many legit senders of our clients are too stupid to setup their > mail-servers correctly. Run 2 instances of your MTA on different IPs.. one for incoming and the other for outgoing.. the incoming can be strictly configured with the above and you can be less strict on the outgoing as long as there is smtp-auth From hvdkooij at vanderkooij.org Sat May 26 11:16:21 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sat May 26 11:17:01 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: References: Message-ID: On Sat, 26 May 2007, Koopmann, Jan-Peter wrote: > On Saturday, May 26, 2007 10:40 AM Hugo van der Kooij wrote: > >> reject_invalid_hostname, >> reject_non_fqdn_hostname, >> reject_unknown_hostname >> reject_non_fqdn_sender, >> reject_unknown_sender_domain >> reject_non_fqdn_recipient, >> reject_unknown_recipient_domain, >> reject_unauth_destination >> check_policy_service unix:/var/spool/postfix/postgrey/socket > > I wish I could use all of those for strict testing. Unfortunatly too > many legit senders of our clients are too stupid to setup their > mail-servers correctly. A part of these restrictions are quite common these days. If your customers are still not setup correctly they will have trouble with a lot of other organisations as well. Even wxs.nl is now doing quite a few of these checks. >> I have tested with Trend Micro RBL and you can take it yourself for a >> spin for 30 days: >> > http://us.trendmicro.com/us/products/enterprise/network-reputation-servi > ces/index.html >> >> I am not sure you will like the pricetag but they are pretty good for >> a RBL. > > Just requested an eval. Thanks for the hint. Do you have an appr. price > for the two RBLs? I cannot find any on their web-page. What about > false-positives and a comparison to spamhouse etc.? Is TM that much > better and worth the price? I would not have clue about the pricetag. (I'm an engineer, not a salesman ;-) Trend bought the RBL service in the past by taking over MAPS (or rather the owner of MAPS) which was among the top of the paid RBL's. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From hvdkooij at vanderkooij.org Sat May 26 11:24:37 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sat May 26 11:25:16 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: <46580875.5090505@netmagicsolutions.com> References: <46580875.5090505@netmagicsolutions.com> Message-ID: On Sat, 26 May 2007, Dhawal Doshy wrote: > Koopmann, Jan-Peter wrote: >> On Saturday, May 26, 2007 10:40 AM Hugo van der Kooij wrote: >> > reject_invalid_hostname, >> > reject_non_fqdn_hostname, >> > reject_unknown_hostname >> > reject_non_fqdn_sender, >> > reject_unknown_sender_domain >> > reject_non_fqdn_recipient, >> > reject_unknown_recipient_domain, >> > reject_unauth_destination >> > check_policy_service unix:/var/spool/postfix/postgrey/socket >> >> I wish I could use all of those for strict testing. Unfortunatly too >> many legit senders of our clients are too stupid to setup their >> mail-servers correctly. > > Run 2 instances of your MTA on different IPs.. one for incoming and the other > for outgoing.. the incoming can be strictly configured with the above and you > can be less strict on the outgoing as long as there is smtp-auth The point is that almost all small fry businesses out there do not have a clue about how hostname in HELO and the A and PTR records should be linked. Their hostname is mail.internal.lan and they will hapily use that for the HELO message. The PTR record does not exist or is something like ADSL-80-1-2-3,someisp.tld and their A record is customerid.someisp.tld That will fail in about half a dozen ways here. I am not loosing any sleep over that at it is rather unlikly there will be any valid mail in those but some people have to live with the unlikly sort of customers. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From jan-peter at koopmann.eu Sat May 26 11:25:39 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Sat May 26 11:25:54 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: <46580875.5090505@netmagicsolutions.com> References: <46580875.5090505@netmagicsolutions.com> Message-ID: On Saturday, May 26, 2007 12:14 PM Dhawal Doshy wrote: > Run 2 instances of your MTA on different IPs.. one for incoming and > the other for outgoing.. the incoming can be strictly configured with > the above and you can be less strict on the outgoing as long as there > is smtp-auth How would that help? Their clients do not use SMTP AUTH but rather send usual mail. From e.g. ships via satellite without SMTP proxies. Or managing directors sending important mail from dynamic IPs etc. If I tell our client to not accept that mail and teach his/her customers to finally setup a correct mail service they will fire me right away since they need those mails and it is not really considered good style to "educate" your customer... Regards, JP From jan-peter at koopmann.eu Sat May 26 11:29:46 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Sat May 26 11:29:58 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: References: Message-ID: On Saturday, May 26, 2007 12:16 PM Hugo van der Kooij wrote: > A part of these restrictions are quite common these days. I know. > If your > customers are still not setup correctly they will have trouble with a > lot of other organisations as well. My customer is setup correctly (that's my job). THEIR customers are not. And of course whenever we try to enforce these policies some of their customers cannot deliver mail to my customer, call them and tell them "You are the only contractor who does not accept our mail. We do not have any problems with all our other contractors!". This either means they are lying or the other contractors are braindead as well and live with spam. > I would not have clue about the pricetag. (I'm an engineer, not a > salesman ;-) Trend bought the RBL service in the past by taking over > MAPS (or rather the owner of MAPS) which was among the top of the > paid RBL's. I see thanks. Strange thing: I requested the eval and they send me an e-mail with an empty activation code: "This is your activation code:" So their system is broken as well and I will probably have to wait a few days before I can start the trial. Kind regards Jan-Peter Koopmann From jan-peter at koopmann.eu Sat May 26 11:30:51 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Sat May 26 11:31:05 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: References: <46580875.5090505@netmagicsolutions.com> Message-ID: On Saturday, May 26, 2007 12:25 PM Hugo van der Kooij wrote: > That will fail in about half a dozen ways here. I am not loosing any > sleep over that at it is rather unlikly there will be any valid mail > in those but some people have to live with the unlikly sort of > customers. I could not have said it any better. Kind regards Jan-Peter Koopmann From hvdkooij at vanderkooij.org Sat May 26 11:57:17 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Sat May 26 11:57:52 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: References: <46580875.5090505@netmagicsolutions.com> Message-ID: On Sat, 26 May 2007, Koopmann, Jan-Peter wrote: > On Saturday, May 26, 2007 12:14 PM Dhawal Doshy wrote: > >> Run 2 instances of your MTA on different IPs.. one for incoming and >> the other for outgoing.. the incoming can be strictly configured with >> the above and you can be less strict on the outgoing as long as there >> is smtp-auth > > How would that help? Their clients do not use SMTP AUTH but rather send > usual mail. From e.g. ships via satellite without SMTP proxies. Or > managing directors sending important mail from dynamic IPs etc. If I > tell our client to not accept that mail and teach his/her customers to > finally setup a correct mail service they will fire me right away since > they need those mails and it is not really considered good style to > "educate" your customer... Then just ask for more hardware and live with the increasing amount of spam. If educating users is considered harmfull I would make sure my resume is up-to-date and start looking for another job. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From rabellino at di.unito.it Sat May 26 12:03:24 2007 From: rabellino at di.unito.it (Sergio Rabellino) Date: Sat May 26 12:03:32 2007 Subject: better blocking at MTA level (off-topic) References: Message-ID: <004501c79f85$7ba92d60$6389a8c0@di.unito.it> I'm very happy about greylisting. I introduced it (smf grey -sendmail filter) one week ago and the spam shrinks by 90%. Obviously we could/would pay the delay of the "first" email against the very high reduction of the spam. Also my server runqueue goes from "uptime 8" to "uptime 0.6", more cpu for other jobs.... Bye. ----- Original Message ----- From: "Koopmann, Jan-Peter" To: "MailScanner discussion" Sent: Saturday, May 26, 2007 10:17 AM Subject: better blocking at MTA level (off-topic) Hi, looking at todays 88% High Scoring Spam ratio I would like to block more at the MTA level. What are relyable RBL services (commercial is fine) that can be used? Or other methods besides tarpitting, pipelining tricks etc. at MTA level (which we all do) that would reduce the load? Or am I the only one suffering from massive attacks the past few days? What are you guys using? Kind regards Jan-Peter Koopmann -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From dhawal at netmagicsolutions.com Sat May 26 12:07:25 2007 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Sat May 26 12:07:42 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: References: <46580875.5090505@netmagicsolutions.com> Message-ID: <465814ED.4010508@netmagicsolutions.com> Koopmann, Jan-Peter wrote: > On Saturday, May 26, 2007 12:14 PM Dhawal Doshy wrote: > >> Run 2 instances of your MTA on different IPs.. one for incoming and >> the other for outgoing.. the incoming can be strictly configured with >> the above and you can be less strict on the outgoing as long as there >> is smtp-auth > > How would that help? Their clients do not use SMTP AUTH but rather send > usual mail. From e.g. ships via satellite without SMTP proxies. Or > managing directors sending important mail from dynamic IPs etc. If I > tell our client to not accept that mail and teach his/her customers to > finally setup a correct mail service they will fire me right away since > they need those mails and it is not really considered good style to > "educate" your customer... maybe i didn't explain it well enough.. When your users connect on the outgoing SMTP server, their MUAs are talking to your servers so you have to relax your rules.. For incoming mails (your MX record), MTAs are talking to you (not MUAs) so you ought to expect someone sensible running them and you can afford to reject on certain criteria. Based on the above assumption, you can for instance use zen.spamhaus.org on the incoming MTA (MX) without worrying, you do not want it on the outgoing MTA since your senders *will* mostly be sending from a DSL like connections. From j.ede at birchenallhowden.co.uk Sat May 26 12:15:16 2007 From: j.ede at birchenallhowden.co.uk (Jason Ede) Date: Sat May 26 12:16:02 2007 Subject: better blocking at MTA level (off-topic) References: <004501c79f85$7ba92d60$6389a8c0@di.unito.it> Message-ID: <77F6B238A9BA7847840CFF3DFDC46E19052044@server03.BHL2.local> The problem with greylisting as we found when we enabled it was that some MTA's treat a temporary reject code (450) as a permanent reject code (550) and our customer was complaining that they weren't getting email. Whilst we could exempt every MTA they flag up to us from greylisting checking there is no way to prevent email from an unknown source getting blocked and not getting through to them. Until we can resolve the problem without telling our customer to tell anyone emailing them with problems to get their MTA fixed it unfortunately has to be off... It did vastly reduce the load on our server whilst greylisting was active though. The hit of the first email being delayed for the 5 minutes we initially chose was insignificant and no-one would really notice... Jason ________________________________ From: mailscanner-bounces@lists.mailscanner.info on behalf of Sergio Rabellino Sent: Sat 26/05/2007 12:03 To: MailScanner discussion Subject: Re: better blocking at MTA level (off-topic) I'm very happy about greylisting. I introduced it (smf grey -sendmail filter) one week ago and the spam shrinks by 90%. Obviously we could/would pay the delay of the "first" email against the very high reduction of the spam. Also my server runqueue goes from "uptime 8" to "uptime 0.6", more cpu for other jobs.... Bye. ----- Original Message ----- From: "Koopmann, Jan-Peter" To: "MailScanner discussion" Sent: Saturday, May 26, 2007 10:17 AM Subject: better blocking at MTA level (off-topic) Hi, looking at todays 88% High Scoring Spam ratio I would like to block more at the MTA level. What are relyable RBL services (commercial is fine) that can be used? Or other methods besides tarpitting, pipelining tricks etc. at MTA level (which we all do) that would reduce the load? Or am I the only one suffering from massive attacks the past few days? What are you guys using? Kind regards Jan-Peter Koopmann -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ----------------------------------------------------------- The information in this e-mail and any attachments is confidential. It is intended solely for the attention and use of the named addressee(s). If you are not the intended recipient, or person responsible for delivering this information to the intended recipient, please notify the sender or email postmaster@birchenallhowden.co.uk and delete it from your computer systems. Unless you are the intended recipient or his/her representative you are not authorised to, and must not, read, copy, distribute, use or retain this message or any part of it. All messages are scanned by Mailscanner and are believed to be clean. Recipients are advised to apply their own virus checks to any message on delivery. No liability is accepted by BirchenallHowden Ltd for any losses caused by viruses contracted during transit over the internet or present in any receiving system. BirchenallHowden Ltd, 233 Edmund Road, Sheffield, S2 4EL -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070526/4680aae0/attachment.html From dhawal at netmagicsolutions.com Sat May 26 12:33:45 2007 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Sat May 26 12:34:05 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: <77F6B238A9BA7847840CFF3DFDC46E19052044@server03.BHL2.local> References: <004501c79f85$7ba92d60$6389a8c0@di.unito.it> <77F6B238A9BA7847840CFF3DFDC46E19052044@server03.BHL2.local> Message-ID: <46581B19.3080006@netmagicsolutions.com> Jason Ede wrote: > The problem with greylisting as we found when we enabled it was that > some MTA's treat a temporary reject code (450) as a permanent reject > code (550) and our customer was complaining that they weren't getting > email. Whilst we could exempt every MTA they flag up to us from > greylisting checking there is no way to prevent email from an unknown > source getting blocked and not getting through to them. Until we can > resolve the problem without telling our customer to tell anyone emailing > them with problems to get their MTA fixed it unfortunately has to be > off... It did vastly reduce the load on our server whilst greylisting > was active though. Change 450 to 451 to reduce false positives.. exchange responds better to a 451 (as compared to 450). See ftp://ftp.rfc-editor.org/in-notes/rfc2821.txt 450 Requested mail action not taken: mailbox unavailable (e.g., mailbox busy) 451 Requested action aborted: error in processing From jan-peter at koopmann.eu Sat May 26 14:00:21 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Sat May 26 14:00:36 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: <465814ED.4010508@netmagicsolutions.com> References: <46580875.5090505@netmagicsolutions.com> <465814ED.4010508@netmagicsolutions.com> Message-ID: On Saturday, May 26, 2007 1:07 PM Dhawal Doshy wrote: > maybe i didn't explain it well enough.. > > When your users connect on the outgoing SMTP server, their MUAs are > talking to your servers so you have to relax your rules.. > > For incoming mails (your MX record), MTAs are talking to you (not > MUAs) so you ought to expect someone sensible running them and you > can afford to reject on certain criteria. > > Based on the above assumption, you can for instance use > zen.spamhaus.org on the incoming MTA (MX) without worrying, you do > not want it on the outgoing MTA since your senders *will* mostly be > sending from a DSL like connections. Obviously I did not explain it well enough. I am aware of all you are saying and it is missing the point completly, which is due to my faulty mail. Sorry. I am running several anti-virus/anti-spam installations for our customers. They are all using Exchange/Outlook etc. behind those installations. It is not their users I am worried about. They are all using SSL VPN or similar to communicate with their server. It is their customers that are using braindead mail installations. Their customers (the ones sending them inquiries, purchase orders etc.) tend to have malconfigured MTAs, send SMTP mail via Outlook from their dynamic DSL connections, ships via satellites etc. Enforcing all the common rules would mean that at least some of those inquiries/purchase orders will not reach them. So they can either not enforce too strict a ruleset or try to teach/educate their customers. And educating customers is not a good thing. :-) So I was talking about the incoming MTA/MX all along and ways to block stuff at the MTA level without too strict a ruleset. We already do things like tarpitting dynamic IPs, turn off pipelining, use several RBL lists for tarpitting and spamhouse for blocking, connection delays etc. Up to a week ago this combination held off most of the spam. We see a massive increase of botnet-spam though that seems to get past this first line of defence. Just wanted to make sure I am not missing something obvious before I tell our customers to either live with it and catch it with SpamAssassin (which currently works fair enough) or to enforce strict rules. Thanks for all your suggestions. Besides the hint for the TrendMicro RBL which I was not aware of I think we are already doing what can be done. Kind regards Jan-Peter Koopmann From jan-peter at koopmann.eu Sat May 26 14:04:23 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Sat May 26 14:04:40 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: <77F6B238A9BA7847840CFF3DFDC46E19052044@server03.BHL2.local> References: <004501c79f85$7ba92d60$6389a8c0@di.unito.it> <77F6B238A9BA7847840CFF3DFDC46E19052044@server03.BHL2.local> Message-ID: On Saturday, May 26, 2007 10:17 AM "Koopmann, Jan-Peter" wrote: > The problem with greylisting as we found when we enabled it was that > some MTA's treat a temporary reject code (450) as a permanent reject > code (550) and our customer was complaining that they weren't getting > email. I fully agree. As someone else mentioned a 451 might give better results. > source getting blocked and not getting through to them. Until we can > resolve the problem without telling our customer to tell anyone > emailing them with problems to get their MTA fixed it unfortunately > has to be off... Just the same problem as I am having enforcing all the other rules. Again: I feel with you. > It did vastly reduce the load on our server whilst > greylisting was active though. Still seems to be quite effective but I suppose more and more botnets will circumvent greylisting. Some already are. > The hit of the first email being delayed for the 5 minutes we > initially chose was insignificant and no-one would really notice... Attention: Just because you choose 5 minutes does not mean there will be a 5 minute delay. Most MTAs I know (at least old Exchange installations and yes there are dumb people out there using Exchange as the only MTA!) use a 15 minute retry cycle. This results in at least 15 minutes delay if not more. And we have several clients not liking that idea. :-( From jan-peter at koopmann.eu Sat May 26 14:06:38 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Sat May 26 14:06:52 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: References: <46580875.5090505@netmagicsolutions.com> Message-ID: On Saturday, May 26, 2007 12:57 PM Hugo van der Kooij wrote: > Then just ask for more hardware and live with the increasing amount of > spam. Yep. Actually that looks like the way to go then (besides trying the product Jules mentioned, better SpamAssassin rules and better RBLs). > If educating users is considered harmfull I would make sure my > resume is up-to-date and start looking for another job. Read my mails again. Not educating users (I am doing that all the time). Educating customers is harmful! :-) And since I own considerable parts of the company I work for, I do not worry too much about my resume. *g* Thanks, JP From alex at nkpanama.com Sat May 26 15:53:27 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Sat May 26 15:54:14 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: References: <004501c79f85$7ba92d60$6389a8c0@di.unito.it> <77F6B238A9BA7847840CFF3DFDC46E19052044@server03.BHL2.local> Message-ID: <465849E7.8000500@nkpanama.com> Koopmann, Jan-Peter wrote: > Attention: Just because you choose 5 minutes does not mean there will be > a 5 minute delay. Most MTAs I know (at least old Exchange installations > and yes there are dumb people out there using Exchange as the only MTA!) > use a 15 minute retry cycle. This results in at least 15 minutes delay > if not more. And we have several clients not liking that idea. :-( > What I've done in the past is to create a report from the MySQL data gathered by MailWatch installations (even if you don't actively use it, at least you have a pretty good database that lists all the characteristics of incoming and outgoing mail) and see, for example, who's sent the client more than a few e-mails (or who the MX is for whoever the client sent more than a few e-mails to) in order to pre-build a "don't use greylisting with" list, and feed it to the greylist milter. That way at least you begin greylisting "relative unknowns" and not greylisting "relatively known" senders. From lars+lister.mailscanner at adventuras.no Sat May 26 16:27:11 2007 From: lars+lister.mailscanner at adventuras.no (Lars Kristiansen) Date: Sat May 26 16:28:09 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: References: <46580875.5090505@netmagicsolutions.com> Message-ID: <465851CF.8090809@adventuras.no> Koopmann, Jan-Peter skrev: > On Saturday, May 26, 2007 12:57 PM Hugo van der Kooij wrote: > >> Then just ask for more hardware and live with the increasing amount of >> spam. > > Yep. Actually that looks like the way to go then (besides trying the > product Jules mentioned, better SpamAssassin rules and better RBLs). John Rudd made a plugin named Botnet: http://people.ucsc.edu/~jrudd/spamassassin/ I use it to give dynamic ip's score two extra points. Works for me. Regards, Lars From j.ede at birchenallhowden.co.uk Sat May 26 18:15:29 2007 From: j.ede at birchenallhowden.co.uk (Jason Ede) Date: Sat May 26 18:15:46 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: References: <004501c79f85$7ba92d60$6389a8c0@di.unito.it><77F6B238A9BA7847840CFF3DFDC46E19052044@server03.BHL2.local> Message-ID: <77F6B238A9BA7847840CFF3DFDC46E190BB0FC@server03.BHL2.local> On Saturday, May 26, 2007 10:17 AM "Koopmann, Jan-Peter" wrote: >Attention: Just because you choose 5 minutes does not mean there will be >a 5 minute delay. Most MTAs I know (at least old Exchange installations >and yes there are dumb people out there using Exchange as the only MTA!) >use a 15 minute retry cycle. This results in at least 15 minutes delay >if not more. And we have several clients not liking that idea. :-( All of our customers use authenticated smtp for outgoing so that's not stuck. Fortunately we can live with the 5 or 15min delay of incoming email for 'new' senders/recipients. Fortunately for us the email that needs to get through quickly tends to be from people they already know. 15minutes is not long a delay for email to get there and that delay could just have easily been caused by a temporary dns lookup failure in the outgoing exchange server... As it is a one off hit then it generally tends not to be a problem... ----------------------------------------------------------- The information in this e-mail and any attachments is confidential. It is intended solely for the attention and use of the named addressee(s). If you are not the intended recipient, or person responsible for delivering this information to the intended recipient, please notify the sender or email postmaster@birchenallhowden.co.uk and delete it from your computer systems. Unless you are the intended recipient or his/her representative you are not authorised to, and must not, read, copy, distribute, use or retain this message or any part of it. All messages are scanned by Mailscanner and are believed to be clean. Recipients are advised to apply their own virus checks to any message on delivery. No liability is accepted by BirchenallHowden Ltd for any losses caused by viruses contracted during transit over the internet or present in any receiving system. BirchenallHowden Ltd, 233 Edmund Road, Sheffield, S2 4EL From j.ede at birchenallhowden.co.uk Sat May 26 18:17:23 2007 From: j.ede at birchenallhowden.co.uk (Jason Ede) Date: Sat May 26 18:17:40 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: <46581B19.3080006@netmagicsolutions.com> References: <004501c79f85$7ba92d60$6389a8c0@di.unito.it><77F6B238A9BA7847840CFF3DFDC46E19052044@server03.BHL2.local> <46581B19.3080006@netmagicsolutions.com> Message-ID: <77F6B238A9BA7847840CFF3DFDC46E190BB0FD@server03.BHL2.local> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Dhawal Doshy > Sent: 26 May 2007 12:34 > To: MailScanner discussion > Subject: Re: better blocking at MTA level (off-topic) > > Jason Ede wrote: > > The problem with greylisting as we found when we enabled it was that > > some MTA's treat a temporary reject code (450) as a permanent reject > > code (550) and our customer was complaining that they weren't getting > > email. Whilst we could exempt every MTA they flag up to us from > > greylisting checking there is no way to prevent email from an unknown > > source getting blocked and not getting through to them. Until we can > > resolve the problem without telling our customer to tell anyone > emailing > > them with problems to get their MTA fixed it unfortunately has to be > > off... It did vastly reduce the load on our server whilst greylisting > > was active though. > > Change 450 to 451 to reduce false positives.. exchange responds better > to a 451 (as compared to 450). See > ftp://ftp.rfc-editor.org/in-notes/rfc2821.txt > > 450 Requested mail action not taken: mailbox unavailable > (e.g., mailbox busy) > 451 Requested action aborted: error in processing Wouldn't 451 responses cause more problems with some MTA's just returning the mail to sender? Or is it just exchange that tends to return 450's immediately? Jason ----------------------------------------------------------- The information in this e-mail and any attachments is confidential. It is intended solely for the attention and use of the named addressee(s). If you are not the intended recipient, or person responsible for delivering this information to the intended recipient, please notify the sender or email postmaster@birchenallhowden.co.uk and delete it from your computer systems. Unless you are the intended recipient or his/her representative you are not authorised to, and must not, read, copy, distribute, use or retain this message or any part of it. All messages are scanned by Mailscanner and are believed to be clean. Recipients are advised to apply their own virus checks to any message on delivery. No liability is accepted by BirchenallHowden Ltd for any losses caused by viruses contracted during transit over the internet or present in any receiving system. BirchenallHowden Ltd, 233 Edmund Road, Sheffield, S2 4EL From nboric at contexte.fr Sat May 26 21:15:39 2007 From: nboric at contexte.fr (nboric@contexte.fr) Date: Sat May 26 21:17:28 2007 Subject: Starting and stoping MailScanner In-Reply-To: <465851CF.8090809@adventuras.no> References: <46580875.5090505@netmagicsolutions.com> <465851CF.8090809@adventuras.no> Message-ID: I have recently installed posfix+mailscanner+mailwatch on Debain server. System is running fine. The Rules du jour config line SQA_RESTART apparently need to be set to SA_RESTART="/etc/init.d/MailScanner reload"; ? Webmin module also needs a command to restart MailScanner My /etc/init.d/MailScanner doesn't work properly. For installation, I used the following link : http://www.howtoforge.com/postfix_antispam_mailscanner_clamav_ubuntu_p4 MailScanner is starting with a server, since I followed the instructions and inserted /opt/MailScanner/bin/check_mailscanner line in /etc/rc.local file. Here is the beggining of my /etc/init.d/mailscanner file : # This file was automatically customized by dh-make on Fri, 4 Jan 2002 20:05:18 +0100 PATH=/sbin:/bin:/usr/sbin:/usr/bin NAME=MailScanner DAEMON=/usr/sbin/$NAME DESC="mail spam/virus scanner" CONFFILE=/opt/MailScanner/etc/MailScanner.conf I changed the DEAMON line to DAEMON=/opt/MailScanner/bin/$NAME. and then script is complaining since the rights to directories are not properly set.The owner is postfix:postfix, in Mailscanner.conf file I set postfix user and www-data group because of MailWatch. The directories are : /var/spool/MailScanner /var/lib/MailScanner /var/run/MailScanner /var/lock/subsys/MailScanner Which are the permissions I need to set for these directories ? There is no /var/lock/subsys/MailScanner on my system, shall I create this directory or shall I use the other one ? Thanks, Nenad -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070526/a2ee7ea2/attachment.html From jan-peter at koopmann.eu Sat May 26 21:29:48 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Sat May 26 21:29:58 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: <465851CF.8090809@adventuras.no> References: <46580875.5090505@netmagicsolutions.com> <465851CF.8090809@adventuras.no> Message-ID: On Saturday, May 26, 2007 5:27 PM Lars Kristiansen wrote: > John Rudd made a plugin named Botnet: > http://people.ucsc.edu/~jrudd/spamassassin/ > > I use it to give dynamic ip's score two extra points. > Works for me. I know but that's way behind MTA level. Works here great as well BTW and helps quite a bit! From tenderby at mailwash.com.au Sun May 27 07:28:01 2007 From: tenderby at mailwash.com.au (Tony Enderby) Date: Sun May 27 07:29:38 2007 Subject: LDAP Domino and AD scripts Message-ID: <200705270628.l4R6SNcG030782@mail2.mailwash.com.au> Hi Folks, A while ago I remember seeing a list member post links to some perl (from memory) scripts that extract domino and AD user lists via LDAP for inclusion in a sendmail access map db. Could I trouble anyone who knows where these scripts live to post a link please? Many thanks in advance, Tony. ----------------------------------------------------------------------------------- Scanned by MailWash Australia - http://www.mailwash.com.au ----------------------------------------------------------------------------------- -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070527/fbef7680/attachment.html From pascal.maes at elec.ucl.ac.be Sun May 27 09:34:03 2007 From: pascal.maes at elec.ucl.ac.be (Pascal Maes) Date: Sun May 27 09:34:10 2007 Subject: SpamCheck report In-Reply-To: <462498A6.2020507@ddihealth.com> References: <462304A8.6030103@ddihealth.com> <46230EAC.5070600@ddihealth.com> <46231A7E.4080003@netmagicsolutions.com> <462498A6.2020507@ddihealth.com> Message-ID: <03203FB5-AC29-4B0B-BFB3-F9802A419917@elec.ucl.ac.be> hello, I'm using a CustomFunction to avoid spam check when the user is authenticated. In MailSanner.conf, I have Always Include SpamAssassin Report = yes In case of authenticated users, this report is empty How could I add a message like "Not spam : authenticated" ? Thanks -- Pascal From oliver at linux-kernel.at Sun May 27 10:45:21 2007 From: oliver at linux-kernel.at (Oliver Falk) Date: Sun May 27 10:45:41 2007 Subject: LDAP Domino and AD scripts In-Reply-To: <200705270628.l4R6SNcG030782@mail2.mailwash.com.au> References: <200705270628.l4R6SNcG030782@mail2.mailwash.com.au> Message-ID: <46595331.8090801@linux-kernel.at> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Tony Enderby schrieb: > A while ago I remember seeing a list member post links to some perl (from > memory) scripts > > that extract domino and AD user lists via LDAP for inclusion in a sendmail > access map db. > > > > Could I trouble anyone who knows where these scripts live to post a link > please? > > > > Many thanks in advance, I have some AD -> Access MAP Perl Script... I found this on one of our company mailservers - I'm quite sure, that this is nothing new that we've written - so no copyright. :-) - -of -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFGWVMxxWN5Ge8lKUMRAqBmAJ4wAvnNKHuSA1XLlEYjHUqVxhK2kQCg9QVk kMaQgaylr25ruLEofkoxTAU= =8xu5 -----END PGP SIGNATURE----- -------------- next part -------------- #!/usr/bin/perl -w # This script will pull all users' SMTP addresses from your Active Directory # (including primary and secondary email addresses) and list them in the # format "user@example.com OK" which Postfix uses with relay_recipient_maps. # Be sure to double-check the path to perl above. use strict; use warnings; use Net::LDAP; use Getopt::Long; # If you use more than 1 domaincontroller you'll have to use a sort -u on the output... my $dcs = 'adserver.office.company.com'; my $result = GetOptions("domaincontrollers|dc|dcs=s" => \$dcs); die "No domaincontrollers specified!" unless $dcs; foreach my $dc (split(/\s/, $dcs)) { # Enter the LDAP container for your userbase. my $hqbase="ou=something,dc=office,dc=company,dc=com"; # Enter the username & password for a valid user in your Active Directory # with username in the form cn=username,cn=Users,dc=example,dc=com my $user="office\\somereadonlyldapuser"; my $passwd="somegoodpassword"; # Connecting to Active Directory domain controllers my $ldap = Net::LDAP->new($dc, version => 2); my $mesg = $ldap->bind( $user, password => $passwd ); if ( $mesg->code()) { die ("error:", $mesg->error()); } my $searchbase = $hqbase; # Searching for users (not contacts) that are mail-enabled $mesg = $ldap->search( base => $searchbase, filter => "(&(sAMAccountName=*)(mail=*))", attrs => "proxyAddresses" ); my $entries = $mesg->count(); if ($entries lt 1) { print "entries=0 \n"; } # Filtering results for proxyAddresses attributes, thanks to Markus Schabel # and Viktor Duchovni foreach my $entry ($mesg->entries()) { # LDAP Attributes are multi-valued, so we have to print each one. foreach my $mail ($entry->get_value("proxyAddresses")) { # Test if the Line starts with one of the following lines: # proxyAddresses: smtp: # proxyAddresses: SMTP: # and also discard this starting string, so that $mail is only the # address without any other characters... if ($mail =~ s/^(smtp|SMTP)://gs) { print $mail." OK\n"; } } } # Unbinding $ldap->unbind(); } From MailScanner at ecs.soton.ac.uk Sun May 27 12:40:52 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun May 27 12:41:23 2007 Subject: SpamCheck report In-Reply-To: <03203FB5-AC29-4B0B-BFB3-F9802A419917@elec.ucl.ac.be> References: <462304A8.6030103@ddihealth.com> <46230EAC.5070600@ddihealth.com> <46231A7E.4080003@netmagicsolutions.com> <462498A6.2020507@ddihealth.com> <03203FB5-AC29-4B0B-BFB3-F9802A419917@elec.ucl.ac.be> Message-ID: <46596E44.9020006@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 You can use the "AddHeader" function to add whatever new header you want. $global::MS->{mta}->AddHeader($message, .....) Pascal Maes wrote: > hello, > > I'm using a CustomFunction to avoid spam check when the user is > authenticated. > In MailSanner.conf, I have > Always Include SpamAssassin Report = yes > > In case of authenticated users, this report is empty > > How could I add a message like "Not spam : authenticated" ? > > Thanks > -- > Pascal > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGWW5JEfZZRxQVtlQRAqCtAJsGbjPYnXaiZzzFRQ+XMkNq2r32egCgor8k d/+mjfhYYni/uoduXzQA2RI= =qCwF -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From j.ede at birchenallhowden.co.uk Sun May 27 14:51:00 2007 From: j.ede at birchenallhowden.co.uk (Jason Ede) Date: Sun May 27 14:51:30 2007 Subject: SpamCheck report In-Reply-To: <03203FB5-AC29-4B0B-BFB3-F9802A419917@elec.ucl.ac.be> References: <462304A8.6030103@ddihealth.com><46230EAC.5070600@ddihealth.com><46231A7E.4080003@netmagicsolutions.com><462498A6.2020507@ddihealth.com> <03203FB5-AC29-4B0B-BFB3-F9802A419917@elec.ucl.ac.be> Message-ID: <77F6B238A9BA7847840CFF3DFDC46E190BB0FE@server03.BHL2.local> Hi, I don't suppose you'd be willing to share that custom function? We'd like to do the same, but the only way I can see to do that so far is to have postfix include the SASL login username in the header which I'm loathe to do if I can really avoid it. Jason > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Pascal Maes > Sent: 27 May 2007 09:34 > To: MailScanner discussion > Subject: SpamCheck report > > hello, > > I'm using a CustomFunction to avoid spam check when the user is > authenticated. > In MailSanner.conf, I have > Always Include SpamAssassin Report = yes > > In case of authenticated users, this report is empty > > How could I add a message like "Not spam : authenticated" ? > > Thanks > -- > Pascal > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ----------------------------------------------------------- The information in this e-mail and any attachments is confidential. It is intended solely for the attention and use of the named addressee(s). If you are not the intended recipient, or person responsible for delivering this information to the intended recipient, please notify the sender or email postmaster@birchenallhowden.co.uk and delete it from your computer systems. Unless you are the intended recipient or his/her representative you are not authorised to, and must not, read, copy, distribute, use or retain this message or any part of it. All messages are scanned by Mailscanner and are believed to be clean. Recipients are advised to apply their own virus checks to any message on delivery. No liability is accepted by BirchenallHowden Ltd for any losses caused by viruses contracted during transit over the internet or present in any receiving system. BirchenallHowden Ltd, 233 Edmund Road, Sheffield, S2 4EL From amaclach at yahoo.co.uk Sun May 27 17:54:06 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Sun May 27 17:54:08 2007 Subject: better blocking at MTA level (off-topic) Message-ID: <421437.76431.qm@web26311.mail.ukl.yahoo.com> Some would consider zen.spamhaus.org a little too hardcore (me!), but sbl-xbl.spamhaus.org and list.dsbl.org are good... ----- Original Message ---- From: Res To: MailScanner discussion Sent: Saturday, 26 May, 2007 10:25:47 AM Subject: Re: better blocking at MTA level (off-topic) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sat, 26 May 2007, Koopmann, Jan-Peter wrote: > Or am I the only one suffering from massive attacks the past few days? > What are you guys using? zen.spamhaus.org dnsbl.sorbs.net bl.spamcop.net rejecting no rDNS, forged hostnames, badmx, bad helo (and a beta broadband hostname block on one of the servers) -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFGV/0dsWhAmSIQh7MRAtijAJwLJLYgbW+ysBPbuxhfrXPojMJkhgCeK6r+ 3FnWYcxqoUNCEEVI41wLTQo= =rGp7 -----END PGP SIGNATURE----- -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From amaclach at yahoo.co.uk Sun May 27 18:05:25 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Sun May 27 18:05:27 2007 Subject: better blocking at MTA level (off-topic) Message-ID: <746377.68039.qm@web26308.mail.ukl.yahoo.com> Mailcontrol treats all 45x responses as 550 - although they should know better... ----- Original Message ---- From: Jason Ede To: MailScanner discussion Sent: Saturday, 26 May, 2007 6:17:23 PM Subject: RE: better blocking at MTA level (off-topic) > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Dhawal Doshy > Sent: 26 May 2007 12:34 > To: MailScanner discussion > Subject: Re: better blocking at MTA level (off-topic) > > Jason Ede wrote: > > The problem with greylisting as we found when we enabled it was that > > some MTA's treat a temporary reject code (450) as a permanent reject > > code (550) and our customer was complaining that they weren't getting > > email. Whilst we could exempt every MTA they flag up to us from > > greylisting checking there is no way to prevent email from an unknown > > source getting blocked and not getting through to them. Until we can > > resolve the problem without telling our customer to tell anyone > emailing > > them with problems to get their MTA fixed it unfortunately has to be > > off... It did vastly reduce the load on our server whilst greylisting > > was active though. > > Change 450 to 451 to reduce false positives.. exchange responds better > to a 451 (as compared to 450). See > ftp://ftp.rfc-editor.org/in-notes/rfc2821.txt > > 450 Requested mail action not taken: mailbox unavailable > (e.g., mailbox busy) > 451 Requested action aborted: error in processing Wouldn't 451 responses cause more problems with some MTA's just returning the mail to sender? Or is it just exchange that tends to return 450's immediately? Jason ----------------------------------------------------------- The information in this e-mail and any attachments is confidential. It is intended solely for the attention and use of the named addressee(s). If you are not the intended recipient, or person responsible for delivering this information to the intended recipient, please notify the sender or email postmaster@birchenallhowden.co.uk and delete it from your computer systems. Unless you are the intended recipient or his/her representative you are not authorised to, and must not, read, copy, distribute, use or retain this message or any part of it. All messages are scanned by Mailscanner and are believed to be clean. Recipients are advised to apply their own virus checks to any message on delivery. No liability is accepted by BirchenallHowden Ltd for any losses caused by viruses contracted during transit over the internet or present in any receiving system. BirchenallHowden Ltd, 233 Edmund Road, Sheffield, S2 4EL -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From pascal.maes at elec.ucl.ac.be Sun May 27 19:26:56 2007 From: pascal.maes at elec.ucl.ac.be (Pascal Maes) Date: Sun May 27 19:27:11 2007 Subject: SpamCheck report In-Reply-To: <77F6B238A9BA7847840CFF3DFDC46E190BB0FE@server03.BHL2.local> References: <462304A8.6030103@ddihealth.com> <46230EAC.5070600@ddihealth.com> <46231A7E.4080003@netmagicsolutions.com> <462498A6.2020507@ddihealth.com> <03203FB5-AC29-4B0B-BFB3-F9802A419917@elec.ucl.ac.be> <77F6B238A9BA7847840CFF3DFDC46E190BB0FE@server03.BHL2.local> Message-ID: <024CA64E-2F65-4219-9D66-EBCE566BB31F@elec.ucl.ac.be> Le 27 mai 07 ? 15:51, Jason Ede a ?crit : > Hi, > > I don't suppose you'd be willing to share that custom function? We'd > like to do the same, but the only way I can see to do that so far > is to > have postfix include the SASL login username in the header which I'm > loathe to do if I can really avoid it. > > Jason Why not ? The first idea comes from the list so I could post it again. But first, thanks to Julian for his quick answer. ------8<------8<------8<------8<------8<------8<------8<------8<------8< ------8<------ package MailScanner::CustomConfig; use strict 'vars'; use strict 'refs'; no strict 'subs'; # Allow bare words for parameter %'s use vars qw($VERSION); ### The package version, both in 1.23 style *and* usable by MakeMaker: $VERSION = substr q$Revision: 2331 $, 10; sub InitCheckSMTPAuth { # Empty } sub EndCheckSMTPAuth { # Empty } sub CheckSMTPAuth { my ($message) = @_; return 1 unless $message; foreach (@{$message->{headers}}) { if (/PUT HERE THE STRING ABOUT THE AUTHENTICATION/) { MailScanner::Log::InfoLog("Message %s from (%s) is authenticated ($1)", $message->{id}, $message->{ fromuser}); $global::MS->{mta}->AddHeader($message, 'X-MailScanner- Spamcheck:', 'Authenticated'); return 0; } } return 1; } 1; ------8<------8<------8<------8<------8<------8<------8<------8<------8< ------8<------ -- Pascal From MailScanner at ecs.soton.ac.uk Sun May 27 21:40:55 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun May 27 21:45:46 2007 Subject: feature request: compress attachments In-Reply-To: <115762.74969.qm@web26310.mail.ukl.yahoo.com> References: <115762.74969.qm@web26310.mail.ukl.yahoo.com> Message-ID: <4659ECD7.3090909@ecs.soton.ac.uk> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Sorry for bringing this thread back on-topic, but I've just written it. Next post will be about it. Andrew MacLachlan wrote: > Nothing better than a kebab with a nice big mug of tea! > > ----- Original Message ---- > From: Matt Kettler > To: MailScanner discussion > Sent: Wednesday, 23 May, 2007 9:51:35 PM > Subject: Re: feature request: compress attachments > > Julian Field wrote: > >> Matt Kettler wrote: >> >>> Scott Silva wrote: >>> >>>> Andrew MacLachlan spake the following on 5/23/2007 9:20 AM: >>>> >>>> >>>>> Guinness & kebabs - works (too well) for me... >>>>> >>>>> >>>>> >>>> Bangers & mash! >>>> >>>> >>> Especially if appropriately paired with a suitable pint. >>> >>> But then again, IIRC, Julian isn't a beer/ale drinker, he's a wine drinker.. >>> >> Unfortunately only half my liver works at the moment, so I'm not really >> supposed to be an anything drinker :-( >> > > Good point.. > > Well, enjoy a nice healthy pint of water anyway :) > Jules - -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -----BEGIN PGP SIGNATURE----- Version: PGP Desktop 9.6.1 (Build 1012) Charset: ISO-8859-1 wj8DBQFGWe3kEfZZRxQVtlQRAqeTAKCQUu7jlpJDfkpxxreUl0CHn4JIswCgsV4Z U8ct7FqJb6v77I/BbucwoWk= =MLsC -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Sun May 27 21:51:57 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Sun May 27 21:53:02 2007 Subject: Beta release: 4.60.5 - compress attachments Message-ID: <4659EF6D.2070107@ecs.soton.ac.uk> I have just written the feature you wanted to compress attachments into a zip file. The new MailScanner.conf configuration settings for this are: # Should the attachments be compressed and put into a single zip file? # This can also be the filename of a ruleset. Zip Attachments = no # If the attachments are to be compressed into a single zip file, # this is the filename of the zip file. # This can also be the filename of a ruleset. Attachments Zip Filename = MessageAttachments.zip You will obviously want to set the first one to "yes" to use it :-) Please test this for me! It is switched off by default, so you will need to set it to "yes" in your MailScanner.conf file to use it. Download it as usual from www.mailscanner.info. The full Change Log for this version is... * New Features and Improvements * 1 Improved Sophos.install script so that it sets up /etc/ld.so.conf ready for installation of Perl-SAVI module required for "sophossavi" virus scanner. 1 Custom Functions can now receive parameters not only to their Init and End functions, but also to their run-time calculation functions (i.e. the real custom function itself used when processing each message). The Custom Function is now passed not only the message, but also a ref to a list of parameters specified in the MailScanner.conf file. 1 Improvement to phishing net. 1 'clamavmodule' scanner no longer detects encrypted zips/rars as viruses, leaving MailScanner to do the check later in the dangerous content scanning. The consequence is that MailWatch will allow them to be released from quarantine. 2 Updated a whole load of Perl modules in the pre-requisites lists for both MailScanner and SpamAssassin. 2 Added a "--nomodules" command-line option to the MailScanner install.sh script to skip installing required Perl modules. 2-2 Fixed bugs introduced by 4.60.2 in generic installer. Only affects 'other Linux and non-Linux' installer. 2-4 Fixed more non-Linux installer problems. 4 Added more modules to the list output by "MailScanner --version". 4 Improved phishing net detection of HTML tags, courtesy of snifer_@hotmail.com. 4 Added patches to provide full "p record" support in Postfix 2.3 and 2.4, courtesy of Glenn Steen . 5 Added a new feature, to compress all the attachments in a message and replace them with a single zip file. Set "Zip Attachments = yes" (no by default), and set "Attachments Zip Filename = MessageAttachments.zip" * Fixes * 1 Phishing net now correctly handles HTML tags inside links. 1 Deprecated clamscan flag replaced with supported one to stop it printing the summary. 1 Added '-b' to nod32-1.99 command-line options in SweepViruses.pm to stop scanner producing licensing details. Thanks to UxBoD. 1 Removed test in RPM distribution's test for RedHat 6 as it will clash with RHEL 6 and Fedora. Anyone still running RedHat 6 has bigger problems! :-) 1 Worked round Perl bug in returning number of RBLs hit by a message. 1 Fixed problem causing some password-protected RAR archives to be missed. 3 Fixed bug introduced in earlier beta in RBL code. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From algorges at gmail.com Sun May 27 22:58:13 2007 From: algorges at gmail.com (ASA) Date: Sun May 27 22:58:16 2007 Subject: Beta release: 4.60.5 - compress attachments In-Reply-To: <4659EF6D.2070107@ecs.soton.ac.uk> References: <4659EF6D.2070107@ecs.soton.ac.uk> Message-ID: <6b484ce70705271458n50b0a34cmfa4c1ab734f0a5f6@mail.gmail.com> that types of archives it will go to compact? 2007/5/27, Julian Field : > > I have just written the feature you wanted to compress attachments into > a zip file. > > The new MailScanner.conf configuration settings for this are: > > # Should the attachments be compressed and put into a single zip file? > # This can also be the filename of a ruleset. > Zip Attachments = no > > # If the attachments are to be compressed into a single zip file, > # this is the filename of the zip file. > # This can also be the filename of a ruleset. > Attachments Zip Filename = MessageAttachments.zip > > You will obviously want to set the first one to "yes" to use it :-) > > Please test this for me! > It is switched off by default, so you will need to set it to "yes" in > your MailScanner.conf file to use it. > > Download it as usual from www.mailscanner.info. > > The full Change Log for this version is... > > * New Features and Improvements * > 1 Improved Sophos.install script so that it sets up /etc/ld.so.conf > ready for > installation of Perl-SAVI module required for "sophossavi" virus > scanner. > 1 Custom Functions can now receive parameters not only to their Init and > End > functions, but also to their run-time calculation functions (i.e. the > real > custom function itself used when processing each message). The Custom > Function is now passed not only the message, but also a ref to a list of > parameters specified in the MailScanner.conf file. > 1 Improvement to phishing net. > 1 'clamavmodule' scanner no longer detects encrypted zips/rars as viruses, > leaving MailScanner to do the check later in the dangerous content > scanning. > The consequence is that MailWatch will allow them to be released from > quarantine. > 2 Updated a whole load of Perl modules in the pre-requisites lists for > both > MailScanner and SpamAssassin. > 2 Added a "--nomodules" command-line option to the MailScanner install.sh > script to skip installing required Perl modules. > 2-2 Fixed bugs introduced by 4.60.2 in generic installer. Only affects > 'other > Linux and non-Linux' installer. > 2-4 Fixed more non-Linux installer problems. > 4 Added more modules to the list output by "MailScanner --version". > 4 Improved phishing net detection of HTML tags, courtesy of > snifer_@hotmail.com. > 4 Added patches to provide full "p record" support in Postfix 2.3 and 2.4, > courtesy of Glenn Steen . > 5 Added a new feature, to compress all the attachments in a message and > replace them with a single zip file. > Set "Zip Attachments = yes" (no by default), and > set "Attachments Zip Filename = MessageAttachments.zip" > > * Fixes * > 1 Phishing net now correctly handles HTML tags inside links. > 1 Deprecated clamscan flag replaced with supported one to stop it printing > the summary. > 1 Added '-b' to nod32-1.99 command-line options in SweepViruses.pm to stop > scanner producing licensing details. Thanks to UxBoD. > 1 Removed test in RPM distribution's test for RedHat 6 as it will clash > with > RHEL 6 and Fedora. Anyone still running RedHat 6 has bigger problems! > :-) > 1 Worked round Perl bug in returning number of RBLs hit by a message. > 1 Fixed problem causing some password-protected RAR archives to be missed. > 3 Fixed bug introduced in earlier beta in RBL code. > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- []'s ASA -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070527/bd3068a6/attachment.html From amaclach at yahoo.co.uk Sun May 27 23:11:49 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Sun May 27 23:11:52 2007 Subject: Beta release: 4.60.5 - compress attachments Message-ID: <997730.74570.qm@web26313.mail.ukl.yahoo.com> Hi Julian, Sad as I am, I'm downloading it now. Just one question though: -Can this use a ruleset (e.g. only zip outbound messages)? -Andy ----- Original Message ---- From: Julian Field To: MailScanner discussion ; MailScanner beta testers Sent: Sunday, 27 May, 2007 9:51:57 PM Subject: Beta release: 4.60.5 - compress attachments I have just written the feature you wanted to compress attachments into a zip file. The new MailScanner.conf configuration settings for this are: # Should the attachments be compressed and put into a single zip file? # This can also be the filename of a ruleset. Zip Attachments = no # If the attachments are to be compressed into a single zip file, # this is the filename of the zip file. # This can also be the filename of a ruleset. Attachments Zip Filename = MessageAttachments.zip You will obviously want to set the first one to "yes" to use it :-) Please test this for me! It is switched off by default, so you will need to set it to "yes" in your MailScanner.conf file to use it. Download it as usual from www.mailscanner.info. The full Change Log for this version is... * New Features and Improvements * 1 Improved Sophos.install script so that it sets up /etc/ld.so.conf ready for installation of Perl-SAVI module required for "sophossavi" virus scanner. 1 Custom Functions can now receive parameters not only to their Init and End functions, but also to their run-time calculation functions (i.e. the real custom function itself used when processing each message). The Custom Function is now passed not only the message, but also a ref to a list of parameters specified in the MailScanner.conf file. 1 Improvement to phishing net. 1 'clamavmodule' scanner no longer detects encrypted zips/rars as viruses, leaving MailScanner to do the check later in the dangerous content scanning. The consequence is that MailWatch will allow them to be released from quarantine. 2 Updated a whole load of Perl modules in the pre-requisites lists for both MailScanner and SpamAssassin. 2 Added a "--nomodules" command-line option to the MailScanner install.sh script to skip installing required Perl modules. 2-2 Fixed bugs introduced by 4.60.2 in generic installer. Only affects 'other Linux and non-Linux' installer. 2-4 Fixed more non-Linux installer problems. 4 Added more modules to the list output by "MailScanner --version". 4 Improved phishing net detection of HTML tags, courtesy of snifer_@hotmail.com. 4 Added patches to provide full "p record" support in Postfix 2.3 and 2.4, courtesy of Glenn Steen . 5 Added a new feature, to compress all the attachments in a message and replace them with a single zip file. Set "Zip Attachments = yes" (no by default), and set "Attachments Zip Filename = MessageAttachments.zip" * Fixes * 1 Phishing net now correctly handles HTML tags inside links. 1 Deprecated clamscan flag replaced with supported one to stop it printing the summary. 1 Added '-b' to nod32-1.99 command-line options in SweepViruses.pm to stop scanner producing licensing details. Thanks to UxBoD. 1 Removed test in RPM distribution's test for RedHat 6 as it will clash with RHEL 6 and Fedora. Anyone still running RedHat 6 has bigger problems! :-) 1 Worked round Perl bug in returning number of RBLs hit by a message. 1 Fixed problem causing some password-protected RAR archives to be missed. 3 Fixed bug introduced in earlier beta in RBL code. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From amaclach at yahoo.co.uk Sun May 27 23:48:59 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Sun May 27 23:49:00 2007 Subject: Beta release: 4.60.5 - compress attachments Message-ID: <323182.52070.qm@web26305.mail.ukl.yahoo.com> OK - I've installed it now and the new MailScanner.conf file has answered my question - yes it can. ----- Original Message ---- From: Andrew MacLachlan To: MailScanner discussion Sent: Sunday, 27 May, 2007 11:11:49 PM Subject: Re: Beta release: 4.60.5 - compress attachments Hi Julian, Sad as I am, I'm downloading it now. Just one question though: -Can this use a ruleset (e.g. only zip outbound messages)? -Andy ----- Original Message ---- From: Julian Field To: MailScanner discussion ; MailScanner beta testers Sent: Sunday, 27 May, 2007 9:51:57 PM Subject: Beta release: 4.60.5 - compress attachments I have just written the feature you wanted to compress attachments into a zip file. The new MailScanner.conf configuration settings for this are: # Should the attachments be compressed and put into a single zip file? # This can also be the filename of a ruleset. Zip Attachments = no # If the attachments are to be compressed into a single zip file, # this is the filename of the zip file. # This can also be the filename of a ruleset. Attachments Zip Filename = MessageAttachments.zip You will obviously want to set the first one to "yes" to use it :-) Please test this for me! It is switched off by default, so you will need to set it to "yes" in your MailScanner.conf file to use it. Download it as usual from www.mailscanner.info. The full Change Log for this version is... * New Features and Improvements * 1 Improved Sophos.install script so that it sets up /etc/ld.so.conf ready for installation of Perl-SAVI module required for "sophossavi" virus scanner. 1 Custom Functions can now receive parameters not only to their Init and End functions, but also to their run-time calculation functions (i.e. the real custom function itself used when processing each message). The Custom Function is now passed not only the message, but also a ref to a list of parameters specified in the MailScanner.conf file. 1 Improvement to phishing net. 1 'clamavmodule' scanner no longer detects encrypted zips/rars as viruses, leaving MailScanner to do the check later in the dangerous content scanning. The consequence is that MailWatch will allow them to be released from quarantine. 2 Updated a whole load of Perl modules in the pre-requisites lists for both MailScanner and SpamAssassin. 2 Added a "--nomodules" command-line option to the MailScanner install.sh script to skip installing required Perl modules. 2-2 Fixed bugs introduced by 4.60.2 in generic installer. Only affects 'other Linux and non-Linux' installer. 2-4 Fixed more non-Linux installer problems. 4 Added more modules to the list output by "MailScanner --version". 4 Improved phishing net detection of HTML tags, courtesy of snifer_@hotmail.com. 4 Added patches to provide full "p record" support in Postfix 2.3 and 2.4, courtesy of Glenn Steen . 5 Added a new feature, to compress all the attachments in a message and replace them with a single zip file. Set "Zip Attachments = yes" (no by default), and set "Attachments Zip Filename = MessageAttachments.zip" * Fixes * 1 Phishing net now correctly handles HTML tags inside links. 1 Deprecated clamscan flag replaced with supported one to stop it printing the summary. 1 Added '-b' to nod32-1.99 command-line options in SweepViruses.pm to stop scanner producing licensing details. Thanks to UxBoD. 1 Removed test in RPM distribution's test for RedHat 6 as it will clash with RHEL 6 and Fedora. Anyone still running RedHat 6 has bigger problems! :-) 1 Worked round Perl bug in returning number of RBLs hit by a message. 1 Fixed problem causing some password-protected RAR archives to be missed. 3 Fixed bug introduced in earlier beta in RBL code. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From amaclach at yahoo.co.uk Mon May 28 00:43:21 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Mon May 28 00:43:22 2007 Subject: Beta release: 4.60.5 - compress attachments Message-ID: <258562.68661.qm@web26305.mail.ukl.yahoo.com> Works just like it says on the tin. Only observation is that the zip program doesn't like apostrophes in file names: "Employer's Liability Certificate.pdf" becomes "Employer%27s Lia.pdf" The file content remains intact, so not really an issue. -Andy ----- Original Message ---- From: Andrew MacLachlan To: MailScanner discussion Sent: Sunday, 27 May, 2007 11:48:59 PM Subject: Re: Beta release: 4.60.5 - compress attachments OK - I've installed it now and the new MailScanner.conf file has answered my question - yes it can. ----- Original Message ---- From: Andrew MacLachlan To: MailScanner discussion Sent: Sunday, 27 May, 2007 11:11:49 PM Subject: Re: Beta release: 4.60.5 - compress attachments Hi Julian, Sad as I am, I'm downloading it now. Just one question though: -Can this use a ruleset (e.g. only zip outbound messages)? -Andy ----- Original Message ---- From: Julian Field To: MailScanner discussion ; MailScanner beta testers Sent: Sunday, 27 May, 2007 9:51:57 PM Subject: Beta release: 4.60.5 - compress attachments I have just written the feature you wanted to compress attachments into a zip file. The new MailScanner.conf configuration settings for this are: # Should the attachments be compressed and put into a single zip file? # This can also be the filename of a ruleset. Zip Attachments = no # If the attachments are to be compressed into a single zip file, # this is the filename of the zip file. # This can also be the filename of a ruleset. Attachments Zip Filename = MessageAttachments.zip You will obviously want to set the first one to "yes" to use it :-) Please test this for me! It is switched off by default, so you will need to set it to "yes" in your MailScanner.conf file to use it. Download it as usual from www.mailscanner.info. The full Change Log for this version is... * New Features and Improvements * 1 Improved Sophos.install script so that it sets up /etc/ld.so.conf ready for installation of Perl-SAVI module required for "sophossavi" virus scanner. 1 Custom Functions can now receive parameters not only to their Init and End functions, but also to their run-time calculation functions (i.e. the real custom function itself used when processing each message). The Custom Function is now passed not only the message, but also a ref to a list of parameters specified in the MailScanner.conf file. 1 Improvement to phishing net. 1 'clamavmodule' scanner no longer detects encrypted zips/rars as viruses, leaving MailScanner to do the check later in the dangerous content scanning. The consequence is that MailWatch will allow them to be released from quarantine. 2 Updated a whole load of Perl modules in the pre-requisites lists for both MailScanner and SpamAssassin. 2 Added a "--nomodules" command-line option to the MailScanner install.sh script to skip installing required Perl modules. 2-2 Fixed bugs introduced by 4.60.2 in generic installer. Only affects 'other Linux and non-Linux' installer. 2-4 Fixed more non-Linux installer problems. 4 Added more modules to the list output by "MailScanner --version". 4 Improved phishing net detection of HTML tags, courtesy of snifer_@hotmail.com. 4 Added patches to provide full "p record" support in Postfix 2.3 and 2.4, courtesy of Glenn Steen . 5 Added a new feature, to compress all the attachments in a message and replace them with a single zip file. Set "Zip Attachments = yes" (no by default), and set "Attachments Zip Filename = MessageAttachments.zip" * Fixes * 1 Phishing net now correctly handles HTML tags inside links. 1 Deprecated clamscan flag replaced with supported one to stop it printing the summary. 1 Added '-b' to nod32-1.99 command-line options in SweepViruses.pm to stop scanner producing licensing details. Thanks to UxBoD. 1 Removed test in RPM distribution's test for RedHat 6 as it will clash with RHEL 6 and Fedora. Anyone still running RedHat 6 has bigger problems! :-) 1 Worked round Perl bug in returning number of RBLs hit by a message. 1 Fixed problem causing some password-protected RAR archives to be missed. 3 Fixed bug introduced in earlier beta in RBL code. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From wilson.galafassi at gmail.com Mon May 28 02:51:21 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Mon May 28 02:51:29 2007 Subject: mcp help Message-ID: Hello to all. I'm configuring mailscanner and mcp settings don't working. When i send or receive a mail with containing in the body the expression "test" the mail isn't mcp marked. Can someone tell me what i have to change? Very thanks. Wilson I have this in my cf file: body SAMPLE_RULE3 /test/i describe SAMPLE_RULE3 Banned body text score SAMPLE_RULE3 5 in MailScanner.conf i have: MCP Checks = yes # Do the spam checks first, or the MCP checks first? # This cannot be the filename of a ruleset, only a fixed value. First Check = mcp # The rest of these options are clones of the equivalent spam options MCP Required SpamAssassin Score = 1 MCP High SpamAssassin Score = 10 MCP Error Score = 1 MCP Header = X-%org-name%-MailScanner-MCPCheck: Non MCP Actions = deliver MCP Actions = deliver store High Scoring MCP Actions = store Bounce MCP As Attachment = no MCP Modify Subject = start MCP Subject Text = {MCP?} High Scoring MCP Modify Subject = start High Scoring MCP Subject Text = {MCP?} Is Definitely MCP = no Is Definitely Not MCP = no Definite MCP Is High Scoring = yes Always Include MCP Report = yes Detailed MCP Report = yes Include Scores In MCP Report = yes Log MCP = yes MCP Max SpamAssassin Timeouts = 20 MCP Max SpamAssassin Size = 100k MCP SpamAssassin Timeout = 10 MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf MCP SpamAssassin User State Dir = MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin Default Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = %mcp-dir% Recipient MCP Report = %report-dir%/recipient.mcp.report.txt Sender MCP Report = %report-dir%/sender.mcp.report.txt From lawrence.oduor at gmail.com Mon May 28 06:33:55 2007 From: lawrence.oduor at gmail.com (Lawi) Date: Mon May 28 06:33:57 2007 Subject: Fwd: MailScanner[9493]: New Batch: Found invalid queue files: In-Reply-To: <432baf410705212345h3e686814xcd25bb23aee00305@mail.gmail.com> References: <432baf410705212345h3e686814xcd25bb23aee00305@mail.gmail.com> Message-ID: <432baf410705272233y6ce29bb2we1e9d8f9554d1c2a@mail.gmail.com> hi guys, any help on this one?? ---------- Forwarded message ---------- From: Lawi Date: May 22, 2007 9:45 AM Subject: MailScanner[9493]: New Batch: Found invalid queue files: To: mailscanner@lists.mailscanner.info I have installed exim 6.47 and Mailscanner 4.59 and now i seem to be getting the error "format error in spool" for a number of messages awaiting delivery by exim on the exim log while MailScanner Says "Found invalid queue files" as shown in the Maillog below May 22 09:36:52 proxy3 MailScanner[9602]: Batch (1 message) processed in 13.79 seconds May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Found invalid queue files: 1HqBRW-0005w6-9i 1HqCcH-0006Ti-Ez 1HqEav-0007Gi-OK 1HqFpu-0007lx-4O 1HqLRJ-0001Wy-JE 1HqM1O-0001l4-6x 1HqMMz-0001uu-00 1HqMwH-0002D5-Qc 1HqNRU-0002Ut-1O May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Found 10 messages waiting May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Scanning 1 messages, 3309 bytes May 22 09:37:28 proxy3 MailScanner[9493]: Spam Checks completed at 423 bytes per second May 22 09:37:28 proxy3 MailScanner[9493]: Virus and Content Scanning: Starting May 22 09:37:29 proxy3 MailScanner[9493]: WARNING: Can't parse the configuration file. what is causing this problem? exim or mailscanner? what is this configuration file Mailscanner cannot parse? how is is it solved? regards, -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070528/7b62f0f3/attachment.html From hvdkooij at vanderkooij.org Mon May 28 07:27:37 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Mon May 28 07:28:14 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: <746377.68039.qm@web26308.mail.ukl.yahoo.com> References: <746377.68039.qm@web26308.mail.ukl.yahoo.com> Message-ID: On Sun, 27 May 2007, Andrew MacLachlan wrote: > Mailcontrol treats all 45x responses as 550 - although they should know better... If you can document it then you can ask them when they will fix it or just use the old equivalent of the tar and feathers and post a nice warning on bugtraq and such. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From j.ede at birchenallhowden.co.uk Mon May 28 08:13:13 2007 From: j.ede at birchenallhowden.co.uk (Jason Ede) Date: Mon May 28 08:11:07 2007 Subject: SpamCheck report References: <462304A8.6030103@ddihealth.com><46230EAC.5070600@ddihealth.com><46231A7E.4080003@netmagicsolutions.com><462498A6.2020507@ddihealth.com><03203FB5-AC29-4B0B-BFB3-F9802A419917@elec.ucl.ac.be><77F6B238A9BA7847840CFF3DFDC46E190BB0FE@server03.BHL2.local> <024CA64E-2F65-4219-9D66-EBCE566BB31F@elec.ucl.ac.be> Message-ID: <77F6B238A9BA7847840CFF3DFDC46E1905204B@server03.BHL2.local> Hmmm.... Simple, but neat :-) Can you use a custom function and a ruleset at the same time? i.e. using the authenticated header check along with an ordinary ruleset containing a list of whitelisted addresses? Jason ________________________________ From: mailscanner-bounces@lists.mailscanner.info on behalf of Pascal Maes Sent: Sun 27/05/2007 19:26 To: MailScanner discussion Subject: Re: SpamCheck report Le 27 mai 07 ? 15:51, Jason Ede a ?crit : > Hi, > > I don't suppose you'd be willing to share that custom function? We'd > like to do the same, but the only way I can see to do that so far > is to > have postfix include the SASL login username in the header which I'm > loathe to do if I can really avoid it. > > Jason Why not ? The first idea comes from the list so I could post it again. But first, thanks to Julian for his quick answer. ------8<------8<------8<------8<------8<------8<------8<------8<------8< ------8<------ package MailScanner::CustomConfig; use strict 'vars'; use strict 'refs'; no strict 'subs'; # Allow bare words for parameter %'s use vars qw($VERSION); ### The package version, both in 1.23 style *and* usable by MakeMaker: $VERSION = substr q$Revision: 2331 $, 10; sub InitCheckSMTPAuth { # Empty } sub EndCheckSMTPAuth { # Empty } sub CheckSMTPAuth { my ($message) = @_; return 1 unless $message; foreach (@{$message->{headers}}) { if (/PUT HERE THE STRING ABOUT THE AUTHENTICATION/) { MailScanner::Log::InfoLog("Message %s from (%s) is authenticated ($1)", $message->{id}, $message->{ fromuser}); $global::MS->{mta}->AddHeader($message, 'X-MailScanner- Spamcheck:', 'Authenticated'); return 0; } } return 1; } 1; ------8<------8<------8<------8<------8<------8<------8<------8<------8< ------8<------ -- Pascal -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ----------------------------------------------------------- The information in this e-mail and any attachments is confidential. It is intended solely for the attention and use of the named addressee(s). If you are not the intended recipient, or person responsible for delivering this information to the intended recipient, please notify the sender or email postmaster@birchenallhowden.co.uk and delete it from your computer systems. Unless you are the intended recipient or his/her representative you are not authorised to, and must not, read, copy, distribute, use or retain this message or any part of it. All messages are scanned by Mailscanner and are believed to be clean. Recipients are advised to apply their own virus checks to any message on delivery. No liability is accepted by BirchenallHowden Ltd for any losses caused by viruses contracted during transit over the internet or present in any receiving system. BirchenallHowden Ltd, 233 Edmund Road, Sheffield, S2 4EL -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070528/c7d2de11/attachment.html From uxbod at splatnix.net Mon May 28 09:20:15 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Mon May 28 09:17:20 2007 Subject: Fwd: MailScanner[9493]: New Batch: Found invalid queue files: In-Reply-To: <432baf410705272233y6ce29bb2we1e9d8f9554d1c2a@mail.gmail.com> References: <432baf410705212345h3e686814xcd25bb23aee00305@mail.gmail.com> <432baf410705272233y6ce29bb2we1e9d8f9554d1c2a@mail.gmail.com> Message-ID: <20070528092015.3e390d94@uxbod.splatnix.net> Try running /bin/MailScanner --lint If that is okay, then try running through in debug mode /bin/MailScanner --debug but ensure no other MailScanner processes are running. On Mon, 28 May 2007 08:33:55 +0300 Lawi wrote: > hi guys, any help on this one?? > > ---------- Forwarded message ---------- > From: Lawi > Date: May 22, 2007 9:45 AM > Subject: MailScanner[9493]: New Batch: Found invalid queue files: > To: mailscanner@lists.mailscanner.info > > I have installed exim 6.47 and Mailscanner 4.59 and now i seem to be > getting the error "format error in spool" for a number of messages > awaiting delivery by exim on the exim log while MailScanner Says > "Found invalid queue files" as shown in the Maillog below > > May 22 09:36:52 proxy3 MailScanner[9602]: Batch (1 message) processed > in 13.79 seconds > May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Found invalid > queue files: 1HqBRW-0005w6-9i 1HqCcH-0006Ti-Ez 1HqEav-0007Gi-OK > 1HqFpu-0007lx-4O 1HqLRJ-0001Wy-JE 1HqM1O-0001l4-6x 1HqMMz-0001uu-00 > 1HqMwH-0002D5-Qc 1HqNRU-0002Ut-1O > May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Found 10 messages > waiting > May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Scanning 1 > messages, 3309 bytes > May 22 09:37:28 proxy3 MailScanner[9493]: Spam Checks completed at > 423 bytes per second > May 22 09:37:28 proxy3 MailScanner[9493]: Virus and Content Scanning: > Starting > May 22 09:37:29 proxy3 MailScanner[9493]: WARNING: Can't parse the > configuration file. > > what is causing this problem? exim or mailscanner? what is this > configuration file Mailscanner cannot parse? how is is it solved? > > regards, > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 845 869 2749 // SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From glenn.steen at gmail.com Mon May 28 09:58:02 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Mon May 28 09:58:05 2007 Subject: MailScanner[9493]: New Batch: Found invalid queue files: In-Reply-To: <432baf410705272233y6ce29bb2we1e9d8f9554d1c2a@mail.gmail.com> References: <432baf410705212345h3e686814xcd25bb23aee00305@mail.gmail.com> <432baf410705272233y6ce29bb2we1e9d8f9554d1c2a@mail.gmail.com> Message-ID: <223f97700705280158pa581a66k877c4816fee284b@mail.gmail.com> On 28/05/07, Lawi wrote: > hi guys, any help on this one?? > (What a fright that subject line gave me (whatwith my changes to the Postfix code)... Until I saw it concerns Exim:-):-) I have really very little to add... That version number for Exim seems a tad newer than what the Exim gurus on the list (Martin etc) usually quote, so I'd guess some queue file format has changed/been added... Making the MS code that "interpretes" the queue file(s) carp a bit... Does the release notes for that version of Exim give any such clues? Other than that... --lint and --debug are good places to start looking, just as Phil advices... > ---------- Forwarded message ---------- > From: Lawi > Date: May 22, 2007 9:45 AM > Subject: MailScanner[9493]: New Batch: Found invalid queue files: > To: mailscanner@lists.mailscanner.info > > I have installed exim 6.47 and Mailscanner 4.59 and now i seem to be getting > the error "format error in spool" for a number of messages awaiting delivery > by exim on the exim log while MailScanner Says "Found invalid queue files" > as shown in the Maillog below > > May 22 09:36:52 proxy3 MailScanner[9602]: Batch (1 message) processed in > 13.79 seconds > May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Found invalid queue > files: 1HqBRW-0005w6-9i 1HqCcH-0006Ti-Ez 1HqEav-0007Gi-OK 1HqFpu-0007lx-4O > 1HqLRJ-0001Wy-JE 1HqM1O-0001l4-6x 1HqMMz-0001uu-00 1HqMwH-0002D5-Qc > 1HqNRU-0002Ut-1O > May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Found 10 messages > waiting > May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Scanning 1 messages, > 3309 bytes > May 22 09:37:28 proxy3 MailScanner[9493]: Spam Checks completed at 423 bytes > per second > May 22 09:37:28 proxy3 MailScanner[9493]: Virus and Content Scanning: > Starting > May 22 09:37:29 proxy3 MailScanner[9493]: WARNING: Can't parse the > configuration file. > > what is causing this problem? exim or mailscanner? what is this > configuration file Mailscanner cannot parse? how is is it solved? > > regards, Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Mon May 28 10:01:03 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Mon May 28 10:01:07 2007 Subject: SpamCheck report In-Reply-To: <77F6B238A9BA7847840CFF3DFDC46E1905204B@server03.BHL2.local> References: <462304A8.6030103@ddihealth.com> <46230EAC.5070600@ddihealth.com> <46231A7E.4080003@netmagicsolutions.com> <462498A6.2020507@ddihealth.com> <03203FB5-AC29-4B0B-BFB3-F9802A419917@elec.ucl.ac.be> <77F6B238A9BA7847840CFF3DFDC46E190BB0FE@server03.BHL2.local> <024CA64E-2F65-4219-9D66-EBCE566BB31F@elec.ucl.ac.be> <77F6B238A9BA7847840CFF3DFDC46E1905204B@server03.BHL2.local> Message-ID: <223f97700705280201q6cab6fd5gf1a703b751c4b6d1@mail.gmail.com> On 28/05/07, Jason Ede wrote: > > > > Hmmm.... Simple, but neat :-) > > Can you use a custom function and a ruleset at the same time? i.e. using the > authenticated header check along with an ordinary ruleset containing a list > of whitelisted addresses? > > Jason IIRC (always a point worth debating:-) Jules showed how to use a ruleset from within a custom function a while back... Search the archives and you might find a gem or two. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From wilson.galafassi at gmail.com Mon May 28 11:38:13 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Mon May 28 11:38:21 2007 Subject: mcp help Message-ID: Hello to all. I'm configuring mailscanner and mcp settings don't working. When i send or receive a mail with containing in the body the expression "test" the mail isn't mcp marked. Can someone tell me what i have to change? Very thanks. Wilson I have this in my cf file: body SAMPLE_RULE3 /test/i describe SAMPLE_RULE3 Banned body text score SAMPLE_RULE3 5 in MailScanner.conf i have: MCP Checks = yes # Do the spam checks first, or the MCP checks first? # This cannot be the filename of a ruleset, only a fixed value. First Check = mcp # The rest of these options are clones of the equivalent spam options MCP Required SpamAssassin Score = 1 MCP High SpamAssassin Score = 10 MCP Error Score = 1 MCP Header = X-%org-name%-MailScanner-MCPCheck: Non MCP Actions = deliver MCP Actions = deliver store High Scoring MCP Actions = store Bounce MCP As Attachment = no MCP Modify Subject = start MCP Subject Text = {MCP?} High Scoring MCP Modify Subject = start High Scoring MCP Subject Text = {MCP?} Is Definitely MCP = no Is Definitely Not MCP = no Definite MCP Is High Scoring = yes Always Include MCP Report = yes Detailed MCP Report = yes Include Scores In MCP Report = yes Log MCP = yes MCP Max SpamAssassin Timeouts = 20 MCP Max SpamAssassin Size = 100k MCP SpamAssassin Timeout = 10 MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf MCP SpamAssassin User State Dir = MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin Default Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = %mcp-dir% Recipient MCP Report = %report-dir%/recipient.mcp.report.txt Sender MCP Report = %report-dir%/sender.mcp.report.txt -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070528/dcc5ada5/attachment.html From wilson.galafassi at gmail.com Mon May 28 11:48:16 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Mon May 28 11:48:29 2007 Subject: MCP help Message-ID: Hello to all. I'm configuring mailscanner and mcp settings don't working. When i send or receive a mail with containing in the body the expression "test" the mail isn't mcp marked. Can someone tell me what i have to change? Very thanks. Wilson I have this in my cf file: body SAMPLE_RULE3 /test/i describe SAMPLE_RULE3 Banned body text score SAMPLE_RULE3 5 in MailScanner.conf i have: MCP Checks = yes # Do the spam checks first, or the MCP checks first? # This cannot be the filename of a ruleset, only a fixed value. First Check = mcp # The rest of these options are clones of the equivalent spam options MCP Required SpamAssassin Score = 1 MCP High SpamAssassin Score = 10 MCP Error Score = 1 MCP Header = X-%org-name%-MailScanner-MCPCheck: Non MCP Actions = deliver MCP Actions = deliver store High Scoring MCP Actions = store Bounce MCP As Attachment = no MCP Modify Subject = start MCP Subject Text = {MCP?} High Scoring MCP Modify Subject = start High Scoring MCP Subject Text = {MCP?} Is Definitely MCP = no Is Definitely Not MCP = no Definite MCP Is High Scoring = yes Always Include MCP Report = yes Detailed MCP Report = yes Include Scores In MCP Report = yes Log MCP = yes MCP Max SpamAssassin Timeouts = 20 MCP Max SpamAssassin Size = 100k MCP SpamAssassin Timeout = 10 MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf MCP SpamAssassin User State Dir = MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin Default Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = %mcp-dir% Recipient MCP Report = %report-dir%/recipient.mcp.report.txt Sender MCP Report = %report-dir%/sender.mcp.report.txt -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070528/31eb7131/attachment.html From wilson.galafassi at gmail.com Mon May 28 11:49:44 2007 From: wilson.galafassi at gmail.com (Wilson Galafassi) Date: Mon May 28 11:49:47 2007 Subject: mcp help Message-ID: <9774f0ba0705280349j7bcacbeag13051046b594ff2d@mail.gmail.com> Hello to all. I'm configuring mailscanner and mcp settings don't working. When i send or receive a mail with containing in the body the expression "test" the mail isn't mcp marked. Can someone tell me what i have to change? Very thanks. Wilson I have this in my cf file: body SAMPLE_RULE3 /test/i describe SAMPLE_RULE3 Banned body text score SAMPLE_RULE3 5 in MailScanner.conf i have: MCP Checks = yes # Do the spam checks first, or the MCP checks first? # This cannot be the filename of a ruleset, only a fixed value. First Check = mcp # The rest of these options are clones of the equivalent spam options MCP Required SpamAssassin Score = 1 MCP High SpamAssassin Score = 10 MCP Error Score = 1 MCP Header = X-%org-name%-MailScanner-MCPCheck: Non MCP Actions = deliver MCP Actions = deliver store High Scoring MCP Actions = store Bounce MCP As Attachment = no MCP Modify Subject = start MCP Subject Text = {MCP?} High Scoring MCP Modify Subject = start High Scoring MCP Subject Text = {MCP?} Is Definitely MCP = no Is Definitely Not MCP = no Definite MCP Is High Scoring = yes Always Include MCP Report = yes Detailed MCP Report = yes Include Scores In MCP Report = yes Log MCP = yes MCP Max SpamAssassin Timeouts = 20 MCP Max SpamAssassin Size = 100k MCP SpamAssassin Timeout = 10 MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf MCP SpamAssassin User State Dir = MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin Default Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = %mcp-dir% Recipient MCP Report = %report-dir%/recipient.mcp.report.txt Sender MCP Report = %report-dir%/sender.mcp.report.txt From uxbod at splatnix.net Mon May 28 11:54:36 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Mon May 28 11:51:38 2007 Subject: mcp help In-Reply-To: References: Message-ID: <20070528115436.731854e0@uxbod.splatnix.net> Hi, Would be useful to see what is in your configuration file with respect to MCP, and also what you have in your rules file. Thanks, On Mon, 28 May 2007 07:38:13 -0300 "Wilson A. Galafassi Jr." wrote: > Hello to all. > > > > I'm configuring mailscanner and mcp settings don't working. > > > > When i send or receive a mail with containing in the body the > expression "test" the mail isn't mcp marked. > > > > Can someone tell me what i have to change? > > > > Very thanks. > > > > Wilson > > > > > > I have this in my cf file: > > > > body SAMPLE_RULE3 /test/i > > describe SAMPLE_RULE3 Banned body text > > score SAMPLE_RULE3 5 > > > > > > in MailScanner.conf i have: > > > > MCP Checks = yes > > > > # Do the spam checks first, or the MCP checks first? > > # This cannot be the filename of a ruleset, only a fixed value. > > First Check = mcp > > > > # The rest of these options are clones of the equivalent spam options > MCP Required SpamAssassin Score = 1 MCP High SpamAssassin Score = 10 > MCP Error Score = 1 > > > > MCP Header = X-%org-name%-MailScanner-MCPCheck: > > Non MCP Actions = deliver > > MCP Actions = deliver store > > High Scoring MCP Actions = store > > Bounce MCP As Attachment = no > > > > MCP Modify Subject = start > > MCP Subject Text = {MCP?} > > High Scoring MCP Modify Subject = start > > High Scoring MCP Subject Text = {MCP?} > > > > Is Definitely MCP = no > > Is Definitely Not MCP = no > > Definite MCP Is High Scoring = yes > > Always Include MCP Report = yes > > Detailed MCP Report = yes > > Include Scores In MCP Report = yes > > Log MCP = yes > > > > MCP Max SpamAssassin Timeouts = 20 > > MCP Max SpamAssassin Size = 100k > > MCP SpamAssassin Timeout = 10 > > > > MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf > > MCP SpamAssassin User State Dir = > > MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin Default > Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = %mcp-dir% > Recipient MCP Report = %report-dir%/recipient.mcp.report.txt > > Sender MCP Report = %report-dir%/sender.mcp.report.txt > > > > > > > > > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 845 869 2749 // SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Mon May 28 12:29:15 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 28 12:33:39 2007 Subject: Beta release: 4.60.5 - compress attachments In-Reply-To: <997730.74570.qm@web26313.mail.ukl.yahoo.com> References: <997730.74570.qm@web26313.mail.ukl.yahoo.com> Message-ID: <465ABD0B.2030307@ecs.soton.ac.uk> Andrew MacLachlan wrote: > Hi Julian, > Sad as I am, I'm downloading it now. Just one question though: > -Can this use a ruleset (e.g. only zip outbound messages)? > My posting (below) answers your question :-) The answer is yes. > -Andy > > ----- Original Message ---- > From: Julian Field > To: MailScanner discussion ; MailScanner beta testers > Sent: Sunday, 27 May, 2007 9:51:57 PM > Subject: Beta release: 4.60.5 - compress attachments > > I have just written the feature you wanted to compress attachments into > a zip file. > > The new MailScanner.conf configuration settings for this are: > > # Should the attachments be compressed and put into a single zip file? > # This can also be the filename of a ruleset. > Zip Attachments = no > > # If the attachments are to be compressed into a single zip file, > # this is the filename of the zip file. > # This can also be the filename of a ruleset. > Attachments Zip Filename = MessageAttachments.zip > > You will obviously want to set the first one to "yes" to use it :-) > > Please test this for me! > It is switched off by default, so you will need to set it to "yes" in > your MailScanner.conf file to use it. > > Download it as usual from www.mailscanner.info. > > The full Change Log for this version is... > > * New Features and Improvements * > 1 Improved Sophos.install script so that it sets up /etc/ld.so.conf > ready for > installation of Perl-SAVI module required for "sophossavi" virus scanner. > 1 Custom Functions can now receive parameters not only to their Init and End > functions, but also to their run-time calculation functions (i.e. the real > custom function itself used when processing each message). The Custom > Function is now passed not only the message, but also a ref to a list of > parameters specified in the MailScanner.conf file. > 1 Improvement to phishing net. > 1 'clamavmodule' scanner no longer detects encrypted zips/rars as viruses, > leaving MailScanner to do the check later in the dangerous content > scanning. > The consequence is that MailWatch will allow them to be released from > quarantine. > 2 Updated a whole load of Perl modules in the pre-requisites lists for both > MailScanner and SpamAssassin. > 2 Added a "--nomodules" command-line option to the MailScanner install.sh > script to skip installing required Perl modules. > 2-2 Fixed bugs introduced by 4.60.2 in generic installer. Only affects > 'other > Linux and non-Linux' installer. > 2-4 Fixed more non-Linux installer problems. > 4 Added more modules to the list output by "MailScanner --version". > 4 Improved phishing net detection of HTML tags, courtesy of > snifer_@hotmail.com. > 4 Added patches to provide full "p record" support in Postfix 2.3 and 2.4, > courtesy of Glenn Steen . > 5 Added a new feature, to compress all the attachments in a message and > replace them with a single zip file. > Set "Zip Attachments = yes" (no by default), and > set "Attachments Zip Filename = MessageAttachments.zip" > > * Fixes * > 1 Phishing net now correctly handles HTML tags inside links. > 1 Deprecated clamscan flag replaced with supported one to stop it printing > the summary. > 1 Added '-b' to nod32-1.99 command-line options in SweepViruses.pm to stop > scanner producing licensing details. Thanks to UxBoD. > 1 Removed test in RPM distribution's test for RedHat 6 as it will clash with > RHEL 6 and Fedora. Anyone still running RedHat 6 has bigger problems! :-) > 1 Worked round Perl bug in returning number of RBLs hit by a message. > 1 Fixed problem causing some password-protected RAR archives to be missed. > 3 Fixed bug introduced in earlier beta in RBL code. > > Jules > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Mon May 28 12:31:34 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 28 12:33:53 2007 Subject: SpamCheck report In-Reply-To: <77F6B238A9BA7847840CFF3DFDC46E1905204B@server03.BHL2.local> References: <462304A8.6030103@ddihealth.com><46230EAC.5070600@ddihealth.com><46231A7E.4080003@netmagicsolutions.com><462498A6.2020507@ddihealth.com><03203FB5-AC29-4B0B-BFB3-F9802A419917@elec.ucl.ac.be><77F6B238A9BA7847840CFF3DFDC46E190BB0FE@server03.BHL2.local> <024CA64E-2F65-4219-9D66-EBCE566BB31F@elec.ucl.ac.be> <77F6B238A9BA7847840CFF3DFDC46E1905204B@server03.BHL2.local> Message-ID: <465ABD96.1020706@ecs.soton.ac.uk> Jason Ede wrote: > Hmmm.... Simple, but neat :-) > > Can you use a custom function and a ruleset at the same time? Yes. Take a look in the example in the /usr/lib/MailScanner/MailScanner/CustomFunctions directory. > i.e. using the authenticated header check along with an ordinary > ruleset containing a list of whitelisted addresses? > > Jason > > ------------------------------------------------------------------------ > *From:* mailscanner-bounces@lists.mailscanner.info on behalf of Pascal > Maes > *Sent:* Sun 27/05/2007 19:26 > *To:* MailScanner discussion > *Subject:* Re: SpamCheck report > > > Le 27 mai 07 ? 15:51, Jason Ede a ?crit : > > > Hi, > > > > I don't suppose you'd be willing to share that custom function? We'd > > like to do the same, but the only way I can see to do that so far > > is to > > have postfix include the SASL login username in the header which I'm > > loathe to do if I can really avoid it. > > > > Jason > > > Why not ? > The first idea comes from the list so I could post it again. > But first, thanks to Julian for his quick answer. > > ------8<------8<------8<------8<------8<------8<------8<------8<------8< > ------8<------ > > package MailScanner::CustomConfig; > > use strict 'vars'; > use strict 'refs'; > no strict 'subs'; # Allow bare words for parameter %'s > > use vars qw($VERSION); > > ### The package version, both in 1.23 style *and* usable by MakeMaker: > $VERSION = substr q$Revision: 2331 $, 10; > > sub InitCheckSMTPAuth > { > # Empty > } > > sub EndCheckSMTPAuth > { > # Empty > } > > sub CheckSMTPAuth > { > my ($message) = @_; > return 1 unless $message; > > foreach (@{$message->{headers}}) > { > if (/PUT HERE THE STRING ABOUT THE AUTHENTICATION/) > { > MailScanner::Log::InfoLog("Message %s from (%s) is > authenticated ($1)", $message->{id}, $message->{ > fromuser}); > $global::MS->{mta}->AddHeader($message, 'X-MailScanner- > Spamcheck:', 'Authenticated'); > return 0; > } > } > return 1; > } > > 1; > > ------8<------8<------8<------8<------8<------8<------8<------8<------8< > ------8<------ > > > -- > Pascal > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > ----------------------------------------------------------- > The information in this e-mail and any attachments is confidential. It > is intended solely for the attention and use of the named > addressee(s). If you are not the intended recipient, or person > responsible for delivering this information to the intended recipient, > please notify the sender or email postmaster@birchenallhowden.co.uk > and delete it from your computer systems. Unless you are the intended > recipient or his/her representative you are not authorised to, and > must not, read, copy, distribute, use or retain this message or any > part of it. All messages are scanned by Mailscanner and are believed > to be clean. Recipients are advised to apply their own virus checks to > any message on delivery. No liability is accepted by BirchenallHowden > Ltd for any losses caused by viruses contracted during transit over > the internet or present in any receiving system. BirchenallHowden Ltd, > 233 Edmund Road, Sheffield S2 4EL. > ----- *BirchenallHowden* Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From wilson.galafassi at gmail.com Mon May 28 13:17:35 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Mon May 28 13:17:46 2007 Subject: RES: mcp help In-Reply-To: <20070528115436.731854e0@uxbod.splatnix.net> References: <20070528115436.731854e0@uxbod.splatnix.net> Message-ID: I have only a cf file with this content: body SAMPLE_RULE3 /test/i describe SAMPLE_RULE3 Banned body text score SAMPLE_RULE3 5 what i need to have in rules file? -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de --[ UxBoD ]-- Enviada em: segunda-feira, 28 de maio de 2007 07:55 Para: mailscanner@lists.mailscanner.info Assunto: Re: mcp help Hi, Would be useful to see what is in your configuration file with respect to MCP, and also what you have in your rules file. Thanks, On Mon, 28 May 2007 07:38:13 -0300 "Wilson A. Galafassi Jr." wrote: > Hello to all. > > > > I'm configuring mailscanner and mcp settings don't working. > > > > When i send or receive a mail with containing in the body the > expression "test" the mail isn't mcp marked. > > > > Can someone tell me what i have to change? > > > > Very thanks. > > > > Wilson > > > > > > I have this in my cf file: > > > > body SAMPLE_RULE3 /test/i > > describe SAMPLE_RULE3 Banned body text > > score SAMPLE_RULE3 5 > > > > > > in MailScanner.conf i have: > > > > MCP Checks = yes > > > > # Do the spam checks first, or the MCP checks first? > > # This cannot be the filename of a ruleset, only a fixed value. > > First Check = mcp > > > > # The rest of these options are clones of the equivalent spam options > MCP Required SpamAssassin Score = 1 MCP High SpamAssassin Score = 10 > MCP Error Score = 1 > > > > MCP Header = X-%org-name%-MailScanner-MCPCheck: > > Non MCP Actions = deliver > > MCP Actions = deliver store > > High Scoring MCP Actions = store > > Bounce MCP As Attachment = no > > > > MCP Modify Subject = start > > MCP Subject Text = {MCP?} > > High Scoring MCP Modify Subject = start > > High Scoring MCP Subject Text = {MCP?} > > > > Is Definitely MCP = no > > Is Definitely Not MCP = no > > Definite MCP Is High Scoring = yes > > Always Include MCP Report = yes > > Detailed MCP Report = yes > > Include Scores In MCP Report = yes > > Log MCP = yes > > > > MCP Max SpamAssassin Timeouts = 20 > > MCP Max SpamAssassin Size = 100k > > MCP SpamAssassin Timeout = 10 > > > > MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf > > MCP SpamAssassin User State Dir = > > MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin Default > Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = %mcp-dir% > Recipient MCP Report = %report-dir%/recipient.mcp.report.txt > > Sender MCP Report = %report-dir%/sender.mcp.report.txt > > > > > > > > > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 845 869 2749 // SIP Phone: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From jan-peter at koopmann.eu Mon May 28 13:20:46 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Mon May 28 13:20:56 2007 Subject: Beta release: 4.60.5 - compress attachments In-Reply-To: <4659EF6D.2070107@ecs.soton.ac.uk> References: <4659EF6D.2070107@ecs.soton.ac.uk> Message-ID: On Sunday, May 27, 2007 10:52 PM Julian Field wrote: > I have just written the feature you wanted to compress attachments > into > a zip file. Wow. > Please test this for me! First tests show all is working. It would be great if later on you could decide what attachments you want to be compressed automatically. Examples: - messages with more than one attachment - attachment size --> makes no sense to zip a 100k file - filetype --> makes no sense to zip archives, movies, mp3 etc. But I am still impressed with the speed of you implementing this feature request! Great! Kind regards, JP From lawrence.oduor at gmail.com Mon May 28 13:36:18 2007 From: lawrence.oduor at gmail.com (Lawi) Date: Mon May 28 13:36:25 2007 Subject: Fwd: MailScanner[9493]: New Batch: Found invalid queue files: In-Reply-To: <20070528092015.3e390d94@uxbod.splatnix.net> References: <432baf410705212345h3e686814xcd25bb23aee00305@mail.gmail.com> <432baf410705272233y6ce29bb2we1e9d8f9554d1c2a@mail.gmail.com> <20070528092015.3e390d94@uxbod.splatnix.net> Message-ID: <432baf410705280536r2c7f3106w2aa9886a690476d7@mail.gmail.com> after doing a /bin/MailScanner --lint this is what i get [root@proxy3 ~]# /usr/sbin/MailScanner --lint Could not read file /var/run/MailScanner.pid at /usr/lib/MailScanner/MailScanner/Config.pm line 2367 Error in line 167, file "/var/run/MailScanner.pid" for pidfile does not exist (or can not be read) at /usr/lib/MailScanner/MailScanner/Config.pm line 2547 Read 764 hostnames from the phishing whitelist Checking version numbers... Version number in MailScanner.conf (4.59.4) is correct. MailScanner setting GID to (93) MailScanner setting UID to (93) but i can see clearly the pid specified in side Mailscanner.conf is /var/run/MailScanner.pid On 5/28/07, --[ UxBoD ]-- wrote: > > Try running /bin/MailScanner --lint > > If that is okay, then try running through in debug mode MailScanner>/bin/MailScanner --debug > > but ensure no other MailScanner processes are running. > > On Mon, 28 May 2007 08:33:55 +0300 > Lawi wrote: > > > hi guys, any help on this one?? > > > > ---------- Forwarded message ---------- > > From: Lawi > > Date: May 22, 2007 9:45 AM > > Subject: MailScanner[9493]: New Batch: Found invalid queue files: > > To: mailscanner@lists.mailscanner.info > > > > I have installed exim 6.47 and Mailscanner 4.59 and now i seem to be > > getting the error "format error in spool" for a number of messages > > awaiting delivery by exim on the exim log while MailScanner Says > > "Found invalid queue files" as shown in the Maillog below > > > > May 22 09:36:52 proxy3 MailScanner[9602]: Batch (1 message) processed > > in 13.79 seconds > > May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Found invalid > > queue files: 1HqBRW-0005w6-9i 1HqCcH-0006Ti-Ez 1HqEav-0007Gi-OK > > 1HqFpu-0007lx-4O 1HqLRJ-0001Wy-JE 1HqM1O-0001l4-6x 1HqMMz-0001uu-00 > > 1HqMwH-0002D5-Qc 1HqNRU-0002Ut-1O > > May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Found 10 messages > > waiting > > May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Scanning 1 > > messages, 3309 bytes > > May 22 09:37:28 proxy3 MailScanner[9493]: Spam Checks completed at > > 423 bytes per second > > May 22 09:37:28 proxy3 MailScanner[9493]: Virus and Content Scanning: > > Starting > > May 22 09:37:29 proxy3 MailScanner[9493]: WARNING: Can't parse the > > configuration file. > > > > what is causing this problem? exim or mailscanner? what is this > > configuration file Mailscanner cannot parse? how is is it solved? > > > > regards, > > > > > -- > --[ UxBoD ]-- > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > // Phone: +44 845 869 2749 > // SIP Phone: uxbod@sip.splatnix.net > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070528/5f82ead3/attachment.html From uxbod at splatnix.net Mon May 28 13:48:36 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Mon May 28 13:45:43 2007 Subject: mcp help In-Reply-To: References: <20070528115436.731854e0@uxbod.splatnix.net> Message-ID: <20070528134836.1dd12365@uxbod.splatnix.net> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Have you run MailScanner using --lint and --debug-sa ? On Mon, 28 May 2007 09:17:35 -0300 "Wilson A. Galafassi Jr." wrote: > I have only a cf file with this content: > > body SAMPLE_RULE3 /test/i > describe SAMPLE_RULE3 Banned body text > score SAMPLE_RULE3 5 > > what i need to have in rules file? > > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de > --[ UxBoD ]-- Enviada em: segunda-feira, 28 de maio de 2007 07:55 > Para: mailscanner@lists.mailscanner.info > Assunto: Re: mcp help > > Hi, > > Would be useful to see what is in your configuration file with respect > to MCP, and also what you have in your rules file. > > Thanks, > > On Mon, 28 May 2007 07:38:13 -0300 > "Wilson A. Galafassi Jr." wrote: > > > Hello to all. > > > > > > > > I'm configuring mailscanner and mcp settings don't working. > > > > > > > > When i send or receive a mail with containing in the body the > > expression "test" the mail isn't mcp marked. > > > > > > > > Can someone tell me what i have to change? > > > > > > > > Very thanks. > > > > > > > > Wilson > > > > > > > > > > > > I have this in my cf file: > > > > > > > > body SAMPLE_RULE3 /test/i > > > > describe SAMPLE_RULE3 Banned body text > > > > score SAMPLE_RULE3 5 > > > > > > > > > > > > in MailScanner.conf i have: > > > > > > > > MCP Checks = yes > > > > > > > > # Do the spam checks first, or the MCP checks first? > > > > # This cannot be the filename of a ruleset, only a fixed value. > > > > First Check = mcp > > > > > > > > # The rest of these options are clones of the equivalent spam > > options MCP Required SpamAssassin Score = 1 MCP High SpamAssassin > > Score = 10 MCP Error Score = 1 > > > > > > > > MCP Header = X-%org-name%-MailScanner-MCPCheck: > > > > Non MCP Actions = deliver > > > > MCP Actions = deliver store > > > > High Scoring MCP Actions = store > > > > Bounce MCP As Attachment = no > > > > > > > > MCP Modify Subject = start > > > > MCP Subject Text = {MCP?} > > > > High Scoring MCP Modify Subject = start > > > > High Scoring MCP Subject Text = {MCP?} > > > > > > > > Is Definitely MCP = no > > > > Is Definitely Not MCP = no > > > > Definite MCP Is High Scoring = yes > > > > Always Include MCP Report = yes > > > > Detailed MCP Report = yes > > > > Include Scores In MCP Report = yes > > > > Log MCP = yes > > > > > > > > MCP Max SpamAssassin Timeouts = 20 > > > > MCP Max SpamAssassin Size = 100k > > > > MCP SpamAssassin Timeout = 10 > > > > > > > > MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf > > > > MCP SpamAssassin User State Dir = > > > > MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin > > Default Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = > > %mcp-dir% Recipient MCP Report = > > %report-dir%/recipient.mcp.report.txt > > > > Sender MCP Report = %report-dir%/sender.mcp.report.txt > > > > > > > > > > > > > > > > > > > > > > - -- - --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.4 (GNU/Linux) iD8DBQFGWs+nH7GwL121aHsRAlTJAJ94n3+bJ6WRqXmi/Vgd7Eul0rB9KACeKGDI MkJKF8NSnFpI9Ry7dD/fzrk= =YGdg -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From johan.boye at latecoere.fr Mon May 28 13:46:15 2007 From: johan.boye at latecoere.fr (johan.boye@latecoere.fr) Date: Mon May 28 13:46:19 2007 Subject: Attachment Warning Filename Question Message-ID: Hello guys, I've been just registered and I tried to click on link above & it fails, same for you guys ? Welcome to the list. Before you post, *please* read http://wiki.mailscanner.info/posting (it's very short). Anyway, here is my question : I'm using Mailscanner since a couple of week and it works great. I just have a question regarding the "Attachment Warning Filename" functionnality. I wish send an email to the recipient when an email for him is blocked, It activated that : Warning Is Attachment = yes Attachment Warning Filename = %report-dir%/stored.filename.message.txt My default installation Mailscanner dir is : /opt/MailScanner/ But this is not sending any email to the recipient, did i mist something ? Thanks by advance, Johan "Les informations contenues dans ce message electronique peuvent etre de nature confidentielles et soumises a une obligation de secret. Elles sont destinees a l'usage exclusif du reel destinataire. Si vous n'etes pas le reel destinataire, ou si vous recevez ce message par erreur, merci de le detruire immediatement et de le notifier a son emetteur." "The information contained in this e-mail may be privileged and confidential. It is intended for the exclusive use of the designated recipients named above. If you are not the intended recipient or if you receive this e-mail in error, please delete it and immediately notify the sender." From uxbod at splatnix.net Mon May 28 14:24:37 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Mon May 28 14:21:45 2007 Subject: Fwd: MailScanner[9493]: New Batch: Found invalid queue files: In-Reply-To: <432baf410705280536r2c7f3106w2aa9886a690476d7@mail.gmail.com> References: <432baf410705212345h3e686814xcd25bb23aee00305@mail.gmail.com> <432baf410705272233y6ce29bb2we1e9d8f9554d1c2a@mail.gmail.com> <20070528092015.3e390d94@uxbod.splatnix.net> <432baf410705280536r2c7f3106w2aa9886a690476d7@mail.gmail.com> Message-ID: <20070528142437.3d351333@uxbod.splatnix.net> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Shutdown MailScanner, remove the .pid and restart. What user have you defined for MailScanner to run as ? What are the permissions on the PID file ? What user are you running the lint test as ? On Mon, 28 May 2007 15:36:18 +0300 Lawi wrote: > after doing a /bin/MailScanner --lint > > this is what i get > > [root@proxy3 ~]# /usr/sbin/MailScanner --lint > Could not read file /var/run/MailScanner.pid at > /usr/lib/MailScanner/MailScanner/Config.pm line 2367 > Error in line 167, file "/var/run/MailScanner.pid" for pidfile does > not exist (or can not be read) > at /usr/lib/MailScanner/MailScanner/Config.pm line 2547 > Read 764 hostnames from the phishing whitelist > Checking version numbers... > Version number in MailScanner.conf (4.59.4) is correct. > MailScanner setting GID to (93) > MailScanner setting UID to (93) > > > but i can see clearly the pid specified in side Mailscanner.conf is > /var/run/MailScanner.pid > > > On 5/28/07, --[ UxBoD ]-- wrote: > > > > Try running /bin/MailScanner --lint > > > > If that is okay, then try running through in debug mode > MailScanner>/bin/MailScanner --debug > > > > but ensure no other MailScanner processes are running. > > > > On Mon, 28 May 2007 08:33:55 +0300 > > Lawi wrote: > > > > > hi guys, any help on this one?? > > > > > > ---------- Forwarded message ---------- > > > From: Lawi > > > Date: May 22, 2007 9:45 AM > > > Subject: MailScanner[9493]: New Batch: Found invalid queue files: > > > To: mailscanner@lists.mailscanner.info > > > > > > I have installed exim 6.47 and Mailscanner 4.59 and now i seem to > > > be getting the error "format error in spool" for a number of > > > messages awaiting delivery by exim on the exim log while > > > MailScanner Says "Found invalid queue files" as shown in the > > > Maillog below > > > > > > May 22 09:36:52 proxy3 MailScanner[9602]: Batch (1 message) > > > processed in 13.79 seconds > > > May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Found invalid > > > queue files: 1HqBRW-0005w6-9i 1HqCcH-0006Ti-Ez 1HqEav-0007Gi-OK > > > 1HqFpu-0007lx-4O 1HqLRJ-0001Wy-JE 1HqM1O-0001l4-6x > > > 1HqMMz-0001uu-00 1HqMwH-0002D5-Qc 1HqNRU-0002Ut-1O > > > May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Found 10 > > > messages waiting > > > May 22 09:37:21 proxy3 MailScanner[9493]: New Batch: Scanning 1 > > > messages, 3309 bytes > > > May 22 09:37:28 proxy3 MailScanner[9493]: Spam Checks completed at > > > 423 bytes per second > > > May 22 09:37:28 proxy3 MailScanner[9493]: Virus and Content > > > Scanning: Starting > > > May 22 09:37:29 proxy3 MailScanner[9493]: WARNING: Can't parse the > > > configuration file. > > > > > > what is causing this problem? exim or mailscanner? what is this > > > configuration file Mailscanner cannot parse? how is is it solved? > > > > > > regards, > > > > > > > > > -- > > --[ UxBoD ]-- > > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg > > --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 > > E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > > // Phone: +44 845 869 2749 > > // SIP Phone: uxbod@sip.splatnix.net > > > > -- > > This message has been scanned for viruses and dangerous content by > > MailScanner, and is > > believed to be clean. > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > - -- - --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.4 (GNU/Linux) iD8DBQFGWtgYH7GwL121aHsRAtjlAKCHjzndafOUSzhihlm+0uF5O3IqoQCgjf2O NIKdpaopndJThSnqcUbDyKU= =75g7 -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From glenn.steen at gmail.com Mon May 28 14:37:45 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Mon May 28 14:37:48 2007 Subject: Attachment Warning Filename Question In-Reply-To: References: Message-ID: <223f97700705280637v5bf31d22hfe4f2ab9d8b5f4d1@mail.gmail.com> On 28/05/07, johan.boye@latecoere.fr wrote: > Hello guys, > > I've been just registered and I tried to click on link above & it fails, > same for you guys ? > Welcome to the list. Before you post, *please* read > http://wiki.mailscanner.info/posting (it's very short). Seems a redirect to http://wiki.mailscanner.info/doku.php?id=lists:posting_guidelines is lacking there... :-). > Anyway, here is my question : > I'm using Mailscanner since a couple of week and it works great. I > just have a question regarding the "Attachment Warning Filename" > functionnality. > I wish send an email to the recipient when an email for him is > blocked, It activated that : > > Warning Is Attachment = yes > Attachment Warning Filename = > %report-dir%/stored.filename.message.txt > > My default installation Mailscanner dir is : /opt/MailScanner/ > But this is not sending any email to the recipient, did i mist > something ? > > > Thanks by advance, > > Johan Likely what you have there is OK, just that you never instruct MS to actually use it:-). Check your "Silent Viruses" and "Still Deliver Silent Viruses" settings, and perhaps some more (attachment "actions" for unacceptable attachment types etc). -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From wilson.galafassi at gmail.com Mon May 28 15:37:37 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Mon May 28 15:37:51 2007 Subject: RES: mcp help In-Reply-To: <20070528134836.1dd12365@uxbod.splatnix.net> References: <20070528115436.731854e0@uxbod.splatnix.net> <20070528134836.1dd12365@uxbod.splatnix.net> Message-ID: Hello. Here is my output using --debug-sa and --lint I'm not using rbl checks. This is done by my external Server. [root@netserver MailScanner]# /usr/sbin/MailScanner --debug-sa In Debugging mode, not forking... [5447] dbg: logger: adding facilities: all [5447] dbg: logger: logging level is DBG [5447] dbg: generic: SpamAssassin version 3.2.0 [5447] dbg: config: score set 0 chosen. [5447] dbg: util: running in taint mode? no [5447] dbg: dns: no ipv6 [5447] dbg: dns: is Net::DNS::Resolver available? yes [5447] dbg: dns: Net::DNS version: 0.59 [5447] dbg: config: mkdir /no/where/.spamassassin failed: mkdir /no: Permission denied at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm line 1578 [5447] dbg: config: Permission denied [5447] info: config: failed to parse line, skipping, in "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf": use_dcc 0 [5447] info: config: failed to parse line, skipping, in "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf": use_pyzor 0 [5447] info: config: failed to parse line, skipping, in "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf": use_razor1 0 [5447] info: config: failed to parse line, skipping, in "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf": use_razor2 0 [5447] info: config: failed to parse line, skipping, in "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf": decode_attachments 1 [5447] dbg: logger: adding facilities: all [5447] dbg: logger: logging level is DBG [5447] dbg: generic: SpamAssassin version 3.2.0 [5447] dbg: config: score set 0 chosen. [5447] dbg: dns: no ipv6 [5447] dbg: dns: is Net::DNS::Resolver available? yes [5447] dbg: dns: Net::DNS version: 0.59 Use of uninitialized value in concatenation (.) or string at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm line 1087. Use of uninitialized value in concatenation (.) or string at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm line 1089. [5447] dbg: config: read_scoreonly_config: cannot open "": No such file or directory [root@netserver MailScanner]# /usr/sbin/MailScanner --lint Read 764 hostnames from the phishing whitelist Config: calling custom init function SQLBlacklist Config: calling custom init function MailWatchLogging Config: calling custom init function SQLWhitelist Checking version numbers... Version number in MailScanner.conf (4.59.4) is correct. MailScanner setting GID to (12345) MailScanner setting UID to (12345) Checking for SpamAssassin errors (if you use it)... Using SpamAssassin results cache Connected to SpamAssassin cache database config: SpamAssassin failed to parse line, "/usr/bin/pyzor" is not valid for "pyzor_path", skipping: pyzor_path /usr/bin/pyzor config: failed to parse line, skipping, in "/etc/mail/spamassassin/mailscanner.cf": use_dcc 0 SpamAssassin reported an error. lock.pl sees Config LockType = flock lock.pl sees have_module = 0 Using locktype = flock MailScanner.conf says "Virus Scanners = clamav" Found these virus scanners installed: clamav, clamd -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de --[ UxBoD ]-- Enviada em: segunda-feira, 28 de maio de 2007 09:49 Para: mailscanner@lists.mailscanner.info Assunto: Re: mcp help -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Have you run MailScanner using --lint and --debug-sa ? On Mon, 28 May 2007 09:17:35 -0300 "Wilson A. Galafassi Jr." wrote: > I have only a cf file with this content: > > body SAMPLE_RULE3 /test/i > describe SAMPLE_RULE3 Banned body text > score SAMPLE_RULE3 5 > > what i need to have in rules file? > > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de --[ > UxBoD ]-- Enviada em: segunda-feira, 28 de maio de 2007 07:55 > Para: mailscanner@lists.mailscanner.info > Assunto: Re: mcp help > > Hi, > > Would be useful to see what is in your configuration file with respect > to MCP, and also what you have in your rules file. > > Thanks, > > On Mon, 28 May 2007 07:38:13 -0300 > "Wilson A. Galafassi Jr." wrote: > > > Hello to all. > > > > > > > > I'm configuring mailscanner and mcp settings don't working. > > > > > > > > When i send or receive a mail with containing in the body the > > expression "test" the mail isn't mcp marked. > > > > > > > > Can someone tell me what i have to change? > > > > > > > > Very thanks. > > > > > > > > Wilson > > > > > > > > > > > > I have this in my cf file: > > > > > > > > body SAMPLE_RULE3 /test/i > > > > describe SAMPLE_RULE3 Banned body text > > > > score SAMPLE_RULE3 5 > > > > > > > > > > > > in MailScanner.conf i have: > > > > > > > > MCP Checks = yes > > > > > > > > # Do the spam checks first, or the MCP checks first? > > > > # This cannot be the filename of a ruleset, only a fixed value. > > > > First Check = mcp > > > > > > > > # The rest of these options are clones of the equivalent spam > > options MCP Required SpamAssassin Score = 1 MCP High SpamAssassin > > Score = 10 MCP Error Score = 1 > > > > > > > > MCP Header = X-%org-name%-MailScanner-MCPCheck: > > > > Non MCP Actions = deliver > > > > MCP Actions = deliver store > > > > High Scoring MCP Actions = store > > > > Bounce MCP As Attachment = no > > > > > > > > MCP Modify Subject = start > > > > MCP Subject Text = {MCP?} > > > > High Scoring MCP Modify Subject = start > > > > High Scoring MCP Subject Text = {MCP?} > > > > > > > > Is Definitely MCP = no > > > > Is Definitely Not MCP = no > > > > Definite MCP Is High Scoring = yes > > > > Always Include MCP Report = yes > > > > Detailed MCP Report = yes > > > > Include Scores In MCP Report = yes > > > > Log MCP = yes > > > > > > > > MCP Max SpamAssassin Timeouts = 20 > > > > MCP Max SpamAssassin Size = 100k > > > > MCP SpamAssassin Timeout = 10 > > > > > > > > MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf > > > > MCP SpamAssassin User State Dir = > > > > MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin > > Default Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = > > %mcp-dir% Recipient MCP Report = > > %report-dir%/recipient.mcp.report.txt > > > > Sender MCP Report = %report-dir%/sender.mcp.report.txt > > > > > > > > > > > > > > > > > > > > > > - -- - --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.4 (GNU/Linux) iD8DBQFGWs+nH7GwL121aHsRAlTJAJ94n3+bJ6WRqXmi/Vgd7Eul0rB9KACeKGDI MkJKF8NSnFpI9Ry7dD/fzrk= =YGdg -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From MailScanner at ecs.soton.ac.uk Mon May 28 15:39:21 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 28 15:42:35 2007 Subject: RES: mcp help In-Reply-To: References: <20070528115436.731854e0@uxbod.splatnix.net> Message-ID: <465AE999.8040005@ecs.soton.ac.uk> What is the name and location of this cf file? Is it being read when MailScanner starts? Do 'ls -lu /etc/MailScanner/mcp' Then wait a minute or two Then 'MailScanner -debug' Then 'ls -lu /etc/MailScanner/mcp' The 'last used' date stamp on the file should have changed. If it hasn't then the file isn't being read, and there's your problem. Wilson A. Galafassi Jr. wrote: > I have only a cf file with this content: > > body SAMPLE_RULE3 /test/i > describe SAMPLE_RULE3 Banned body text > score SAMPLE_RULE3 5 > > what i need to have in rules file? > > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de --[ UxBoD ]-- > Enviada em: segunda-feira, 28 de maio de 2007 07:55 > Para: mailscanner@lists.mailscanner.info > Assunto: Re: mcp help > > Hi, > > Would be useful to see what is in your configuration file with respect > to MCP, and also what you have in your rules file. > > Thanks, > > On Mon, 28 May 2007 07:38:13 -0300 > "Wilson A. Galafassi Jr." wrote: > > >> Hello to all. >> >> >> >> I'm configuring mailscanner and mcp settings don't working. >> >> >> >> When i send or receive a mail with containing in the body the >> expression "test" the mail isn't mcp marked. >> >> >> >> Can someone tell me what i have to change? >> >> >> >> Very thanks. >> >> >> >> Wilson >> >> >> >> >> >> I have this in my cf file: >> >> >> >> body SAMPLE_RULE3 /test/i >> >> describe SAMPLE_RULE3 Banned body text >> >> score SAMPLE_RULE3 5 >> >> >> >> >> >> in MailScanner.conf i have: >> >> >> >> MCP Checks = yes >> >> >> >> # Do the spam checks first, or the MCP checks first? >> >> # This cannot be the filename of a ruleset, only a fixed value. >> >> First Check = mcp >> >> >> >> # The rest of these options are clones of the equivalent spam options >> MCP Required SpamAssassin Score = 1 MCP High SpamAssassin Score = 10 >> MCP Error Score = 1 >> >> >> >> MCP Header = X-%org-name%-MailScanner-MCPCheck: >> >> Non MCP Actions = deliver >> >> MCP Actions = deliver store >> >> High Scoring MCP Actions = store >> >> Bounce MCP As Attachment = no >> >> >> >> MCP Modify Subject = start >> >> MCP Subject Text = {MCP?} >> >> High Scoring MCP Modify Subject = start >> >> High Scoring MCP Subject Text = {MCP?} >> >> >> >> Is Definitely MCP = no >> >> Is Definitely Not MCP = no >> >> Definite MCP Is High Scoring = yes >> >> Always Include MCP Report = yes >> >> Detailed MCP Report = yes >> >> Include Scores In MCP Report = yes >> >> Log MCP = yes >> >> >> >> MCP Max SpamAssassin Timeouts = 20 >> >> MCP Max SpamAssassin Size = 100k >> >> MCP SpamAssassin Timeout = 10 >> >> >> >> MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf >> >> MCP SpamAssassin User State Dir = >> >> MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin Default >> Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = %mcp-dir% >> Recipient MCP Report = %report-dir%/recipient.mcp.report.txt >> >> Sender MCP Report = %report-dir%/sender.mcp.report.txt >> >> >> >> >> >> >> >> >> >> >> > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From wilson.galafassi at gmail.com Mon May 28 15:57:46 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Mon May 28 15:58:01 2007 Subject: RES: RES: mcp help In-Reply-To: <465AE999.8040005@ecs.soton.ac.uk> References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> Message-ID: The file is readed. The time is changed. -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field Enviada em: segunda-feira, 28 de maio de 2007 11:39 Para: MailScanner discussion Assunto: Re: RES: mcp help What is the name and location of this cf file? Is it being read when MailScanner starts? Do 'ls -lu /etc/MailScanner/mcp' Then wait a minute or two Then 'MailScanner -debug' Then 'ls -lu /etc/MailScanner/mcp' The 'last used' date stamp on the file should have changed. If it hasn't then the file isn't being read, and there's your problem. Wilson A. Galafassi Jr. wrote: > I have only a cf file with this content: > > body SAMPLE_RULE3 /test/i > describe SAMPLE_RULE3 Banned body text > score SAMPLE_RULE3 5 > > what i need to have in rules file? > > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de --[ UxBoD ]-- > Enviada em: segunda-feira, 28 de maio de 2007 07:55 > Para: mailscanner@lists.mailscanner.info > Assunto: Re: mcp help > > Hi, > > Would be useful to see what is in your configuration file with respect > to MCP, and also what you have in your rules file. > > Thanks, > > On Mon, 28 May 2007 07:38:13 -0300 > "Wilson A. Galafassi Jr." wrote: > > >> Hello to all. >> >> >> >> I'm configuring mailscanner and mcp settings don't working. >> >> >> >> When i send or receive a mail with containing in the body the >> expression "test" the mail isn't mcp marked. >> >> >> >> Can someone tell me what i have to change? >> >> >> >> Very thanks. >> >> >> >> Wilson >> >> >> >> >> >> I have this in my cf file: >> >> >> >> body SAMPLE_RULE3 /test/i >> >> describe SAMPLE_RULE3 Banned body text >> >> score SAMPLE_RULE3 5 >> >> >> >> >> >> in MailScanner.conf i have: >> >> >> >> MCP Checks = yes >> >> >> >> # Do the spam checks first, or the MCP checks first? >> >> # This cannot be the filename of a ruleset, only a fixed value. >> >> First Check = mcp >> >> >> >> # The rest of these options are clones of the equivalent spam options >> MCP Required SpamAssassin Score = 1 MCP High SpamAssassin Score = 10 >> MCP Error Score = 1 >> >> >> >> MCP Header = X-%org-name%-MailScanner-MCPCheck: >> >> Non MCP Actions = deliver >> >> MCP Actions = deliver store >> >> High Scoring MCP Actions = store >> >> Bounce MCP As Attachment = no >> >> >> >> MCP Modify Subject = start >> >> MCP Subject Text = {MCP?} >> >> High Scoring MCP Modify Subject = start >> >> High Scoring MCP Subject Text = {MCP?} >> >> >> >> Is Definitely MCP = no >> >> Is Definitely Not MCP = no >> >> Definite MCP Is High Scoring = yes >> >> Always Include MCP Report = yes >> >> Detailed MCP Report = yes >> >> Include Scores In MCP Report = yes >> >> Log MCP = yes >> >> >> >> MCP Max SpamAssassin Timeouts = 20 >> >> MCP Max SpamAssassin Size = 100k >> >> MCP SpamAssassin Timeout = 10 >> >> >> >> MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf >> >> MCP SpamAssassin User State Dir = >> >> MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin Default >> Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = %mcp-dir% >> Recipient MCP Report = %report-dir%/recipient.mcp.report.txt >> >> Sender MCP Report = %report-dir%/sender.mcp.report.txt >> >> >> >> >> >> >> >> >> >> >> > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From wilson.galafassi at gmail.com Mon May 28 16:01:36 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Mon May 28 16:01:47 2007 Subject: RES: RES: mcp help In-Reply-To: <465AE999.8040005@ecs.soton.ac.uk> References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> Message-ID: Running in debug mode i see: [7297] dbg: config: mkdir /no/where/.spamassassin failed: mkdir /no: Permission denied at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm line 1578 I can't find where to change this setting. This is related to my mcp problem? -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field Enviada em: segunda-feira, 28 de maio de 2007 11:39 Para: MailScanner discussion Assunto: Re: RES: mcp help What is the name and location of this cf file? Is it being read when MailScanner starts? Do 'ls -lu /etc/MailScanner/mcp' Then wait a minute or two Then 'MailScanner -debug' Then 'ls -lu /etc/MailScanner/mcp' The 'last used' date stamp on the file should have changed. If it hasn't then the file isn't being read, and there's your problem. Wilson A. Galafassi Jr. wrote: > I have only a cf file with this content: > > body SAMPLE_RULE3 /test/i > describe SAMPLE_RULE3 Banned body text > score SAMPLE_RULE3 5 > > what i need to have in rules file? > > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de --[ UxBoD ]-- > Enviada em: segunda-feira, 28 de maio de 2007 07:55 > Para: mailscanner@lists.mailscanner.info > Assunto: Re: mcp help > > Hi, > > Would be useful to see what is in your configuration file with respect > to MCP, and also what you have in your rules file. > > Thanks, > > On Mon, 28 May 2007 07:38:13 -0300 > "Wilson A. Galafassi Jr." wrote: > > >> Hello to all. >> >> >> >> I'm configuring mailscanner and mcp settings don't working. >> >> >> >> When i send or receive a mail with containing in the body the >> expression "test" the mail isn't mcp marked. >> >> >> >> Can someone tell me what i have to change? >> >> >> >> Very thanks. >> >> >> >> Wilson >> >> >> >> >> >> I have this in my cf file: >> >> >> >> body SAMPLE_RULE3 /test/i >> >> describe SAMPLE_RULE3 Banned body text >> >> score SAMPLE_RULE3 5 >> >> >> >> >> >> in MailScanner.conf i have: >> >> >> >> MCP Checks = yes >> >> >> >> # Do the spam checks first, or the MCP checks first? >> >> # This cannot be the filename of a ruleset, only a fixed value. >> >> First Check = mcp >> >> >> >> # The rest of these options are clones of the equivalent spam options >> MCP Required SpamAssassin Score = 1 MCP High SpamAssassin Score = 10 >> MCP Error Score = 1 >> >> >> >> MCP Header = X-%org-name%-MailScanner-MCPCheck: >> >> Non MCP Actions = deliver >> >> MCP Actions = deliver store >> >> High Scoring MCP Actions = store >> >> Bounce MCP As Attachment = no >> >> >> >> MCP Modify Subject = start >> >> MCP Subject Text = {MCP?} >> >> High Scoring MCP Modify Subject = start >> >> High Scoring MCP Subject Text = {MCP?} >> >> >> >> Is Definitely MCP = no >> >> Is Definitely Not MCP = no >> >> Definite MCP Is High Scoring = yes >> >> Always Include MCP Report = yes >> >> Detailed MCP Report = yes >> >> Include Scores In MCP Report = yes >> >> Log MCP = yes >> >> >> >> MCP Max SpamAssassin Timeouts = 20 >> >> MCP Max SpamAssassin Size = 100k >> >> MCP SpamAssassin Timeout = 10 >> >> >> >> MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf >> >> MCP SpamAssassin User State Dir = >> >> MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin Default >> Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = %mcp-dir% >> Recipient MCP Report = %report-dir%/recipient.mcp.report.txt >> >> Sender MCP Report = %report-dir%/sender.mcp.report.txt >> >> >> >> >> >> >> >> >> >> >> > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Mon May 28 15:59:35 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 28 16:02:24 2007 Subject: Attachment Warning Filename Question In-Reply-To: <223f97700705280637v5bf31d22hfe4f2ab9d8b5f4d1@mail.gmail.com> References: <223f97700705280637v5bf31d22hfe4f2ab9d8b5f4d1@mail.gmail.com> Message-ID: <465AEE57.1090006@ecs.soton.ac.uk> Glenn Steen wrote: > On 28/05/07, johan.boye@latecoere.fr wrote: >> Hello guys, >> >> I've been just registered and I tried to click on link above & it fails, >> same for you guys ? >> Welcome to the list. Before you post, *please* read >> http://wiki.mailscanner.info/posting (it's very short). > > Seems a redirect to > http://wiki.mailscanner.info/doku.php?id=lists:posting_guidelines is > lacking there... :-). I'm working on this, with never-ending help and assistance (thank you guys at Blacknight Solutions!). > >> Anyway, here is my question : >> I'm using Mailscanner since a couple of week and it works great. I >> just have a question regarding the "Attachment Warning Filename" >> functionnality. >> I wish send an email to the recipient when an email for him is >> blocked, It activated that : >> >> Warning Is Attachment = yes >> Attachment Warning Filename = >> %report-dir%/stored.filename.message.txt That option wants a filename to put into the delivered message, not the contents of the file. Something like Attachment Warning Filename = %org-name%-Attachments-Read-Me.txt would be a suitable setting IIRC. It's what the replacement attachment warning will be called, not what will go in it. If you can come up with a better explanation than is currently in the MailScanner.conf file, then please let me know, as the current explanation is far from ideal. If you want to set the text to go into the Attachments-Read-Me.txt, then you should be setting # Set where to find the message text sent to users when one of their # attachments has been deleted from a message. # These can also be the filenames of rulesets. Deleted Bad Content Message Report = %report-dir%/deleted.content.message.txt Deleted Bad Filename Message Report = %report-dir%/deleted.filename.message.txt Deleted Virus Message Report = %report-dir%/deleted.virus.message.txt Deleted Size Message Report = %report-dir%/deleted.size.message.txt # Set where to find the message text sent to users when one of their # attachments has been deleted from a message and stored in the quarantine. # These can also be the filenames of rulesets. Stored Bad Content Message Report = %report-dir%/stored.content.message.txt Stored Bad Filename Message Report = %report-dir%/stored.filename.message.txt Stored Virus Message Report = %report-dir%/stored.virus.message.txt Stored Size Message Report = %report-dir%/stored.size.message.txt >> >> My default installation Mailscanner dir is : /opt/MailScanner/ >> But this is not sending any email to the recipient, did i mist >> something ? >> >> >> Thanks by advance, >> >> Johan > > Likely what you have there is OK, just that you never instruct MS to > actually use it:-). > > Check your "Silent Viruses" and "Still Deliver Silent Viruses" > settings, and perhaps some more (attachment "actions" for unacceptable > attachment types etc). > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Mon May 28 16:08:26 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 28 16:09:29 2007 Subject: Beta release: 4.60.5 - compress attachments In-Reply-To: References: <4659EF6D.2070107@ecs.soton.ac.uk> Message-ID: <465AF06A.1030706@ecs.soton.ac.uk> Koopmann, Jan-Peter wrote: > - attachment size --> makes no sense to zip a 100k file > - filetype --> makes no sense to zip archives, movies, mp3 etc. > Who else wants these? The filetype checks would be done by filename suffix, not by reading the actual file or launching any external program (such as the 'file' command). I don't want to make this a huge heavyweight beast. Zip Attachments Minimum Size = 100k Don't Zip Attachments Ending = .zip .rar .gz .mp3 .mpg .mpeg If I do implement either of these, this is as complicated as it's going to get. Who wants either (please specify which one) or both of these settings? Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Mon May 28 16:10:49 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 28 16:12:31 2007 Subject: RES: RES: mcp help In-Reply-To: References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> Message-ID: <465AF0F9.3030504@ecs.soton.ac.uk> Make sure that the account you are using for MailScanner (set in "Run As User =" in MailScanner.conf) can write to its home directory. If it doesn't have a home directory, then create one. Looks like you are using Postfix or Exim and their home dir is set in /etc/passwd to "/no/where". Wilson A. Galafassi Jr. wrote: > Running in debug mode i see: > [7297] dbg: config: mkdir /no/where/.spamassassin failed: mkdir /no: > Permission denied at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm > line 1578 > > I can't find where to change this setting. > This is related to my mcp problem? > > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field > Enviada em: segunda-feira, 28 de maio de 2007 11:39 > Para: MailScanner discussion > Assunto: Re: RES: mcp help > > What is the name and location of this cf file? > Is it being read when MailScanner starts? > Do 'ls -lu /etc/MailScanner/mcp' > Then wait a minute or two > Then 'MailScanner -debug' > Then 'ls -lu /etc/MailScanner/mcp' > The 'last used' date stamp on the file should have changed. If it hasn't > then the file isn't being read, and there's your problem. > > Wilson A. Galafassi Jr. wrote: > >> I have only a cf file with this content: >> >> body SAMPLE_RULE3 /test/i >> describe SAMPLE_RULE3 Banned body text >> score SAMPLE_RULE3 5 >> >> what i need to have in rules file? >> >> -----Mensagem original----- >> De: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de --[ UxBoD >> > ]-- > >> Enviada em: segunda-feira, 28 de maio de 2007 07:55 >> Para: mailscanner@lists.mailscanner.info >> Assunto: Re: mcp help >> >> Hi, >> >> Would be useful to see what is in your configuration file with respect >> to MCP, and also what you have in your rules file. >> >> Thanks, >> >> On Mon, 28 May 2007 07:38:13 -0300 >> "Wilson A. Galafassi Jr." wrote: >> >> >> >>> Hello to all. >>> >>> >>> >>> I'm configuring mailscanner and mcp settings don't working. >>> >>> >>> >>> When i send or receive a mail with containing in the body the >>> expression "test" the mail isn't mcp marked. >>> >>> >>> >>> Can someone tell me what i have to change? >>> >>> >>> >>> Very thanks. >>> >>> >>> >>> Wilson >>> >>> >>> >>> >>> >>> I have this in my cf file: >>> >>> >>> >>> body SAMPLE_RULE3 /test/i >>> >>> describe SAMPLE_RULE3 Banned body text >>> >>> score SAMPLE_RULE3 5 >>> >>> >>> >>> >>> >>> in MailScanner.conf i have: >>> >>> >>> >>> MCP Checks = yes >>> >>> >>> >>> # Do the spam checks first, or the MCP checks first? >>> >>> # This cannot be the filename of a ruleset, only a fixed value. >>> >>> First Check = mcp >>> >>> >>> >>> # The rest of these options are clones of the equivalent spam options >>> MCP Required SpamAssassin Score = 1 MCP High SpamAssassin Score = 10 >>> MCP Error Score = 1 >>> >>> >>> >>> MCP Header = X-%org-name%-MailScanner-MCPCheck: >>> >>> Non MCP Actions = deliver >>> >>> MCP Actions = deliver store >>> >>> High Scoring MCP Actions = store >>> >>> Bounce MCP As Attachment = no >>> >>> >>> >>> MCP Modify Subject = start >>> >>> MCP Subject Text = {MCP?} >>> >>> High Scoring MCP Modify Subject = start >>> >>> High Scoring MCP Subject Text = {MCP?} >>> >>> >>> >>> Is Definitely MCP = no >>> >>> Is Definitely Not MCP = no >>> >>> Definite MCP Is High Scoring = yes >>> >>> Always Include MCP Report = yes >>> >>> Detailed MCP Report = yes >>> >>> Include Scores In MCP Report = yes >>> >>> Log MCP = yes >>> >>> >>> >>> MCP Max SpamAssassin Timeouts = 20 >>> >>> MCP Max SpamAssassin Size = 100k >>> >>> MCP SpamAssassin Timeout = 10 >>> >>> >>> >>> MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf >>> >>> MCP SpamAssassin User State Dir = >>> >>> MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin Default >>> Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = %mcp-dir% >>> Recipient MCP Report = %report-dir%/recipient.mcp.report.txt >>> >>> Sender MCP Report = %report-dir%/sender.mcp.report.txt >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >> >> > > Jules > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From amaclach at yahoo.co.uk Mon May 28 16:19:51 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Mon May 28 16:19:52 2007 Subject: Beta release: 4.60.5 - compress attachments Message-ID: <398103.542.qm@web26307.mail.ukl.yahoo.com> I would suggest 2 rules: Don't zip anything when the total attachments are under say 100kb (nice to have) Don't zip archives (zip, rar, *gz etc - base this on filename though) (nicer to have) I can't see too many people complaining if you hardcoded these. (asbestos suit on just in case) -Andy ----- Original Message ---- From: Julian Field To: MailScanner Beta-testers Cc: MailScanner discussion Sent: Monday, 28 May, 2007 4:08:26 PM Subject: Re: Beta release: 4.60.5 - compress attachments Koopmann, Jan-Peter wrote: > - attachment size --> makes no sense to zip a 100k file > - filetype --> makes no sense to zip archives, movies, mp3 etc. > Who else wants these? The filetype checks would be done by filename suffix, not by reading the actual file or launching any external program (such as the 'file' command). I don't want to make this a huge heavyweight beast. Zip Attachments Minimum Size = 100k Don't Zip Attachments Ending = .zip .rar .gz .mp3 .mpg .mpeg If I do implement either of these, this is as complicated as it's going to get. Who wants either (please specify which one) or both of these settings? Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From MailScanner at ecs.soton.ac.uk Mon May 28 16:23:59 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 28 16:25:11 2007 Subject: Attachment Warning Filename Question In-Reply-To: References: Message-ID: <465AF40F.5080806@ecs.soton.ac.uk> johan.boye@latecoere.fr wrote: > Hello guys, > > I've been just registered and I tried to click on link above & it fails, > same for you guys ? > Welcome to the list. Before you post, *please* read > http://wiki.mailscanner.info/posting (it's very short). > I surprise myself sometimes: I added a couple of lines to a .htaccess file and not only was it the right .htaccess file in the right place, but my additions worked first time! This is almost unprecedented! :-) I'm not good with .htaccess, like a lot people I believe. Anyway that link should work now. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Mon May 28 16:30:36 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 28 16:31:28 2007 Subject: Beta release: 4.60.5 - compress attachments In-Reply-To: <398103.542.qm@web26307.mail.ukl.yahoo.com> References: <398103.542.qm@web26307.mail.ukl.yahoo.com> Message-ID: <465AF59C.8030006@ecs.soton.ac.uk> Andrew MacLachlan wrote: > I would suggest 2 rules: > Don't zip anything when the total attachments are under say 100kb (nice to have) > Good point about it being the total size, not the size of each attachment. I'll go for that instead of measuring the size of each attachment. > Don't zip archives (zip, rar, *gz etc - base this on filename though) (nicer to have) > > I can't see too many people complaining if you hardcoded these. (asbestos suit on just in case) > Hardcoding in one version usually upsets enough people that they become configurable in the next version :-) > -Andy > > ----- Original Message ---- > From: Julian Field > To: MailScanner Beta-testers > Cc: MailScanner discussion > Sent: Monday, 28 May, 2007 4:08:26 PM > Subject: Re: Beta release: 4.60.5 - compress attachments > > > > Koopmann, Jan-Peter wrote: > >> - attachment size --> makes no sense to zip a 100k file >> - filetype --> makes no sense to zip archives, movies, mp3 etc. >> >> > Who else wants these? The filetype checks would be done by filename > suffix, not by reading the actual file or launching any external program > (such as the 'file' command). I don't want to make this a huge > heavyweight beast. > > Zip Attachments Minimum Size = 100k > Don't Zip Attachments Ending = .zip .rar .gz .mp3 .mpg .mpeg > > If I do implement either of these, this is as complicated as it's going > to get. > Who wants either (please specify which one) or both of these settings? > > Jules > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From wilson.galafassi at gmail.com Mon May 28 16:34:05 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Mon May 28 16:34:23 2007 Subject: RES: RES: RES: mcp help In-Reply-To: <465AF0F9.3030504@ecs.soton.ac.uk> References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> Message-ID: Fixed. But mcp still don't working. Any suggestion? May 28 12:31:37 netserver MailScanner[13591]: New Batch: Scanning 1 messages, 1885 bytes May 28 12:31:37 netserver MailScanner[13591]: Created attachment dirs for 1 messages May 28 12:31:37 netserver MailScanner[13591]: MCP Checks: Starting May 28 12:31:37 netserver MailScanner[13591]: Message Content Protection SpamAssassin returned 512 May 28 12:31:39 netserver MailScanner[13591]: SpamAssassin returned 0 May 28 12:31:39 netserver MailScanner[13591]: Virus and Content Scanning: Starting May 28 12:31:39 netserver MailScanner[13591]: Commencing scanning by clamav... May 28 12:31:47 netserver MailScanner[13591]: Completed scanning by clamav May 28 12:31:47 netserver MailScanner[13591]: Completed checking by /usr/bin/file May 28 12:31:47 netserver MailScanner[13591]: Requeue: 46CF01086FB.48D13 to 6438F1086FD May 28 12:31:47 netserver MailScanner[13591]: About to deliver 1 messages May 28 12:31:47 netserver postfix/qmgr[13574]: 6438F1086FD: from=, size=1367, nrcpt=1 (queue active) May 28 12:31:47 netserver MailScanner[13591]: Uninfected: Delivered 1 messages May 28 12:31:47 netserver MailScanner[13591]: Logging message 46CF01086FB.48D13 to SQL May 28 12:31:47 netserver MailScanner[13594]: 46CF01086FB.48D13: Logged to MailWatch SQL May 28 12:31:47 netserver MailScanner[13591]: Config: calling custom end function SQLBlacklist May 28 12:31:47 netserver MailScanner[13591]: Closing down by-domain spam blacklist May 28 12:31:47 netserver MailScanner[13591]: Config: calling custom end function MailWatchLogging May 28 12:31:47 netserver MailScanner[13591]: Config: calling custom end function SQLWhitelist May 28 12:31:47 netserver MailScanner[13591]: Closing down by-domain spam whitelist May 28 12:31:47 netserver MailScanner[13591]: MailScanner child dying of old age May 28 12:31:51 netserver postfix/smtp[13631]: 6438F1086FD: to=, relay=ftpmanager.com[65.132.196.114]:25, delay=20, delays=16/0.02/3.2/0.85, dsn=2.0.0, status=sent (250 OK id=1HshCI-0007g4-TE) May 28 12:31:51 netserver postfix/qmgr[13574]: 6438F1086FD: removed -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field Enviada em: segunda-feira, 28 de maio de 2007 12:11 Para: MailScanner discussion Assunto: Re: RES: RES: mcp help Make sure that the account you are using for MailScanner (set in "Run As User =" in MailScanner.conf) can write to its home directory. If it doesn't have a home directory, then create one. Looks like you are using Postfix or Exim and their home dir is set in /etc/passwd to "/no/where". Wilson A. Galafassi Jr. wrote: > Running in debug mode i see: > [7297] dbg: config: mkdir /no/where/.spamassassin failed: mkdir /no: > Permission denied at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm > line 1578 > > I can't find where to change this setting. > This is related to my mcp problem? > > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field > Enviada em: segunda-feira, 28 de maio de 2007 11:39 > Para: MailScanner discussion > Assunto: Re: RES: mcp help > > What is the name and location of this cf file? > Is it being read when MailScanner starts? > Do 'ls -lu /etc/MailScanner/mcp' > Then wait a minute or two > Then 'MailScanner -debug' > Then 'ls -lu /etc/MailScanner/mcp' > The 'last used' date stamp on the file should have changed. If it hasn't > then the file isn't being read, and there's your problem. > > Wilson A. Galafassi Jr. wrote: > >> I have only a cf file with this content: >> >> body SAMPLE_RULE3 /test/i >> describe SAMPLE_RULE3 Banned body text >> score SAMPLE_RULE3 5 >> >> what i need to have in rules file? >> >> -----Mensagem original----- >> De: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de --[ UxBoD >> > ]-- > >> Enviada em: segunda-feira, 28 de maio de 2007 07:55 >> Para: mailscanner@lists.mailscanner.info >> Assunto: Re: mcp help >> >> Hi, >> >> Would be useful to see what is in your configuration file with respect >> to MCP, and also what you have in your rules file. >> >> Thanks, >> >> On Mon, 28 May 2007 07:38:13 -0300 >> "Wilson A. Galafassi Jr." wrote: >> >> >> >>> Hello to all. >>> >>> >>> >>> I'm configuring mailscanner and mcp settings don't working. >>> >>> >>> >>> When i send or receive a mail with containing in the body the >>> expression "test" the mail isn't mcp marked. >>> >>> >>> >>> Can someone tell me what i have to change? >>> >>> >>> >>> Very thanks. >>> >>> >>> >>> Wilson >>> >>> >>> >>> >>> >>> I have this in my cf file: >>> >>> >>> >>> body SAMPLE_RULE3 /test/i >>> >>> describe SAMPLE_RULE3 Banned body text >>> >>> score SAMPLE_RULE3 5 >>> >>> >>> >>> >>> >>> in MailScanner.conf i have: >>> >>> >>> >>> MCP Checks = yes >>> >>> >>> >>> # Do the spam checks first, or the MCP checks first? >>> >>> # This cannot be the filename of a ruleset, only a fixed value. >>> >>> First Check = mcp >>> >>> >>> >>> # The rest of these options are clones of the equivalent spam options >>> MCP Required SpamAssassin Score = 1 MCP High SpamAssassin Score = 10 >>> MCP Error Score = 1 >>> >>> >>> >>> MCP Header = X-%org-name%-MailScanner-MCPCheck: >>> >>> Non MCP Actions = deliver >>> >>> MCP Actions = deliver store >>> >>> High Scoring MCP Actions = store >>> >>> Bounce MCP As Attachment = no >>> >>> >>> >>> MCP Modify Subject = start >>> >>> MCP Subject Text = {MCP?} >>> >>> High Scoring MCP Modify Subject = start >>> >>> High Scoring MCP Subject Text = {MCP?} >>> >>> >>> >>> Is Definitely MCP = no >>> >>> Is Definitely Not MCP = no >>> >>> Definite MCP Is High Scoring = yes >>> >>> Always Include MCP Report = yes >>> >>> Detailed MCP Report = yes >>> >>> Include Scores In MCP Report = yes >>> >>> Log MCP = yes >>> >>> >>> >>> MCP Max SpamAssassin Timeouts = 20 >>> >>> MCP Max SpamAssassin Size = 100k >>> >>> MCP SpamAssassin Timeout = 10 >>> >>> >>> >>> MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf >>> >>> MCP SpamAssassin User State Dir = >>> >>> MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin Default >>> Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = %mcp-dir% >>> Recipient MCP Report = %report-dir%/recipient.mcp.report.txt >>> >>> Sender MCP Report = %report-dir%/sender.mcp.report.txt >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >> >> > > Jules > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From amaclach at yahoo.co.uk Mon May 28 16:50:04 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Mon May 28 16:50:06 2007 Subject: possible enhancement request Message-ID: <178215.9566.qm@web26310.mail.ukl.yahoo.com> How difficult would it be to remove old footers off the bottom of forwards/replies - e.g. I have a click to report as spam link in the footer of my incoming messages (not in outbound messages for obvious reasons!): This message was scanned by ESVA and is believed to be clean. Click here to report this message as spam. http://mail-gw.global-domination.org/cgi-bin/learn-msg.cgi?id=756162822B.0F47C I guess the request has two purposes: - Remove the report as spam link for outbound messages to prevent Bayes poisoning from inadvertent clicks - Clean up the mass of footers in an email exchange for tidiness. Snowball's chance? From wilson.galafassi at gmail.com Mon May 28 16:52:07 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Mon May 28 16:52:17 2007 Subject: RES: RES: mcp help In-Reply-To: <465AE999.8040005@ecs.soton.ac.uk> References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> Message-ID: Hello. Using debug-sa option i have this other error: Use of uninitialized value in concatenation (.) or string at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm line 1087. Use of uninitialized value in concatenation (.) or string at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm line 1089. [14206] dbg: config: read_scoreonly_config: cannot open "": No such file or directory -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field Enviada em: segunda-feira, 28 de maio de 2007 11:39 Para: MailScanner discussion Assunto: Re: RES: mcp help What is the name and location of this cf file? Is it being read when MailScanner starts? Do 'ls -lu /etc/MailScanner/mcp' Then wait a minute or two Then 'MailScanner -debug' Then 'ls -lu /etc/MailScanner/mcp' The 'last used' date stamp on the file should have changed. If it hasn't then the file isn't being read, and there's your problem. Wilson A. Galafassi Jr. wrote: > I have only a cf file with this content: > > body SAMPLE_RULE3 /test/i > describe SAMPLE_RULE3 Banned body text > score SAMPLE_RULE3 5 > > what i need to have in rules file? > > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de --[ UxBoD ]-- > Enviada em: segunda-feira, 28 de maio de 2007 07:55 > Para: mailscanner@lists.mailscanner.info > Assunto: Re: mcp help > > Hi, > > Would be useful to see what is in your configuration file with respect > to MCP, and also what you have in your rules file. > > Thanks, > > On Mon, 28 May 2007 07:38:13 -0300 > "Wilson A. Galafassi Jr." wrote: > > >> Hello to all. >> >> >> >> I'm configuring mailscanner and mcp settings don't working. >> >> >> >> When i send or receive a mail with containing in the body the >> expression "test" the mail isn't mcp marked. >> >> >> >> Can someone tell me what i have to change? >> >> >> >> Very thanks. >> >> >> >> Wilson >> >> >> >> >> >> I have this in my cf file: >> >> >> >> body SAMPLE_RULE3 /test/i >> >> describe SAMPLE_RULE3 Banned body text >> >> score SAMPLE_RULE3 5 >> >> >> >> >> >> in MailScanner.conf i have: >> >> >> >> MCP Checks = yes >> >> >> >> # Do the spam checks first, or the MCP checks first? >> >> # This cannot be the filename of a ruleset, only a fixed value. >> >> First Check = mcp >> >> >> >> # The rest of these options are clones of the equivalent spam options >> MCP Required SpamAssassin Score = 1 MCP High SpamAssassin Score = 10 >> MCP Error Score = 1 >> >> >> >> MCP Header = X-%org-name%-MailScanner-MCPCheck: >> >> Non MCP Actions = deliver >> >> MCP Actions = deliver store >> >> High Scoring MCP Actions = store >> >> Bounce MCP As Attachment = no >> >> >> >> MCP Modify Subject = start >> >> MCP Subject Text = {MCP?} >> >> High Scoring MCP Modify Subject = start >> >> High Scoring MCP Subject Text = {MCP?} >> >> >> >> Is Definitely MCP = no >> >> Is Definitely Not MCP = no >> >> Definite MCP Is High Scoring = yes >> >> Always Include MCP Report = yes >> >> Detailed MCP Report = yes >> >> Include Scores In MCP Report = yes >> >> Log MCP = yes >> >> >> >> MCP Max SpamAssassin Timeouts = 20 >> >> MCP Max SpamAssassin Size = 100k >> >> MCP SpamAssassin Timeout = 10 >> >> >> >> MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf >> >> MCP SpamAssassin User State Dir = >> >> MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin Default >> Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = %mcp-dir% >> Recipient MCP Report = %report-dir%/recipient.mcp.report.txt >> >> Sender MCP Report = %report-dir%/sender.mcp.report.txt >> >> >> >> >> >> >> >> >> >> >> > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From wilson.galafassi at gmail.com Mon May 28 17:07:18 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Mon May 28 17:07:30 2007 Subject: RES: RES: RES: mcp help In-Reply-To: <465AF0F9.3030504@ecs.soton.ac.uk> References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> Message-ID: If i put in the /etc/MailScanner/spam.assassin.prefs.conf body MY_RULE_2 /Block this too/i score MY_RULE_2 100 the mail is marked as spam. But if i put in the my cf file inside mcp directory the same rule the message isn't mcp marked. Thanks for all, Wilson -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field Enviada em: segunda-feira, 28 de maio de 2007 12:11 Para: MailScanner discussion Assunto: Re: RES: RES: mcp help Make sure that the account you are using for MailScanner (set in "Run As User =" in MailScanner.conf) can write to its home directory. If it doesn't have a home directory, then create one. Looks like you are using Postfix or Exim and their home dir is set in /etc/passwd to "/no/where". Wilson A. Galafassi Jr. wrote: > Running in debug mode i see: > [7297] dbg: config: mkdir /no/where/.spamassassin failed: mkdir /no: > Permission denied at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm > line 1578 > > I can't find where to change this setting. > This is related to my mcp problem? > > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field > Enviada em: segunda-feira, 28 de maio de 2007 11:39 > Para: MailScanner discussion > Assunto: Re: RES: mcp help > > What is the name and location of this cf file? > Is it being read when MailScanner starts? > Do 'ls -lu /etc/MailScanner/mcp' > Then wait a minute or two > Then 'MailScanner -debug' > Then 'ls -lu /etc/MailScanner/mcp' > The 'last used' date stamp on the file should have changed. If it hasn't > then the file isn't being read, and there's your problem. > > Wilson A. Galafassi Jr. wrote: > >> I have only a cf file with this content: >> >> body SAMPLE_RULE3 /test/i >> describe SAMPLE_RULE3 Banned body text >> score SAMPLE_RULE3 5 >> >> what i need to have in rules file? >> >> -----Mensagem original----- >> De: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de --[ UxBoD >> > ]-- > >> Enviada em: segunda-feira, 28 de maio de 2007 07:55 >> Para: mailscanner@lists.mailscanner.info >> Assunto: Re: mcp help >> >> Hi, >> >> Would be useful to see what is in your configuration file with respect >> to MCP, and also what you have in your rules file. >> >> Thanks, >> >> On Mon, 28 May 2007 07:38:13 -0300 >> "Wilson A. Galafassi Jr." wrote: >> >> >> >>> Hello to all. >>> >>> >>> >>> I'm configuring mailscanner and mcp settings don't working. >>> >>> >>> >>> When i send or receive a mail with containing in the body the >>> expression "test" the mail isn't mcp marked. >>> >>> >>> >>> Can someone tell me what i have to change? >>> >>> >>> >>> Very thanks. >>> >>> >>> >>> Wilson >>> >>> >>> >>> >>> >>> I have this in my cf file: >>> >>> >>> >>> body SAMPLE_RULE3 /test/i >>> >>> describe SAMPLE_RULE3 Banned body text >>> >>> score SAMPLE_RULE3 5 >>> >>> >>> >>> >>> >>> in MailScanner.conf i have: >>> >>> >>> >>> MCP Checks = yes >>> >>> >>> >>> # Do the spam checks first, or the MCP checks first? >>> >>> # This cannot be the filename of a ruleset, only a fixed value. >>> >>> First Check = mcp >>> >>> >>> >>> # The rest of these options are clones of the equivalent spam options >>> MCP Required SpamAssassin Score = 1 MCP High SpamAssassin Score = 10 >>> MCP Error Score = 1 >>> >>> >>> >>> MCP Header = X-%org-name%-MailScanner-MCPCheck: >>> >>> Non MCP Actions = deliver >>> >>> MCP Actions = deliver store >>> >>> High Scoring MCP Actions = store >>> >>> Bounce MCP As Attachment = no >>> >>> >>> >>> MCP Modify Subject = start >>> >>> MCP Subject Text = {MCP?} >>> >>> High Scoring MCP Modify Subject = start >>> >>> High Scoring MCP Subject Text = {MCP?} >>> >>> >>> >>> Is Definitely MCP = no >>> >>> Is Definitely Not MCP = no >>> >>> Definite MCP Is High Scoring = yes >>> >>> Always Include MCP Report = yes >>> >>> Detailed MCP Report = yes >>> >>> Include Scores In MCP Report = yes >>> >>> Log MCP = yes >>> >>> >>> >>> MCP Max SpamAssassin Timeouts = 20 >>> >>> MCP Max SpamAssassin Size = 100k >>> >>> MCP SpamAssassin Timeout = 10 >>> >>> >>> >>> MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf >>> >>> MCP SpamAssassin User State Dir = >>> >>> MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin Default >>> Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = %mcp-dir% >>> Recipient MCP Report = %report-dir%/recipient.mcp.report.txt >>> >>> Sender MCP Report = %report-dir%/sender.mcp.report.txt >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >> >> > > Jules > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From jlcostinha at halla.pt Mon May 28 17:16:15 2007 From: jlcostinha at halla.pt (Jorge Costinha) Date: Mon May 28 17:16:21 2007 Subject: Reject mail from invalid domains Message-ID: <465B004F.1@halla.pt> hi all, im using Fedora core 6, with Mailscanner 4.59.4 and sendmail 8.13.8. I want to block email from invalid domains. Can i do this with Mailscanner/spamassassin or has to be done at MTA level? thanks. From uxbod at splatnix.net Mon May 28 17:24:21 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Mon May 28 17:21:25 2007 Subject: mcp help In-Reply-To: References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> Message-ID: <20070528172421.68cb5c01@uxbod.splatnix.net> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Wilson, I think you need to concentrate on your SA perms and configuration. Get them right first and then re-check. UxBoD On Mon, 28 May 2007 12:34:05 -0300 "Wilson A. Galafassi Jr." wrote: > Fixed. But mcp still don't working. Any suggestion? > > May 28 12:31:37 netserver MailScanner[13591]: New Batch: Scanning 1 > messages, 1885 bytes > May 28 12:31:37 netserver MailScanner[13591]: Created attachment dirs > for 1 messages > May 28 12:31:37 netserver MailScanner[13591]: MCP Checks: Starting > May 28 12:31:37 netserver MailScanner[13591]: Message Content > Protection SpamAssassin returned 512 > May 28 12:31:39 netserver MailScanner[13591]: SpamAssassin returned 0 > May 28 12:31:39 netserver MailScanner[13591]: Virus and Content > Scanning: Starting > May 28 12:31:39 netserver MailScanner[13591]: Commencing scanning by > clamav... > May 28 12:31:47 netserver MailScanner[13591]: Completed scanning by > clamav May 28 12:31:47 netserver MailScanner[13591]: Completed > checking by /usr/bin/file > May 28 12:31:47 netserver MailScanner[13591]: Requeue: > 46CF01086FB.48D13 to 6438F1086FD > May 28 12:31:47 netserver MailScanner[13591]: About to deliver 1 > messages May 28 12:31:47 netserver postfix/qmgr[13574]: 6438F1086FD: > from=, size=1367, nrcpt=1 (queue active) > May 28 12:31:47 netserver MailScanner[13591]: Uninfected: Delivered 1 > messages > May 28 12:31:47 netserver MailScanner[13591]: Logging message > 46CF01086FB.48D13 to SQL > May 28 12:31:47 netserver MailScanner[13594]: 46CF01086FB.48D13: > Logged to MailWatch SQL > May 28 12:31:47 netserver MailScanner[13591]: Config: calling custom > end function SQLBlacklist > May 28 12:31:47 netserver MailScanner[13591]: Closing down by-domain > spam blacklist > May 28 12:31:47 netserver MailScanner[13591]: Config: calling custom > end function MailWatchLogging > May 28 12:31:47 netserver MailScanner[13591]: Config: calling custom > end function SQLWhitelist > May 28 12:31:47 netserver MailScanner[13591]: Closing down by-domain > spam whitelist > May 28 12:31:47 netserver MailScanner[13591]: MailScanner child dying > of old age > May 28 12:31:51 netserver postfix/smtp[13631]: 6438F1086FD: > to=, > relay=ftpmanager.com[65.132.196.114]:25, delay=20, > delays=16/0.02/3.2/0.85, dsn=2.0.0, status=sent (250 OK > id=1HshCI-0007g4-TE) May 28 12:31:51 netserver postfix/qmgr[13574]: > 6438F1086FD: removed > > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian > Field Enviada em: segunda-feira, 28 de maio de 2007 12:11 > Para: MailScanner discussion > Assunto: Re: RES: RES: mcp help > > Make sure that the account you are using for MailScanner (set in "Run > As User =" in MailScanner.conf) can write to its home directory. If > it doesn't have a home directory, then create one. Looks like you are > using Postfix or Exim and their home dir is set in /etc/passwd to > "/no/where". > > Wilson A. Galafassi Jr. wrote: > > Running in debug mode i see: > > [7297] dbg: config: mkdir /no/where/.spamassassin failed: mkdir /no: > > Permission denied > > at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm line 1578 > > > > I can't find where to change this setting. > > This is related to my mcp problem? > > > > -----Mensagem original----- > > De: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de > > Julian > Field > > Enviada em: segunda-feira, 28 de maio de 2007 11:39 > > Para: MailScanner discussion > > Assunto: Re: RES: mcp help > > > > What is the name and location of this cf file? > > Is it being read when MailScanner starts? > > Do 'ls -lu /etc/MailScanner/mcp' > > Then wait a minute or two > > Then 'MailScanner -debug' > > Then 'ls -lu /etc/MailScanner/mcp' > > The 'last used' date stamp on the file should have changed. If it > > hasn't then the file isn't being read, and there's your problem. > > > > Wilson A. Galafassi Jr. wrote: > > > >> I have only a cf file with this content: > >> > >> body SAMPLE_RULE3 /test/i > >> describe SAMPLE_RULE3 Banned body text > >> score SAMPLE_RULE3 5 > >> > >> what i need to have in rules file? > >> > >> -----Mensagem original----- > >> De: mailscanner-bounces@lists.mailscanner.info > >> [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de > >> --[ UxBoD > > ]-- > > > >> Enviada em: segunda-feira, 28 de maio de 2007 07:55 > >> Para: mailscanner@lists.mailscanner.info > >> Assunto: Re: mcp help > >> > >> Hi, > >> > >> Would be useful to see what is in your configuration file with > >> respect to MCP, and also what you have in your rules file. > >> > >> Thanks, > >> > >> On Mon, 28 May 2007 07:38:13 -0300 > >> "Wilson A. Galafassi Jr." wrote: > >> > >> > >> > >>> Hello to all. > >>> > >>> > >>> > >>> I'm configuring mailscanner and mcp settings don't working. > >>> > >>> > >>> > >>> When i send or receive a mail with containing in the body the > >>> expression "test" the mail isn't mcp marked. > >>> > >>> > >>> > >>> Can someone tell me what i have to change? > >>> > >>> > >>> > >>> Very thanks. > >>> > >>> > >>> > >>> Wilson > >>> > >>> > >>> > >>> > >>> > >>> I have this in my cf file: > >>> > >>> > >>> > >>> body SAMPLE_RULE3 /test/i > >>> > >>> describe SAMPLE_RULE3 Banned body text > >>> > >>> score SAMPLE_RULE3 5 > >>> > >>> > >>> > >>> > >>> > >>> in MailScanner.conf i have: > >>> > >>> > >>> > >>> MCP Checks = yes > >>> > >>> > >>> > >>> # Do the spam checks first, or the MCP checks first? > >>> > >>> # This cannot be the filename of a ruleset, only a fixed value. > >>> > >>> First Check = mcp > >>> > >>> > >>> > >>> # The rest of these options are clones of the equivalent spam > >>> options MCP Required SpamAssassin Score = 1 MCP High SpamAssassin > >>> Score = 10 MCP Error Score = 1 > >>> > >>> > >>> > >>> MCP Header = X-%org-name%-MailScanner-MCPCheck: > >>> > >>> Non MCP Actions = deliver > >>> > >>> MCP Actions = deliver store > >>> > >>> High Scoring MCP Actions = store > >>> > >>> Bounce MCP As Attachment = no > >>> > >>> > >>> > >>> MCP Modify Subject = start > >>> > >>> MCP Subject Text = {MCP?} > >>> > >>> High Scoring MCP Modify Subject = start > >>> > >>> High Scoring MCP Subject Text = {MCP?} > >>> > >>> > >>> > >>> Is Definitely MCP = no > >>> > >>> Is Definitely Not MCP = no > >>> > >>> Definite MCP Is High Scoring = yes > >>> > >>> Always Include MCP Report = yes > >>> > >>> Detailed MCP Report = yes > >>> > >>> Include Scores In MCP Report = yes > >>> > >>> Log MCP = yes > >>> > >>> > >>> > >>> MCP Max SpamAssassin Timeouts = 20 > >>> > >>> MCP Max SpamAssassin Size = 100k > >>> > >>> MCP SpamAssassin Timeout = 10 > >>> > >>> > >>> > >>> MCP SpamAssassin Prefs File = > >>> %mcp-dir%/mcp.spam.assassin.prefs.conf > >>> > >>> MCP SpamAssassin User State Dir = > >>> > >>> MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin > >>> Default Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = > >>> %mcp-dir% Recipient MCP Report = > >>> %report-dir%/recipient.mcp.report.txt > >>> > >>> Sender MCP Report = %report-dir%/sender.mcp.report.txt > >>> > >>> > >>> > >>> > >>> > >>> > >>> > >>> > >>> > >>> > >>> > >>> > >> > >> > > > > Jules > > > > > > Jules > - -- - --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.4 (GNU/Linux) iD8DBQFGWwI5H7GwL121aHsRAkwMAJ9AT/ohhFUYY9l0jZg41dJ/ajXKPwCgrpsL JJACR7i6g68vYDzClM7+JLI= =ksEJ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From jan-peter at koopmann.eu Mon May 28 17:56:02 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Mon May 28 17:56:18 2007 Subject: Reject mail from invalid domains In-Reply-To: <465B004F.1@halla.pt> References: <465B004F.1@halla.pt> Message-ID: On Monday, May 28, 2007 6:16 PM Jorge Costinha wrote: > im using Fedora core 6, with Mailscanner 4.59.4 and sendmail > 8.13.8. I want to block email from invalid domains. Can i do this with > Mailscanner/spamassassin or has to be done at MTA level? You probably could do this with spamassassin but the MTA is the correct place. How do you define "invalid domain"? That's the interesting question. Regards, JP From jan-peter at koopmann.eu Mon May 28 17:57:53 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Mon May 28 17:58:07 2007 Subject: possible enhancement request In-Reply-To: <178215.9566.qm@web26310.mail.ukl.yahoo.com> References: <178215.9566.qm@web26310.mail.ukl.yahoo.com> Message-ID: On Monday, May 28, 2007 5:50 PM Andrew MacLachlan wrote: > How difficult would it be to remove old footers off the bottom of > forwards/replies I am afraid extremely difficult as you are opening pandoras box here. :-) How do you discover an "old footer"? Kind regards Jan-Peter Koopmann From MailScanner at ecs.soton.ac.uk Mon May 28 18:27:20 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Mon May 28 18:28:30 2007 Subject: Beta release 4.60.6 Message-ID: <465B10F8.6060405@ecs.soton.ac.uk> I have added the 2 configuration options that seemed worthwhile for the new "Zip Attachments" feature: # If the original total size of all the attachments to be compressed is # less than this number of bytes, they will not be zipped at all. # This can also be the filename of a ruleset. Attachments Min Total Size To Zip = 100k # Attachments whose filenames end in these strings will not be zipped. # This can also be the filename of a ruleset. Attachment Extensions Not To Zip = .zip .rar .gz .tgz .mpg .mpeg .mp3 .rpm Download as usual from www.mailscanner.info. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From doc at maddoc.net Mon May 28 18:50:07 2007 From: doc at maddoc.net (Doc Schneider) Date: Mon May 28 18:50:15 2007 Subject: UTF-8 errors. Message-ID: <465B164F.3000003@maddoc.net> I just now committed more fixes for 70_sare_obfu.cf, obfu0 and obfu1. These should be available within the hour. Please folks if you have a problem with a rule set from SARE please let us know what rule it is and what rule set it is in. Note to Steve Swaney: I've updated mta30.fsl.com 8*) Thanks, -- -Doc Lincoln, NE. http://www.genealogyforyou.com/ http://www.cairnproductions.com/ From fssilva at gmail.com Mon May 28 19:13:26 2007 From: fssilva at gmail.com (Fabio Silva) Date: Mon May 28 19:13:28 2007 Subject: Question... Message-ID: Hi list, i need to store all emails in the quarantine folder... what option should i set to make this?? All mails ... without virus and with virus, by default the mails with virus are stored in the quarantine folder, but i need to store all the mails. Regards, Fabio -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070528/36e95e28/attachment.html From fssilva at gmail.com Mon May 28 19:24:51 2007 From: fssilva at gmail.com (Fabio Silva) Date: Mon May 28 19:24:54 2007 Subject: Question... In-Reply-To: References: Message-ID: Thanks, i have this working.... helped me in the irc Regards for all See ya On 5/28/07, Fabio Silva wrote: > > Hi list, i need to store all emails in the quarantine folder... what > option should i set to make this?? All mails ... without virus and with > virus, by default the mails with virus are stored in the quarantine folder, > but i need to store all the mails. > > > Regards, > Fabio > > -- Fabio S. Silva Mail: fssilva@gmail.com CCNA / LPIC-2 / MCP -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070528/115befa5/attachment.html From wilson.galafassi at gmail.com Mon May 28 19:27:25 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Mon May 28 19:27:42 2007 Subject: RES: mcp help In-Reply-To: <20070528172421.68cb5c01@uxbod.splatnix.net> References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> Message-ID: Hello. Thanks again in advance. My file is readed: read file /etc/MailScanner/mcp/digital.cf In digital.cf i have: header MY_RULE_1 Subject =~ /block this phrase/i score MY_RULE_1 100 body MY_RULE_2 /Block this too/i score MY_RULE_2 100 body MY_RULE_3 /this\s*is\s*more\s*complicated/i score MY_RULE_3 100 but when i send and email containing any matching rules i dont see marked as mcp. My complete debug above: Starting MailScanner daemons: incoming postfix: [ OK ] outgoing postfix: [ OK ] MailScanner: In Debugging mode, not forking... [18193] dbg: logger: adding facilities: all [18193] dbg: logger: logging level is DBG [18193] dbg: generic: SpamAssassin version 3.2.0 [18193] dbg: config: score set 0 chosen. [18193] dbg: util: running in taint mode? no [18193] dbg: dns: no ipv6 [18193] dbg: dns: is Net::DNS::Resolver available? yes [18193] dbg: dns: Net::DNS version: 0.59 [18193] dbg: logger: adding facilities: all [18193] dbg: logger: logging level is DBG [18193] dbg: generic: SpamAssassin version 3.2.0 [18193] dbg: config: score set 0 chosen. [18193] dbg: dns: no ipv6 [18193] dbg: dns: is Net::DNS::Resolver available? yes [18193] dbg: dns: Net::DNS version: 0.59 Use of uninitialized value in concatenation (.) or string at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm line 1087. Use of uninitialized value in concatenation (.) or string at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm line 1089. [18193] dbg: config: read_scoreonly_config: cannot open "": No such file or directory [18203] dbg: config: using "/etc/MailScanner/mcp" for site rules pre files [18203] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files [18203] dbg: config: using "/etc/MailScanner/mcp" for default rules dir [18203] dbg: config: read file /etc/MailScanner/mcp/digital.cf [18203] dbg: config: using "/etc/MailScanner/mcp" for site rules dir [18203] dbg: config: read file /etc/MailScanner/mcp/digital.cf [18203] dbg: config: using "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file [18203] dbg: config: read file /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf [18203] dbg: conf: finish parsing [18203] dbg: bayes: no dbs present, cannot tie DB R/O: /home/postfix/.spamassassin/bayes_toks [18203] dbg: config: score set 1 chosen. [18203] dbg: message: main message type: multipart/alternative [18203] dbg: message: ---- MIME PARSER START ---- [18203] dbg: message: parsing multipart, got boundary: ----=_NextPart_000_009B_01C7A13B.DBA3DC80 [18203] dbg: message: found part of type text/plain, boundary: ----=_NextPart_000_009B_01C7A13B.DBA3DC80 [18203] dbg: message: added part, type: text/plain [18203] dbg: message: found part of type text/html, boundary: ----=_NextPart_000_009B_01C7A13B.DBA3DC80 [18203] dbg: message: added part, type: text/html [18203] dbg: message: parsing normal part [18203] dbg: message: parsing normal part [18203] dbg: message: ---- MIME PARSER END ---- [18203] dbg: bayes: no dbs present, cannot tie DB R/O: /home/postfix/.spamassassin/bayes_toks check: no loaded plugin implements 'check_main': cannot scan! at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin/PerMsgStatus.pm line 164. [18204] dbg: config: using "/etc/mail/spamassassin" for site rules pre files [18204] dbg: config: read file /etc/mail/spamassassin/init.pre [18204] dbg: config: read file /etc/mail/spamassassin/v310.pre [18204] dbg: config: read file /etc/mail/spamassassin/v312.pre [18204] dbg: config: read file /etc/mail/spamassassin/v320.pre [18204] dbg: config: using "/usr/share/spamassassin" for sys rules pre files [18204] dbg: config: using "/usr/share/spamassassin" for default rules dir [18204] dbg: config: read file /usr/share/spamassassin/10_default_prefs.cf [18204] dbg: config: read file /usr/share/spamassassin/20_advance_fee.cf [18204] dbg: config: read file /usr/share/spamassassin/20_body_tests.cf [18204] dbg: config: read file /usr/share/spamassassin/20_compensate.cf [18204] dbg: config: read file /usr/share/spamassassin/20_dnsbl_tests.cf [18204] dbg: config: read file /usr/share/spamassassin/20_drugs.cf [18204] dbg: config: read file /usr/share/spamassassin/20_dynrdns.cf [18204] dbg: config: read file /usr/share/spamassassin/20_fake_helo_tests.cf [18204] dbg: config: read file /usr/share/spamassassin/20_head_tests.cf [18204] dbg: config: read file /usr/share/spamassassin/20_html_tests.cf [18204] dbg: config: read file /usr/share/spamassassin/20_imageinfo.cf [18204] dbg: config: read file /usr/share/spamassassin/20_meta_tests.cf [18204] dbg: config: read file /usr/share/spamassassin/20_net_tests.cf [18204] dbg: config: read file /usr/share/spamassassin/20_phrases.cf [18204] dbg: config: read file /usr/share/spamassassin/20_porn.cf [18204] dbg: config: read file /usr/share/spamassassin/20_ratware.cf [18204] dbg: config: read file /usr/share/spamassassin/20_uri_tests.cf [18204] dbg: config: read file /usr/share/spamassassin/20_vbounce.cf [18204] dbg: config: read file /usr/share/spamassassin/23_bayes.cf [18204] dbg: config: read file /usr/share/spamassassin/25_accessdb.cf [18204] dbg: config: read file /usr/share/spamassassin/25_antivirus.cf [18204] dbg: config: read file /usr/share/spamassassin/25_asn.cf [18204] dbg: config: read file /usr/share/spamassassin/25_dcc.cf [18204] dbg: config: read file /usr/share/spamassassin/25_dkim.cf [18204] dbg: config: read file /usr/share/spamassassin/25_domainkeys.cf [18204] dbg: config: read file /usr/share/spamassassin/25_hashcash.cf [18204] dbg: config: read file /usr/share/spamassassin/25_pyzor.cf [18204] dbg: config: read file /usr/share/spamassassin/25_razor2.cf [18204] dbg: config: read file /usr/share/spamassassin/25_replace.cf [18204] dbg: config: read file /usr/share/spamassassin/25_spf.cf [18204] dbg: config: read file /usr/share/spamassassin/25_textcat.cf [18204] dbg: config: read file /usr/share/spamassassin/25_uribl.cf [18204] dbg: config: read file /usr/share/spamassassin/30_text_de.cf [18204] dbg: config: read file /usr/share/spamassassin/30_text_fr.cf [18204] dbg: config: read file /usr/share/spamassassin/30_text_it.cf [18204] dbg: config: read file /usr/share/spamassassin/30_text_nl.cf [18204] dbg: config: read file /usr/share/spamassassin/30_text_pl.cf [18204] dbg: config: read file /usr/share/spamassassin/30_text_pt_br.cf [18204] dbg: config: read file /usr/share/spamassassin/50_scores.cf [18204] dbg: config: read file /usr/share/spamassassin/60_awl.cf [18204] dbg: config: read file /usr/share/spamassassin/60_shortcircuit.cf [18204] dbg: config: read file /usr/share/spamassassin/60_whitelist.cf [18204] dbg: config: read file /usr/share/spamassassin/60_whitelist_dk.cf [18204] dbg: config: read file /usr/share/spamassassin/60_whitelist_dkim.cf [18204] dbg: config: read file /usr/share/spamassassin/60_whitelist_spf.cf [18204] dbg: config: read file /usr/share/spamassassin/60_whitelist_subject.cf [18204] dbg: config: read file /usr/share/spamassassin/72_active.cf [18204] dbg: config: using "/etc/mail/spamassassin" for site rules dir [18204] dbg: config: read file /etc/mail/spamassassin/local.cf [18204] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [18204] dbg: razor2: razor2 is not available [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC [18204] dbg: pyzor: network tests on, attempting Pyzor [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [18204] dbg: razor2: razor2 is not available [18204] dbg: plugin: did not register Mail::SpamAssassin::Plugin::Razor2=HASH(0xb0a97d8), already registered [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::SpamCop from @INC [18204] dbg: reporter: network tests on, attempting SpamCop [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [18204] dbg: plugin: did not register Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xafc78c4), already registered [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [18204] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SPF=HASH(0xb0ce618), already registered [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [18204] dbg: plugin: did not register Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0xb000478), already registered [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [18204] dbg: plugin: did not register Mail::SpamAssassin::Plugin::ASN=HASH(0xafbc9b0), already registered [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [18204] dbg: plugin: did not register Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xb425ddc), already registered [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [18204] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SPF=HASH(0xb0ceb10), already registered [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [18204] dbg: plugin: did not register Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0xafc7dc8), already registered [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [18204] dbg: razor2: razor2 is not available [18204] dbg: plugin: did not register Mail::SpamAssassin::Plugin::Razor2=HASH(0xafc7f6c), already registered [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [18204] dbg: plugin: did not register Mail::SpamAssassin::Plugin::ASN=HASH(0xafe6e10), already registered [18204] dbg: config: allowing user rules! [18204] dbg: rules: __MO_OL_9B90B merged duplicates: __MO_OL_C65FA [18204] dbg: rules: __XM_OL_22B61 merged duplicates: __XM_OL_A842E [18204] dbg: rules: __MO_OL_07794 merged duplicates: __MO_OL_8627E __MO_OL_F3B05 [18204] dbg: rules: __XM_OL_07794 merged duplicates: __XM_OL_25340 __XM_OL_3857F __XM_OL_4F240 __XM_OL_58CB5 __XM_OL_6554A __XM_OL_812FF __XM_OL_C65FA __XM_OL_CF0C0 __XM_OL_F475E __XM_OL_F6D01 [18204] dbg: rules: FH_MSGID_01C67 merged duplicates: __MSGID_VGA [18204] dbg: rules: FS_NEW_SOFT_UPLOAD merged duplicates: HS_SUBJ_NEW_SOFTWARE [18204] dbg: rules: __FH_HAS_XMSMAIL merged duplicates: __HAS_MSMAIL_PRI [18204] dbg: rules: __MO_OL_015D5 merged duplicates: __MO_OL_6554A [18204] dbg: rules: __MO_OL_91287 merged duplicates: __MO_OL_B30D1 __MO_OL_CF0C0 [18204] dbg: rules: __XM_OL_015D5 merged duplicates: __XM_OL_4BF4C __XM_OL_4EEDB __XM_OL_5B79A __XM_OL_9B90B __XM_OL_ADFF7 __XM_OL_B30D1 __XM_OL_B4B40 __XM_OL_BC7E6 __XM_OL_F3B05 __XM_OL_FF5C8 [18204] dbg: rules: __XM_OL_5E7ED merged duplicates: __XM_OL_D03AB [18204] dbg: rules: __MO_OL_22B61 merged duplicates: __MO_OL_4F240 __MO_OL_ADFF7 [18204] dbg: rules: __MO_OL_812FF merged duplicates: __MO_OL_BC7E6 [18204] dbg: rules: __MO_OL_25340 merged duplicates: __MO_OL_4EEDB __MO_OL_7533E [18204] dbg: rules: __MO_OL_58CB5 merged duplicates: __MO_OL_B4B40 [18204] dbg: rules: __DOS_HAS_ANY_URI merged duplicates: __HAS_ANY_URI [18204] dbg: rules: __XM_OL_C7C33 merged duplicates: __XM_OL_C9068 __XM_OL_EF20B [18204] dbg: rules: __MO_OL_72641 merged duplicates: __MO_OL_A842E [18204] dbg: rules: __MO_OL_5E7ED merged duplicates: __MO_OL_C7C33 [18204] dbg: rules: __MO_OL_F475E merged duplicates: __MO_OL_FF5C8 [18204] dbg: rules: __MO_OL_4BF4C merged duplicates: __MO_OL_F6D01 [18204] dbg: conf: finish parsing [18204] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0xafc7840) implements 'finish_parsing_end', priority 0 [18204] dbg: replacetags: replacing tags [18204] dbg: replacetags: done replacing tags [18204] dbg: bayes: tie-ing to DB file R/O /var/spool/MailScanner/spamassassin/bayes_toks [18204] dbg: bayes: tie-ing to DB file R/O /var/spool/MailScanner/spamassassin/bayes_seen [18204] dbg: bayes: found bayes db version 3 [18204] dbg: bayes: DB journal sync: last sync: 0 [18204] dbg: bayes: not available for scanning, only 7 spam(s) in bayes DB < 200 [18204] dbg: bayes: untie-ing [18204] dbg: config: score set 1 chosen. [18204] dbg: message: main message type: multipart/alternative [18204] dbg: message: ---- MIME PARSER START ---- [18204] dbg: message: parsing multipart, got boundary: ----=_NextPart_000_009B_01C7A13B.DBA3DC80 [18204] dbg: message: found part of type text/plain, boundary: ----=_NextPart_000_009B_01C7A13B.DBA3DC80 [18204] dbg: message: added part, type: text/plain [18204] dbg: message: found part of type text/html, boundary: ----=_NextPart_000_009B_01C7A13B.DBA3DC80 [18204] dbg: message: added part, type: text/html [18204] dbg: message: parsing normal part [18204] dbg: message: parsing normal part [18204] dbg: message: ---- MIME PARSER END ---- [18204] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0xb2e6dcc) implements 'check_start', priority 0 [18204] dbg: bayes: tie-ing to DB file R/O /var/spool/MailScanner/spamassassin/bayes_toks [18204] dbg: bayes: tie-ing to DB file R/O /var/spool/MailScanner/spamassassin/bayes_seen [18204] dbg: bayes: found bayes db version 3 [18204] dbg: bayes: DB journal sync: last sync: 0 [18204] dbg: bayes: not available for scanning, only 7 spam(s) in bayes DB < 200 [18204] dbg: bayes: untie-ing [18204] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0xb2cb8a4) implements 'check_main', priority 0 [18204] dbg: conf: trusted_networks are not configured; it is recommended that you configure trusted_networks manually [18204] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp by=netserver.ftpmanager.com ident= envfrom= intl=0 id=7F1861086FB auth= msa=0 ] [18204] dbg: received-header: 'from' 192.168.0.1 has private IP [18204] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes msa? no [18204] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= helo=sdxp by=netserver.ftpmanager.com ident= envfrom= intl=1 id=7F1861086FB auth= msa=0 ] [18204] dbg: metadata: X-Spam-Relays-Untrusted: [18204] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= helo=sdxp by=netserver.ftpmanager.com ident= envfrom= intl=1 id=7F1861086FB auth= msa=0 ] [18204] dbg: metadata: X-Spam-Relays-External: [18204] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xb00a13c) implements 'extract_metadata', priority 0 [18204] dbg: metadata: X-Relay-Countries: [18204] dbg: message: decoding quoted-printable [18204] dbg: message: decoding quoted-printable [18204] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0xafbc6d4) implements 'parsed_metadata', priority 0 [18204] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xb00a13c) implements 'parsed_metadata', priority 0 [18204] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0xafe4c68) implements 'parsed_metadata', priority 0 [18204] dbg: dns: dns_available set to yes in config file, skipping test [18204] dbg: uridnsbl: domains to query: [18204] dbg: asn: could not parse IP from first external relay, skipping ASN check [18204] dbg: check: running tests for priority: -1000 [18204] dbg: rules: running head tests; score so far=0 [18204] dbg: rules: compiled head tests [18204] dbg: eval: all '*From' addrs: wilson@ftpmanager.com [18204] dbg: eval: all '*To' addrs: wilson.galafassi@gmail.com [18204] dbg: rules: running body tests; score so far=0 [18204] dbg: rules: compiled body tests [18204] dbg: rules: running uri tests; score so far=0 [18204] dbg: rules: compiled uri tests [18204] dbg: rules: running rawbody tests; score so far=0 [18204] dbg: rules: compiled rawbody tests [18204] dbg: rules: running full tests; score so far=0 [18204] dbg: rules: compiled full tests [18204] dbg: rules: running meta tests; score so far=0 [18204] dbg: rules: compiled meta tests [18204] dbg: check: running tests for priority: -950 [18204] dbg: rules: running head tests; score so far=0 [18204] dbg: rules: compiled head tests [18204] dbg: rules: ran eval rule ALL_TRUSTED ======> got hit (1) [18204] dbg: rules: running body tests; score so far=-1.44 [18204] dbg: rules: compiled body tests [18204] dbg: rules: running uri tests; score so far=-1.44 [18204] dbg: rules: compiled uri tests [18204] dbg: rules: running rawbody tests; score so far=-1.44 [18204] dbg: rules: compiled rawbody tests [18204] dbg: rules: running full tests; score so far=-1.44 [18204] dbg: rules: compiled full tests [18204] dbg: rules: running meta tests; score so far=-1.44 [18204] dbg: rules: compiled meta tests [18204] dbg: check: running tests for priority: -900 [18204] dbg: rules: running head tests; score so far=-1.44 [18204] dbg: rules: compiled head tests [18204] dbg: rules: running body tests; score so far=-1.44 [18204] dbg: rules: compiled body tests [18204] dbg: rules: running uri tests; score so far=-1.44 [18204] dbg: rules: compiled uri tests [18204] dbg: rules: running rawbody tests; score so far=-1.44 [18204] dbg: rules: compiled rawbody tests [18204] dbg: rules: running full tests; score so far=-1.44 [18204] dbg: rules: compiled full tests [18204] dbg: rules: running meta tests; score so far=-1.44 [18204] dbg: rules: compiled meta tests [18204] dbg: check: running tests for priority: -400 [18204] dbg: rules: running head tests; score so far=-1.44 [18204] dbg: rules: compiled head tests [18204] dbg: rules: running body tests; score so far=-1.44 [18204] dbg: rules: compiled body tests [18204] dbg: rules: running uri tests; score so far=-1.44 [18204] dbg: rules: compiled uri tests [18204] dbg: rules: running rawbody tests; score so far=-1.44 [18204] dbg: rules: compiled rawbody tests [18204] dbg: rules: running full tests; score so far=-1.44 [18204] dbg: rules: compiled full tests [18204] dbg: rules: running meta tests; score so far=-1.44 [18204] dbg: rules: compiled meta tests [18204] dbg: check: running tests for priority: 0 [18204] dbg: rules: running head tests; score so far=-1.44 [18204] dbg: rules: compiled head tests [18204] dbg: rules: ran header rule __CTYPE_MULTIPART_ALT ======> got hit: "multipart/alternative" [18204] dbg: rules: ran header rule __CTYPE_HAS_BOUNDARY ======> got hit: "boundary" [18204] dbg: rules: ran header rule __CT ======> got hit: "m" [18204] dbg: rules: ran header rule __MISSING_REF ======> got hit: "UNSET" [18204] dbg: rules: ran header rule __FH_HAS_XPRIORITY ======> got hit: "3" [18204] dbg: rules: ran header rule __MIME_VERSION ======> got hit: "1" [18204] dbg: rules: ran header rule __HAS_RCVD ======> got hit: "f" [18204] dbg: rules: ran header rule __DOS_RCVD_MON ======> got hit: " Mon, " [18204] dbg: rules: ran header rule __TOCC_EXISTS ======> got hit: "<" [18204] dbg: rules: ran header rule __MSGID_OK_HOST ======> got hit: "@sdxp>" [18204] dbg: rules: ran header rule __MSGID_OK_HEX ======> got hit: "010b5340" [18204] dbg: rules: ran header rule __MIMEOLE_MS ======> got hit: "Produced By Microsoft MimeOLE" [18204] dbg: rules: ran header rule __HDR_ORDER_FTSDMCXXXX ======> got hit: " [18204] dbg: rules: From: "Wilson - FTP" [18204] dbg: rules: To: [18204] dbg: rules: Subject: Fw: block this phrase [18204] dbg: rules: Date: Mon, 28 May 2007 15:21:26 -0300 [18204] dbg: rules: MIME-Version: 1.0 [18204] dbg: rules: Content-Type: multipart/alternative; boundary="----=_NextPart_000_009B_01C7A13B.DBA3DC80" [18204] dbg: rules: X-Priority: 3 [18204] dbg: rules: X-MSMail-Priority: Normal [18204] dbg: rules: X-Mailer: Microsoft Outlook Express 6.00.2900.3028 [18204] dbg: rules: X-MimeOLE:" [18204] dbg: rules: ran header rule __HAS_MSGID ======> got hit: "<" [18204] dbg: rules: ran header rule __SANE_MSGID ======> got hit: "<009e01c7a155$010b5340$0100a8c0@sdxp> [18204] dbg: rules: " [18204] dbg: rules: ran header rule __MSGID_DOLLARS_MAYBE ======> got hit: "<009e01c7a155$010b5340$0100a8c0@sdxp>" [18204] dbg: rules: ran header rule __MSGID_DOLLARS_OK ======> got hit: "<009e01c7a155$010b5340$0100a8c0@sdxp>" [18204] dbg: rules: ran header rule __OE_MSGID_2 ======> got hit: "<009e01c7a155$010b5340$0100a8c0@sdxp>" [18204] dbg: rules: ran header rule __FH_HAS_XMSMAIL ======> got hit: "N" [18204] dbg: rules: ran header rule __HAS_SUBJECT ======> got hit: "F" [18204] dbg: rules: ran header rule __XM_MS_IN_GENERAL ======> got hit: "Microsoft Outlook" [18204] dbg: rules: ran header rule __XM_OUTLOOK_EXPRESS ======> got hit: "Microsoft Outlook Express 6" [18204] dbg: rules: ran header rule __ANY_OUTLOOK_MUA ======> got hit: "Microsoft Outlook" [18204] dbg: rules: ran header rule __OE_MUA ======> got hit: "Outlook Express 6." [18204] dbg: rules: ran header rule __HAS_X_MAILER ======> got hit: "M" [18204] dbg: rules: ran header rule __XM_MSOE6 ======> got hit: "Microsoft Outlook Express 6" [18204] dbg: rules: ran header rule __HAS_MIMEOLE ======> got hit: "P" [18204] dbg: spf: checking to see if the message has a Received-SPF header that we can use [18204] dbg: spf: using Mail::SPF for SPF checks [18204] dbg: spf: no suitable relay for spf use found, skipping SPF-helo check [18204] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [18204] dbg: spf: no suitable relay for spf use found, skipping SPF check [18204] dbg: spf: def_spf_whitelist_from: already checked spf and didn't get pass, skipping whitelist check [18204] dbg: spf: whitelist_from_spf: already checked spf and didn't get pass, skipping whitelist check [18204] dbg: rules: running body tests; score so far=-1.44 [18204] dbg: rules: compiled body tests [18204] dbg: rules: ran body rule __DOS_BODY_MON ======> got hit: "Monday" [18204] dbg: rules: ran body rule __HAS_ANY_EMAIL ======> got hit: "i@gmail.c" [18204] dbg: rules: ran body rule __NONEMPTY_BODY ======> got hit: "F" [18204] dbg: rules: running uri tests; score so far=-1.44 [18204] dbg: rules: compiled uri tests [18204] dbg: rules: ran uri rule __DOS_HAS_ANY_URI ======> got hit: "m" [18204] dbg: rules: ran eval rule __HTML_LENGTH_1024_1536 ======> got hit (1) [18204] dbg: https_http_mismatch: anchors 0 [18204] dbg: eval: stock info total: 0 [18204] dbg: rules: ran eval rule __TAG_EXISTS_BODY ======> got hit (1) [18204] dbg: eval: text words: 20, html words: 20 [18204] dbg: eval: madiff: left: 0, orig: 20, max-difference: 0.00% [18204] dbg: rules: ran eval rule __MIME_HTML ======> got hit (1) [18204] dbg: rules: ran eval rule HTML_MESSAGE ======> got hit (1) [18204] dbg: rules: ran eval rule __TAG_EXISTS_HTML ======> got hit (1) [18204] dbg: rules: ran eval rule __TAG_EXISTS_HEAD ======> got hit (1) [18204] dbg: rules: ran eval rule __TAG_EXISTS_META ======> got hit (1) [18204] dbg: rules: running rawbody tests; score so far=-1.439 [18204] dbg: rules: compiled rawbody tests [18204] dbg: rules: ran eval rule __MIME_QP ======> got hit (2) [18204] dbg: rules: running full tests; score so far=-1.439 [18204] dbg: rules: compiled full tests [18204] dbg: pyzor: use_pyzor option not enabled, disabling Pyzor [18204] dbg: rules: running meta tests; score so far=-1.439 [18204] dbg: rules: compiled meta tests [18204] dbg: check: running tests for priority: 500 [18204] dbg: rules: running head tests; score so far=-1.439 [18204] dbg: rules: compiled head tests [18204] dbg: rules: running body tests; score so far=-1.439 [18204] dbg: rules: compiled body tests [18204] dbg: rules: running uri tests; score so far=-1.439 [18204] dbg: rules: compiled uri tests [18204] dbg: rules: running rawbody tests; score so far=-1.439 [18204] dbg: rules: compiled rawbody tests [18204] dbg: rules: running full tests; score so far=-1.439 [18204] dbg: rules: compiled full tests [18204] dbg: rules: running meta tests; score so far=-1.439 [18204] dbg: rules: meta test DIGEST_MULTIPLE has undefined dependency 'DCC_CHECK' [18204] info: rules: meta test HS_PHARMA_1 has dependency 'HS_SUBJ_ONLINE_PHARMACEUTICAL' with a zero score [18204] dbg: rules: compiled meta tests [18204] dbg: check: running tests for priority: 1000 [18204] dbg: rules: running head tests; score so far=-1.439 [18204] dbg: rules: compiled head tests [18204] dbg: rules: running body tests; score so far=-1.439 [18204] dbg: rules: compiled body tests [18204] dbg: rules: running uri tests; score so far=-1.439 [18204] dbg: rules: compiled uri tests [18204] dbg: rules: running rawbody tests; score so far=-1.439 [18204] dbg: rules: compiled rawbody tests [18204] dbg: rules: running full tests; score so far=-1.439 [18204] dbg: rules: compiled full tests [18204] dbg: rules: running meta tests; score so far=-1.439 [18204] dbg: rules: compiled meta tests [18204] dbg: plugin: Mail::SpamAssassin::Plugin::AutoLearnThreshold=HASH(0xafc50c8) implements 'autolearn_discriminator', priority 0 [18204] dbg: learn: auto-learn: currently using scoreset 1 [18204] dbg: learn: auto-learn: message score: -1.439, computed score for autolearn: 0.001 [18204] dbg: learn: auto-learn? ham=-1, spam=12, body-points=0.001, head-points=0.001, learned-points=0 [18204] dbg: learn: auto-learn? no: inside auto-learn thresholds, not considered ham or spam [18204] dbg: check: is spam? score=-1.439 required=5 [18204] dbg: check: tests=ALL_TRUSTED,HTML_MESSAGE [18204] dbg: check: subtests=__ANY_OUTLOOK_MUA,__CT,__CTYPE_HAS_BOUNDARY,__CTYPE_MULTIPART_ALT,_ _DOS_BODY_MON,__DOS_HAS_ANY_URI,__DOS_RCVD_MON,__DOS_REF_TODAY,__FH_HAS_XMSM AIL,__FH_HAS_XPRIORITY,__HAS_ANY_EMAIL,__HAS_ANY_URI,__HAS_MIMEOLE,__HAS_MSG ID,__HAS_MSMAIL_PRI,__HAS_RCVD,__HAS_SUBJECT,__HAS_X_MAILER,__HDR_ORDER_FTSD MCXXXX,__HTML_LENGTH_1024_1536,__MIMEOLE_MS,__MIME_HTML,__MIME_QP,__MIME_VER SION,__MISSING_REF,__MSGID_DOLLARS_MAYBE,__MSGID_DOLLARS_OK,__MSGID_OK_HEX,_ _MSGID_OK_HOST,__NONEMPTY_BODY,__NO_INR_YES_REF,__OE_MSGID_2,__OE_MUA,__SANE _MSGID,__TAG_EXISTS_BODY,__TAG_EXISTS_HEAD,__TAG_EXISTS_HTML,__TAG_EXISTS_ME TA,__TOCC_EXISTS,__XM_MSOE6,__XM_MS_IN_GENERAL,__XM_OUTLOOK_EXPRESS [18204] dbg: learn: auto-learn? ham=-1, spam=12, body-points=0.001, head-points=0.001, learned-points=0 [18204] dbg: learn: auto-learn? no: inside auto-learn thresholds, not considered ham or spam Ignore errors about failing to find EOCD signature format error: can't find EOCD signature at /usr/sbin/MailScanner line 832 format error: file is too short at /usr/sbin/MailScanner line 832 in maillog: May 28 15:25:08 netserver postfix/smtpd[18264]: connect from unknown[192.168.0.1] May 28 15:25:08 netserver postfix/smtpd[18264]: AF8251086E9: client=unknown[192.168.0.1] May 28 15:25:08 netserver postfix/cleanup[18267]: AF8251086E9: hold: header Received: from sdxp (unknown [192.168.0.1])??by netserver.ftpmanager.com (Postfix) with SMTP id AF8251086E9??for ; Mon, 28 May 2007 15:25:08 -0300 (BRT) from unknown[192.168.0.1]; from= to= proto=SMTP helo= May 28 15:25:08 netserver postfix/cleanup[18267]: AF8251086E9: message-id=<00a501c7a155$8015e880$0100a8c0@sdxp> May 28 15:25:08 netserver postfix/smtpd[18264]: disconnect from unknown[192.168.0.1] May 28 15:25:12 netserver MailScanner[18258]: New Batch: Scanning 1 messages, 1924 bytes May 28 15:25:12 netserver MailScanner[18258]: Created attachment dirs for 1 messages May 28 15:25:12 netserver MailScanner[18258]: MCP Checks: Starting May 28 15:25:12 netserver MailScanner[18258]: Message Content Protection SpamAssassin returned 512 May 28 15:25:14 netserver MailScanner[18258]: SpamAssassin returned 0 May 28 15:25:14 netserver MailScanner[18258]: Virus and Content Scanning: Starting May 28 15:25:14 netserver MailScanner[18258]: Commencing scanning by clamav... May 28 15:25:22 netserver MailScanner[18258]: Completed scanning by clamav May 28 15:25:22 netserver MailScanner[18258]: Completed checking by /usr/bin/file May 28 15:25:22 netserver MailScanner[18258]: Requeue: AF8251086E9.6F306 to 788411086FD May 28 15:25:22 netserver MailScanner[18258]: About to deliver 1 messages May 28 15:25:22 netserver MailScanner[18258]: Uninfected: Delivered 1 messages May 28 15:25:22 netserver MailScanner[18258]: Logging message AF8251086E9.6F306 to SQL May 28 15:25:22 netserver MailScanner[18258]: Config: calling custom end function SQLBlacklist May 28 15:25:22 netserver MailScanner[18258]: Closing down by-domain spam blacklist May 28 15:25:22 netserver MailScanner[18258]: Config: calling custom end function MailWatchLogging May 28 15:25:22 netserver MailScanner[18258]: Config: calling custom end function SQLWhitelist May 28 15:25:22 netserver MailScanner[18258]: Closing down by-domain spam whitelist May 28 15:25:22 netserver MailScanner[18258]: MailScanner child dying of old age May 28 15:25:22 netserver MailScanner[18261]: AF8251086E9.6F306: Logged to MailWatch SQL May 28 15:25:22 netserver postfix/qmgr[18177]: 788411086FD: from=, size=1406, nrcpt=1 (queue active) May 28 15:25:26 netserver postfix/smtp[18279]: 788411086FD: to=, relay=ftpmanager.com[72.232.196.114]:25, delay=18, delays=14/0.01/3.3/0.77, dsn=2.0.0, status=sent (250 OK id=1HsjuI-0008N5-Dk) May 28 15:25:26 netserver postfix/qmgr[18177]: 788411086FD: removed -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de --[ UxBoD ]-- Enviada em: segunda-feira, 28 de maio de 2007 13:24 Para: mailscanner@lists.mailscanner.info Assunto: Re: mcp help -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Wilson, I think you need to concentrate on your SA perms and configuration. Get them right first and then re-check. UxBoD On Mon, 28 May 2007 12:34:05 -0300 "Wilson A. Galafassi Jr." wrote: > Fixed. But mcp still don't working. Any suggestion? > > May 28 12:31:37 netserver MailScanner[13591]: New Batch: Scanning 1 > messages, 1885 bytes May 28 12:31:37 netserver MailScanner[13591]: > Created attachment dirs for 1 messages May 28 12:31:37 netserver > MailScanner[13591]: MCP Checks: Starting May 28 12:31:37 netserver > MailScanner[13591]: Message Content Protection SpamAssassin returned > 512 May 28 12:31:39 netserver MailScanner[13591]: SpamAssassin > returned 0 May 28 12:31:39 netserver MailScanner[13591]: Virus and > Content > Scanning: Starting > May 28 12:31:39 netserver MailScanner[13591]: Commencing scanning by > clamav... > May 28 12:31:47 netserver MailScanner[13591]: Completed scanning by > clamav May 28 12:31:47 netserver MailScanner[13591]: Completed > checking by /usr/bin/file May 28 12:31:47 netserver > MailScanner[13591]: Requeue: > 46CF01086FB.48D13 to 6438F1086FD > May 28 12:31:47 netserver MailScanner[13591]: About to deliver 1 > messages May 28 12:31:47 netserver postfix/qmgr[13574]: 6438F1086FD: > from=, size=1367, nrcpt=1 (queue active) May 28 > 12:31:47 netserver MailScanner[13591]: Uninfected: Delivered 1 > messages May 28 12:31:47 netserver MailScanner[13591]: Logging message > 46CF01086FB.48D13 to SQL > May 28 12:31:47 netserver MailScanner[13594]: 46CF01086FB.48D13: > Logged to MailWatch SQL > May 28 12:31:47 netserver MailScanner[13591]: Config: calling custom > end function SQLBlacklist May 28 12:31:47 netserver > MailScanner[13591]: Closing down by-domain spam blacklist May 28 > 12:31:47 netserver MailScanner[13591]: Config: calling custom end > function MailWatchLogging May 28 12:31:47 netserver > MailScanner[13591]: Config: calling custom end function SQLWhitelist > May 28 12:31:47 netserver MailScanner[13591]: Closing down by-domain > spam whitelist May 28 12:31:47 netserver MailScanner[13591]: > MailScanner child dying of old age May 28 12:31:51 netserver > postfix/smtp[13631]: 6438F1086FD: > to=, > relay=ftpmanager.com[65.132.196.114]:25, delay=20, > delays=16/0.02/3.2/0.85, dsn=2.0.0, status=sent (250 OK > id=1HshCI-0007g4-TE) May 28 12:31:51 netserver postfix/qmgr[13574]: > 6438F1086FD: removed > > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian > Field Enviada em: segunda-feira, 28 de maio de 2007 12:11 > Para: MailScanner discussion > Assunto: Re: RES: RES: mcp help > > Make sure that the account you are using for MailScanner (set in "Run > As User =" in MailScanner.conf) can write to its home directory. If it > doesn't have a home directory, then create one. Looks like you are > using Postfix or Exim and their home dir is set in /etc/passwd to > "/no/where". > > Wilson A. Galafassi Jr. wrote: > > Running in debug mode i see: > > [7297] dbg: config: mkdir /no/where/.spamassassin failed: mkdir /no: > > Permission denied > > at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm line 1578 > > > > I can't find where to change this setting. > > This is related to my mcp problem? > > > > -----Mensagem original----- > > De: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de > > Julian > Field > > Enviada em: segunda-feira, 28 de maio de 2007 11:39 > > Para: MailScanner discussion > > Assunto: Re: RES: mcp help > > > > What is the name and location of this cf file? > > Is it being read when MailScanner starts? > > Do 'ls -lu /etc/MailScanner/mcp' > > Then wait a minute or two > > Then 'MailScanner -debug' > > Then 'ls -lu /etc/MailScanner/mcp' > > The 'last used' date stamp on the file should have changed. If it > > hasn't then the file isn't being read, and there's your problem. > > > > Wilson A. Galafassi Jr. wrote: > > > >> I have only a cf file with this content: > >> > >> body SAMPLE_RULE3 /test/i > >> describe SAMPLE_RULE3 Banned body text > >> score SAMPLE_RULE3 5 > >> > >> what i need to have in rules file? > >> > >> -----Mensagem original----- > >> De: mailscanner-bounces@lists.mailscanner.info > >> [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de --[ > >> UxBoD > > ]-- > > > >> Enviada em: segunda-feira, 28 de maio de 2007 07:55 > >> Para: mailscanner@lists.mailscanner.info > >> Assunto: Re: mcp help > >> > >> Hi, > >> > >> Would be useful to see what is in your configuration file with > >> respect to MCP, and also what you have in your rules file. > >> > >> Thanks, > >> > >> On Mon, 28 May 2007 07:38:13 -0300 > >> "Wilson A. Galafassi Jr." wrote: > >> > >> > >> > >>> Hello to all. > >>> > >>> > >>> > >>> I'm configuring mailscanner and mcp settings don't working. > >>> > >>> > >>> > >>> When i send or receive a mail with containing in the body the > >>> expression "test" the mail isn't mcp marked. > >>> > >>> > >>> > >>> Can someone tell me what i have to change? > >>> > >>> > >>> > >>> Very thanks. > >>> > >>> > >>> > >>> Wilson > >>> > >>> > >>> > >>> > >>> > >>> I have this in my cf file: > >>> > >>> > >>> > >>> body SAMPLE_RULE3 /test/i > >>> > >>> describe SAMPLE_RULE3 Banned body text > >>> > >>> score SAMPLE_RULE3 5 > >>> > >>> > >>> > >>> > >>> > >>> in MailScanner.conf i have: > >>> > >>> > >>> > >>> MCP Checks = yes > >>> > >>> > >>> > >>> # Do the spam checks first, or the MCP checks first? > >>> > >>> # This cannot be the filename of a ruleset, only a fixed value. > >>> > >>> First Check = mcp > >>> > >>> > >>> > >>> # The rest of these options are clones of the equivalent spam > >>> options MCP Required SpamAssassin Score = 1 MCP High SpamAssassin > >>> Score = 10 MCP Error Score = 1 > >>> > >>> > >>> > >>> MCP Header = X-%org-name%-MailScanner-MCPCheck: > >>> > >>> Non MCP Actions = deliver > >>> > >>> MCP Actions = deliver store > >>> > >>> High Scoring MCP Actions = store > >>> > >>> Bounce MCP As Attachment = no > >>> > >>> > >>> > >>> MCP Modify Subject = start > >>> > >>> MCP Subject Text = {MCP?} > >>> > >>> High Scoring MCP Modify Subject = start > >>> > >>> High Scoring MCP Subject Text = {MCP?} > >>> > >>> > >>> > >>> Is Definitely MCP = no > >>> > >>> Is Definitely Not MCP = no > >>> > >>> Definite MCP Is High Scoring = yes > >>> > >>> Always Include MCP Report = yes > >>> > >>> Detailed MCP Report = yes > >>> > >>> Include Scores In MCP Report = yes > >>> > >>> Log MCP = yes > >>> > >>> > >>> > >>> MCP Max SpamAssassin Timeouts = 20 > >>> > >>> MCP Max SpamAssassin Size = 100k > >>> > >>> MCP SpamAssassin Timeout = 10 > >>> > >>> > >>> > >>> MCP SpamAssassin Prefs File = > >>> %mcp-dir%/mcp.spam.assassin.prefs.conf > >>> > >>> MCP SpamAssassin User State Dir = > >>> > >>> MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin > >>> Default Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = > >>> %mcp-dir% Recipient MCP Report = > >>> %report-dir%/recipient.mcp.report.txt > >>> > >>> Sender MCP Report = %report-dir%/sender.mcp.report.txt > >>> > >>> > >>> > >>> > >>> > >>> > >>> > >>> > >>> > >>> > >>> > >>> > >> > >> > > > > Jules > > > > > > Jules > - -- - --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.4 (GNU/Linux) iD8DBQFGWwI5H7GwL121aHsRAkwMAJ9AT/ohhFUYY9l0jZg41dJ/ajXKPwCgrpsL JJACR7i6g68vYDzClM7+JLI= =ksEJ -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From uxbod at splatnix.net Mon May 28 20:41:35 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Mon May 28 20:38:46 2007 Subject: mcp help In-Reply-To: References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> Message-ID: <20070528204135.045a9d5a@uxbod.splatnix.net> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Wilson, Are you running a valid email through ? What does spammassasin --D - --lint > /tmp/sa.log 2>&1 show ? - From your posting it does seem other errors are apparent. Regards, On Mon, 28 May 2007 15:27:25 -0300 "Wilson A. Galafassi Jr." wrote: > Hello. > > Thanks again in advance. > > My file is readed: read file /etc/MailScanner/mcp/digital.cf > > In digital.cf i have: > > header MY_RULE_1 Subject =~ /block this phrase/i > score MY_RULE_1 100 > > body MY_RULE_2 /Block this too/i > score MY_RULE_2 100 > > body MY_RULE_3 /this\s*is\s*more\s*complicated/i > score MY_RULE_3 100 > > > but when i send and email containing any matching rules i dont see > marked as mcp. > > > My complete debug above: > > Starting MailScanner daemons: > incoming postfix: [ OK ] > outgoing postfix: [ OK ] > MailScanner: In Debugging mode, not forking... > [18193] dbg: logger: adding facilities: all > [18193] dbg: logger: logging level is DBG > [18193] dbg: generic: SpamAssassin version 3.2.0 > [18193] dbg: config: score set 0 chosen. > [18193] dbg: util: running in taint mode? no > [18193] dbg: dns: no ipv6 > [18193] dbg: dns: is Net::DNS::Resolver available? yes > [18193] dbg: dns: Net::DNS version: 0.59 > [18193] dbg: logger: adding facilities: all > [18193] dbg: logger: logging level is DBG > [18193] dbg: generic: SpamAssassin version 3.2.0 > [18193] dbg: config: score set 0 chosen. > [18193] dbg: dns: no ipv6 > [18193] dbg: dns: is Net::DNS::Resolver available? yes > [18193] dbg: dns: Net::DNS version: 0.59 > Use of uninitialized value in concatenation (.) or string at > /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm line 1087. > Use of uninitialized value in concatenation (.) or string at > /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm line 1089. > [18193] dbg: config: read_scoreonly_config: cannot open "": No such > file or directory > [18203] dbg: config: using "/etc/MailScanner/mcp" for site rules pre > files [18203] dbg: config: using "/etc/MailScanner/mcp" for sys rules > pre files [18203] dbg: config: using "/etc/MailScanner/mcp" for > default rules dir [18203] dbg: config: read > file /etc/MailScanner/mcp/digital.cf [18203] dbg: config: using > "/etc/MailScanner/mcp" for site rules dir [18203] dbg: config: read > file /etc/MailScanner/mcp/digital.cf [18203] dbg: config: using > "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs > file [18203] dbg: config: read file > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf > [18203] dbg: conf: finish parsing > [18203] dbg: bayes: no dbs present, cannot tie DB R/O: > /home/postfix/.spamassassin/bayes_toks > [18203] dbg: config: score set 1 chosen. > [18203] dbg: message: main message type: multipart/alternative > [18203] dbg: message: ---- MIME PARSER START ---- > [18203] dbg: message: parsing multipart, got boundary: > ----=_NextPart_000_009B_01C7A13B.DBA3DC80 > [18203] dbg: message: found part of type text/plain, boundary: > ----=_NextPart_000_009B_01C7A13B.DBA3DC80 > [18203] dbg: message: added part, type: text/plain > [18203] dbg: message: found part of type text/html, boundary: > ----=_NextPart_000_009B_01C7A13B.DBA3DC80 > [18203] dbg: message: added part, type: text/html > [18203] dbg: message: parsing normal part > [18203] dbg: message: parsing normal part > [18203] dbg: message: ---- MIME PARSER END ---- > [18203] dbg: bayes: no dbs present, cannot tie DB R/O: > /home/postfix/.spamassassin/bayes_toks > check: no loaded plugin implements 'check_main': cannot scan! at > /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin/PerMsgStatus.pm line > 164. [18204] dbg: config: using "/etc/mail/spamassassin" for site > rules pre files [18204] dbg: config: read > file /etc/mail/spamassassin/init.pre [18204] dbg: config: read > file /etc/mail/spamassassin/v310.pre [18204] dbg: config: read > file /etc/mail/spamassassin/v312.pre [18204] dbg: config: read > file /etc/mail/spamassassin/v320.pre [18204] dbg: config: using > "/usr/share/spamassassin" for sys rules pre files [18204] dbg: > config: using "/usr/share/spamassassin" for default rules dir [18204] > dbg: config: read file /usr/share/spamassassin/10_default_prefs.cf > [18204] dbg: config: read > file /usr/share/spamassassin/20_advance_fee.cf [18204] dbg: config: > read file /usr/share/spamassassin/20_body_tests.cf [18204] dbg: > config: read file /usr/share/spamassassin/20_compensate.cf [18204] > dbg: config: read file /usr/share/spamassassin/20_dnsbl_tests.cf > [18204] dbg: config: read file /usr/share/spamassassin/20_drugs.cf > [18204] dbg: config: read file /usr/share/spamassassin/20_dynrdns.cf > [18204] dbg: config: read > file /usr/share/spamassassin/20_fake_helo_tests.cf [18204] dbg: > config: read file /usr/share/spamassassin/20_head_tests.cf [18204] > dbg: config: read file /usr/share/spamassassin/20_html_tests.cf > [18204] dbg: config: read > file /usr/share/spamassassin/20_imageinfo.cf [18204] dbg: config: > read file /usr/share/spamassassin/20_meta_tests.cf [18204] dbg: > config: read file /usr/share/spamassassin/20_net_tests.cf [18204] > dbg: config: read file /usr/share/spamassassin/20_phrases.cf [18204] > dbg: config: read file /usr/share/spamassassin/20_porn.cf [18204] > dbg: config: read file /usr/share/spamassassin/20_ratware.cf [18204] > dbg: config: read file /usr/share/spamassassin/20_uri_tests.cf > [18204] dbg: config: read file /usr/share/spamassassin/20_vbounce.cf > [18204] dbg: config: read file /usr/share/spamassassin/23_bayes.cf > [18204] dbg: config: read file /usr/share/spamassassin/25_accessdb.cf > [18204] dbg: config: read > file /usr/share/spamassassin/25_antivirus.cf [18204] dbg: config: > read file /usr/share/spamassassin/25_asn.cf [18204] dbg: config: read > file /usr/share/spamassassin/25_dcc.cf [18204] dbg: config: read > file /usr/share/spamassassin/25_dkim.cf [18204] dbg: config: read > file /usr/share/spamassassin/25_domainkeys.cf [18204] dbg: config: > read file /usr/share/spamassassin/25_hashcash.cf [18204] dbg: config: > read file /usr/share/spamassassin/25_pyzor.cf [18204] dbg: config: > read file /usr/share/spamassassin/25_razor2.cf [18204] dbg: config: > read file /usr/share/spamassassin/25_replace.cf [18204] dbg: config: > read file /usr/share/spamassassin/25_spf.cf [18204] dbg: config: read > file /usr/share/spamassassin/25_textcat.cf [18204] dbg: config: read > file /usr/share/spamassassin/25_uribl.cf [18204] dbg: config: read > file /usr/share/spamassassin/30_text_de.cf [18204] dbg: config: read > file /usr/share/spamassassin/30_text_fr.cf [18204] dbg: config: read > file /usr/share/spamassassin/30_text_it.cf [18204] dbg: config: read > file /usr/share/spamassassin/30_text_nl.cf [18204] dbg: config: read > file /usr/share/spamassassin/30_text_pl.cf [18204] dbg: config: read > file /usr/share/spamassassin/30_text_pt_br.cf [18204] dbg: config: > read file /usr/share/spamassassin/50_scores.cf [18204] dbg: config: > read file /usr/share/spamassassin/60_awl.cf [18204] dbg: config: read > file /usr/share/spamassassin/60_shortcircuit.cf [18204] dbg: config: > read file /usr/share/spamassassin/60_whitelist.cf [18204] dbg: > config: read file /usr/share/spamassassin/60_whitelist_dk.cf [18204] > dbg: config: read file /usr/share/spamassassin/60_whitelist_dkim.cf > [18204] dbg: config: read > file /usr/share/spamassassin/60_whitelist_spf.cf [18204] dbg: config: > read file /usr/share/spamassassin/60_whitelist_subject.cf [18204] > dbg: config: read file /usr/share/spamassassin/72_active.cf [18204] > dbg: config: using "/etc/mail/spamassassin" for site rules dir > [18204] dbg: config: read file /etc/mail/spamassassin/local.cf > [18204] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf > [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL > from @INC [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::Hashcash from @INC [18204] dbg: plugin: > loading Mail::SpamAssassin::Plugin::SPF from @INC [18204] dbg: > plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC > [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from > @INC [18204] dbg: razor2: razor2 is not available [18204] dbg: > plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [18204] > dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC > [18204] dbg: pyzor: network tests on, attempting Pyzor [18204] dbg: > plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [18204] > dbg: razor2: razor2 is not available [18204] dbg: plugin: did not > register Mail::SpamAssassin::Plugin::Razor2=HASH(0xb0a97d8), already > registered [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::SpamCop from @INC [18204] dbg: reporter: > network tests on, attempting SpamCop [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::AWL from @INC [18204] dbg: plugin: > loading Mail::SpamAssassin::Plugin::AutoLearnThreshold from @INC > [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::WhiteListSubject from @INC [18204] dbg: > plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from @INC > [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags > from @INC [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::RelayCountry from @INC [18204] dbg: > plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xafc78c4), already > registered [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::SPF from @INC [18204] dbg: plugin: did > not register Mail::SpamAssassin::Plugin::SPF=HASH(0xb0ce618), already > registered [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::URIDNSBL from @INC [18204] dbg: plugin: > did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0xb000478), already > registered [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::ASN from @INC [18204] dbg: plugin: did > not register Mail::SpamAssassin::Plugin::ASN=HASH(0xafbc9b0), already > registered [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::Check from @INC [18204] dbg: plugin: > loading Mail::SpamAssassin::Plugin::HTTPSMismatch from @INC [18204] > dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC > [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from > @INC [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::BodyEval from @INC [18204] dbg: plugin: > loading Mail::SpamAssassin::Plugin::DNSEval from @INC [18204] dbg: > plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC > [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval > from @INC [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::MIMEEval from @INC [18204] dbg: plugin: > loading Mail::SpamAssassin::Plugin::RelayEval from @INC [18204] dbg: > plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC [18204] > dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC > [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from > @INC [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::ImageInfo from @INC [18204] dbg: plugin: > loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [18204] > dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xb425ddc), already > registered [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::SPF from @INC [18204] dbg: plugin: did > not register Mail::SpamAssassin::Plugin::SPF=HASH(0xb0ceb10), already > registered [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::URIDNSBL from @INC [18204] dbg: plugin: > did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0xafc7dc8), already > registered [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::Razor2 from @INC [18204] dbg: razor2: > razor2 is not available [18204] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0xafc7f6c), already > registered [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::ASN from @INC [18204] dbg: plugin: did > not register Mail::SpamAssassin::Plugin::ASN=HASH(0xafe6e10), already > registered [18204] dbg: config: allowing user rules! [18204] dbg: > rules: __MO_OL_9B90B merged duplicates: __MO_OL_C65FA [18204] dbg: > rules: __XM_OL_22B61 merged duplicates: __XM_OL_A842E [18204] dbg: > rules: __MO_OL_07794 merged duplicates: __MO_OL_8627E __MO_OL_F3B05 > [18204] dbg: rules: __XM_OL_07794 merged duplicates: __XM_OL_25340 > __XM_OL_3857F __XM_OL_4F240 __XM_OL_58CB5 __XM_OL_6554A __XM_OL_812FF > __XM_OL_C65FA __XM_OL_CF0C0 __XM_OL_F475E __XM_OL_F6D01 [18204] dbg: > rules: FH_MSGID_01C67 merged duplicates: __MSGID_VGA [18204] dbg: > rules: FS_NEW_SOFT_UPLOAD merged duplicates: HS_SUBJ_NEW_SOFTWARE > [18204] dbg: rules: __FH_HAS_XMSMAIL merged duplicates: > __HAS_MSMAIL_PRI [18204] dbg: rules: __MO_OL_015D5 merged duplicates: > __MO_OL_6554A [18204] dbg: rules: __MO_OL_91287 merged duplicates: > __MO_OL_B30D1 __MO_OL_CF0C0 [18204] dbg: rules: __XM_OL_015D5 merged > duplicates: __XM_OL_4BF4C __XM_OL_4EEDB __XM_OL_5B79A __XM_OL_9B90B > __XM_OL_ADFF7 __XM_OL_B30D1 __XM_OL_B4B40 __XM_OL_BC7E6 __XM_OL_F3B05 > __XM_OL_FF5C8 [18204] dbg: rules: __XM_OL_5E7ED merged duplicates: > __XM_OL_D03AB [18204] dbg: rules: __MO_OL_22B61 merged duplicates: > __MO_OL_4F240 __MO_OL_ADFF7 [18204] dbg: rules: __MO_OL_812FF merged > duplicates: __MO_OL_BC7E6 [18204] dbg: rules: __MO_OL_25340 merged > duplicates: __MO_OL_4EEDB __MO_OL_7533E [18204] dbg: rules: > __MO_OL_58CB5 merged duplicates: __MO_OL_B4B40 [18204] dbg: rules: > __DOS_HAS_ANY_URI merged duplicates: __HAS_ANY_URI [18204] dbg: > rules: __XM_OL_C7C33 merged duplicates: __XM_OL_C9068 __XM_OL_EF20B > [18204] dbg: rules: __MO_OL_72641 merged duplicates: __MO_OL_A842E > [18204] dbg: rules: __MO_OL_5E7ED merged duplicates: __MO_OL_C7C33 > [18204] dbg: rules: __MO_OL_F475E merged duplicates: __MO_OL_FF5C8 > [18204] dbg: rules: __MO_OL_4BF4C merged duplicates: __MO_OL_F6D01 > [18204] dbg: conf: finish parsing > [18204] dbg: plugin: > Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0xafc7840) implements > 'finish_parsing_end', priority 0 [18204] dbg: replacetags: replacing > tags [18204] dbg: replacetags: done replacing tags > [18204] dbg: bayes: tie-ing to DB file R/O > /var/spool/MailScanner/spamassassin/bayes_toks > [18204] dbg: bayes: tie-ing to DB file R/O > /var/spool/MailScanner/spamassassin/bayes_seen > [18204] dbg: bayes: found bayes db version 3 > [18204] dbg: bayes: DB journal sync: last sync: 0 > [18204] dbg: bayes: not available for scanning, only 7 spam(s) in > bayes DB < 200 > [18204] dbg: bayes: untie-ing > [18204] dbg: config: score set 1 chosen. > [18204] dbg: message: main message type: multipart/alternative > [18204] dbg: message: ---- MIME PARSER START ---- > [18204] dbg: message: parsing multipart, got boundary: > ----=_NextPart_000_009B_01C7A13B.DBA3DC80 > [18204] dbg: message: found part of type text/plain, boundary: > ----=_NextPart_000_009B_01C7A13B.DBA3DC80 > [18204] dbg: message: added part, type: text/plain > [18204] dbg: message: found part of type text/html, boundary: > ----=_NextPart_000_009B_01C7A13B.DBA3DC80 > [18204] dbg: message: added part, type: text/html > [18204] dbg: message: parsing normal part > [18204] dbg: message: parsing normal part > [18204] dbg: message: ---- MIME PARSER END ---- > [18204] dbg: plugin: > Mail::SpamAssassin::Plugin::DNSEval=HASH(0xb2e6dcc) implements > 'check_start', priority 0 [18204] dbg: bayes: tie-ing to DB file R/O > /var/spool/MailScanner/spamassassin/bayes_toks > [18204] dbg: bayes: tie-ing to DB file R/O > /var/spool/MailScanner/spamassassin/bayes_seen > [18204] dbg: bayes: found bayes db version 3 > [18204] dbg: bayes: DB journal sync: last sync: 0 > [18204] dbg: bayes: not available for scanning, only 7 spam(s) in > bayes DB < 200 > [18204] dbg: bayes: untie-ing > [18204] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0xb2cb8a4) > implements 'check_main', priority 0 > [18204] dbg: conf: trusted_networks are not configured; it is > recommended that you configure trusted_networks manually > [18204] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanager.com ident= envfrom= intl=0 > id=7F1861086FB auth= msa=0 ] > [18204] dbg: received-header: 'from' 192.168.0.1 has private IP > [18204] dbg: received-header: relay 192.168.0.1 trusted? yes > internal? yes msa? no > [18204] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanager.com ident= envfrom= intl=1 > id=7F1861086FB auth= msa=0 ] > [18204] dbg: metadata: X-Spam-Relays-Untrusted: > [18204] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanager.com ident= envfrom= intl=1 > id=7F1861086FB auth= msa=0 ] > [18204] dbg: metadata: X-Spam-Relays-External: > [18204] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xb00a13c) implements > 'extract_metadata', priority 0 > [18204] dbg: metadata: X-Relay-Countries: > [18204] dbg: message: decoding quoted-printable > [18204] dbg: message: decoding quoted-printable > [18204] dbg: plugin: > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0xafbc6d4) implements > 'parsed_metadata', priority 0 [18204] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xb00a13c) implements > 'parsed_metadata', priority 0 > [18204] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0xafe4c68) > implements 'parsed_metadata', priority 0 > [18204] dbg: dns: dns_available set to yes in config file, skipping > test [18204] dbg: uridnsbl: domains to query: > [18204] dbg: asn: could not parse IP from first external relay, > skipping ASN check > [18204] dbg: check: running tests for priority: -1000 > [18204] dbg: rules: running head tests; score so far=0 > [18204] dbg: rules: compiled head tests > [18204] dbg: eval: all '*From' addrs: wilson@ftpmanager.com > [18204] dbg: eval: all '*To' addrs: wilson.galafassi@gmail.com > [18204] dbg: rules: running body tests; score so far=0 > [18204] dbg: rules: compiled body tests > [18204] dbg: rules: running uri tests; score so far=0 > [18204] dbg: rules: compiled uri tests > [18204] dbg: rules: running rawbody tests; score so far=0 > [18204] dbg: rules: compiled rawbody tests > [18204] dbg: rules: running full tests; score so far=0 > [18204] dbg: rules: compiled full tests > [18204] dbg: rules: running meta tests; score so far=0 > [18204] dbg: rules: compiled meta tests > [18204] dbg: check: running tests for priority: -950 > [18204] dbg: rules: running head tests; score so far=0 > [18204] dbg: rules: compiled head tests > [18204] dbg: rules: ran eval rule ALL_TRUSTED ======> got hit (1) > [18204] dbg: rules: running body tests; score so far=-1.44 > [18204] dbg: rules: compiled body tests > [18204] dbg: rules: running uri tests; score so far=-1.44 > [18204] dbg: rules: compiled uri tests > [18204] dbg: rules: running rawbody tests; score so far=-1.44 > [18204] dbg: rules: compiled rawbody tests > [18204] dbg: rules: running full tests; score so far=-1.44 > [18204] dbg: rules: compiled full tests > [18204] dbg: rules: running meta tests; score so far=-1.44 > [18204] dbg: rules: compiled meta tests > [18204] dbg: check: running tests for priority: -900 > [18204] dbg: rules: running head tests; score so far=-1.44 > [18204] dbg: rules: compiled head tests > [18204] dbg: rules: running body tests; score so far=-1.44 > [18204] dbg: rules: compiled body tests > [18204] dbg: rules: running uri tests; score so far=-1.44 > [18204] dbg: rules: compiled uri tests > [18204] dbg: rules: running rawbody tests; score so far=-1.44 > [18204] dbg: rules: compiled rawbody tests > [18204] dbg: rules: running full tests; score so far=-1.44 > [18204] dbg: rules: compiled full tests > [18204] dbg: rules: running meta tests; score so far=-1.44 > [18204] dbg: rules: compiled meta tests > [18204] dbg: check: running tests for priority: -400 > [18204] dbg: rules: running head tests; score so far=-1.44 > [18204] dbg: rules: compiled head tests > [18204] dbg: rules: running body tests; score so far=-1.44 > [18204] dbg: rules: compiled body tests > [18204] dbg: rules: running uri tests; score so far=-1.44 > [18204] dbg: rules: compiled uri tests > [18204] dbg: rules: running rawbody tests; score so far=-1.44 > [18204] dbg: rules: compiled rawbody tests > [18204] dbg: rules: running full tests; score so far=-1.44 > [18204] dbg: rules: compiled full tests > [18204] dbg: rules: running meta tests; score so far=-1.44 > [18204] dbg: rules: compiled meta tests > [18204] dbg: check: running tests for priority: 0 > [18204] dbg: rules: running head tests; score so far=-1.44 > [18204] dbg: rules: compiled head tests > [18204] dbg: rules: ran header rule __CTYPE_MULTIPART_ALT ======> got > hit: "multipart/alternative" > [18204] dbg: rules: ran header rule __CTYPE_HAS_BOUNDARY ======> got > hit: "boundary" > [18204] dbg: rules: ran header rule __CT ======> got hit: "m" > [18204] dbg: rules: ran header rule __MISSING_REF ======> got hit: > "UNSET" [18204] dbg: rules: ran header rule __FH_HAS_XPRIORITY > ======> got hit: "3" [18204] dbg: rules: ran header rule > __MIME_VERSION ======> got hit: "1" [18204] dbg: rules: ran header > rule __HAS_RCVD ======> got hit: "f" [18204] dbg: rules: ran header > rule __DOS_RCVD_MON ======> got hit: " Mon, " [18204] dbg: rules: ran > header rule __TOCC_EXISTS ======> got hit: "<" [18204] dbg: rules: > ran header rule __MSGID_OK_HOST ======> got hit: "@sdxp>" > [18204] dbg: rules: ran header rule __MSGID_OK_HEX ======> got hit: > "010b5340" > [18204] dbg: rules: ran header rule __MIMEOLE_MS ======> got hit: > "Produced By Microsoft MimeOLE" > [18204] dbg: rules: ran header rule __HDR_ORDER_FTSDMCXXXX ======> > got hit: " > [18204] dbg: rules: From: "Wilson - FTP" > [18204] dbg: rules: To: > [18204] dbg: rules: Subject: Fw: block this phrase > [18204] dbg: rules: Date: Mon, 28 May 2007 15:21:26 -0300 > [18204] dbg: rules: MIME-Version: 1.0 > [18204] dbg: rules: Content-Type: multipart/alternative; > boundary="----=_NextPart_000_009B_01C7A13B.DBA3DC80" > [18204] dbg: rules: X-Priority: 3 > [18204] dbg: rules: X-MSMail-Priority: Normal > [18204] dbg: rules: X-Mailer: Microsoft Outlook Express 6.00.2900.3028 > [18204] dbg: rules: X-MimeOLE:" > [18204] dbg: rules: ran header rule __HAS_MSGID ======> got hit: "<" > [18204] dbg: rules: ran header rule __SANE_MSGID ======> got hit: > "<009e01c7a155$010b5340$0100a8c0@sdxp> > [18204] dbg: rules: " > [18204] dbg: rules: ran header rule __MSGID_DOLLARS_MAYBE ======> got > hit: "<009e01c7a155$010b5340$0100a8c0@sdxp>" > [18204] dbg: rules: ran header rule __MSGID_DOLLARS_OK ======> got > hit: "<009e01c7a155$010b5340$0100a8c0@sdxp>" > [18204] dbg: rules: ran header rule __OE_MSGID_2 ======> got hit: > "<009e01c7a155$010b5340$0100a8c0@sdxp>" > [18204] dbg: rules: ran header rule __FH_HAS_XMSMAIL ======> got hit: > "N" [18204] dbg: rules: ran header rule __HAS_SUBJECT ======> got > hit: "F" [18204] dbg: rules: ran header rule __XM_MS_IN_GENERAL > ======> got hit: "Microsoft Outlook" > [18204] dbg: rules: ran header rule __XM_OUTLOOK_EXPRESS ======> got > hit: "Microsoft Outlook Express 6" > [18204] dbg: rules: ran header rule __ANY_OUTLOOK_MUA ======> got hit: > "Microsoft Outlook" > [18204] dbg: rules: ran header rule __OE_MUA ======> got hit: "Outlook > Express 6." > [18204] dbg: rules: ran header rule __HAS_X_MAILER ======> got hit: > "M" [18204] dbg: rules: ran header rule __XM_MSOE6 ======> got hit: > "Microsoft Outlook Express 6" > [18204] dbg: rules: ran header rule __HAS_MIMEOLE ======> got hit: "P" > [18204] dbg: spf: checking to see if the message has a Received-SPF > header that we can use > [18204] dbg: spf: using Mail::SPF for SPF checks > [18204] dbg: spf: no suitable relay for spf use found, skipping > SPF-helo check > [18204] dbg: spf: already checked for Received-SPF headers, > proceeding with DNS based checks > [18204] dbg: spf: no suitable relay for spf use found, skipping SPF > check [18204] dbg: spf: def_spf_whitelist_from: already checked spf > and didn't get pass, skipping whitelist check > [18204] dbg: spf: whitelist_from_spf: already checked spf and didn't > get pass, skipping whitelist check > [18204] dbg: rules: running body tests; score so far=-1.44 > [18204] dbg: rules: compiled body tests > [18204] dbg: rules: ran body rule __DOS_BODY_MON ======> got hit: > "Monday" [18204] dbg: rules: ran body rule __HAS_ANY_EMAIL ======> > got hit: "i@gmail.c" > [18204] dbg: rules: ran body rule __NONEMPTY_BODY ======> got hit: "F" > [18204] dbg: rules: running uri tests; score so far=-1.44 > [18204] dbg: rules: compiled uri tests > [18204] dbg: rules: ran uri rule __DOS_HAS_ANY_URI ======> got hit: > "m" [18204] dbg: rules: ran eval rule __HTML_LENGTH_1024_1536 ======> > got hit (1) > [18204] dbg: https_http_mismatch: anchors 0 > [18204] dbg: eval: stock info total: 0 > [18204] dbg: rules: ran eval rule __TAG_EXISTS_BODY ======> got hit > (1) [18204] dbg: eval: text words: 20, html words: 20 > [18204] dbg: eval: madiff: left: 0, orig: 20, max-difference: 0.00% > [18204] dbg: rules: ran eval rule __MIME_HTML ======> got hit (1) > [18204] dbg: rules: ran eval rule HTML_MESSAGE ======> got hit (1) > [18204] dbg: rules: ran eval rule __TAG_EXISTS_HTML ======> got hit > (1) [18204] dbg: rules: ran eval rule __TAG_EXISTS_HEAD ======> got > hit (1) [18204] dbg: rules: ran eval rule __TAG_EXISTS_META ======> > got hit (1) [18204] dbg: rules: running rawbody tests; score so > far=-1.439 [18204] dbg: rules: compiled rawbody tests > [18204] dbg: rules: ran eval rule __MIME_QP ======> got hit (2) > [18204] dbg: rules: running full tests; score so far=-1.439 > [18204] dbg: rules: compiled full tests > [18204] dbg: pyzor: use_pyzor option not enabled, disabling Pyzor > [18204] dbg: rules: running meta tests; score so far=-1.439 > [18204] dbg: rules: compiled meta tests > [18204] dbg: check: running tests for priority: 500 > [18204] dbg: rules: running head tests; score so far=-1.439 > [18204] dbg: rules: compiled head tests > [18204] dbg: rules: running body tests; score so far=-1.439 > [18204] dbg: rules: compiled body tests > [18204] dbg: rules: running uri tests; score so far=-1.439 > [18204] dbg: rules: compiled uri tests > [18204] dbg: rules: running rawbody tests; score so far=-1.439 > [18204] dbg: rules: compiled rawbody tests > [18204] dbg: rules: running full tests; score so far=-1.439 > [18204] dbg: rules: compiled full tests > [18204] dbg: rules: running meta tests; score so far=-1.439 > [18204] dbg: rules: meta test DIGEST_MULTIPLE has undefined dependency > 'DCC_CHECK' > [18204] info: rules: meta test HS_PHARMA_1 has dependency > 'HS_SUBJ_ONLINE_PHARMACEUTICAL' with a zero score > [18204] dbg: rules: compiled meta tests > [18204] dbg: check: running tests for priority: 1000 > [18204] dbg: rules: running head tests; score so far=-1.439 > [18204] dbg: rules: compiled head tests > [18204] dbg: rules: running body tests; score so far=-1.439 > [18204] dbg: rules: compiled body tests > [18204] dbg: rules: running uri tests; score so far=-1.439 > [18204] dbg: rules: compiled uri tests > [18204] dbg: rules: running rawbody tests; score so far=-1.439 > [18204] dbg: rules: compiled rawbody tests > [18204] dbg: rules: running full tests; score so far=-1.439 > [18204] dbg: rules: compiled full tests > [18204] dbg: rules: running meta tests; score so far=-1.439 > [18204] dbg: rules: compiled meta tests > [18204] dbg: plugin: > Mail::SpamAssassin::Plugin::AutoLearnThreshold=HASH(0xafc50c8) > implements 'autolearn_discriminator', priority 0 > [18204] dbg: learn: auto-learn: currently using scoreset 1 > [18204] dbg: learn: auto-learn: message score: -1.439, computed score > for autolearn: 0.001 > [18204] dbg: learn: auto-learn? ham=-1, spam=12, body-points=0.001, > head-points=0.001, learned-points=0 > [18204] dbg: learn: auto-learn? no: inside auto-learn thresholds, not > considered ham or spam > [18204] dbg: check: is spam? score=-1.439 required=5 > [18204] dbg: check: tests=ALL_TRUSTED,HTML_MESSAGE > [18204] dbg: check: > subtests=__ANY_OUTLOOK_MUA,__CT,__CTYPE_HAS_BOUNDARY,__CTYPE_MULTIPART_ALT,_ > _DOS_BODY_MON,__DOS_HAS_ANY_URI,__DOS_RCVD_MON,__DOS_REF_TODAY,__FH_HAS_XMSM > AIL,__FH_HAS_XPRIORITY,__HAS_ANY_EMAIL,__HAS_ANY_URI,__HAS_MIMEOLE,__HAS_MSG > ID,__HAS_MSMAIL_PRI,__HAS_RCVD,__HAS_SUBJECT,__HAS_X_MAILER,__HDR_ORDER_FTSD > MCXXXX,__HTML_LENGTH_1024_1536,__MIMEOLE_MS,__MIME_HTML,__MIME_QP,__MIME_VER > SION,__MISSING_REF,__MSGID_DOLLARS_MAYBE,__MSGID_DOLLARS_OK,__MSGID_OK_HEX,_ > _MSGID_OK_HOST,__NONEMPTY_BODY,__NO_INR_YES_REF,__OE_MSGID_2,__OE_MUA,__SANE > _MSGID,__TAG_EXISTS_BODY,__TAG_EXISTS_HEAD,__TAG_EXISTS_HTML,__TAG_EXISTS_ME > TA,__TOCC_EXISTS,__XM_MSOE6,__XM_MS_IN_GENERAL,__XM_OUTLOOK_EXPRESS > [18204] dbg: learn: auto-learn? ham=-1, spam=12, body-points=0.001, > head-points=0.001, learned-points=0 > [18204] dbg: learn: auto-learn? no: inside auto-learn thresholds, not > considered ham or spam > Ignore errors about failing to find EOCD signature > format error: can't find EOCD signature > at /usr/sbin/MailScanner line 832 > format error: file is too short > at /usr/sbin/MailScanner line 832 > > > in maillog: > > May 28 15:25:08 netserver postfix/smtpd[18264]: connect from > unknown[192.168.0.1] > May 28 15:25:08 netserver postfix/smtpd[18264]: AF8251086E9: > client=unknown[192.168.0.1] > May 28 15:25:08 netserver postfix/cleanup[18267]: AF8251086E9: hold: > header Received: from sdxp (unknown [192.168.0.1])??by > netserver.ftpmanager.com (Postfix) with SMTP id AF8251086E9??for > ; Mon, 28 May 2007 15:25:08 -0300 (BRT) > from unknown[192.168.0.1]; from= > to= proto=SMTP helo= > May 28 15:25:08 netserver postfix/cleanup[18267]: AF8251086E9: > message-id=<00a501c7a155$8015e880$0100a8c0@sdxp> > May 28 15:25:08 netserver postfix/smtpd[18264]: disconnect from > unknown[192.168.0.1] > May 28 15:25:12 netserver MailScanner[18258]: New Batch: Scanning 1 > messages, 1924 bytes > May 28 15:25:12 netserver MailScanner[18258]: Created attachment dirs > for 1 messages > May 28 15:25:12 netserver MailScanner[18258]: MCP Checks: Starting > May 28 15:25:12 netserver MailScanner[18258]: Message Content > Protection SpamAssassin returned 512 > May 28 15:25:14 netserver MailScanner[18258]: SpamAssassin returned 0 > May 28 15:25:14 netserver MailScanner[18258]: Virus and Content > Scanning: Starting > May 28 15:25:14 netserver MailScanner[18258]: Commencing scanning by > clamav... > May 28 15:25:22 netserver MailScanner[18258]: Completed scanning by > clamav May 28 15:25:22 netserver MailScanner[18258]: Completed > checking by /usr/bin/file > May 28 15:25:22 netserver MailScanner[18258]: Requeue: > AF8251086E9.6F306 to 788411086FD > May 28 15:25:22 netserver MailScanner[18258]: About to deliver 1 > messages May 28 15:25:22 netserver MailScanner[18258]: Uninfected: > Delivered 1 messages > May 28 15:25:22 netserver MailScanner[18258]: Logging message > AF8251086E9.6F306 to SQL > May 28 15:25:22 netserver MailScanner[18258]: Config: calling custom > end function SQLBlacklist > May 28 15:25:22 netserver MailScanner[18258]: Closing down by-domain > spam blacklist > May 28 15:25:22 netserver MailScanner[18258]: Config: calling custom > end function MailWatchLogging > May 28 15:25:22 netserver MailScanner[18258]: Config: calling custom > end function SQLWhitelist > May 28 15:25:22 netserver MailScanner[18258]: Closing down by-domain > spam whitelist > May 28 15:25:22 netserver MailScanner[18258]: MailScanner child dying > of old age > May 28 15:25:22 netserver MailScanner[18261]: AF8251086E9.6F306: > Logged to MailWatch SQL > May 28 15:25:22 netserver postfix/qmgr[18177]: 788411086FD: > from=, size=1406, nrcpt=1 (queue active) > May 28 15:25:26 netserver postfix/smtp[18279]: 788411086FD: > to=, > relay=ftpmanager.com[72.232.196.114]:25, delay=18, > delays=14/0.01/3.3/0.77, dsn=2.0.0, status=sent (250 OK > id=1HsjuI-0008N5-Dk) May 28 15:25:26 netserver postfix/qmgr[18177]: > 788411086FD: removed > > > > > > > > > > > > > > > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de > --[ UxBoD ]-- Enviada em: segunda-feira, 28 de maio de 2007 13:24 > Para: mailscanner@lists.mailscanner.info > Assunto: Re: mcp help > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Wilson, > > I think you need to concentrate on your SA perms and configuration. > > Get them right first and then re-check. > > UxBoD > > On Mon, 28 May 2007 12:34:05 -0300 > "Wilson A. Galafassi Jr." wrote: > > > Fixed. But mcp still don't working. Any suggestion? > > > > May 28 12:31:37 netserver MailScanner[13591]: New Batch: Scanning 1 > > messages, 1885 bytes May 28 12:31:37 netserver MailScanner[13591]: > > Created attachment dirs for 1 messages May 28 12:31:37 netserver > > MailScanner[13591]: MCP Checks: Starting May 28 12:31:37 netserver > > MailScanner[13591]: Message Content Protection SpamAssassin > > returned 512 May 28 12:31:39 netserver MailScanner[13591]: > > SpamAssassin returned 0 May 28 12:31:39 netserver > > MailScanner[13591]: Virus and Content > > Scanning: Starting > > May 28 12:31:39 netserver MailScanner[13591]: Commencing scanning > > by clamav... > > May 28 12:31:47 netserver MailScanner[13591]: Completed scanning by > > clamav May 28 12:31:47 netserver MailScanner[13591]: Completed > > checking by /usr/bin/file May 28 12:31:47 netserver > > MailScanner[13591]: Requeue: > > 46CF01086FB.48D13 to 6438F1086FD > > May 28 12:31:47 netserver MailScanner[13591]: About to deliver 1 > > messages May 28 12:31:47 netserver postfix/qmgr[13574]: 6438F1086FD: > > from=, size=1367, nrcpt=1 (queue active) May > > 28 12:31:47 netserver MailScanner[13591]: Uninfected: Delivered 1 > > messages May 28 12:31:47 netserver MailScanner[13591]: Logging > > message 46CF01086FB.48D13 to SQL > > May 28 12:31:47 netserver MailScanner[13594]: 46CF01086FB.48D13: > > Logged to MailWatch SQL > > May 28 12:31:47 netserver MailScanner[13591]: Config: calling > > custom end function SQLBlacklist May 28 12:31:47 netserver > > MailScanner[13591]: Closing down by-domain spam blacklist May 28 > > 12:31:47 netserver MailScanner[13591]: Config: calling custom end > > function MailWatchLogging May 28 12:31:47 netserver > > MailScanner[13591]: Config: calling custom end function > > SQLWhitelist May 28 12:31:47 netserver MailScanner[13591]: Closing > > down by-domain spam whitelist May 28 12:31:47 netserver > > MailScanner[13591]: MailScanner child dying of old age May 28 > > 12:31:51 netserver postfix/smtp[13631]: 6438F1086FD: > > to=, > > relay=ftpmanager.com[65.132.196.114]:25, delay=20, > > delays=16/0.02/3.2/0.85, dsn=2.0.0, status=sent (250 OK > > id=1HshCI-0007g4-TE) May 28 12:31:51 netserver postfix/qmgr[13574]: > > 6438F1086FD: removed > > > > -----Mensagem original----- > > De: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de > > Julian Field Enviada em: segunda-feira, 28 de maio de 2007 12:11 > > Para: MailScanner discussion > > Assunto: Re: RES: RES: mcp help > > > > Make sure that the account you are using for MailScanner (set in > > "Run As User =" in MailScanner.conf) can write to its home > > directory. If it doesn't have a home directory, then create one. > > Looks like you are using Postfix or Exim and their home dir is set > > in /etc/passwd to "/no/where". > > > > Wilson A. Galafassi Jr. wrote: > > > Running in debug mode i see: > > > [7297] dbg: config: mkdir /no/where/.spamassassin failed: > > > mkdir /no: Permission denied > > > at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm line 1578 > > > > > > I can't find where to change this setting. > > > This is related to my mcp problem? > > > > > > -----Mensagem original----- > > > De: mailscanner-bounces@lists.mailscanner.info > > > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de > > > Julian > > Field > > > Enviada em: segunda-feira, 28 de maio de 2007 11:39 > > > Para: MailScanner discussion > > > Assunto: Re: RES: mcp help > > > > > > What is the name and location of this cf file? > > > Is it being read when MailScanner starts? > > > Do 'ls -lu /etc/MailScanner/mcp' > > > Then wait a minute or two > > > Then 'MailScanner -debug' > > > Then 'ls -lu /etc/MailScanner/mcp' > > > The 'last used' date stamp on the file should have changed. If it > > > hasn't then the file isn't being read, and there's your problem. > > > > > > Wilson A. Galafassi Jr. wrote: > > > > > >> I have only a cf file with this content: > > >> > > >> body SAMPLE_RULE3 /test/i > > >> describe SAMPLE_RULE3 Banned body text > > >> score SAMPLE_RULE3 5 > > >> > > >> what i need to have in rules file? > > >> > > >> -----Mensagem original----- > > >> De: mailscanner-bounces@lists.mailscanner.info > > >> [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de > > >> --[ UxBoD > > > ]-- > > > > > >> Enviada em: segunda-feira, 28 de maio de 2007 07:55 > > >> Para: mailscanner@lists.mailscanner.info > > >> Assunto: Re: mcp help > > >> > > >> Hi, > > >> > > >> Would be useful to see what is in your configuration file with > > >> respect to MCP, and also what you have in your rules file. > > >> > > >> Thanks, > > >> > > >> On Mon, 28 May 2007 07:38:13 -0300 > > >> "Wilson A. Galafassi Jr." wrote: > > >> > > >> > > >> > > >>> Hello to all. > > >>> > > >>> > > >>> > > >>> I'm configuring mailscanner and mcp settings don't working. > > >>> > > >>> > > >>> > > >>> When i send or receive a mail with containing in the body the > > >>> expression "test" the mail isn't mcp marked. > > >>> > > >>> > > >>> > > >>> Can someone tell me what i have to change? > > >>> > > >>> > > >>> > > >>> Very thanks. > > >>> > > >>> > > >>> > > >>> Wilson > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> I have this in my cf file: > > >>> > > >>> > > >>> > > >>> body SAMPLE_RULE3 /test/i > > >>> > > >>> describe SAMPLE_RULE3 Banned body text > > >>> > > >>> score SAMPLE_RULE3 5 > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> in MailScanner.conf i have: > > >>> > > >>> > > >>> > > >>> MCP Checks = yes > > >>> > > >>> > > >>> > > >>> # Do the spam checks first, or the MCP checks first? > > >>> > > >>> # This cannot be the filename of a ruleset, only a fixed value. > > >>> > > >>> First Check = mcp > > >>> > > >>> > > >>> > > >>> # The rest of these options are clones of the equivalent spam > > >>> options MCP Required SpamAssassin Score = 1 MCP High > > >>> SpamAssassin Score = 10 MCP Error Score = 1 > > >>> > > >>> > > >>> > > >>> MCP Header = X-%org-name%-MailScanner-MCPCheck: > > >>> > > >>> Non MCP Actions = deliver > > >>> > > >>> MCP Actions = deliver store > > >>> > > >>> High Scoring MCP Actions = store > > >>> > > >>> Bounce MCP As Attachment = no > > >>> > > >>> > > >>> > > >>> MCP Modify Subject = start > > >>> > > >>> MCP Subject Text = {MCP?} > > >>> > > >>> High Scoring MCP Modify Subject = start > > >>> > > >>> High Scoring MCP Subject Text = {MCP?} > > >>> > > >>> > > >>> > > >>> Is Definitely MCP = no > > >>> > > >>> Is Definitely Not MCP = no > > >>> > > >>> Definite MCP Is High Scoring = yes > > >>> > > >>> Always Include MCP Report = yes > > >>> > > >>> Detailed MCP Report = yes > > >>> > > >>> Include Scores In MCP Report = yes > > >>> > > >>> Log MCP = yes > > >>> > > >>> > > >>> > > >>> MCP Max SpamAssassin Timeouts = 20 > > >>> > > >>> MCP Max SpamAssassin Size = 100k > > >>> > > >>> MCP SpamAssassin Timeout = 10 > > >>> > > >>> > > >>> > > >>> MCP SpamAssassin Prefs File = > > >>> %mcp-dir%/mcp.spam.assassin.prefs.conf > > >>> > > >>> MCP SpamAssassin User State Dir = > > >>> > > >>> MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin > > >>> Default Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = > > >>> %mcp-dir% Recipient MCP Report = > > >>> %report-dir%/recipient.mcp.report.txt > > >>> > > >>> Sender MCP Report = %report-dir%/sender.mcp.report.txt > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> > > >> > > >> > > > > > > Jules > > > > > > > > > > Jules > > > > > - -- > - --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg > --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F > 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // > Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -----BEGIN > PGP SIGNATURE----- Version: GnuPG v2.0.4 (GNU/Linux) > > iD8DBQFGWwI5H7GwL121aHsRAkwMAJ9AT/ohhFUYY9l0jZg41dJ/ajXKPwCgrpsL > JJACR7i6g68vYDzClM7+JLI= > =ksEJ > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > - -- - --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.4 (GNU/Linux) iD8DBQFGWzB3H7GwL121aHsRAkIMAJ9h/2kEed1xQ3n+ApHgXFSKQpk97QCfQyF3 u6y+IhmRpJyDd4x1P0ZPVmI= =zRHE -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From hvdkooij at vanderkooij.org Mon May 28 20:43:13 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Mon May 28 20:43:56 2007 Subject: Question... In-Reply-To: References: Message-ID: On Mon, 28 May 2007, Fabio Silva wrote: > Thanks, i have this working.... > helped me in the irc >From a practical point. Please be more descriptive on the solution provided. As some people will be bound to look for it based on your original question once the search engines have indexed the mailinglist archives today. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From gerard at seibercom.net Mon May 28 21:32:49 2007 From: gerard at seibercom.net (Gerard Seibert) Date: Mon May 28 21:31:47 2007 Subject: Reject mail from invalid domains In-Reply-To: References: <465B004F.1@halla.pt> Message-ID: <20070528162743.6AD3.GERARD@seibercom.net> On Monday May 28, 2007 at 12:56:02 (PM) Koopmann, Jan-Peter wrote: > > im using Fedora core 6, with Mailscanner 4.59.4 and sendmail > > 8.13.8. I want to block email from invalid domains. Can i do this with > > Mailscanner/spamassassin or has to be done at MTA level? > > You probably could do this with spamassassin but the MTA is the correct > place. How do you define "invalid domain"? That's the interesting > question. The mail should definitely be blocked by your MTA. If you accept it and then try to bounce it, it will cause 'backscatter' which could cause you to be blacklisted yourself. -- Gerard "I once heard two ladies going on and on about the pains of childbirth and how men don't seem to know what real pain is. I asked if either of them ever got themselves caught in a zipper." Emo Philips From fssilva at gmail.com Mon May 28 21:44:09 2007 From: fssilva at gmail.com (Fabio Silva) Date: Mon May 28 21:44:13 2007 Subject: Question... In-Reply-To: References: Message-ID: Ok... good... so.. i did this: In the file /etc/MailScanner/MailScanner.conf the options Spam Actions = store deliver header "X-Spam-Status: Yes" High Scoring Spam Actions = store deliver header "X-Spam-Status: Yes" Non Spam Actions = store deliver header "X-Spam-Status: No" I set this options with the option "store" to store all the mails... the emails with spam, with high spam and the mails that isnt spam.... it is usefull if you have any mail that is SPAM but the mailscanner didnt know it... so you can open the message through mailwatch and tell to mailscanner that its message is SPAM ... you teach the spamassassin. Regards, On 5/28/07, Hugo van der Kooij wrote: > > On Mon, 28 May 2007, Fabio Silva wrote: > > > Thanks, i have this working.... > > helped me in the irc > > >From a practical point. Please be more descriptive on the solution > provided. As some people will be bound to look for it based on your > original question once the search engines have indexed the mailinglist > archives today. > > Hugo. > > -- > hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ > This message is using 100% recycled electrons. > > Some men see computers as they are and say "Windows" > I use computers with Linux and say "Why Windows?" > (Thanks JFK, for the insight.) > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070528/a415bacf/attachment.html From ssilva at sgvwater.com Mon May 28 22:30:19 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 28 22:30:57 2007 Subject: semi [OT] IEFT moves DK to draft standard In-Reply-To: <7EF0EE5CB3B263488C8C18823239BEBA03CEDB@HC-MBX02.herefordshire.gov.uk> References: <3abb4d8b6610964cad498e381c76e521@solidstatelogic.com> <005501c79f17$af69f710$6389a8c0@di.unito.it> <7EF0EE5CB3B263488C8C18823239BEBA03CEDB@HC-MBX02.herefordshire.gov.uk> Message-ID: Randal, Phil spake the following on 5/26/2007 2:05 AM: > For what it's worth, I've already seen DomainKeys signed spam here. > > All DKIM is going to do is tell you that the sender is in charge of the > DNS for that domain. > > It could help blocking stuff from spambots if enough people adopt it, I > guess. > > Cheers, > > Phil That is what I think, too. But spambots are near the top of the spam chain, so I guess it will help. I think Domainkeys will be like SPF. You will have to get it working so others will accept YOUR mail. I had to get SPF working because the people who sign my paychecks needed to send mail to addresses that used SPF as a filtering point. And I always make the check signers happy!! ;-P -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Mon May 28 22:46:06 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 28 22:46:33 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: References: <46580875.5090505@netmagicsolutions.com> <465814ED.4010508@netmagicsolutions.com> Message-ID: Koopmann, Jan-Peter spake the following on 5/26/2007 6:00 AM: > On Saturday, May 26, 2007 1:07 PM Dhawal Doshy wrote: > >> maybe i didn't explain it well enough.. >> >> When your users connect on the outgoing SMTP server, their MUAs are >> talking to your servers so you have to relax your rules.. >> >> For incoming mails (your MX record), MTAs are talking to you (not >> MUAs) so you ought to expect someone sensible running them and you >> can afford to reject on certain criteria. >> >> Based on the above assumption, you can for instance use >> zen.spamhaus.org on the incoming MTA (MX) without worrying, you do >> not want it on the outgoing MTA since your senders *will* mostly be >> sending from a DSL like connections. > > > Obviously I did not explain it well enough. I am aware of all you are > saying and it is missing the point completly, which is due to my faulty > mail. Sorry. > > I am running several anti-virus/anti-spam installations for our > customers. They are all using Exchange/Outlook etc. behind those > installations. It is not their users I am worried about. They are all > using SSL VPN or similar to communicate with their server. > > It is their customers that are using braindead mail installations. Their > customers (the ones sending them inquiries, purchase orders etc.) tend > to have malconfigured MTAs, send SMTP mail via Outlook from their > dynamic DSL connections, ships via satellites etc. Enforcing all the > common rules would mean that at least some of those inquiries/purchase > orders will not reach them. So they can either not enforce too strict a > ruleset or try to teach/educate their customers. And educating customers > is not a good thing. :-) > > So I was talking about the incoming MTA/MX all along and ways to block > stuff at the MTA level without too strict a ruleset. We already do > things like tarpitting dynamic IPs, turn off pipelining, use several RBL > lists for tarpitting and spamhouse for blocking, connection delays etc. > Up to a week ago this combination held off most of the spam. We see a > massive increase of botnet-spam though that seems to get past this first > line of defence. > > Just wanted to make sure I am not missing something obvious before I > tell our customers to either live with it and catch it with SpamAssassin > (which currently works fair enough) or to enforce strict rules. > > Thanks for all your suggestions. Besides the hint for the TrendMicro RBL > which I was not aware of I think we are already doing what can be done. > > > Kind regards > > Jan-Peter Koopmann You might be at that point. Sometimes you just have to do a lot of post MTA processing if you nned to accept mail (and money) from customers. You are right about one thing. If a customer can't order your product easily, they will take their money elsewhere. What you could consider would be more than one gateway, one more strict than the other, and then let the customers decide which one suits their business requirements. The customers with less reliance on outside customers might like a more strict gateway. That way you can make more of "your" customers happy. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Mon May 28 22:56:01 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Mon May 28 22:57:04 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: <421437.76431.qm@web26311.mail.ukl.yahoo.com> References: <421437.76431.qm@web26311.mail.ukl.yahoo.com> Message-ID: Andrew MacLachlan spake the following on 5/27/2007 9:54 AM: > Some would consider zen.spamhaus.org a little too hardcore (me!), but sbl-xbl.spamhaus.org and list.dsbl.org are good... > AFAIR the sbl-xbl lookups might be disabled sometime in the future. Up to spamhaus discretion. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From wilson.galafassi at gmail.com Tue May 29 00:09:25 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Tue May 29 00:09:39 2007 Subject: RES: mcp help In-Reply-To: <20070528204135.045a9d5a@uxbod.splatnix.net> References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> Message-ID: spamassassin --D --lint > /tmp/sa.log 2>&1 This is the result. [root@netserver tmp]# cat sa.log [26391] dbg: logger: adding facilities: all [26391] dbg: logger: logging level is DBG [26391] dbg: generic: SpamAssassin version 3.2.0 [26391] dbg: config: score set 0 chosen. [26391] dbg: util: running in taint mode? yes [26391] dbg: util: taint mode: deleting unsafe environment variables, resetting PATH [26391] dbg: util: PATH included '/usr/kerberos/sbin', keeping [26391] dbg: util: PATH included '/usr/kerberos/bin', keeping [26391] dbg: util: PATH included '/usr/local/sbin', keeping [26391] dbg: util: PATH included '/usr/local/bin', keeping [26391] dbg: util: PATH included '/sbin', keeping [26391] dbg: util: PATH included '/bin', keeping [26391] dbg: util: PATH included '/usr/sbin', keeping [26391] dbg: util: PATH included '/usr/bin', keeping [26391] dbg: util: PATH included '/root/bin', which doesn't exist, dropping [26391] dbg: util: final PATH set to: /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b in:/usr/sbin:/usr/bin [26391] dbg: dns: no ipv6 [26391] dbg: dns: is Net::DNS::Resolver available? yes [26391] dbg: dns: Net::DNS version: 0.59 [26391] dbg: diag: perl platform: 5.008008 linux [26391] dbg: diag: module installed: Digest::SHA1, version 2.10 [26391] dbg: diag: module installed: HTML::Parser, version 3.54 [26391] dbg: diag: module installed: Net::DNS, version 0.59 [26391] dbg: diag: module installed: MIME::Base64, version 3.07 [26391] dbg: diag: module installed: DB_File, version 1.814 [26391] dbg: diag: module installed: Net::SMTP, version 2.31 [26391] dbg: diag: module installed: Mail::SPF, version v2.004 [26391] dbg: diag: module installed: Mail::SPF::Query, version 1.999001 [26391] dbg: diag: module installed: IP::Country::Fast, version 604.001 [26391] dbg: diag: module not installed: Razor2::Client::Agent ('require' failed) [26391] dbg: diag: module not installed: Net::Ident ('require' failed) [26391] dbg: diag: module not installed: IO::Socket::INET6 ('require' failed) [26391] dbg: diag: module not installed: IO::Socket::SSL ('require' failed) [26391] dbg: diag: module installed: Compress::Zlib, version 1.41 [26391] dbg: diag: module installed: Time::HiRes, version 1.9707 [26391] dbg: diag: module not installed: Mail::DomainKeys ('require' failed) [26391] dbg: diag: module not installed: Mail::DKIM ('require' failed) [26391] dbg: diag: module installed: DBI, version 1.52 [26391] dbg: diag: module installed: Getopt::Long, version 2.35 [26391] dbg: diag: module installed: LWP::UserAgent, version 2.033 [26391] dbg: diag: module installed: HTTP::Date, version 1.47 [26391] dbg: diag: module installed: Archive::Tar, version 1.32 [26391] dbg: diag: module installed: IO::Zlib, version 1.04 [26391] dbg: diag: module installed: Encode::Detect, version 1.00 [26391] dbg: ignore: using a test message to lint rules [26391] dbg: config: using "/etc/mail/spamassassin" for site rules pre files [26391] dbg: config: read file /etc/mail/spamassassin/init.pre [26391] dbg: config: read file /etc/mail/spamassassin/v310.pre [26391] dbg: config: read file /etc/mail/spamassassin/v312.pre [26391] dbg: config: read file /etc/mail/spamassassin/v320.pre [26391] dbg: config: using "/usr/share/spamassassin" for sys rules pre files [26391] dbg: config: using "/usr/share/spamassassin" for default rules dir [26391] dbg: config: read file /usr/share/spamassassin/10_default_prefs.cf [26391] dbg: config: read file /usr/share/spamassassin/20_advance_fee.cf [26391] dbg: config: read file /usr/share/spamassassin/20_body_tests.cf [26391] dbg: config: read file /usr/share/spamassassin/20_compensate.cf [26391] dbg: config: read file /usr/share/spamassassin/20_dnsbl_tests.cf [26391] dbg: config: read file /usr/share/spamassassin/20_drugs.cf [26391] dbg: config: read file /usr/share/spamassassin/20_dynrdns.cf [26391] dbg: config: read file /usr/share/spamassassin/20_fake_helo_tests.cf [26391] dbg: config: read file /usr/share/spamassassin/20_head_tests.cf [26391] dbg: config: read file /usr/share/spamassassin/20_html_tests.cf [26391] dbg: config: read file /usr/share/spamassassin/20_imageinfo.cf [26391] dbg: config: read file /usr/share/spamassassin/20_meta_tests.cf [26391] dbg: config: read file /usr/share/spamassassin/20_net_tests.cf [26391] dbg: config: read file /usr/share/spamassassin/20_phrases.cf [26391] dbg: config: read file /usr/share/spamassassin/20_porn.cf [26391] dbg: config: read file /usr/share/spamassassin/20_ratware.cf [26391] dbg: config: read file /usr/share/spamassassin/20_uri_tests.cf [26391] dbg: config: read file /usr/share/spamassassin/20_vbounce.cf [26391] dbg: config: read file /usr/share/spamassassin/23_bayes.cf [26391] dbg: config: read file /usr/share/spamassassin/25_accessdb.cf [26391] dbg: config: read file /usr/share/spamassassin/25_antivirus.cf [26391] dbg: config: read file /usr/share/spamassassin/25_asn.cf [26391] dbg: config: read file /usr/share/spamassassin/25_dcc.cf [26391] dbg: config: read file /usr/share/spamassassin/25_dkim.cf [26391] dbg: config: read file /usr/share/spamassassin/25_domainkeys.cf [26391] dbg: config: read file /usr/share/spamassassin/25_hashcash.cf [26391] dbg: config: read file /usr/share/spamassassin/25_pyzor.cf [26391] dbg: config: read file /usr/share/spamassassin/25_razor2.cf [26391] dbg: config: read file /usr/share/spamassassin/25_replace.cf [26391] dbg: config: read file /usr/share/spamassassin/25_spf.cf [26391] dbg: config: read file /usr/share/spamassassin/25_textcat.cf [26391] dbg: config: read file /usr/share/spamassassin/25_uribl.cf [26391] dbg: config: read file /usr/share/spamassassin/30_text_de.cf [26391] dbg: config: read file /usr/share/spamassassin/30_text_fr.cf [26391] dbg: config: read file /usr/share/spamassassin/30_text_it.cf [26391] dbg: config: read file /usr/share/spamassassin/30_text_nl.cf [26391] dbg: config: read file /usr/share/spamassassin/30_text_pl.cf [26391] dbg: config: read file /usr/share/spamassassin/30_text_pt_br.cf [26391] dbg: config: read file /usr/share/spamassassin/50_scores.cf [26391] dbg: config: read file /usr/share/spamassassin/60_awl.cf [26391] dbg: config: read file /usr/share/spamassassin/60_shortcircuit.cf [26391] dbg: config: read file /usr/share/spamassassin/60_whitelist.cf [26391] dbg: config: read file /usr/share/spamassassin/60_whitelist_dk.cf [26391] dbg: config: read file /usr/share/spamassassin/60_whitelist_dkim.cf [26391] dbg: config: read file /usr/share/spamassassin/60_whitelist_spf.cf [26391] dbg: config: read file /usr/share/spamassassin/60_whitelist_subject.cf [26391] dbg: config: read file /usr/share/spamassassin/72_active.cf [26391] dbg: config: using "/etc/mail/spamassassin" for site rules dir [26391] dbg: config: read file /etc/mail/spamassassin/local.cf [26391] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [26391] dbg: razor2: local tests only, skipping Razor [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC [26391] dbg: pyzor: local tests only, disabling Pyzor [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [26391] dbg: razor2: local tests only, skipping Razor [26391] dbg: plugin: did not register Mail::SpamAssassin::Plugin::Razor2=HASH(0x9a471b8), already registered [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::SpamCop from @INC [26391] dbg: reporter: local tests only, disabling SpamCop [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [26391] dbg: plugin: did not register Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x99ea030), already registered [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [26391] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SPF=HASH(0x9a47374), already registered [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [26391] dbg: plugin: did not register Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x99e131c), already registered [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [26391] dbg: plugin: did not register Mail::SpamAssassin::Plugin::ASN=HASH(0x986ce94), already registered [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [26391] dbg: plugin: did not register Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x9d35878), already registered [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [26391] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SPF=HASH(0x9a4786c), already registered [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [26391] dbg: plugin: did not register Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x99ea54c), already registered [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [26391] dbg: razor2: local tests only, skipping Razor [26391] dbg: plugin: did not register Mail::SpamAssassin::Plugin::Razor2=HASH(0x99ea6e4), already registered [26391] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [26391] dbg: plugin: did not register Mail::SpamAssassin::Plugin::ASN=HASH(0x989b800), already registered [26391] dbg: rules: __MO_OL_9B90B merged duplicates: __MO_OL_C65FA [26391] dbg: rules: __XM_OL_22B61 merged duplicates: __XM_OL_A842E [26391] dbg: rules: __MO_OL_07794 merged duplicates: __MO_OL_8627E __MO_OL_F3B05 [26391] dbg: rules: __XM_OL_07794 merged duplicates: __XM_OL_25340 __XM_OL_3857F __XM_OL_4F240 __XM_OL_58CB5 __XM_OL_6554A __XM_OL_812FF __XM_OL_C65FA __XM_OL_CF0C0 __XM_OL_F475E __XM_OL_F6D01 [26391] dbg: rules: FH_MSGID_01C67 merged duplicates: __MSGID_VGA [26391] dbg: rules: FS_NEW_SOFT_UPLOAD merged duplicates: HS_SUBJ_NEW_SOFTWARE [26391] dbg: rules: __FH_HAS_XMSMAIL merged duplicates: __HAS_MSMAIL_PRI [26391] dbg: rules: __MO_OL_015D5 merged duplicates: __MO_OL_6554A [26391] dbg: rules: __MO_OL_91287 merged duplicates: __MO_OL_B30D1 __MO_OL_CF0C0 [26391] dbg: rules: __XM_OL_015D5 merged duplicates: __XM_OL_4BF4C __XM_OL_4EEDB __XM_OL_5B79A __XM_OL_9B90B __XM_OL_ADFF7 __XM_OL_B30D1 __XM_OL_B4B40 __XM_OL_BC7E6 __XM_OL_F3B05 __XM_OL_FF5C8 [26391] dbg: rules: __XM_OL_5E7ED merged duplicates: __XM_OL_D03AB [26391] dbg: rules: __MO_OL_22B61 merged duplicates: __MO_OL_4F240 __MO_OL_ADFF7 [26391] dbg: rules: __MO_OL_812FF merged duplicates: __MO_OL_BC7E6 [26391] dbg: rules: __MO_OL_25340 merged duplicates: __MO_OL_4EEDB __MO_OL_7533E [26391] dbg: rules: __MO_OL_58CB5 merged duplicates: __MO_OL_B4B40 [26391] dbg: rules: __DOS_HAS_ANY_URI merged duplicates: __HAS_ANY_URI [26391] dbg: rules: __XM_OL_C7C33 merged duplicates: __XM_OL_C9068 __XM_OL_EF20B [26391] dbg: rules: __MO_OL_72641 merged duplicates: __MO_OL_A842E [26391] dbg: rules: __MO_OL_5E7ED merged duplicates: __MO_OL_C7C33 [26391] dbg: rules: __MO_OL_F475E merged duplicates: __MO_OL_FF5C8 [26391] dbg: rules: __MO_OL_4BF4C merged duplicates: __MO_OL_F6D01 [26391] dbg: conf: finish parsing [26391] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x99e9fac) implements 'finish_parsing_end', priority 0 [26391] dbg: replacetags: replacing tags [26391] dbg: replacetags: done replacing tags [26391] dbg: config: score set 0 chosen. [26391] dbg: message: main message type: text/plain [26391] dbg: message: ---- MIME PARSER START ---- [26391] dbg: message: parsing normal part [26391] dbg: message: ---- MIME PARSER END ---- [26391] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x9c1c160) implements 'check_start', priority 0 [26391] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x996d650) implements 'check_main', priority 0 [26391] dbg: conf: trusted_networks are not configured; it is recommended that you configure trusted_networks manually [26391] dbg: metadata: X-Spam-Relays-Trusted: [26391] dbg: metadata: X-Spam-Relays-Untrusted: [26391] dbg: metadata: X-Spam-Relays-Internal: [26391] dbg: metadata: X-Spam-Relays-External: [26391] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x98be748) implements 'extract_metadata', priority 0 [26391] dbg: metadata: X-Relay-Countries: [26391] dbg: message: no encoding detected [26391] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x986cba0) implements 'parsed_metadata', priority 0 [26391] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x98be748) implements 'parsed_metadata', priority 0 [26391] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x9899640) implements 'parsed_metadata', priority 0 [26391] dbg: dns: is DNS available? 0 [26391] dbg: asn: DNS is not available, skipping ASN checks [26391] dbg: rules: local tests only, ignoring RBL eval [26391] dbg: check: running tests for priority: -1000 [26391] dbg: rules: running head tests; score so far=0 [26391] dbg: rules: compiled head tests [26391] dbg: eval: all '*From' addrs: ignore@compiling.spamassassin.taint.org [26391] dbg: eval: all '*To' addrs: [26391] dbg: rules: running body tests; score so far=0 [26391] dbg: rules: compiled body tests [26391] dbg: rules: running uri tests; score so far=0 [26391] dbg: rules: compiled uri tests [26391] dbg: rules: running rawbody tests; score so far=0 [26391] dbg: rules: compiled rawbody tests [26391] dbg: rules: running full tests; score so far=0 [26391] dbg: rules: compiled full tests [26391] dbg: rules: running meta tests; score so far=0 [26391] dbg: rules: compiled meta tests [26391] dbg: check: running tests for priority: -950 [26391] dbg: rules: running head tests; score so far=0 [26391] dbg: rules: compiled head tests [26391] dbg: rules: running body tests; score so far=0 [26391] dbg: rules: compiled body tests [26391] dbg: rules: running uri tests; score so far=0 [26391] dbg: rules: compiled uri tests [26391] dbg: rules: running rawbody tests; score so far=0 [26391] dbg: rules: compiled rawbody tests [26391] dbg: rules: running full tests; score so far=0 [26391] dbg: rules: compiled full tests [26391] dbg: rules: running meta tests; score so far=0 [26391] dbg: rules: compiled meta tests [26391] dbg: check: running tests for priority: -900 [26391] dbg: rules: running head tests; score so far=0 [26391] dbg: rules: compiled head tests [26391] dbg: rules: running body tests; score so far=0 [26391] dbg: rules: compiled body tests [26391] dbg: rules: running uri tests; score so far=0 [26391] dbg: rules: compiled uri tests [26391] dbg: rules: running rawbody tests; score so far=0 [26391] dbg: rules: compiled rawbody tests [26391] dbg: rules: running full tests; score so far=0 [26391] dbg: rules: compiled full tests [26391] dbg: rules: running meta tests; score so far=0 [26391] dbg: rules: compiled meta tests [26391] dbg: check: running tests for priority: -400 [26391] dbg: rules: running head tests; score so far=0 [26391] dbg: rules: compiled head tests [26391] dbg: rules: running body tests; score so far=0 [26391] dbg: rules: compiled body tests [26391] dbg: rules: running uri tests; score so far=0 [26391] dbg: rules: compiled uri tests [26391] dbg: rules: running rawbody tests; score so far=0 [26391] dbg: rules: compiled rawbody tests [26391] dbg: rules: running full tests; score so far=0 [26391] dbg: rules: compiled full tests [26391] dbg: rules: running meta tests; score so far=0 [26391] dbg: rules: compiled meta tests [26391] dbg: check: running tests for priority: 0 [26391] dbg: rules: running head tests; score so far=0 [26391] dbg: rules: compiled head tests [26391] dbg: rules: ran header rule __MISSING_REF ======> got hit: "UNSET" [26391] dbg: rules: ran header rule __MSGID_OK_HOST ======> got hit: "@lint_rules>" [26391] dbg: rules: ran header rule __MSGID_OK_DIGITS ======> got hit: "1180382336" [26391] dbg: rules: ran header rule __MSOE_MID_WRONG_CASE ======> got hit: " [26391] dbg: rules: Message-Id: " [26391] dbg: rules: ran header rule __HAS_MSGID ======> got hit: "<" [26391] dbg: rules: ran header rule __SANE_MSGID ======> got hit: "<1180382336@lint_rules> [26391] dbg: rules: " [26391] dbg: rules: ran header rule MISSING_DATE ======> got hit: "UNSET" [26391] dbg: spf: checking to see if the message has a Received-SPF header that we can use [26391] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [26391] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [26391] dbg: rules: ran eval rule NO_RELAYS ======> got hit (1) [26391] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [26391] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [26391] dbg: spf: cannot get Envelope-From, cannot use SPF [26391] dbg: spf: def_spf_whitelist_from: could not find useable envelope sender [26391] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [26391] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [26391] dbg: spf: already checked for Received-SPF headers, proceeding with DNS based checks [26391] dbg: rules: ran eval rule __UNUSABLE_MSGID ======> got hit (1) [26391] dbg: rules: ran eval rule MISSING_HEADERS ======> got hit (1) [26391] dbg: spf: spf_whitelist_from: could not find useable envelope sender [26391] dbg: rules: running body tests; score so far=1.899 [26391] dbg: rules: compiled body tests [26391] dbg: rules: ran body rule __NONEMPTY_BODY ======> got hit: "I" [26391] dbg: rules: running uri tests; score so far=1.899 [26391] dbg: rules: compiled uri tests [26391] dbg: https_http_mismatch: anchors 0 [26391] dbg: eval: stock info total: 0 [26391] dbg: rules: running rawbody tests; score so far=1.899 [26391] dbg: rules: compiled rawbody tests [26391] dbg: rules: running full tests; score so far=1.899 [26391] dbg: rules: compiled full tests [26391] dbg: rules: running meta tests; score so far=1.899 [26391] dbg: rules: compiled meta tests [26391] dbg: check: running tests for priority: 500 [26391] dbg: rules: running head tests; score so far=1.899 [26391] dbg: rules: compiled head tests [26391] dbg: rules: running body tests; score so far=1.899 [26391] dbg: rules: compiled body tests [26391] dbg: rules: running uri tests; score so far=1.899 [26391] dbg: rules: compiled uri tests [26391] dbg: rules: running rawbody tests; score so far=1.899 [26391] dbg: rules: compiled rawbody tests [26391] dbg: rules: running full tests; score so far=1.899 [26391] dbg: rules: compiled full tests [26391] dbg: rules: running meta tests; score so far=1.899 [26391] dbg: rules: meta test DIGEST_MULTIPLE has undefined dependency 'DCC_CHECK' [26391] info: rules: meta test HS_PHARMA_1 has dependency 'HS_SUBJ_ONLINE_PHARMACEUTICAL' with a zero score [26391] dbg: rules: compiled meta tests [26391] dbg: check: running tests for priority: 1000 [26391] dbg: rules: running head tests; score so far=4.205 [26391] dbg: rules: compiled head tests [26391] dbg: rules: running body tests; score so far=4.205 [26391] dbg: rules: compiled body tests [26391] dbg: rules: running uri tests; score so far=4.205 [26391] dbg: rules: compiled uri tests [26391] dbg: rules: running rawbody tests; score so far=4.205 [26391] dbg: rules: compiled rawbody tests [26391] dbg: rules: running full tests; score so far=4.205 [26391] dbg: rules: compiled full tests [26391] dbg: rules: running meta tests; score so far=4.205 [26391] dbg: rules: compiled meta tests [26391] dbg: check: is spam? score=4.205 required=5 [26391] dbg: check: tests=MISSING_DATE,MISSING_HEADERS,MISSING_SUBJECT,NO_RECEIVED,NO_RELAYS [26391] dbg: check: subtests=__HAS_MSGID,__MISSING_REF,__MSGID_OK_DIGITS,__MSGID_OK_HOST,__MSOE_ MID_WRONG_CASE,__NONEMPTY_BODY,__SANE_MSGID,__UNUSABLE_MSGID -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de --[ UxBoD ]-- Enviada em: segunda-feira, 28 de maio de 2007 16:42 Para: mailscanner@lists.mailscanner.info Assunto: Re: mcp help -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Wilson, Are you running a valid email through ? What does spammassasin --D - --lint > /tmp/sa.log 2>&1 show ? - From your posting it does seem other errors are apparent. Regards, On Mon, 28 May 2007 15:27:25 -0300 "Wilson A. Galafassi Jr." wrote: > Hello. > > Thanks again in advance. > > My file is readed: read file /etc/MailScanner/mcp/digital.cf > > In digital.cf i have: > > header MY_RULE_1 Subject =~ /block this phrase/i score MY_RULE_1 100 > > body MY_RULE_2 /Block this too/i > score MY_RULE_2 100 > > body MY_RULE_3 /this\s*is\s*more\s*complicated/i score MY_RULE_3 100 > > > but when i send and email containing any matching rules i dont see > marked as mcp. > > > My complete debug above: > > Starting MailScanner daemons: > incoming postfix: [ OK ] > outgoing postfix: [ OK ] > MailScanner: In Debugging mode, not forking... > [18193] dbg: logger: adding facilities: all [18193] dbg: logger: > logging level is DBG [18193] dbg: generic: SpamAssassin version 3.2.0 > [18193] dbg: config: score set 0 chosen. > [18193] dbg: util: running in taint mode? no [18193] dbg: dns: no ipv6 > [18193] dbg: dns: is Net::DNS::Resolver available? yes [18193] dbg: > dns: Net::DNS version: 0.59 [18193] dbg: logger: adding facilities: > all [18193] dbg: logger: logging level is DBG [18193] dbg: generic: > SpamAssassin version 3.2.0 [18193] dbg: config: score set 0 chosen. > [18193] dbg: dns: no ipv6 > [18193] dbg: dns: is Net::DNS::Resolver available? yes [18193] dbg: > dns: Net::DNS version: 0.59 Use of uninitialized value in > concatenation (.) or string at > /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm line 1087. > Use of uninitialized value in concatenation (.) or string at > /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm line 1089. > [18193] dbg: config: read_scoreonly_config: cannot open "": No such > file or directory [18203] dbg: config: using "/etc/MailScanner/mcp" > for site rules pre files [18203] dbg: config: using > "/etc/MailScanner/mcp" for sys rules pre files [18203] dbg: config: > using "/etc/MailScanner/mcp" for default rules dir [18203] dbg: > config: read file /etc/MailScanner/mcp/digital.cf [18203] dbg: config: > using "/etc/MailScanner/mcp" for site rules dir [18203] dbg: config: > read file /etc/MailScanner/mcp/digital.cf [18203] dbg: config: using > "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs > file [18203] dbg: config: read file > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf > [18203] dbg: conf: finish parsing > [18203] dbg: bayes: no dbs present, cannot tie DB R/O: > /home/postfix/.spamassassin/bayes_toks > [18203] dbg: config: score set 1 chosen. > [18203] dbg: message: main message type: multipart/alternative [18203] > dbg: message: ---- MIME PARSER START ---- [18203] dbg: message: > parsing multipart, got boundary: > ----=_NextPart_000_009B_01C7A13B.DBA3DC80 > [18203] dbg: message: found part of type text/plain, boundary: > ----=_NextPart_000_009B_01C7A13B.DBA3DC80 > [18203] dbg: message: added part, type: text/plain [18203] dbg: > message: found part of type text/html, boundary: > ----=_NextPart_000_009B_01C7A13B.DBA3DC80 > [18203] dbg: message: added part, type: text/html [18203] dbg: > message: parsing normal part [18203] dbg: message: parsing normal part > [18203] dbg: message: ---- MIME PARSER END ---- [18203] dbg: bayes: no > dbs present, cannot tie DB R/O: > /home/postfix/.spamassassin/bayes_toks > check: no loaded plugin implements 'check_main': cannot scan! at > /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin/PerMsgStatus.pm line > 164. [18204] dbg: config: using "/etc/mail/spamassassin" for site > rules pre files [18204] dbg: config: read file > /etc/mail/spamassassin/init.pre [18204] dbg: config: read file > /etc/mail/spamassassin/v310.pre [18204] dbg: config: read file > /etc/mail/spamassassin/v312.pre [18204] dbg: config: read file > /etc/mail/spamassassin/v320.pre [18204] dbg: config: using > "/usr/share/spamassassin" for sys rules pre files [18204] dbg: > config: using "/usr/share/spamassassin" for default rules dir [18204] > dbg: config: read file /usr/share/spamassassin/10_default_prefs.cf > [18204] dbg: config: read > file /usr/share/spamassassin/20_advance_fee.cf [18204] dbg: config: > read file /usr/share/spamassassin/20_body_tests.cf [18204] dbg: > config: read file /usr/share/spamassassin/20_compensate.cf [18204] > dbg: config: read file /usr/share/spamassassin/20_dnsbl_tests.cf > [18204] dbg: config: read file /usr/share/spamassassin/20_drugs.cf > [18204] dbg: config: read file /usr/share/spamassassin/20_dynrdns.cf > [18204] dbg: config: read > file /usr/share/spamassassin/20_fake_helo_tests.cf [18204] dbg: > config: read file /usr/share/spamassassin/20_head_tests.cf [18204] > dbg: config: read file /usr/share/spamassassin/20_html_tests.cf > [18204] dbg: config: read > file /usr/share/spamassassin/20_imageinfo.cf [18204] dbg: config: > read file /usr/share/spamassassin/20_meta_tests.cf [18204] dbg: > config: read file /usr/share/spamassassin/20_net_tests.cf [18204] > dbg: config: read file /usr/share/spamassassin/20_phrases.cf [18204] > dbg: config: read file /usr/share/spamassassin/20_porn.cf [18204] > dbg: config: read file /usr/share/spamassassin/20_ratware.cf [18204] > dbg: config: read file /usr/share/spamassassin/20_uri_tests.cf > [18204] dbg: config: read file /usr/share/spamassassin/20_vbounce.cf > [18204] dbg: config: read file /usr/share/spamassassin/23_bayes.cf > [18204] dbg: config: read file /usr/share/spamassassin/25_accessdb.cf > [18204] dbg: config: read > file /usr/share/spamassassin/25_antivirus.cf [18204] dbg: config: > read file /usr/share/spamassassin/25_asn.cf [18204] dbg: config: read > file /usr/share/spamassassin/25_dcc.cf [18204] dbg: config: read file > /usr/share/spamassassin/25_dkim.cf [18204] dbg: config: read file > /usr/share/spamassassin/25_domainkeys.cf [18204] dbg: config: > read file /usr/share/spamassassin/25_hashcash.cf [18204] dbg: config: > read file /usr/share/spamassassin/25_pyzor.cf [18204] dbg: config: > read file /usr/share/spamassassin/25_razor2.cf [18204] dbg: config: > read file /usr/share/spamassassin/25_replace.cf [18204] dbg: config: > read file /usr/share/spamassassin/25_spf.cf [18204] dbg: config: read > file /usr/share/spamassassin/25_textcat.cf [18204] dbg: config: read > file /usr/share/spamassassin/25_uribl.cf [18204] dbg: config: read > file /usr/share/spamassassin/30_text_de.cf [18204] dbg: config: read > file /usr/share/spamassassin/30_text_fr.cf [18204] dbg: config: read > file /usr/share/spamassassin/30_text_it.cf [18204] dbg: config: read > file /usr/share/spamassassin/30_text_nl.cf [18204] dbg: config: read > file /usr/share/spamassassin/30_text_pl.cf [18204] dbg: config: read > file /usr/share/spamassassin/30_text_pt_br.cf [18204] dbg: config: > read file /usr/share/spamassassin/50_scores.cf [18204] dbg: config: > read file /usr/share/spamassassin/60_awl.cf [18204] dbg: config: read > file /usr/share/spamassassin/60_shortcircuit.cf [18204] dbg: config: > read file /usr/share/spamassassin/60_whitelist.cf [18204] dbg: > config: read file /usr/share/spamassassin/60_whitelist_dk.cf [18204] > dbg: config: read file /usr/share/spamassassin/60_whitelist_dkim.cf > [18204] dbg: config: read > file /usr/share/spamassassin/60_whitelist_spf.cf [18204] dbg: config: > read file /usr/share/spamassassin/60_whitelist_subject.cf [18204] > dbg: config: read file /usr/share/spamassassin/72_active.cf [18204] > dbg: config: using "/etc/mail/spamassassin" for site rules dir [18204] > dbg: config: read file /etc/mail/spamassassin/local.cf [18204] dbg: > config: read file /etc/mail/spamassassin/mailscanner.cf > [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL > from @INC [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::Hashcash from @INC [18204] dbg: plugin: > loading Mail::SpamAssassin::Plugin::SPF from @INC [18204] dbg: > plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC > [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from > @INC [18204] dbg: razor2: razor2 is not available [18204] dbg: > plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [18204] > dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC > [18204] dbg: pyzor: network tests on, attempting Pyzor [18204] dbg: > plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [18204] > dbg: razor2: razor2 is not available [18204] dbg: plugin: did not > register Mail::SpamAssassin::Plugin::Razor2=HASH(0xb0a97d8), already > registered [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::SpamCop from @INC [18204] dbg: reporter: > network tests on, attempting SpamCop [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::AWL from @INC [18204] dbg: plugin: > loading Mail::SpamAssassin::Plugin::AutoLearnThreshold from @INC > [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::WhiteListSubject from @INC [18204] dbg: > plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from @INC > [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags > from @INC [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::RelayCountry from @INC [18204] dbg: > plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xafc78c4), already > registered [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::SPF from @INC [18204] dbg: plugin: did not > register Mail::SpamAssassin::Plugin::SPF=HASH(0xb0ce618), already > registered [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::URIDNSBL from @INC [18204] dbg: plugin: > did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0xb000478), already > registered [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::ASN from @INC [18204] dbg: plugin: did not > register Mail::SpamAssassin::Plugin::ASN=HASH(0xafbc9b0), already > registered [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::Check from @INC [18204] dbg: plugin: > loading Mail::SpamAssassin::Plugin::HTTPSMismatch from @INC [18204] > dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC > [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from > @INC [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval > from @INC [18204] dbg: plugin: > loading Mail::SpamAssassin::Plugin::DNSEval from @INC [18204] dbg: > plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC [18204] > dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval > from @INC [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::MIMEEval from @INC [18204] dbg: plugin: > loading Mail::SpamAssassin::Plugin::RelayEval from @INC [18204] dbg: > plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC [18204] > dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC > [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from > @INC [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::ImageInfo from @INC [18204] dbg: plugin: > loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [18204] > dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xb425ddc), already > registered [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::SPF from @INC [18204] dbg: plugin: did not > register Mail::SpamAssassin::Plugin::SPF=HASH(0xb0ceb10), already > registered [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::URIDNSBL from @INC [18204] dbg: plugin: > did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0xafc7dc8), already > registered [18204] dbg: plugin: loading > Mail::SpamAssassin::Plugin::Razor2 from @INC [18204] dbg: razor2: > razor2 is not available [18204] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0xafc7f6c), already registered > [18204] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [18204] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0xafe6e10), already registered > [18204] dbg: config: allowing user rules! [18204] dbg: > rules: __MO_OL_9B90B merged duplicates: __MO_OL_C65FA [18204] dbg: > rules: __XM_OL_22B61 merged duplicates: __XM_OL_A842E [18204] dbg: > rules: __MO_OL_07794 merged duplicates: __MO_OL_8627E __MO_OL_F3B05 > [18204] dbg: rules: __XM_OL_07794 merged duplicates: __XM_OL_25340 > __XM_OL_3857F __XM_OL_4F240 __XM_OL_58CB5 __XM_OL_6554A __XM_OL_812FF > __XM_OL_C65FA __XM_OL_CF0C0 __XM_OL_F475E __XM_OL_F6D01 [18204] dbg: > rules: FH_MSGID_01C67 merged duplicates: __MSGID_VGA [18204] dbg: > rules: FS_NEW_SOFT_UPLOAD merged duplicates: HS_SUBJ_NEW_SOFTWARE > [18204] dbg: rules: __FH_HAS_XMSMAIL merged duplicates: > __HAS_MSMAIL_PRI [18204] dbg: rules: __MO_OL_015D5 merged duplicates: > __MO_OL_6554A [18204] dbg: rules: __MO_OL_91287 merged duplicates: > __MO_OL_B30D1 __MO_OL_CF0C0 [18204] dbg: rules: __XM_OL_015D5 merged > duplicates: __XM_OL_4BF4C __XM_OL_4EEDB __XM_OL_5B79A __XM_OL_9B90B > __XM_OL_ADFF7 __XM_OL_B30D1 __XM_OL_B4B40 __XM_OL_BC7E6 __XM_OL_F3B05 > __XM_OL_FF5C8 [18204] dbg: rules: __XM_OL_5E7ED merged duplicates: > __XM_OL_D03AB [18204] dbg: rules: __MO_OL_22B61 merged duplicates: > __MO_OL_4F240 __MO_OL_ADFF7 [18204] dbg: rules: __MO_OL_812FF merged > duplicates: __MO_OL_BC7E6 [18204] dbg: rules: __MO_OL_25340 merged > duplicates: __MO_OL_4EEDB __MO_OL_7533E [18204] dbg: rules: > __MO_OL_58CB5 merged duplicates: __MO_OL_B4B40 [18204] dbg: rules: > __DOS_HAS_ANY_URI merged duplicates: __HAS_ANY_URI [18204] dbg: > rules: __XM_OL_C7C33 merged duplicates: __XM_OL_C9068 __XM_OL_EF20B > [18204] dbg: rules: __MO_OL_72641 merged duplicates: __MO_OL_A842E > [18204] dbg: rules: __MO_OL_5E7ED merged duplicates: __MO_OL_C7C33 > [18204] dbg: rules: __MO_OL_F475E merged duplicates: __MO_OL_FF5C8 > [18204] dbg: rules: __MO_OL_4BF4C merged duplicates: __MO_OL_F6D01 > [18204] dbg: conf: finish parsing [18204] dbg: plugin: > Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0xafc7840) implements > 'finish_parsing_end', priority 0 [18204] dbg: replacetags: replacing > tags [18204] dbg: replacetags: done replacing tags [18204] dbg: bayes: > tie-ing to DB file R/O /var/spool/MailScanner/spamassassin/bayes_toks > [18204] dbg: bayes: tie-ing to DB file R/O > /var/spool/MailScanner/spamassassin/bayes_seen > [18204] dbg: bayes: found bayes db version 3 [18204] dbg: bayes: DB > journal sync: last sync: 0 [18204] dbg: bayes: not available for > scanning, only 7 spam(s) in bayes DB < 200 [18204] dbg: bayes: > untie-ing [18204] dbg: config: score set 1 chosen. > [18204] dbg: message: main message type: multipart/alternative [18204] > dbg: message: ---- MIME PARSER START ---- [18204] dbg: message: > parsing multipart, got boundary: > ----=_NextPart_000_009B_01C7A13B.DBA3DC80 > [18204] dbg: message: found part of type text/plain, boundary: > ----=_NextPart_000_009B_01C7A13B.DBA3DC80 > [18204] dbg: message: added part, type: text/plain [18204] dbg: > message: found part of type text/html, boundary: > ----=_NextPart_000_009B_01C7A13B.DBA3DC80 > [18204] dbg: message: added part, type: text/html [18204] dbg: > message: parsing normal part [18204] dbg: message: parsing normal part > [18204] dbg: message: ---- MIME PARSER END ---- [18204] dbg: plugin: > Mail::SpamAssassin::Plugin::DNSEval=HASH(0xb2e6dcc) implements > 'check_start', priority 0 [18204] dbg: bayes: tie-ing to DB file R/O > /var/spool/MailScanner/spamassassin/bayes_toks > [18204] dbg: bayes: tie-ing to DB file R/O > /var/spool/MailScanner/spamassassin/bayes_seen > [18204] dbg: bayes: found bayes db version 3 [18204] dbg: bayes: DB > journal sync: last sync: 0 [18204] dbg: bayes: not available for > scanning, only 7 spam(s) in bayes DB < 200 [18204] dbg: bayes: > untie-ing [18204] dbg: plugin: > Mail::SpamAssassin::Plugin::Check=HASH(0xb2cb8a4) > implements 'check_main', priority 0 > [18204] dbg: conf: trusted_networks are not configured; it is > recommended that you configure trusted_networks manually [18204] dbg: > received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp > by=netserver.ftpmanager.com ident= envfrom= intl=0 id=7F1861086FB > auth= msa=0 ] [18204] dbg: received-header: 'from' 192.168.0.1 has > private IP [18204] dbg: received-header: relay 192.168.0.1 trusted? > yes internal? yes msa? no [18204] dbg: metadata: > X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= helo=sdxp > by=netserver.ftpmanager.com ident= envfrom= intl=1 id=7F1861086FB > auth= msa=0 ] [18204] dbg: metadata: X-Spam-Relays-Untrusted: > [18204] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanager.com ident= envfrom= intl=1 > id=7F1861086FB auth= msa=0 ] [18204] dbg: metadata: > X-Spam-Relays-External: > [18204] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xb00a13c) implements > 'extract_metadata', priority 0 [18204] dbg: metadata: > X-Relay-Countries: > [18204] dbg: message: decoding quoted-printable [18204] dbg: message: > decoding quoted-printable [18204] dbg: plugin: > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0xafbc6d4) implements > 'parsed_metadata', priority 0 [18204] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0xb00a13c) implements > 'parsed_metadata', priority 0 [18204] dbg: plugin: > Mail::SpamAssassin::Plugin::ASN=HASH(0xafe4c68) > implements 'parsed_metadata', priority 0 [18204] dbg: dns: > dns_available set to yes in config file, skipping test [18204] dbg: > uridnsbl: domains to query: > [18204] dbg: asn: could not parse IP from first external relay, > skipping ASN check [18204] dbg: check: running tests for priority: > -1000 [18204] dbg: rules: running head tests; score so far=0 [18204] > dbg: rules: compiled head tests [18204] dbg: eval: all '*From' addrs: > wilson@ftpmanager.com [18204] dbg: eval: all '*To' addrs: > wilson.galafassi@gmail.com [18204] dbg: rules: running body tests; > score so far=0 [18204] dbg: rules: compiled body tests [18204] dbg: > rules: running uri tests; score so far=0 [18204] dbg: rules: compiled > uri tests [18204] dbg: rules: running rawbody tests; score so far=0 > [18204] dbg: rules: compiled rawbody tests [18204] dbg: rules: running > full tests; score so far=0 [18204] dbg: rules: compiled full tests > [18204] dbg: rules: running meta tests; score so far=0 [18204] dbg: > rules: compiled meta tests [18204] dbg: check: running tests for > priority: -950 [18204] dbg: rules: running head tests; score so far=0 > [18204] dbg: rules: compiled head tests [18204] dbg: rules: ran eval > rule ALL_TRUSTED ======> got hit (1) [18204] dbg: rules: running body > tests; score so far=-1.44 [18204] dbg: rules: compiled body tests > [18204] dbg: rules: running uri tests; score so far=-1.44 [18204] dbg: > rules: compiled uri tests [18204] dbg: rules: running rawbody tests; > score so far=-1.44 [18204] dbg: rules: compiled rawbody tests [18204] > dbg: rules: running full tests; score so far=-1.44 [18204] dbg: rules: > compiled full tests [18204] dbg: rules: running meta tests; score so > far=-1.44 [18204] dbg: rules: compiled meta tests [18204] dbg: check: > running tests for priority: -900 [18204] dbg: rules: running head > tests; score so far=-1.44 [18204] dbg: rules: compiled head tests > [18204] dbg: rules: running body tests; score so far=-1.44 [18204] > dbg: rules: compiled body tests [18204] dbg: rules: running uri tests; > score so far=-1.44 [18204] dbg: rules: compiled uri tests [18204] dbg: > rules: running rawbody tests; score so far=-1.44 [18204] dbg: rules: > compiled rawbody tests [18204] dbg: rules: running full tests; score > so far=-1.44 [18204] dbg: rules: compiled full tests [18204] dbg: > rules: running meta tests; score so far=-1.44 [18204] dbg: rules: > compiled meta tests [18204] dbg: check: running tests for priority: > -400 [18204] dbg: rules: running head tests; score so far=-1.44 > [18204] dbg: rules: compiled head tests [18204] dbg: rules: running > body tests; score so far=-1.44 [18204] dbg: rules: compiled body tests > [18204] dbg: rules: running uri tests; score so far=-1.44 [18204] dbg: > rules: compiled uri tests [18204] dbg: rules: running rawbody tests; > score so far=-1.44 [18204] dbg: rules: compiled rawbody tests [18204] > dbg: rules: running full tests; score so far=-1.44 [18204] dbg: rules: > compiled full tests [18204] dbg: rules: running meta tests; score so > far=-1.44 [18204] dbg: rules: compiled meta tests [18204] dbg: check: > running tests for priority: 0 [18204] dbg: rules: running head tests; > score so far=-1.44 [18204] dbg: rules: compiled head tests [18204] > dbg: rules: ran header rule __CTYPE_MULTIPART_ALT ======> got > hit: "multipart/alternative" > [18204] dbg: rules: ran header rule __CTYPE_HAS_BOUNDARY ======> got > hit: "boundary" > [18204] dbg: rules: ran header rule __CT ======> got hit: "m" > [18204] dbg: rules: ran header rule __MISSING_REF ======> got hit: > "UNSET" [18204] dbg: rules: ran header rule __FH_HAS_XPRIORITY ======> > got hit: "3" [18204] dbg: rules: ran header rule __MIME_VERSION > ======> got hit: "1" [18204] dbg: rules: ran header rule __HAS_RCVD > ======> got hit: "f" [18204] dbg: rules: ran header rule > __DOS_RCVD_MON ======> got hit: " Mon, " [18204] dbg: rules: ran > header rule __TOCC_EXISTS ======> got hit: "<" [18204] dbg: rules: > ran header rule __MSGID_OK_HOST ======> got hit: "@sdxp>" > [18204] dbg: rules: ran header rule __MSGID_OK_HEX ======> got hit: > "010b5340" > [18204] dbg: rules: ran header rule __MIMEOLE_MS ======> got hit: > "Produced By Microsoft MimeOLE" > [18204] dbg: rules: ran header rule __HDR_ORDER_FTSDMCXXXX ======> got > hit: " > [18204] dbg: rules: From: "Wilson - FTP" > [18204] dbg: rules: To: [18204] dbg: > rules: Subject: Fw: block this phrase [18204] dbg: rules: Date: Mon, > 28 May 2007 15:21:26 -0300 [18204] dbg: rules: MIME-Version: 1.0 > [18204] dbg: rules: Content-Type: multipart/alternative; > boundary="----=_NextPart_000_009B_01C7A13B.DBA3DC80" > [18204] dbg: rules: X-Priority: 3 > [18204] dbg: rules: X-MSMail-Priority: Normal [18204] dbg: rules: > X-Mailer: Microsoft Outlook Express 6.00.2900.3028 [18204] dbg: rules: > X-MimeOLE:" > [18204] dbg: rules: ran header rule __HAS_MSGID ======> got hit: "<" > [18204] dbg: rules: ran header rule __SANE_MSGID ======> got hit: > "<009e01c7a155$010b5340$0100a8c0@sdxp> > [18204] dbg: rules: " > [18204] dbg: rules: ran header rule __MSGID_DOLLARS_MAYBE ======> got > hit: "<009e01c7a155$010b5340$0100a8c0@sdxp>" > [18204] dbg: rules: ran header rule __MSGID_DOLLARS_OK ======> got > hit: "<009e01c7a155$010b5340$0100a8c0@sdxp>" > [18204] dbg: rules: ran header rule __OE_MSGID_2 ======> got hit: > "<009e01c7a155$010b5340$0100a8c0@sdxp>" > [18204] dbg: rules: ran header rule __FH_HAS_XMSMAIL ======> got hit: > "N" [18204] dbg: rules: ran header rule __HAS_SUBJECT ======> got > hit: "F" [18204] dbg: rules: ran header rule __XM_MS_IN_GENERAL > ======> got hit: "Microsoft Outlook" > [18204] dbg: rules: ran header rule __XM_OUTLOOK_EXPRESS ======> got > hit: "Microsoft Outlook Express 6" > [18204] dbg: rules: ran header rule __ANY_OUTLOOK_MUA ======> got hit: > "Microsoft Outlook" > [18204] dbg: rules: ran header rule __OE_MUA ======> got hit: "Outlook > Express 6." > [18204] dbg: rules: ran header rule __HAS_X_MAILER ======> got hit: > "M" [18204] dbg: rules: ran header rule __XM_MSOE6 ======> got hit: > "Microsoft Outlook Express 6" > [18204] dbg: rules: ran header rule __HAS_MIMEOLE ======> got hit: "P" > [18204] dbg: spf: checking to see if the message has a Received-SPF > header that we can use [18204] dbg: spf: using Mail::SPF for SPF > checks [18204] dbg: spf: no suitable relay for spf use found, skipping > SPF-helo check [18204] dbg: spf: already checked for Received-SPF > headers, proceeding with DNS based checks [18204] dbg: spf: no > suitable relay for spf use found, skipping SPF check [18204] dbg: spf: > def_spf_whitelist_from: already checked spf and didn't get pass, > skipping whitelist check [18204] dbg: spf: whitelist_from_spf: already > checked spf and didn't get pass, skipping whitelist check [18204] dbg: > rules: running body tests; score so far=-1.44 [18204] dbg: rules: > compiled body tests [18204] dbg: rules: ran body rule __DOS_BODY_MON > ======> got hit: > "Monday" [18204] dbg: rules: ran body rule __HAS_ANY_EMAIL ======> got > hit: "i@gmail.c" > [18204] dbg: rules: ran body rule __NONEMPTY_BODY ======> got hit: "F" > [18204] dbg: rules: running uri tests; score so far=-1.44 [18204] dbg: > rules: compiled uri tests [18204] dbg: rules: ran uri rule > __DOS_HAS_ANY_URI ======> got hit: > "m" [18204] dbg: rules: ran eval rule __HTML_LENGTH_1024_1536 ======> > got hit (1) [18204] dbg: https_http_mismatch: anchors 0 [18204] dbg: > eval: stock info total: 0 [18204] dbg: rules: ran eval rule > __TAG_EXISTS_BODY ======> got hit > (1) [18204] dbg: eval: text words: 20, html words: 20 [18204] dbg: > eval: madiff: left: 0, orig: 20, max-difference: 0.00% [18204] dbg: > rules: ran eval rule __MIME_HTML ======> got hit (1) [18204] dbg: > rules: ran eval rule HTML_MESSAGE ======> got hit (1) [18204] dbg: > rules: ran eval rule __TAG_EXISTS_HTML ======> got hit > (1) [18204] dbg: rules: ran eval rule __TAG_EXISTS_HEAD ======> got > hit (1) [18204] dbg: rules: ran eval rule __TAG_EXISTS_META ======> > got hit (1) [18204] dbg: rules: running rawbody tests; score so > far=-1.439 [18204] dbg: rules: compiled rawbody tests [18204] dbg: > rules: ran eval rule __MIME_QP ======> got hit (2) [18204] dbg: rules: > running full tests; score so far=-1.439 [18204] dbg: rules: compiled > full tests [18204] dbg: pyzor: use_pyzor option not enabled, disabling > Pyzor [18204] dbg: rules: running meta tests; score so far=-1.439 > [18204] dbg: rules: compiled meta tests [18204] dbg: check: running > tests for priority: 500 [18204] dbg: rules: running head tests; score > so far=-1.439 [18204] dbg: rules: compiled head tests [18204] dbg: > rules: running body tests; score so far=-1.439 [18204] dbg: rules: > compiled body tests [18204] dbg: rules: running uri tests; score so > far=-1.439 [18204] dbg: rules: compiled uri tests [18204] dbg: rules: > running rawbody tests; score so far=-1.439 [18204] dbg: rules: > compiled rawbody tests [18204] dbg: rules: running full tests; score > so far=-1.439 [18204] dbg: rules: compiled full tests [18204] dbg: > rules: running meta tests; score so far=-1.439 [18204] dbg: rules: > meta test DIGEST_MULTIPLE has undefined dependency 'DCC_CHECK' > [18204] info: rules: meta test HS_PHARMA_1 has dependency > 'HS_SUBJ_ONLINE_PHARMACEUTICAL' with a zero score [18204] dbg: rules: > compiled meta tests [18204] dbg: check: running tests for priority: > 1000 [18204] dbg: rules: running head tests; score so far=-1.439 > [18204] dbg: rules: compiled head tests [18204] dbg: rules: running > body tests; score so far=-1.439 [18204] dbg: rules: compiled body > tests [18204] dbg: rules: running uri tests; score so far=-1.439 > [18204] dbg: rules: compiled uri tests [18204] dbg: rules: running > rawbody tests; score so far=-1.439 [18204] dbg: rules: compiled > rawbody tests [18204] dbg: rules: running full tests; score so > far=-1.439 [18204] dbg: rules: compiled full tests [18204] dbg: rules: > running meta tests; score so far=-1.439 [18204] dbg: rules: compiled > meta tests [18204] dbg: plugin: > Mail::SpamAssassin::Plugin::AutoLearnThreshold=HASH(0xafc50c8) > implements 'autolearn_discriminator', priority 0 [18204] dbg: learn: > auto-learn: currently using scoreset 1 [18204] dbg: learn: auto-learn: > message score: -1.439, computed score for autolearn: 0.001 [18204] > dbg: learn: auto-learn? ham=-1, spam=12, body-points=0.001, > head-points=0.001, learned-points=0 [18204] dbg: learn: auto-learn? > no: inside auto-learn thresholds, not considered ham or spam [18204] > dbg: check: is spam? score=-1.439 required=5 [18204] dbg: check: > tests=ALL_TRUSTED,HTML_MESSAGE [18204] dbg: check: > subtests=__ANY_OUTLOOK_MUA,__CT,__CTYPE_HAS_BOUNDARY,__CTYPE_MULTIPART > _ALT,_ > _DOS_BODY_MON,__DOS_HAS_ANY_URI,__DOS_RCVD_MON,__DOS_REF_TODAY,__FH_HA > S_XMSM > AIL,__FH_HAS_XPRIORITY,__HAS_ANY_EMAIL,__HAS_ANY_URI,__HAS_MIMEOLE,__H > AS_MSG > ID,__HAS_MSMAIL_PRI,__HAS_RCVD,__HAS_SUBJECT,__HAS_X_MAILER,__HDR_ORDE > R_FTSD > MCXXXX,__HTML_LENGTH_1024_1536,__MIMEOLE_MS,__MIME_HTML,__MIME_QP,__MI > ME_VER > SION,__MISSING_REF,__MSGID_DOLLARS_MAYBE,__MSGID_DOLLARS_OK,__MSGID_OK > _HEX,_ > _MSGID_OK_HOST,__NONEMPTY_BODY,__NO_INR_YES_REF,__OE_MSGID_2,__OE_MUA, > __SANE > _MSGID,__TAG_EXISTS_BODY,__TAG_EXISTS_HEAD,__TAG_EXISTS_HTML,__TAG_EXI > STS_ME > TA,__TOCC_EXISTS,__XM_MSOE6,__XM_MS_IN_GENERAL,__XM_OUTLOOK_EXPRESS > [18204] dbg: learn: auto-learn? ham=-1, spam=12, body-points=0.001, > head-points=0.001, learned-points=0 [18204] dbg: learn: auto-learn? > no: inside auto-learn thresholds, not considered ham or spam Ignore > errors about failing to find EOCD signature format error: can't find > EOCD signature at /usr/sbin/MailScanner line 832 format error: file > is too short at /usr/sbin/MailScanner line 832 > > > in maillog: > > May 28 15:25:08 netserver postfix/smtpd[18264]: connect from > unknown[192.168.0.1] May 28 15:25:08 netserver postfix/smtpd[18264]: > AF8251086E9: > client=unknown[192.168.0.1] > May 28 15:25:08 netserver postfix/cleanup[18267]: AF8251086E9: hold: > header Received: from sdxp (unknown [192.168.0.1])??by > netserver.ftpmanager.com (Postfix) with SMTP id AF8251086E9??for > ; Mon, 28 May 2007 15:25:08 -0300 (BRT) > from unknown[192.168.0.1]; from= > to= proto=SMTP helo= May 28 15:25:08 > netserver postfix/cleanup[18267]: AF8251086E9: > message-id=<00a501c7a155$8015e880$0100a8c0@sdxp> > May 28 15:25:08 netserver postfix/smtpd[18264]: disconnect from > unknown[192.168.0.1] May 28 15:25:12 netserver MailScanner[18258]: New > Batch: Scanning 1 messages, 1924 bytes May 28 15:25:12 netserver > MailScanner[18258]: Created attachment dirs for 1 messages May 28 > 15:25:12 netserver MailScanner[18258]: MCP Checks: Starting May 28 > 15:25:12 netserver MailScanner[18258]: Message Content Protection > SpamAssassin returned 512 May 28 15:25:14 netserver > MailScanner[18258]: SpamAssassin returned 0 May 28 15:25:14 netserver > MailScanner[18258]: Virus and Content > Scanning: Starting > May 28 15:25:14 netserver MailScanner[18258]: Commencing scanning by > clamav... > May 28 15:25:22 netserver MailScanner[18258]: Completed scanning by > clamav May 28 15:25:22 netserver MailScanner[18258]: Completed > checking by /usr/bin/file May 28 15:25:22 netserver > MailScanner[18258]: Requeue: > AF8251086E9.6F306 to 788411086FD > May 28 15:25:22 netserver MailScanner[18258]: About to deliver 1 > messages May 28 15:25:22 netserver MailScanner[18258]: Uninfected: > Delivered 1 messages > May 28 15:25:22 netserver MailScanner[18258]: Logging message > AF8251086E9.6F306 to SQL > May 28 15:25:22 netserver MailScanner[18258]: Config: calling custom > end function SQLBlacklist May 28 15:25:22 netserver > MailScanner[18258]: Closing down by-domain spam blacklist May 28 > 15:25:22 netserver MailScanner[18258]: Config: calling custom end > function MailWatchLogging May 28 15:25:22 netserver > MailScanner[18258]: Config: calling custom end function SQLWhitelist > May 28 15:25:22 netserver MailScanner[18258]: Closing down by-domain > spam whitelist May 28 15:25:22 netserver MailScanner[18258]: > MailScanner child dying of old age May 28 15:25:22 netserver > MailScanner[18261]: AF8251086E9.6F306: > Logged to MailWatch SQL > May 28 15:25:22 netserver postfix/qmgr[18177]: 788411086FD: > from=, size=1406, nrcpt=1 (queue active) May 28 > 15:25:26 netserver postfix/smtp[18279]: 788411086FD: > to=, > relay=ftpmanager.com[72.232.196.114]:25, delay=18, > delays=14/0.01/3.3/0.77, dsn=2.0.0, status=sent (250 OK > id=1HsjuI-0008N5-Dk) May 28 15:25:26 netserver postfix/qmgr[18177]: > 788411086FD: removed > > > > > > > > > > > > > > > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de --[ > UxBoD ]-- Enviada em: segunda-feira, 28 de maio de 2007 13:24 > Para: mailscanner@lists.mailscanner.info > Assunto: Re: mcp help > > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Wilson, > > I think you need to concentrate on your SA perms and configuration. > > Get them right first and then re-check. > > UxBoD > > On Mon, 28 May 2007 12:34:05 -0300 > "Wilson A. Galafassi Jr." wrote: > > > Fixed. But mcp still don't working. Any suggestion? > > > > May 28 12:31:37 netserver MailScanner[13591]: New Batch: Scanning 1 > > messages, 1885 bytes May 28 12:31:37 netserver MailScanner[13591]: > > Created attachment dirs for 1 messages May 28 12:31:37 netserver > > MailScanner[13591]: MCP Checks: Starting May 28 12:31:37 netserver > > MailScanner[13591]: Message Content Protection SpamAssassin returned > > 512 May 28 12:31:39 netserver MailScanner[13591]: > > SpamAssassin returned 0 May 28 12:31:39 netserver > > MailScanner[13591]: Virus and Content > > Scanning: Starting > > May 28 12:31:39 netserver MailScanner[13591]: Commencing scanning by > > clamav... > > May 28 12:31:47 netserver MailScanner[13591]: Completed scanning by > > clamav May 28 12:31:47 netserver MailScanner[13591]: Completed > > checking by /usr/bin/file May 28 12:31:47 netserver > > MailScanner[13591]: Requeue: > > 46CF01086FB.48D13 to 6438F1086FD > > May 28 12:31:47 netserver MailScanner[13591]: About to deliver 1 > > messages May 28 12:31:47 netserver postfix/qmgr[13574]: 6438F1086FD: > > from=, size=1367, nrcpt=1 (queue active) May > > 28 12:31:47 netserver MailScanner[13591]: Uninfected: Delivered 1 > > messages May 28 12:31:47 netserver MailScanner[13591]: Logging > > message 46CF01086FB.48D13 to SQL May 28 12:31:47 netserver > > MailScanner[13594]: 46CF01086FB.48D13: > > Logged to MailWatch SQL > > May 28 12:31:47 netserver MailScanner[13591]: Config: calling custom > > end function SQLBlacklist May 28 12:31:47 netserver > > MailScanner[13591]: Closing down by-domain spam blacklist May 28 > > 12:31:47 netserver MailScanner[13591]: Config: calling custom end > > function MailWatchLogging May 28 12:31:47 netserver > > MailScanner[13591]: Config: calling custom end function SQLWhitelist > > May 28 12:31:47 netserver MailScanner[13591]: Closing down by-domain > > spam whitelist May 28 12:31:47 netserver > > MailScanner[13591]: MailScanner child dying of old age May 28 > > 12:31:51 netserver postfix/smtp[13631]: 6438F1086FD: > > to=, > > relay=ftpmanager.com[65.132.196.114]:25, delay=20, > > delays=16/0.02/3.2/0.85, dsn=2.0.0, status=sent (250 OK > > id=1HshCI-0007g4-TE) May 28 12:31:51 netserver postfix/qmgr[13574]: > > 6438F1086FD: removed > > > > -----Mensagem original----- > > De: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de > > Julian Field Enviada em: segunda-feira, 28 de maio de 2007 12:11 > > Para: MailScanner discussion > > Assunto: Re: RES: RES: mcp help > > > > Make sure that the account you are using for MailScanner (set in > > "Run As User =" in MailScanner.conf) can write to its home > > directory. If it doesn't have a home directory, then create one. > > Looks like you are using Postfix or Exim and their home dir is set > > in /etc/passwd to "/no/where". > > > > Wilson A. Galafassi Jr. wrote: > > > Running in debug mode i see: > > > [7297] dbg: config: mkdir /no/where/.spamassassin failed: > > > mkdir /no: Permission denied > > > at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin.pm line 1578 > > > > > > I can't find where to change this setting. > > > This is related to my mcp problem? > > > > > > -----Mensagem original----- > > > De: mailscanner-bounces@lists.mailscanner.info > > > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de > > > Julian > > Field > > > Enviada em: segunda-feira, 28 de maio de 2007 11:39 > > > Para: MailScanner discussion > > > Assunto: Re: RES: mcp help > > > > > > What is the name and location of this cf file? > > > Is it being read when MailScanner starts? > > > Do 'ls -lu /etc/MailScanner/mcp' > > > Then wait a minute or two > > > Then 'MailScanner -debug' > > > Then 'ls -lu /etc/MailScanner/mcp' > > > The 'last used' date stamp on the file should have changed. If it > > > hasn't then the file isn't being read, and there's your problem. > > > > > > Wilson A. Galafassi Jr. wrote: > > > > > >> I have only a cf file with this content: > > >> > > >> body SAMPLE_RULE3 /test/i > > >> describe SAMPLE_RULE3 Banned body text > > >> score SAMPLE_RULE3 5 > > >> > > >> what i need to have in rules file? > > >> > > >> -----Mensagem original----- > > >> De: mailscanner-bounces@lists.mailscanner.info > > >> [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de > > >> --[ UxBoD > > > ]-- > > > > > >> Enviada em: segunda-feira, 28 de maio de 2007 07:55 > > >> Para: mailscanner@lists.mailscanner.info > > >> Assunto: Re: mcp help > > >> > > >> Hi, > > >> > > >> Would be useful to see what is in your configuration file with > > >> respect to MCP, and also what you have in your rules file. > > >> > > >> Thanks, > > >> > > >> On Mon, 28 May 2007 07:38:13 -0300 "Wilson A. Galafassi Jr." > > >> wrote: > > >> > > >> > > >> > > >>> Hello to all. > > >>> > > >>> > > >>> > > >>> I'm configuring mailscanner and mcp settings don't working. > > >>> > > >>> > > >>> > > >>> When i send or receive a mail with containing in the body the > > >>> expression "test" the mail isn't mcp marked. > > >>> > > >>> > > >>> > > >>> Can someone tell me what i have to change? > > >>> > > >>> > > >>> > > >>> Very thanks. > > >>> > > >>> > > >>> > > >>> Wilson > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> I have this in my cf file: > > >>> > > >>> > > >>> > > >>> body SAMPLE_RULE3 /test/i > > >>> > > >>> describe SAMPLE_RULE3 Banned body text > > >>> > > >>> score SAMPLE_RULE3 5 > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> in MailScanner.conf i have: > > >>> > > >>> > > >>> > > >>> MCP Checks = yes > > >>> > > >>> > > >>> > > >>> # Do the spam checks first, or the MCP checks first? > > >>> > > >>> # This cannot be the filename of a ruleset, only a fixed value. > > >>> > > >>> First Check = mcp > > >>> > > >>> > > >>> > > >>> # The rest of these options are clones of the equivalent spam > > >>> options MCP Required SpamAssassin Score = 1 MCP High > > >>> SpamAssassin Score = 10 MCP Error Score = 1 > > >>> > > >>> > > >>> > > >>> MCP Header = X-%org-name%-MailScanner-MCPCheck: > > >>> > > >>> Non MCP Actions = deliver > > >>> > > >>> MCP Actions = deliver store > > >>> > > >>> High Scoring MCP Actions = store > > >>> > > >>> Bounce MCP As Attachment = no > > >>> > > >>> > > >>> > > >>> MCP Modify Subject = start > > >>> > > >>> MCP Subject Text = {MCP?} > > >>> > > >>> High Scoring MCP Modify Subject = start > > >>> > > >>> High Scoring MCP Subject Text = {MCP?} > > >>> > > >>> > > >>> > > >>> Is Definitely MCP = no > > >>> > > >>> Is Definitely Not MCP = no > > >>> > > >>> Definite MCP Is High Scoring = yes > > >>> > > >>> Always Include MCP Report = yes > > >>> > > >>> Detailed MCP Report = yes > > >>> > > >>> Include Scores In MCP Report = yes > > >>> > > >>> Log MCP = yes > > >>> > > >>> > > >>> > > >>> MCP Max SpamAssassin Timeouts = 20 > > >>> > > >>> MCP Max SpamAssassin Size = 100k > > >>> > > >>> MCP SpamAssassin Timeout = 10 > > >>> > > >>> > > >>> > > >>> MCP SpamAssassin Prefs File = > > >>> %mcp-dir%/mcp.spam.assassin.prefs.conf > > >>> > > >>> MCP SpamAssassin User State Dir = > > >>> > > >>> MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin > > >>> Default Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = > > >>> %mcp-dir% Recipient MCP Report = > > >>> %report-dir%/recipient.mcp.report.txt > > >>> > > >>> Sender MCP Report = %report-dir%/sender.mcp.report.txt > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> > > >>> > > >> > > >> > > > > > > Jules > > > > > > > > > > Jules > > > > > - -- > - --[ UxBoD ]-- > // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg > --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F > 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // > Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -----BEGIN > PGP SIGNATURE----- Version: GnuPG v2.0.4 (GNU/Linux) > > iD8DBQFGWwI5H7GwL121aHsRAkwMAJ9AT/ohhFUYY9l0jZg41dJ/ajXKPwCgrpsL > JJACR7i6g68vYDzClM7+JLI= > =ksEJ > -----END PGP SIGNATURE----- > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is believed to be clean. > > - -- - --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.4 (GNU/Linux) iD8DBQFGWzB3H7GwL121aHsRAkIMAJ9h/2kEed1xQ3n+ApHgXFSKQpk97QCfQyF3 u6y+IhmRpJyDd4x1P0ZPVmI= =zRHE -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From amaclach at yahoo.co.uk Tue May 29 00:59:36 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Tue May 29 00:59:37 2007 Subject: possible enhancement request Message-ID: <526565.91273.qm@web26315.mail.ukl.yahoo.com> It would have to be a pre-defined string So to put some logic around it, if a message is outbound, remove any inbound signature. To be honest, I'd be happy with just removing/breaking the report as spam link to stop people clicking on it just to see what happens... The report as spam link always starts the same way: http://mail-gw.global-domination.org/cgi-bin/learn-msg.cgi?id=.... Maybe the function could just break that to make it something like: http://mail-gw.global-domination.org/cgi-bin/dont-learn-msg.cgi?id=... or just remove that line completely... ----- Original Message ---- From: "Koopmann, Jan-Peter" To: MailScanner discussion Sent: Monday, 28 May, 2007 5:57:53 PM Subject: RE: possible enhancement request On Monday, May 28, 2007 5:50 PM Andrew MacLachlan wrote: > How difficult would it be to remove old footers off the bottom of > forwards/replies I am afraid extremely difficult as you are opening pandoras box here. :-) How do you discover an "old footer"? Kind regards Jan-Peter Koopmann -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From amaclach at yahoo.co.uk Tue May 29 01:16:54 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Tue May 29 01:16:55 2007 Subject: better blocking at MTA level (off-topic) Message-ID: <506679.43981.qm@web26311.mail.ukl.yahoo.com> That would be a shame, because many non dynamic addresses get caught by zen because they have a dynamic-like reverse lookup and the ISP refuses to update the reverse... The correct time to treat dynamic addresses with more suspicion is at the SA level by adding points, not just killing them at the MTA. ----- Original Message ---- From: Scott Silva To: mailscanner@lists.mailscanner.info Sent: Monday, 28 May, 2007 10:56:01 PM Subject: Re: better blocking at MTA level (off-topic) Andrew MacLachlan spake the following on 5/27/2007 9:54 AM: > Some would consider zen.spamhaus.org a little too hardcore (me!), but sbl-xbl.spamhaus.org and list.dsbl.org are good... > AFAIR the sbl-xbl lookups might be disabled sometime in the future. Up to spamhaus discretion. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From amaclach at yahoo.co.uk Tue May 29 01:33:28 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Tue May 29 01:33:30 2007 Subject: Question... Message-ID: <177594.7833.qm@web26315.mail.ukl.yahoo.com> Fabio - Which country are you in? I have had one of my users complaining that this isn't legal in Italy (!) - Seem like a crazy law... Can anyone clarify this? -Andy ----- Original Message ---- From: Fabio Silva To: MailScanner discussion Sent: Monday, 28 May, 2007 9:44:09 PM Subject: Re: Question... Ok... good... so.. i did this: In the file /etc/MailScanner/MailScanner.conf the options Spam Actions = store deliver header "X-Spam-Status: Yes" High Scoring Spam Actions = store deliver header "X-Spam-Status: Yes" Non Spam Actions = store deliver header "X-Spam-Status: No" I set this options with the option "store" to store all the mails... the emails with spam, with high spam and the mails that isnt spam.... it is usefull if you have any mail that is SPAM but the mailscanner didnt know it... so you can open the message through mailwatch and tell to mailscanner that its message is SPAM ... you teach the spamassassin. Regards, On 5/28/07, Hugo van der Kooij wrote: On Mon, 28 May 2007, Fabio Silva wrote: > Thanks, i have this working.... > helped me in the irc >From a practical point. Please be more descriptive on the solution provided. As some people will be bound to look for it based on your original question once the search engines have indexed the mailinglist archives today. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070529/2f02504a/attachment.html From febrianto at sioenasia.com Tue May 29 03:46:09 2007 From: febrianto at sioenasia.com (Budi Febrianto) Date: Tue May 29 03:41:26 2007 Subject: Beta release: 4.60.5 - compress attachments In-Reply-To: <4659EF6D.2070107@ecs.soton.ac.uk> Message-ID: mailscanner-bounces@lists.mailscanner.info wrote on 05-28-2007 03:51:57 AM: > I have just written the feature you wanted to compress attachments into > a zip file. > Wow. This is a great feature. I can wait for it stable release. :) Thanks Julian. From febrianto at sioenasia.com Tue May 29 03:56:34 2007 From: febrianto at sioenasia.com (Budi Febrianto) Date: Tue May 29 03:51:49 2007 Subject: Beta release 4.60.6 In-Reply-To: <465B10F8.6060405@ecs.soton.ac.uk> Message-ID: mailscanner-bounces@lists.mailscanner.info wrote on 05-29-2007 12:27:20 AM: > I have added the 2 configuration options that seemed worthwhile for the > new "Zip Attachments" feature: > > # If the original total size of all the attachments to be compressed is > # less than this number of bytes, they will not be zipped at all. > # This can also be the filename of a ruleset. > Attachments Min Total Size To Zip = 100k > > # Attachments whose filenames end in these strings will not be zipped. > # This can also be the filename of a ruleset. > Attachment Extensions Not To Zip = .zip .rar .gz .tgz .mpg .mpeg .mp3 .rpm > > Download as usual from www.mailscanner.info. > > Jules Julian, Now I'm feel sorry for those third party softwares that offers the same (and mostly less) features like Mailscanner and sell it for expensive price. From hvdkooij at vanderkooij.org Tue May 29 06:40:07 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue May 29 06:40:47 2007 Subject: Question... In-Reply-To: <177594.7833.qm@web26315.mail.ukl.yahoo.com> References: <177594.7833.qm@web26315.mail.ukl.yahoo.com> Message-ID: On Tue, 29 May 2007, Andrew MacLachlan wrote: > Fabio - Which country are you in? > I have had one of my users complaining that this isn't legal in Italy (!) - Seem like a crazy law... > Can anyone clarify this? I suggest you contact a local (italian) open source group. They are likely to be more aware of the issue at hand. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From jan-peter at koopmann.eu Tue May 29 07:02:55 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Tue May 29 07:03:07 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: <506679.43981.qm@web26311.mail.ukl.yahoo.com> References: <506679.43981.qm@web26311.mail.ukl.yahoo.com> Message-ID: On Tuesday, May 29, 2007 2:17 AM Andrew MacLachlan wrote: > That would be a shame, because many non dynamic addresses get caught > by zen because they have a dynamic-like reverse lookup and the ISP > refuses to update the reverse... I just rechecked. The ISP does not have to update rDNS. They simply have to contact spamhaus and say that direct-mx from those blocks is ok with their policy. Spamhaus just puts those suspicious blocks in the PBL list if they could not contact the ISP or the ISP was not willing/able to participate. > The correct time to treat dynamic > addresses with more suspicion is at the SA level by adding points, > not just killing them at the MTA. Actually I believe in the long run the correct place is the MTA. Most spam comes from dynamic adresses. Cutting all direct-mx from dynamic adresses is probably the only solution. Now people will start screaming "I do not want to be forced to route all my mail through the ISPs mail-server". Wake up: 1. The ISP could analyze your traffic transparently if he wishes/is forced to. 2. If you want to deliver directly, get a suitable setup (static IP, well-setup MTA). Not that expensive! But for reasons I pointed out myself in this thread I agree: At this time PBL is as far as I would go at MTA level and I can understand if you do not want to do this. Blocking all dynamic IPs currently remains a dream of mine. :-) From jan-peter at koopmann.eu Tue May 29 07:05:16 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Tue May 29 07:05:26 2007 Subject: Beta release 4.60.6 In-Reply-To: References: <465B10F8.6060405@ecs.soton.ac.uk> Message-ID: On Tuesday, May 29, 2007 4:57 AM Budi Febrianto wrote: > Now I'm feel sorry for those third party softwares that offers the > same (and mostly less) features like Mailscanner and sell it for > expensive price. :-) Now? Why not any earlier? .-) Oh and BTW: Commercial software still has its place. You would wounder how many Administrators simply are not capable of setting up a Linux/BSD system with MailScanner on it. They want a simple box they can put in their rack without having to worry about it. Yet on the other hand there is a commercial mailscanner solution which solves exactly this problem... :-) Regards, JP From jlcostinha at halla.pt Tue May 29 08:12:42 2007 From: jlcostinha at halla.pt (Jorge Costinha) Date: Tue May 29 08:12:51 2007 Subject: Reject mail from invalid domains In-Reply-To: References: <465B004F.1@halla.pt> Message-ID: <465BD26A.6060105@halla.pt> invalid domain, are domains that cannot be resolved by DNS. i belive it is a good practice to reduce spam and workload of mailscanner and spamassassin if mails coming from invalid domains are block. am i right? Koopmann, Jan-Peter wrote: > On Monday, May 28, 2007 6:16 PM Jorge Costinha wrote: > > > >> im using Fedora core 6, with Mailscanner 4.59.4 and sendmail >> 8.13.8. I want to block email from invalid domains. Can i do this with >> Mailscanner/spamassassin or has to be done at MTA level? >> > > You probably could do this with spamassassin but the MTA is the correct > place. How do you define "invalid domain"? That's the interesting > question. > > Regards, > JP > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > From jan-peter at koopmann.eu Tue May 29 08:58:45 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Tue May 29 08:59:02 2007 Subject: Reject mail from invalid domains In-Reply-To: <465BD26A.6060105@halla.pt> References: <465B004F.1@halla.pt> <465BD26A.6060105@halla.pt> Message-ID: On Tuesday, May 29, 2007 9:13 AM Jorge Costinha wrote: > invalid domain, are domains that cannot be resolved by DNS. i belive > it is a good practice to reduce spam and workload of mailscanner and > spamassassin if mails coming from invalid domains are block. am i > right? In theory: Yes. The question is how do you make sure the domain can be resolved? Nameservers exist? Whois is successful (would not work probably)? Sender callout (google for SAV or Sender address verification to find out that many people seriously dislike it). And even if the domain resolves you could check if the domain has valid MX records. Or SPF and so on. Implementation depends on your MTA of course. Kind regards Jan-Peter Koopmann From writetoashok at gmail.com Tue May 29 09:30:44 2007 From: writetoashok at gmail.com (ashok Kumar) Date: Tue May 29 09:30:48 2007 Subject: Forcing processing of mails in incomming queue Message-ID: Hi The mails in the outgoing queue for a particular domain can be flushed by the command sendmail -v -qRexample.com. But suppose i want to speed up the processing and delivery of some mails in the incomming queue, (/var/spool/mqueue.in), say for a particular domain, how it can be done. Can this be done using sendmail or MailScanner. -- regards, Ashok. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070529/d7d634a2/attachment.html From Q.G.Campbell at newcastle.ac.uk Tue May 29 09:30:46 2007 From: Q.G.Campbell at newcastle.ac.uk (Quentin Campbell) Date: Tue May 29 09:31:52 2007 Subject: Recognising and flagging 'foreign' language e-mails in MCP In-Reply-To: <465592F0.9050809@ecs.soton.ac.uk> References: <4165CF7A7F12DE4B96622CCBB90586470A4D1400@largo.campus.ncl.ac.uk> <465592F0.9050809@ecs.soton.ac.uk> Message-ID: <4165CF7A7F12DE4B96622CCBB90586470A6EED85@largo.campus.ncl.ac.uk> >-----Original Message----- >From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >bounces@lists.mailscanner.info] On Behalf Of Julian Field >Sent: 24 May 2007 14:28 >To: MailScanner discussion >Subject: Re: Recognising and flagging 'foreign' language e-mails in MCP > >-----BEGIN PGP SIGNED MESSAGE----- >Hash: SHA1 > [snip] >I have done this too, but I didn't see any need to do it in MCP (as MCP >has a very high speed overhead). Just a normal SA rule with a small >score will do fine, just put your initials or something similar at the >start of the rule name. Julian Thanks for the reply and heads-up on MCP. For historical reasons we have 'Always Include SpamAssassin Report = no'. Thus SA rule hits and scores are only ever visible in message headers when a message is tagged as spam. Hence the need for the MCP work around in this particular case. The reason for setting that MS option to 'no' is that some users here were advised in the early days to check for spam by looking for the 'SpamCheck' header rather than the flag in the Subject line. Perhaps it is time we revisited this and see whether I can now set 'Always Include SpamAssassin Report = yes' to avoid the MCP overhead. Quentin From febrianto at sioenasia.com Tue May 29 09:39:54 2007 From: febrianto at sioenasia.com (Budi Febrianto) Date: Tue May 29 09:35:10 2007 Subject: Beta release 4.60.6 In-Reply-To: Message-ID: mailscanner-bounces@lists.mailscanner.info wrote on 05-29-2007 01:05:16 PM: > Yet on the other hand there is a commercial mailscanner solution > which solves exactly this problem... :-) > > > Regards, > JP I'm forget about that one. :-) From dhawal at netmagicsolutions.com Tue May 29 09:41:45 2007 From: dhawal at netmagicsolutions.com (Dhawal Doshy) Date: Tue May 29 09:42:06 2007 Subject: Reject mail from invalid domains In-Reply-To: References: <465B004F.1@halla.pt> <465BD26A.6060105@halla.pt> Message-ID: <465BE749.7030207@netmagicsolutions.com> Koopmann, Jan-Peter wrote: > On Tuesday, May 29, 2007 9:13 AM Jorge Costinha wrote: > >> invalid domain, are domains that cannot be resolved by DNS. i belive >> it is a good practice to reduce spam and workload of mailscanner and >> spamassassin if mails coming from invalid domains are block. am i >> right? > > In theory: Yes. The question is how do you make sure the domain can be resolved? Nameservers exist? Whois is successful (would not work probably)? Sender callout (google for SAV or Sender address verification to find out that many people seriously dislike it). And even if the domain resolves you could check if the domain has valid MX records. Or SPF and so on. > > Implementation depends on your MTA of course. Postfix does this well.. it considers lack of A/MX record OR a malformed record as an invalid domain. See: http://www.postfix.org/postconf.5.html#reject_unknown_sender_domain From j.ede at birchenallhowden.co.uk Tue May 29 09:45:20 2007 From: j.ede at birchenallhowden.co.uk (Jason Ede) Date: Tue May 29 10:05:43 2007 Subject: Reject mail from invalid domains In-Reply-To: References: <465B004F.1@halla.pt><465BD26A.6060105@halla.pt>, Message-ID: Surely it makes sense to at least check if the sender is a fully qualified domain and also that there is an MX record for that domain? Jason From: Koopmann, Jan-Peter Sent: Tue 29/05/2007 08:58 To: MailScanner discussion Subject: RE: Reject mail from invalid domains On Tuesday, May 29, 2007 9:13 AM Jorge Costinha wrote: > invalid domain, are domains that cannot be resolved by DNS. i belive > it is a good practice to reduce spam and workload of mailscanner and > spamassassin if mails coming from invalid domains are block. am i > right? In theory: Yes. The question is how do you make sure the domain can be resolved? Nameservers exist? Whois is successful (would not work probably)? Sender callout (google for SAV or Sender address verification to find out that many people seriously dislike it). And even if the domain resolves you could check if the domain has valid MX records. Or SPF and so on. Implementation depends on your MTA of course. Kind regards Jan-Peter Koopmann -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ----------------------------------------------------------- The information in this e-mail and any attachments is confidential. It is intended solely for the attention and use of the named addressee(s). If you are not the intended recipient, or person responsible for delivering this information to the intended recipient, please notify the sender or email postmaster@birchenallhowden.co.uk and delete it from your computer systems. Unless you are the intended recipient or his/her representative you are not authorised to, and must not, read, copy, distribute, use or retain this message or any part of it. All messages are scanned by Mailscanner and are believed to be clean. Recipients are advised to apply their own virus checks to any message on delivery. No liability is accepted by BirchenallHowden Ltd for any losses caused by viruses contracted during transit over the internet or present in any receiving system. BirchenallHowden Ltd, 233 Edmund Road, Sheffield, S2 4EL -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070529/e5f08967/attachment.html From x72m35 at gmail.com Tue May 29 10:14:24 2007 From: x72m35 at gmail.com (Lasantha Marian) Date: Tue May 29 10:11:42 2007 Subject: RES: mcp help In-Reply-To: References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> Message-ID: <465BEEF0.6000505@gmail.com> Dear Julian, I have been experiencing some strange behaviors in my MCP setup (SA 3.2.0/MS 4.59.4) too, i.e. MCP setup works very fine when tested from command line so does SpamAssassin setup (from both ends; command line and from MailScanner), but MCP would not work properly from MailScanner. It would happily scan but does not report against customized MCP rules. MCP rules are properly applied and correct scores are shown when run from command line without any errors. The very same MCP rules set works fine with earlier versions (SA 3.1.1/MS 4.53.8). I think it is the same kind of problem that Wilson is experiencing in MCP. It identifies MCP, but then may be a reporting problem ! Thanks and regards, Lasantha. *-------- Original Message --------* *Subject: * RES: mcp help *Date: * Tue, 29/May/2007 4:39:25 AM +0550 *From: * "Wilson A. Galafassi Jr." *To: * "'MailScanner discussion'" > spamassassin --D --lint > /tmp/sa.log 2>&1 > > This is the result. > > [root@netserver tmp]# cat sa.log > [26391] dbg: logger: adding facilities: all > [26391] dbg: logger: logging level is DBG > [26391] dbg: generic: SpamAssassin version 3.2.0 > [26391] dbg: config: score set 0 chosen. > [26391] dbg: util: running in taint mode? yes > [26391] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070529/a212e761/attachment.html From john at tradoc.fr Tue May 29 10:27:25 2007 From: john at tradoc.fr (John Wilcock) Date: Tue May 29 10:27:48 2007 Subject: Reject mail from invalid domains In-Reply-To: References: <465B004F.1@halla.pt><465BD26A.6060105@halla.pt>, Message-ID: <465BF1FD.7030002@tradoc.fr> Jason Ede wrote: > Surely it makes sense to at least check if the sender is a fully > qualified domain and also that there is an MX record for that domain? In theory, yes. In practice, poorly configured mail servers are not uncommon and sooner or later you will end up rejecting genuine mail if you insist on this. Also, consider what will happens if a sender domain's name servers are temporarily unavailable. [With postfix, the default reject code for an unknown helo hostname is 450 rather than 554 for precisely this reason]. John. -- -- Over 3000 webcams from ski resorts around the world - www.snoweye.com -- Translate your technical documents and web pages - www.tradoc.fr From bilias at edu.physics.uoc.gr Tue May 29 11:23:31 2007 From: bilias at edu.physics.uoc.gr (Kapetanakis Giannis) Date: Tue May 29 11:23:43 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: <46580113.10806@ecs.soton.ac.uk> References: <46580113.10806@ecs.soton.ac.uk> Message-ID: On Sat, 26 May 2007, Julian Field wrote: > Look out very soon for the announcement of a new product from Fort > Systems. This will do exactly what you're looking for. All the beta > sites have been raving about it, the test results from them have been > fantastic! > > Keep an eye open on the -announce list, should appear in the next few weeks. > > Jules Which product are you talking about? DefenderMX? Is it open source/free? Thanx Giannis From wilson.galafassi at gmail.com Tue May 29 11:34:48 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Tue May 29 11:35:07 2007 Subject: RES: RES: mcp help In-Reply-To: <465BEEF0.6000505@gmail.com> References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> <465BEEF0.6000505@gmail.com> Message-ID: How i can test from command line to grant that i have the same problem? De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Lasantha Marian Enviada em: ter?a-feira, 29 de maio de 2007 06:14 Para: MailScanner discussion Assunto: Re: RES: mcp help Dear Julian, I have been experiencing some strange behaviors in my MCP setup (SA 3.2.0/MS 4.59.4) too, i.e. MCP setup works very fine when tested from command line so does SpamAssassin setup (from both ends; command line and from MailScanner), but MCP would not work properly from MailScanner. It would happily scan but does not report against customized MCP rules. MCP rules are properly applied and correct scores are shown when run from command line without any errors. The very same MCP rules set works fine with earlier versions (SA 3.1.1/MS 4.53.8). I think it is the same kind of problem that Wilson is experiencing in MCP. It identifies MCP, but then may be a reporting problem ! Thanks and regards, Lasantha. *-------- Original Message --------* *Subject: * RES: mcp help *Date: * Tue, 29/May/2007 4:39:25 AM +0550 *From: * "Wilson A. Galafassi Jr." *To: * "'MailScanner discussion'" > spamassassin --D --lint > /tmp/sa.log 2>&1 > > This is the result. > > [root@netserver tmp]# cat sa.log > [26391] dbg: logger: adding facilities: all > [26391] dbg: logger: logging level is DBG > [26391] dbg: generic: SpamAssassin version 3.2.0 > [26391] dbg: config: score set 0 chosen. > [26391] dbg: util: running in taint mode? yes > [26391] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070529/a37a0f4e/attachment.html From j.ede at birchenallhowden.co.uk Tue May 29 10:37:07 2007 From: j.ede at birchenallhowden.co.uk (Jason Ede) Date: Tue May 29 11:58:11 2007 Subject: Reject mail from invalid domains In-Reply-To: <465BF1FD.7030002@tradoc.fr> References: <465B004F.1@halla.pt><465BD26A.6060105@halla.pt>, , <465BF1FD.7030002@tradoc.fr> Message-ID: <52DA4A29-76F5-4BF1-A73F-6007F4E29A37@mimectl> We use postfix and yes if it was a 550 reject code then we wouldn't use this facility. Have also found recently that if you reject on non fully qualified domain names then alert emails from mcafee's alert manager that send through internet are rejected as the emails aren't correctly formed. The from field gets picked up as empty by postfix. From: John Wilcock Sent: Tue 29/05/2007 10:27 To: MailScanner discussion Subject: Re: Reject mail from invalid domains Jason Ede wrote: > Surely it makes sense to at least check if the sender is a fully > qualified domain and also that there is an MX record for that domain? In theory, yes. In practice, poorly configured mail servers are not uncommon and sooner or later you will end up rejecting genuine mail if you insist on this. Also, consider what will happens if a sender domain's name servers are temporarily unavailable. [With postfix, the default reject code for an unknown helo hostname is 450 rather than 554 for precisely this reason]. John. -- -- Over 3000 webcams from ski resorts around the world - www.snoweye.com -- Translate your technical documents and web pages - www.tradoc.fr -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! ----------------------------------------------------------- The information in this e-mail and any attachments is confidential. It is intended solely for the attention and use of the named addressee(s). If you are not the intended recipient, or person responsible for delivering this information to the intended recipient, please notify the sender or email postmaster@birchenallhowden.co.uk and delete it from your computer systems. Unless you are the intended recipient or his/her representative you are not authorised to, and must not, read, copy, distribute, use or retain this message or any part of it. All messages are scanned by Mailscanner and are believed to be clean. Recipients are advised to apply their own virus checks to any message on delivery. No liability is accepted by BirchenallHowden Ltd for any losses caused by viruses contracted during transit over the internet or present in any receiving system. BirchenallHowden Ltd, 233 Edmund Road, Sheffield, S2 4EL -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070529/86b3ff5f/attachment.html From uxbod at splatnix.net Tue May 29 12:02:13 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Tue May 29 11:59:15 2007 Subject: mcp help In-Reply-To: References: <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> <465BEEF0.6000505@gmail.com> Message-ID: <20070529120213.42e338d4@uxbod.splatnix.net> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 You could try :- spamassassin - -C /opt/MailScanner/etc/mcp/mcp.spam.assassin.prefs.conf -D < > /tmp/sa.log 2>&1 On Tue, 29 May 2007 07:34:48 -0300 "Wilson A. Galafassi Jr." wrote: > How i can test from command line to grant that i have the same > problem? > > > > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de > Lasantha Marian > Enviada em: ter?a-feira, 29 de maio de 2007 06:14 > Para: MailScanner discussion > Assunto: Re: RES: mcp help > > > > Dear Julian, > > I have been experiencing some strange behaviors in my MCP setup (SA > 3.2.0/MS 4.59.4) too, i.e. MCP setup works very fine when tested from > command line so does SpamAssassin setup (from both ends; command line > and from MailScanner), but MCP would not work properly from > MailScanner. It would happily scan but does not report against > customized MCP rules. MCP rules are properly applied and correct > scores are shown when run from command line without any errors. The > very same MCP rules set works fine with earlier versions (SA 3.1.1/MS > 4.53.8). > > I think it is the same kind of problem that Wilson is experiencing in > MCP. It identifies MCP, but then may be a reporting problem ! > > Thanks and regards, > > Lasantha. > > > *-------- Original Message --------* > *Subject: * RES: mcp help > *Date: * Tue, 29/May/2007 4:39:25 AM +0550 > *From: * "Wilson A. Galafassi Jr." > > *To: * "'MailScanner discussion'" > > > > > > spamassassin --D --lint > > > /tmp/sa.log 2>&1 > > > > > > > > > > This is the result. > > > > > > > > > > [root@netserver tmp]# cat sa.log > > > > > [26391] dbg: logger: adding facilities: all > > > > > [26391] dbg: logger: logging level is DBG > > > > > [26391] dbg: generic: SpamAssassin version 3.2.0 > > > > > [26391] dbg: config: score set 0 chosen. > > > > > [26391] dbg: util: running in taint mode? yes > > > > > [26391] dbg: util: taint mode: deleting unsafe environment > > variables, > > > > > resetting PATH > > > > > > > > > - -- - --[ UxBoD ]-- // PGP Key: "curl -s https://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: C759 8F52 1D17 B3C5 5854 36BD 1FB1 B02F 5DB5 687B // Keyserver: www.keyserver.net Key-ID: 0x5DB5687B // Phone: +44 845 869 2749 SIP Phone: uxbod@sip.splatnix.net -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.4 (GNU/Linux) iD8DBQFGXAg5H7GwL121aHsRAvUFAJ9QuCAHm3DcjCSWIh6ZT7zYY/u4QgCeMina DqmHTUvgbAAbhRdnWxBowsI= =86JD -----END PGP SIGNATURE----- -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From jan-peter at koopmann.eu Tue May 29 12:05:47 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Tue May 29 12:05:57 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: References: <46580113.10806@ecs.soton.ac.uk> Message-ID: On Tuesday, May 29, 2007 12:24 PM Kapetanakis Giannis wrote: > Which product are you talking about? DefenderMX? No but close. As it has not been published yet I cannot talk about it but it looks very promising. Same company. > Is it open source/free? No. Kind regards Jan-Peter Koopmann From x72m35 at gmail.com Tue May 29 12:09:24 2007 From: x72m35 at gmail.com (Lasantha Marian) Date: Tue May 29 12:06:43 2007 Subject: RES: RES: mcp help In-Reply-To: References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> <465BEEF0.6000505@gmail.com> Message-ID: <465C09E4.6090500@gmail.com> Dear Wilson, You could use the following command. spamassassin -D -t -C /usr/local/MailScanner/etc/mcp
*To: * "'MailScanner discussion'" > How i can test from command line to grant that i have the same problem? > > > > *De:* mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] *Em nome de > *Lasantha Marian > *Enviada em:* ter?a-feira, 29 de maio de 2007 06:14 > *Para:* MailScanner discussion > *Assunto:* Re: RES: mcp help > > > > Dear Julian, > > I have been experiencing some strange behaviors in my MCP setup (SA > 3.2.0/MS 4.59.4) too, i.e. MCP setup works very fine when tested from > command line so does SpamAssassin setup (from both ends; command line > and from MailScanner), but MCP would not work properly from > MailScanner. It would happily scan but does not report against > customized MCP rules. MCP rules are properly applied and correct > scores are shown when run from command line without any errors. The > very same MCP rules set works fine with earlier versions (SA 3.1.1/MS > 4.53.8). > > I think it is the same kind of problem that Wilson is experiencing in > MCP. It identifies MCP, but then may be a reporting problem ! > > Thanks and regards, > > Lasantha. > > > *-------- Original Message --------* > *Subject: * RES: mcp help > *Date: * Tue, 29/May/2007 4:39:25 AM +0550 > *From: * "Wilson A. Galafassi Jr." > > *To: * "'MailScanner discussion'" > > > > > > spamassassin --D --lint > > > /tmp/sa.log 2>&1 > > > > > > This is the result. > > > > > > [root@netserver tmp]# cat sa.log > > > [26391] dbg: logger: adding facilities: all > > > [26391] dbg: logger: logging level is DBG > > > [26391] dbg: generic: SpamAssassin version 3.2.0 > > > [26391] dbg: config: score set 0 chosen. > > > [26391] dbg: util: running in taint mode? yes > > > [26391] dbg: util: taint mode: deleting unsafe environment > > variables, > > > resetting PATH > > > > -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070529/77c709bb/attachment.html From P.G.M.Peters at utwente.nl Tue May 29 12:49:29 2007 From: P.G.M.Peters at utwente.nl (Peter Peters) Date: Tue May 29 12:49:34 2007 Subject: semi [OT] IEFT moves DK to draft standard In-Reply-To: References: <3abb4d8b6610964cad498e381c76e521@solidstatelogic.com> <005501c79f17$af69f710$6389a8c0@di.unito.it> <7EF0EE5CB3B263488C8C18823239BEBA03CEDB@HC-MBX02.herefordshire.gov.uk> Message-ID: <465C1349.4090601@utwente.nl> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Scott Silva wrote on 28-5-2007 23:30: > That is what I think, too. But spambots are near the top of the spam chain, so > I guess it will help. I think Domainkeys will be like SPF. You will have to > get it working so others will accept YOUR mail. I had to get SPF working > because the people who sign my paychecks needed to send mail to addresses that > used SPF as a filtering point. And I always make the check signers happy!! ;-P The same bots that send out spam also can host the spamvertised websites and I have seen nets where a couple of the bots ran nameservices. - -- Peter Peters, senior beheerder (Security) Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) Universiteit Twente, Postbus 217, 7500 AE Enschede telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFGXBNIelLo80lrIdIRAru/AJwJDUEsfOETb3HrBumBH9i8dO/qDgCeK4Z0 5G49WQOpOJ9GQUoyMWDmzFo= =dQf+ -----END PGP SIGNATURE----- From alex at nkpanama.com Tue May 29 13:16:15 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Tue May 29 13:16:59 2007 Subject: Forcing processing of mails in incomming queue In-Reply-To: References: Message-ID: <465C198F.3030103@nkpanama.com> ashok Kumar wrote: > Hi > > The mails in the outgoing queue for a particular domain can > be flushed by the command sendmail -v -qRexample.com. But suppose i > want to speed up the processing and delivery of some mails in the > incomming queue, (/var/spool/mqueue.in), say for a particular domain, > how it can be done. Can this be done using sendmail or MailScanner. > > -- > regards, > Ashok. I'm guessing it could be done using sendmail -v -qRexample.com -O QueueDirectory=/var/spool/mqueue.in ... From glenn.steen at gmail.com Tue May 29 13:48:06 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Tue May 29 13:48:09 2007 Subject: Forcing processing of mails in incomming queue In-Reply-To: <465C198F.3030103@nkpanama.com> References: <465C198F.3030103@nkpanama.com> Message-ID: <223f97700705290548t2794c863sb0b935e986b5b892@mail.gmail.com> On 29/05/07, Alex Neuman van der Hans wrote: > ashok Kumar wrote: > > Hi > > > > The mails in the outgoing queue for a particular domain can > > be flushed by the command sendmail -v -qRexample.com. But suppose i > > want to speed up the processing and delivery of some mails in the > > incomming queue, (/var/spool/mqueue.in), say for a particular domain, > > how it can be done. Can this be done using sendmail or MailScanner. > > > > -- > > regards, > > Ashok. > I'm guessing it could be done using sendmail -v -qRexample.com -O > QueueDirectory=/var/spool/mqueue.in > ... Um, exactly what effect are you looking for there Alex? If it's in that queue, doesn't it stay there until MS is well and truly done with it (Just out of curiosity, since I don't use Sendmail:-)....? That's what I'd expect anyway... So... Maiking MailScanner work as well as possible would be the sole "true solution" there, now wouldn't you agree? Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From alex at nkpanama.com Tue May 29 14:03:28 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Tue May 29 14:04:12 2007 Subject: Forcing processing of mails in incomming queue In-Reply-To: <223f97700705290548t2794c863sb0b935e986b5b892@mail.gmail.com> References: <465C198F.3030103@nkpanama.com> <223f97700705290548t2794c863sb0b935e986b5b892@mail.gmail.com> Message-ID: <465C24A0.8040209@nkpanama.com> Glenn Steen wrote: > Um, exactly what effect are you looking for there Alex? If it's in > that queue, doesn't it stay there until MS is well and truly done with > it (Just out of curiosity, since I don't use Sendmail:-)....? That's > what I'd expect anyway... > > So... Maiking MailScanner work as well as possible would be the sole > "true solution" there, now wouldn't you agree? > > Cheers True. I was just answering the question. I would guess a situation where this would be needed would be one where, for some reason (say, a corrupted /etc/MailScanner directory, broken perl, etc.) would require you to free the incoming queue (at least until you can "fix" whatever's wrong with MailScanner). Of course, this would have to be done after stopping (and/or killing) any running MailScanner processes. I think I've had this happen once or twice. After the broken MailScanner install was fixed, everything worked normally. In the meantime I would either sendmail -q -v -O QueueDirectory=/var/spool/mqueue.in and run plain old sendmail until MailScanner was fixed, and then stop sendmail and run MailScanner. From amaclach at yahoo.co.uk Tue May 29 14:19:13 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Tue May 29 14:19:18 2007 Subject: better blocking at MTA level (off-topic) Message-ID: <418312.38090.qm@web26315.mail.ukl.yahoo.com> Can it be added to existing MailScanner installations? ----- Original Message ---- From: "Koopmann, Jan-Peter" To: MailScanner discussion Sent: Tuesday, 29 May, 2007 12:05:47 PM Subject: RE: better blocking at MTA level (off-topic) On Tuesday, May 29, 2007 12:24 PM Kapetanakis Giannis wrote: > Which product are you talking about? DefenderMX? No but close. As it has not been published yet I cannot talk about it but it looks very promising. Same company. > Is it open source/free? No. Kind regards Jan-Peter Koopmann -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From wilson.galafassi at gmail.com Tue May 29 14:30:29 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Tue May 29 14:31:06 2007 Subject: RES: RES: mcp help In-Reply-To: <465BEEF0.6000505@gmail.com> References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> <465BEEF0.6000505@gmail.com> Message-ID: I have something wrong... any help is very apreciated! Thanks Wilson My mailscanner.cf First Check = mcp # The rest of these options are clones of the equivalent spam options MCP Required SpamAssassin Score = 1 MCP High SpamAssassin Score = 10 MCP Error Score = 1 MCP Header = X-%org-name%-MailScanner-MCPCheck: Non MCP Actions = deliver MCP Actions = store High Scoring MCP Actions = store Bounce MCP As Attachment = no MCP Modify Subject = start MCP Subject Text = {MCP?} High Scoring MCP Modify Subject = start High Scoring MCP Subject Text = {MCP?} Is Definitely MCP = no Is Definitely Not MCP = no Definite MCP Is High Scoring = yes Always Include MCP Report = yes Detailed MCP Report = yes Include Scores In MCP Report = yes Log MCP = yes MCP Max SpamAssassin Timeouts = 20 MCP Max SpamAssassin Size = 100k MCP SpamAssassin Timeout = 10 MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf MCP SpamAssassin User State Dir = /var/spool/MailScanner/mcp MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin Default Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = %mcp-dir% Recipient MCP Report = %report-dir%/recipient.mcp.report.txt Sender MCP Report = %report-dir%/sender.mcp.report.txt My test mail: >From wilson@ftpmanager.com Tue May 29 10:19:42 2007 Return-Path: X-Original-To: wilson@ftpmanager.com Delivered-To: wilson@ftpmanager.com Received: from sdxp (unknown [192.168.0.1]) by netserver.ftpmanager.com (Postfix) with SMTP id 1784D107F90 for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> From: "Wilson - FTP" To: Subject: teste Date: Tue, 29 May 2007 10:19:11 -0300 MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2900.3028 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more information X-ftpmanagerbr_net-MailScanner: Found to be clean X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, requerido 1) X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanager.com X-Spam-Status: No This is a multi-part message in MIME format. ------=_NextPart_000_0005_01C7A1DA.CCACFD20 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Block this t?o My cf file: header MY_RULE_1 Subject =~ /block this phrase/i score MY_RULE_1 100 body MY_RULE_2 /Block this too/i score MY_RULE_2 100 body MY_RULE_3 /this\s*is\s*more\s*complicated/i score MY_RULE_3 100 body SAMPLE_RULE2 /this/i describe SAMPLE_RULE2 Banned body text score SAMPLE_RULE2 5 body LOCAL_DEMONSTRATION_RULE /test/ score LOCAL_DEMONSTRATION_RULE 100 describe LOCAL_DEMONSTRATION_RULE This is a simple test rule header LOCAL_DEMONSTRATION_SUBJECT Subject =~ /\btest\b/i score LOCAL_DEMONSTRATION_SUBJECT 100 The spamassassin test: spamassassin -C /etc/MailScanner/mcp -p /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < teste.mail [15603] dbg: logger: adding facilities: all [15603] dbg: logger: logging level is DBG [15603] dbg: generic: SpamAssassin version 3.2.0 [15603] dbg: config: score set 0 chosen. [15603] dbg: util: running in taint mode? yes [15603] dbg: util: taint mode: deleting unsafe environment variables, resetting PATH [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping [15603] dbg: util: PATH included '/usr/local/sbin', keeping [15603] dbg: util: PATH included '/usr/local/bin', keeping [15603] dbg: util: PATH included '/sbin', keeping [15603] dbg: util: PATH included '/bin', keeping [15603] dbg: util: PATH included '/usr/sbin', keeping [15603] dbg: util: PATH included '/usr/bin', keeping [15603] dbg: util: PATH included '/root/bin', which doesn't exist, dropping [15603] dbg: util: final PATH set to: /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b in:/usr/sbin:/usr/bin [15603] dbg: dns: no ipv6 [15603] dbg: dns: is Net::DNS::Resolver available? yes [15603] dbg: dns: Net::DNS version: 0.59 [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre files [15603] dbg: config: read file /etc/mail/spamassassin/init.pre [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir [15603] dbg: config: read file /etc/mail/spamassassin/local.cf [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf [15603] dbg: config: using "/root/.spamassassin" for user state dir [15603] dbg: config: using "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file [15603] dbg: config: read file /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [15603] dbg: razor2: razor2 is not available [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC [15603] dbg: pyzor: network tests on, attempting Pyzor [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [15603] dbg: razor2: razor2 is not available [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [15603] dbg: razor2: razor2 is not available [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered [15603] dbg: conf: finish parsing [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) implements 'finish_parsing_end', priority 0 [15603] dbg: replacetags: replacing tags [15603] dbg: replacetags: done replacing tags [15603] dbg: config: score set 1 chosen. [15603] dbg: message: main message type: multipart/alternative [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) implements 'check_start', priority 0 [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) implements 'check_main', priority 0 [15603] dbg: conf: trusted_networks are not configured; it is recommended that you configure trusted_networks manually [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= msa=0 ] [15603] dbg: received-header: 'from' 192.168.0.1 has private IP [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes msa? no [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 id=1784D107F90 auth= msa=0 ] [15603] dbg: metadata: X-Spam-Relays-Untrusted: [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 id=1784D107F90 auth= msa=0 ] [15603] dbg: metadata: X-Spam-Relays-External: [15603] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements 'extract_metadata', priority 0 [15603] dbg: metadata: X-Relay-Countries: [15603] dbg: message: ---- MIME PARSER START ---- [15603] dbg: message: parsing multipart, got boundary: ----=_NextPart_000_0005_01C7A1DA.CCACFD20 [15603] dbg: message: found part of type text/plain, boundary: ----=_NextPart_000_0005_01C7A1DA.CCACFD20 [15603] dbg: message: added part, type: text/plain [15603] dbg: message: parsing normal part [15603] dbg: message: ---- MIME PARSER END ---- [15603] dbg: message: decoding quoted-printable [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) implements 'parsed_metadata', priority 0 [15603] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements 'parsed_metadata', priority 0 [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) implements 'parsed_metadata', priority 0 [15603] dbg: dns: dns_available set to yes in config file, skipping test [15603] dbg: uridnsbl: domains to query: [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups [15603] dbg: check: running tests for priority: 0 [15603] dbg: rules: running head tests; score so far=0 [15603] dbg: rules: compiled head tests [15603] dbg: rules: running body tests; score so far=0 [15603] dbg: rules: compiled body tests [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got hit: "test" [15603] dbg: rules: running uri tests; score so far=100 [15603] dbg: rules: compiled uri tests [15603] dbg: rules: running rawbody tests; score so far=100 [15603] dbg: rules: compiled rawbody tests [15603] dbg: rules: running full tests; score so far=100 [15603] dbg: rules: compiled full tests [15603] dbg: rules: running meta tests; score so far=100 [15603] dbg: rules: compiled meta tests [15603] dbg: check: is spam? score=100 required=5 [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE [15603] dbg: check: subtests= >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 Received: from localhost by netserver.ftpmanagerbr.net with SpamAssassin (version 3.2.0); Tue, 29 May 2007 10:28:40 -0300 From: "Wilson - FTP" To: Subject: teste Date: Tue, 29 May 2007 10:19:11 -0300 Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on netserver.ftpmanagerbr.net MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" This is a multi-part message in MIME format. ------------=_465C2A88.4A78356A Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit (no report template found) ------------=_465C2A88.4A78356A Content-Type: message/rfc822; x-spam-type=original Content-Description: original message before SpamAssassin Content-Disposition: attachment Content-Transfer-Encoding: 8bit Return-Path: X-Original-To: wilson@ftpmanagerbr.net Delivered-To: wilson@ftpmanagerbr.net Received: from sdxp (unknown [192.168.0.1]) by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> From: "Wilson - FTP" To: Subject: teste Date: Tue, 29 May 2007 10:19:11 -0300 MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2900.3028 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more information X-ftpmanagerbr_net-MailScanner: Found to be clean X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, requerido 1) X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net X-Spam-Status: No This is a multi-part message in MIME format. ------=_NextPart_000_0005_01C7A1DA.CCACFD20 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Block this too ------------=_465C2A88.4A78356A-- (no report template found) spamassassin -C /etc/MailScanner/mcp -p /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < teste.mail [15603] dbg: logger: adding facilities: all [15603] dbg: logger: logging level is DBG [15603] dbg: generic: SpamAssassin version 3.2.0 [15603] dbg: config: score set 0 chosen. [15603] dbg: util: running in taint mode? yes [15603] dbg: util: taint mode: deleting unsafe environment variables, resetting PATH [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping [15603] dbg: util: PATH included '/usr/local/sbin', keeping [15603] dbg: util: PATH included '/usr/local/bin', keeping [15603] dbg: util: PATH included '/sbin', keeping [15603] dbg: util: PATH included '/bin', keeping [15603] dbg: util: PATH included '/usr/sbin', keeping [15603] dbg: util: PATH included '/usr/bin', keeping [15603] dbg: util: PATH included '/root/bin', which doesn't exist, dropping [15603] dbg: util: final PATH set to: /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b in:/usr/sbin:/usr/bin [15603] dbg: dns: no ipv6 [15603] dbg: dns: is Net::DNS::Resolver available? yes [15603] dbg: dns: Net::DNS version: 0.59 [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre files [15603] dbg: config: read file /etc/mail/spamassassin/init.pre [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir [15603] dbg: config: read file /etc/mail/spamassassin/local.cf [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf [15603] dbg: config: using "/root/.spamassassin" for user state dir [15603] dbg: config: using "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file [15603] dbg: config: read file /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [15603] dbg: razor2: razor2 is not available [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC [15603] dbg: pyzor: network tests on, attempting Pyzor [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [15603] dbg: razor2: razor2 is not available [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [15603] dbg: razor2: razor2 is not available [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered [15603] dbg: conf: finish parsing [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) implements 'finish_parsing_end', priority 0 [15603] dbg: replacetags: replacing tags [15603] dbg: replacetags: done replacing tags [15603] dbg: config: score set 1 chosen. [15603] dbg: message: main message type: multipart/alternative [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) implements 'check_start', priority 0 [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) implements 'check_main', priority 0 [15603] dbg: conf: trusted_networks are not configured; it is recommended that you configure trusted_networks manually [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= msa=0 ] [15603] dbg: received-header: 'from' 192.168.0.1 has private IP [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes msa? no [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 id=1784D107F90 auth= msa=0 ] [15603] dbg: metadata: X-Spam-Relays-Untrusted: [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 id=1784D107F90 auth= msa=0 ] [15603] dbg: metadata: X-Spam-Relays-External: [15603] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements 'extract_metadata', priority 0 [15603] dbg: metadata: X-Relay-Countries: [15603] dbg: message: ---- MIME PARSER START ---- [15603] dbg: message: parsing multipart, got boundary: ----=_NextPart_000_0005_01C7A1DA.CCACFD20 [15603] dbg: message: found part of type text/plain, boundary: ----=_NextPart_000_0005_01C7A1DA.CCACFD20 [15603] dbg: message: added part, type: text/plain [15603] dbg: message: parsing normal part [15603] dbg: message: ---- MIME PARSER END ---- [15603] dbg: message: decoding quoted-printable [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) implements 'parsed_metadata', priority 0 [15603] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements 'parsed_metadata', priority 0 [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) implements 'parsed_metadata', priority 0 [15603] dbg: dns: dns_available set to yes in config file, skipping test [15603] dbg: uridnsbl: domains to query: [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups [15603] dbg: check: running tests for priority: 0 [15603] dbg: rules: running head tests; score so far=0 [15603] dbg: rules: compiled head tests [15603] dbg: rules: running body tests; score so far=0 [15603] dbg: rules: compiled body tests [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got hit: "test" [15603] dbg: rules: running uri tests; score so far=100 [15603] dbg: rules: compiled uri tests [15603] dbg: rules: running rawbody tests; score so far=100 [15603] dbg: rules: compiled rawbody tests [15603] dbg: rules: running full tests; score so far=100 [15603] dbg: rules: compiled full tests [15603] dbg: rules: running meta tests; score so far=100 [15603] dbg: rules: compiled meta tests [15603] dbg: check: is spam? score=100 required=5 [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE [15603] dbg: check: subtests= >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 Received: from localhost by netserver.ftpmanagerbr.net with SpamAssassin (version 3.2.0); Tue, 29 May 2007 10:28:40 -0300 From: "Wilson - FTP" To: Subject: teste Date: Tue, 29 May 2007 10:19:11 -0300 Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on netserver.ftpmanagerbr.net MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" This is a multi-part message in MIME format. ------------=_465C2A88.4A78356A Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit (no report template found) ------------=_465C2A88.4A78356A Content-Type: message/rfc822; x-spam-type=original Content-Description: original message before SpamAssassin Content-Disposition: attachment Content-Transfer-Encoding: 8bit Return-Path: X-Original-To: wilson@ftpmanagerbr.net Delivered-To: wilson@ftpmanagerbr.net Received: from sdxp (unknown [192.168.0.1]) by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> From: "Wilson - FTP" To: Subject: teste Date: Tue, 29 May 2007 10:19:11 -0300 MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2900.3028 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more information X-ftpmanagerbr_net-MailScanner: Found to be clean X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, requerido 1) X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net X-Spam-Status: No This is a multi-part message in MIME format. ------=_NextPart_000_0005_01C7A1DA.CCACFD20 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Block this too ------------=_465C2A88.4A78356A-- (no report template found) De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Lasantha Marian Enviada em: ter?a-feira, 29 de maio de 2007 06:14 Para: MailScanner discussion Assunto: Re: RES: mcp help Dear Julian, I have been experiencing some strange behaviors in my MCP setup (SA 3.2.0/MS 4.59.4) too, i.e. MCP setup works very fine when tested from command line so does SpamAssassin setup (from both ends; command line and from MailScanner), but MCP would not work properly from MailScanner. It would happily scan but does not report against customized MCP rules. MCP rules are properly applied and correct scores are shown when run from command line without any errors. The very same MCP rules set works fine with earlier versions (SA 3.1.1/MS 4.53.8). I think it is the same kind of problem that Wilson is experiencing in MCP. It identifies MCP, but then may be a reporting problem ! Thanks and regards, Lasantha. *-------- Original Message --------* *Subject: *?? ?RES: mcp help *Date: *?? ?Tue, 29/May/2007 4:39:25 AM +0550 *From: *?? ?"Wilson A. Galafassi Jr." *To: *?? ?"'MailScanner discussion'" > spamassassin --D --lint > /tmp/sa.log 2>&1 > > This is the result. > > [root@netserver tmp]# cat sa.log > [26391] dbg: logger: adding facilities: all > [26391] dbg: logger: logging level is DBG > [26391] dbg: generic: SpamAssassin version 3.2.0 > [26391] dbg: config: score set 0 chosen. > [26391] dbg: util: running in taint mode? yes > [26391] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH From mscanlist at drisp.com Tue May 29 14:59:26 2007 From: mscanlist at drisp.com (Michael Kain) Date: Tue May 29 14:59:53 2007 Subject: Reject mail from invalid domains In-Reply-To: <465B004F.1@halla.pt> References: <465B004F.1@halla.pt> Message-ID: <465C31BE.4070409@drisp.com> Jorge Costinha wrote: > hi all, > > im using Fedora core 6, with Mailscanner 4.59.4 and sendmail > 8.13.8. I want to block email from invalid domains. Can i do this with > Mailscanner/spamassassin or has to be done at MTA level? > > thanks. If you mean unresolvable (by your dns) domains, you would do this: edit /etc/sendmail.mc and look for this line: FEATURE(`accept_unresolvable_domains')dnl add dnl to the beginning like this: dnl FEATURE(`accept_unresolvable_domains')dnl save file. # m4 sendmail.mc > sendmail.cf restart sendmail. From wilson.galafassi at gmail.com Tue May 29 15:03:03 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Tue May 29 15:03:19 2007 Subject: RES: RES: mcp help In-Reply-To: <465BEEF0.6000505@gmail.com> References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> <465BEEF0.6000505@gmail.com> Message-ID: I found this using command line: [16438] dbg: rules: ran header rule MY_RULE_1 ======> got hit: "block this phrase" [16438] dbg: rules: running body tests; score so far=100 [16438] dbg: rules: compiled body tests [16438] dbg: rules: ran body rule SAMPLE_RULE2 ======> got hit: "this" [16438] dbg: rules: running uri tests; score so far=105 [16438] dbg: rules: compiled uri tests [16438] dbg: rules: running rawbody tests; score so far=105 [16438] dbg: rules: compiled rawbody tests [16438] dbg: rules: running full tests; score so far=105 [16438] dbg: rules: compiled full tests [16438] dbg: rules: running meta tests; score so far=105 [16438] dbg: rules: compiled meta tests [16438] dbg: check: is spam? score=105 required=5 [16438] dbg: check: tests=MY_RULE_1,SAMPLE_RULE2 [16438] dbg: check: subtests= The score is 105. But isn?t marked as mcp. So i don?t know what is wrong... the messages don?t are marked as mcp. De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Lasantha Marian Enviada em: ter?a-feira, 29 de maio de 2007 06:14 Para: MailScanner discussion Assunto: Re: RES: mcp help Dear Julian, I have been experiencing some strange behaviors in my MCP setup (SA 3.2.0/MS 4.59.4) too, i.e. MCP setup works very fine when tested from command line so does SpamAssassin setup (from both ends; command line and from MailScanner), but MCP would not work properly from MailScanner. It would happily scan but does not report against customized MCP rules. MCP rules are properly applied and correct scores are shown when run from command line without any errors. The very same MCP rules set works fine with earlier versions (SA 3.1.1/MS 4.53.8). I think it is the same kind of problem that Wilson is experiencing in MCP. It identifies MCP, but then may be a reporting problem ! Thanks and regards, Lasantha. *-------- Original Message --------* *Subject: * RES: mcp help *Date: * Tue, 29/May/2007 4:39:25 AM +0550 *From: * "Wilson A. Galafassi Jr." *To: * "'MailScanner discussion'" > spamassassin --D --lint > /tmp/sa.log 2>&1 > > This is the result. > > [root@netserver tmp]# cat sa.log > [26391] dbg: logger: adding facilities: all > [26391] dbg: logger: logging level is DBG > [26391] dbg: generic: SpamAssassin version 3.2.0 > [26391] dbg: config: score set 0 chosen. > [26391] dbg: util: running in taint mode? yes > [26391] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070529/833505ab/attachment.html From MailScanner at ecs.soton.ac.uk Tue May 29 15:08:07 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 29 15:10:42 2007 Subject: RES: RES: mcp help In-Reply-To: References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> <465BEEF0.6000505@gmail.com> Message-ID: <465C33C7.6040301@ecs.soton.ac.uk> Yes, but what about the setting MCP Checks = yes ? Remember MCP is off by default. Wilson A. Galafassi Jr. wrote: > I have something wrong... any help is very apreciated! > > Thanks > Wilson > > > My mailscanner.cf > > First Check = mcp > > # The rest of these options are clones of the equivalent spam options > MCP Required SpamAssassin Score = 1 > MCP High SpamAssassin Score = 10 > MCP Error Score = 1 > > MCP Header = X-%org-name%-MailScanner-MCPCheck: > Non MCP Actions = deliver > MCP Actions = store > High Scoring MCP Actions = store > Bounce MCP As Attachment = no > > MCP Modify Subject = start > MCP Subject Text = {MCP?} > High Scoring MCP Modify Subject = start > High Scoring MCP Subject Text = {MCP?} > > Is Definitely MCP = no > Is Definitely Not MCP = no > Definite MCP Is High Scoring = yes > Always Include MCP Report = yes > Detailed MCP Report = yes > Include Scores In MCP Report = yes > Log MCP = yes > > MCP Max SpamAssassin Timeouts = 20 > MCP Max SpamAssassin Size = 100k > MCP SpamAssassin Timeout = 10 > > MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf > MCP SpamAssassin User State Dir = /var/spool/MailScanner/mcp > MCP SpamAssassin Local Rules Dir = %mcp-dir% > MCP SpamAssassin Default Rules Dir = %mcp-dir% > MCP SpamAssassin Install Prefix = %mcp-dir% > Recipient MCP Report = %report-dir%/recipient.mcp.report.txt > Sender MCP Report = %report-dir%/sender.mcp.report.txt > > > My test mail: > > >From wilson@ftpmanager.com Tue May 29 10:19:42 2007 > Return-Path: > X-Original-To: wilson@ftpmanager.com > Delivered-To: wilson@ftpmanager.com > Received: from sdxp (unknown [192.168.0.1]) > by netserver.ftpmanager.com (Postfix) with SMTP id 1784D107F90 > for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) > Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" > X-Priority: 3 > X-MSMail-Priority: Normal > X-Mailer: Microsoft Outlook Express 6.00.2900.3028 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 > X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more > information > X-ftpmanagerbr_net-MailScanner: Found to be clean > X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, > requerido 1) > X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanager.com > X-Spam-Status: No > > This is a multi-part message in MIME format. > > ------=_NextPart_000_0005_01C7A1DA.CCACFD20 > Content-Type: text/plain; > charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > Block this t?o > > > My cf file: > > header MY_RULE_1 Subject =~ /block this phrase/i > score MY_RULE_1 100 > > body MY_RULE_2 /Block this too/i > score MY_RULE_2 100 > > body MY_RULE_3 /this\s*is\s*more\s*complicated/i > score MY_RULE_3 100 > > > body SAMPLE_RULE2 /this/i > describe SAMPLE_RULE2 Banned body text > score SAMPLE_RULE2 5 > > body LOCAL_DEMONSTRATION_RULE /test/ > score LOCAL_DEMONSTRATION_RULE 100 > describe LOCAL_DEMONSTRATION_RULE This is a simple test rule > > header LOCAL_DEMONSTRATION_SUBJECT Subject =~ /\btest\b/i > score LOCAL_DEMONSTRATION_SUBJECT 100 > > > The spamassassin test: > > spamassassin -C /etc/MailScanner/mcp -p > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < teste.mail > [15603] dbg: logger: adding facilities: all > [15603] dbg: logger: logging level is DBG > [15603] dbg: generic: SpamAssassin version 3.2.0 > [15603] dbg: config: score set 0 chosen. > [15603] dbg: util: running in taint mode? yes > [15603] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH > [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping > [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping > [15603] dbg: util: PATH included '/usr/local/sbin', keeping > [15603] dbg: util: PATH included '/usr/local/bin', keeping > [15603] dbg: util: PATH included '/sbin', keeping > [15603] dbg: util: PATH included '/bin', keeping > [15603] dbg: util: PATH included '/usr/sbin', keeping > [15603] dbg: util: PATH included '/usr/bin', keeping > [15603] dbg: util: PATH included '/root/bin', which doesn't exist, dropping > [15603] dbg: util: final PATH set to: > /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b > in:/usr/sbin:/usr/bin > [15603] dbg: dns: no ipv6 > [15603] dbg: dns: is Net::DNS::Resolver available? yes > [15603] dbg: dns: Net::DNS version: 0.59 > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre files > [15603] dbg: config: read file /etc/mail/spamassassin/init.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre > [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files > [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir > [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir > [15603] dbg: config: read file /etc/mail/spamassassin/local.cf > [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf > [15603] dbg: config: using "/root/.spamassassin" for user state dir > [15603] dbg: config: using > "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file > [15603] dbg: config: read file > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC > [15603] dbg: pyzor: network tests on, attempting Pyzor > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered > [15603] dbg: conf: finish parsing > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) > implements 'finish_parsing_end', priority 0 > [15603] dbg: replacetags: replacing tags > [15603] dbg: replacetags: done replacing tags > [15603] dbg: config: score set 1 chosen. > [15603] dbg: message: main message type: multipart/alternative > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) > implements 'check_start', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) > implements 'check_main', priority 0 > [15603] dbg: conf: trusted_networks are not configured; it is recommended > that you configure trusted_networks manually > [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp > by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= > msa=0 ] > [15603] dbg: received-header: 'from' 192.168.0.1 has private IP > [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes > msa? no > [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-Untrusted: > [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-External: > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'extract_metadata', priority 0 > [15603] dbg: metadata: X-Relay-Countries: > [15603] dbg: message: ---- MIME PARSER START ---- > [15603] dbg: message: parsing multipart, got boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: found part of type text/plain, boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: added part, type: text/plain > [15603] dbg: message: parsing normal part > [15603] dbg: message: ---- MIME PARSER END ---- > [15603] dbg: message: decoding quoted-printable > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) > implements 'parsed_metadata', priority 0 > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'parsed_metadata', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) > implements 'parsed_metadata', priority 0 > [15603] dbg: dns: dns_available set to yes in config file, skipping test > [15603] dbg: uridnsbl: domains to query: > [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups > [15603] dbg: check: running tests for priority: 0 > [15603] dbg: rules: running head tests; score so far=0 > [15603] dbg: rules: compiled head tests > [15603] dbg: rules: running body tests; score so far=0 > [15603] dbg: rules: compiled body tests > [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got hit: > "test" > [15603] dbg: rules: running uri tests; score so far=100 > [15603] dbg: rules: compiled uri tests > [15603] dbg: rules: running rawbody tests; score so far=100 > [15603] dbg: rules: compiled rawbody tests > [15603] dbg: rules: running full tests; score so far=100 > [15603] dbg: rules: compiled full tests > [15603] dbg: rules: running meta tests; score so far=100 > [15603] dbg: rules: compiled meta tests > [15603] dbg: check: is spam? score=100 required=5 > [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE > [15603] dbg: check: subtests= > >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 > Received: from localhost by netserver.ftpmanagerbr.net > with SpamAssassin (version 3.2.0); > Tue, 29 May 2007 10:28:40 -0300 > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on > netserver.ftpmanagerbr.net > MIME-Version: 1.0 > Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" > > This is a multi-part message in MIME format. > > ------------=_465C2A88.4A78356A > Content-Type: text/plain; charset=iso-8859-1 > Content-Disposition: inline > Content-Transfer-Encoding: 8bit > > (no report template found) > > > > ------------=_465C2A88.4A78356A > Content-Type: message/rfc822; x-spam-type=original > Content-Description: original message before SpamAssassin > Content-Disposition: attachment > Content-Transfer-Encoding: 8bit > > Return-Path: > X-Original-To: wilson@ftpmanagerbr.net > Delivered-To: wilson@ftpmanagerbr.net > Received: from sdxp (unknown [192.168.0.1]) > by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 > for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) > Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" > X-Priority: 3 > X-MSMail-Priority: Normal > X-Mailer: Microsoft Outlook Express 6.00.2900.3028 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 > X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more > information > X-ftpmanagerbr_net-MailScanner: Found to be clean > X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, > requerido 1) > X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net > X-Spam-Status: No > > This is a multi-part message in MIME format. > > ------=_NextPart_000_0005_01C7A1DA.CCACFD20 > Content-Type: text/plain; > charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > Block this too > > ------------=_465C2A88.4A78356A-- > > (no report template found) spamassassin -C /etc/MailScanner/mcp -p > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < teste.mail > [15603] dbg: logger: adding facilities: all > [15603] dbg: logger: logging level is DBG > [15603] dbg: generic: SpamAssassin version 3.2.0 > [15603] dbg: config: score set 0 chosen. > [15603] dbg: util: running in taint mode? yes > [15603] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH > [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping > [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping > [15603] dbg: util: PATH included '/usr/local/sbin', keeping > [15603] dbg: util: PATH included '/usr/local/bin', keeping > [15603] dbg: util: PATH included '/sbin', keeping > [15603] dbg: util: PATH included '/bin', keeping > [15603] dbg: util: PATH included '/usr/sbin', keeping > [15603] dbg: util: PATH included '/usr/bin', keeping > [15603] dbg: util: PATH included '/root/bin', which doesn't exist, dropping > [15603] dbg: util: final PATH set to: > /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b > in:/usr/sbin:/usr/bin > [15603] dbg: dns: no ipv6 > [15603] dbg: dns: is Net::DNS::Resolver available? yes > [15603] dbg: dns: Net::DNS version: 0.59 > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre files > [15603] dbg: config: read file /etc/mail/spamassassin/init.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre > [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files > [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir > [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir > [15603] dbg: config: read file /etc/mail/spamassassin/local.cf > [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf > [15603] dbg: config: using "/root/.spamassassin" for user state dir > [15603] dbg: config: using > "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file > [15603] dbg: config: read file > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC > [15603] dbg: pyzor: network tests on, attempting Pyzor > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered > [15603] dbg: conf: finish parsing > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) > implements 'finish_parsing_end', priority 0 > [15603] dbg: replacetags: replacing tags > [15603] dbg: replacetags: done replacing tags > [15603] dbg: config: score set 1 chosen. > [15603] dbg: message: main message type: multipart/alternative > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) > implements 'check_start', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) > implements 'check_main', priority 0 > [15603] dbg: conf: trusted_networks are not configured; it is recommended > that you configure trusted_networks manually > [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp > by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= > msa=0 ] > [15603] dbg: received-header: 'from' 192.168.0.1 has private IP > [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes > msa? no > [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-Untrusted: > [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-External: > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'extract_metadata', priority 0 > [15603] dbg: metadata: X-Relay-Countries: > [15603] dbg: message: ---- MIME PARSER START ---- > [15603] dbg: message: parsing multipart, got boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: found part of type text/plain, boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: added part, type: text/plain > [15603] dbg: message: parsing normal part > [15603] dbg: message: ---- MIME PARSER END ---- > [15603] dbg: message: decoding quoted-printable > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) > implements 'parsed_metadata', priority 0 > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'parsed_metadata', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) > implements 'parsed_metadata', priority 0 > [15603] dbg: dns: dns_available set to yes in config file, skipping test > [15603] dbg: uridnsbl: domains to query: > [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups > [15603] dbg: check: running tests for priority: 0 > [15603] dbg: rules: running head tests; score so far=0 > [15603] dbg: rules: compiled head tests > [15603] dbg: rules: running body tests; score so far=0 > [15603] dbg: rules: compiled body tests > [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got hit: > "test" > [15603] dbg: rules: running uri tests; score so far=100 > [15603] dbg: rules: compiled uri tests > [15603] dbg: rules: running rawbody tests; score so far=100 > [15603] dbg: rules: compiled rawbody tests > [15603] dbg: rules: running full tests; score so far=100 > [15603] dbg: rules: compiled full tests > [15603] dbg: rules: running meta tests; score so far=100 > [15603] dbg: rules: compiled meta tests > [15603] dbg: check: is spam? score=100 required=5 > [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE > [15603] dbg: check: subtests= > >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 > Received: from localhost by netserver.ftpmanagerbr.net > with SpamAssassin (version 3.2.0); > Tue, 29 May 2007 10:28:40 -0300 > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on > netserver.ftpmanagerbr.net > MIME-Version: 1.0 > Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" > > This is a multi-part message in MIME format. > > ------------=_465C2A88.4A78356A > Content-Type: text/plain; charset=iso-8859-1 > Content-Disposition: inline > Content-Transfer-Encoding: 8bit > > (no report template found) > > > > ------------=_465C2A88.4A78356A > Content-Type: message/rfc822; x-spam-type=original > Content-Description: original message before SpamAssassin > Content-Disposition: attachment > Content-Transfer-Encoding: 8bit > > Return-Path: > X-Original-To: wilson@ftpmanagerbr.net > Delivered-To: wilson@ftpmanagerbr.net > Received: from sdxp (unknown [192.168.0.1]) > by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 > for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) > Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" > X-Priority: 3 > X-MSMail-Priority: Normal > X-Mailer: Microsoft Outlook Express 6.00.2900.3028 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 > X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more > information > X-ftpmanagerbr_net-MailScanner: Found to be clean > X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, > requerido 1) > X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net > X-Spam-Status: No > > This is a multi-part message in MIME format. > > ------=_NextPart_000_0005_01C7A1DA.CCACFD20 > Content-Type: text/plain; > charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > Block this too > > ------------=_465C2A88.4A78356A-- > > (no report template found) > > > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Lasantha > Marian > Enviada em: ter?a-feira, 29 de maio de 2007 06:14 > Para: MailScanner discussion > Assunto: Re: RES: mcp help > > Dear Julian, > > I have been experiencing some strange behaviors in my MCP setup (SA 3.2.0/MS > 4.59.4) too, i.e. MCP setup works very fine when tested from command line so > does SpamAssassin setup (from both ends; command line and from MailScanner), > but MCP would not work properly from MailScanner. It would happily scan but > does not report against customized MCP rules. MCP rules are properly applied > and correct scores are shown when run from command line without any errors. > The very same MCP rules set works fine with earlier versions (SA 3.1.1/MS > 4.53.8). > > I think it is the same kind of problem that Wilson is experiencing in MCP. > It identifies MCP, but then may be a reporting problem ! > > Thanks and regards, > > Lasantha. > > > *-------- Original Message --------* > *Subject: * RES: mcp help > *Date: * Tue, 29/May/2007 4:39:25 AM +0550 > *From: * "Wilson A. Galafassi Jr." > *To: * "'MailScanner discussion'" > > > >> spamassassin --D --lint > >> > /tmp/sa.log 2>&1 > > > > >> This is the result. >> > > > > >> [root@netserver tmp]# cat sa.log >> > > >> [26391] dbg: logger: adding facilities: all >> > > >> [26391] dbg: logger: logging level is DBG >> > > >> [26391] dbg: generic: SpamAssassin version 3.2.0 >> > > >> [26391] dbg: config: score set 0 chosen. >> > > >> [26391] dbg: util: running in taint mode? yes >> > > >> [26391] dbg: util: taint mode: deleting unsafe environment >> > variables, > > >> resetting PATH >> > > > > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Tue May 29 15:06:46 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 29 15:10:49 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: <418312.38090.qm@web26315.mail.ukl.yahoo.com> References: <418312.38090.qm@web26315.mail.ukl.yahoo.com> Message-ID: <465C3376.2090300@ecs.soton.ac.uk> Andrew MacLachlan wrote: > Can it be added to existing MailScanner installations? > Yes. > ----- Original Message ---- > From: "Koopmann, Jan-Peter" > To: MailScanner discussion > Sent: Tuesday, 29 May, 2007 12:05:47 PM > Subject: RE: better blocking at MTA level (off-topic) > > On Tuesday, May 29, 2007 12:24 PM Kapetanakis Giannis wrote: > > >> Which product are you talking about? DefenderMX? >> > > No but close. As it has not been published yet I cannot talk about it but it looks very promising. Same company. > > >> Is it open source/free? >> > > No. > > > Kind regards > > Jan-Peter Koopmann > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From P.G.M.Peters at utwente.nl Tue May 29 15:26:35 2007 From: P.G.M.Peters at utwente.nl (Peter Peters) Date: Tue May 29 15:26:42 2007 Subject: Forcing processing of mails in incomming queue In-Reply-To: <465C24A0.8040209@nkpanama.com> References: <465C198F.3030103@nkpanama.com> <223f97700705290548t2794c863sb0b935e986b5b892@mail.gmail.com> <465C24A0.8040209@nkpanama.com> Message-ID: <465C381B.7070703@utwente.nl> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 > I think I've had this happen once or twice. After the broken MailScanner > install was fixed, everything worked normally. In the meantime I would > either sendmail -q -v -O QueueDirectory=/var/spool/mqueue.in and run > plain old sendmail until MailScanner was fixed, and then stop sendmail > and run MailScanner. I have done about the same. But I had the luck to have more than one system. So I moved the complete queue over to the other working machine. If I remember correctly it had nothing to do with MailScanner but there was a problem with the hardware. The disk could be mounted in another system so I could get to the files. - -- Peter Peters, senior beheerder (Security) Dienst Informatietechnologie, Bibliotheek en Educatie (ITBE) Universiteit Twente, Postbus 217, 7500 AE Enschede telefoon: 053 - 489 2301, fax: 053 - 489 2383, http://www.utwente.nl/itbe -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFGXDgbelLo80lrIdIRAhDRAKCBzJISupsvBpkCC0NOGrNXNGV0CQCfVO4m gcuH2LaUq63ya1soLiH2YiQ= =Iv1L -----END PGP SIGNATURE----- From Richard.Frovarp at sendit.nodak.edu Tue May 29 15:28:22 2007 From: Richard.Frovarp at sendit.nodak.edu (Richard Frovarp) Date: Tue May 29 15:28:25 2007 Subject: Reject mail from invalid domains In-Reply-To: References: <465B004F.1@halla.pt><465BD26A.6060105@halla.pt>, Message-ID: <465C3886.90804@sendit.nodak.edu> Jason Ede wrote: > Surely it makes sense to at least check if the sender is a fully > qualified domain and also that there is an MX record for that domain? > > Jason Remember you don't need to have an MX record to accept mail. A records work just fine and would be common for small setups. From wilson.galafassi at gmail.com Tue May 29 15:29:22 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Tue May 29 15:29:53 2007 Subject: RES: RES: RES: mcp help In-Reply-To: <465C33C7.6040301@ecs.soton.ac.uk> References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> <465BEEF0.6000505@gmail.com> <465C33C7.60403 01@ecs.soton.ac.uk> Message-ID: My setting is Yes. -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field Enviada em: ter?a-feira, 29 de maio de 2007 11:08 Para: MailScanner discussion Assunto: Re: RES: RES: mcp help Yes, but what about the setting MCP Checks = yes ? Remember MCP is off by default. Wilson A. Galafassi Jr. wrote: > I have something wrong... any help is very apreciated! > > Thanks > Wilson > > > My mailscanner.cf > > First Check = mcp > > # The rest of these options are clones of the equivalent spam options > MCP Required SpamAssassin Score = 1 > MCP High SpamAssassin Score = 10 > MCP Error Score = 1 > > MCP Header = X-%org-name%-MailScanner-MCPCheck: > Non MCP Actions = deliver > MCP Actions = store > High Scoring MCP Actions = store > Bounce MCP As Attachment = no > > MCP Modify Subject = start > MCP Subject Text = {MCP?} > High Scoring MCP Modify Subject = start > High Scoring MCP Subject Text = {MCP?} > > Is Definitely MCP = no > Is Definitely Not MCP = no > Definite MCP Is High Scoring = yes > Always Include MCP Report = yes > Detailed MCP Report = yes > Include Scores In MCP Report = yes > Log MCP = yes > > MCP Max SpamAssassin Timeouts = 20 > MCP Max SpamAssassin Size = 100k > MCP SpamAssassin Timeout = 10 > > MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf > MCP SpamAssassin User State Dir = /var/spool/MailScanner/mcp > MCP SpamAssassin Local Rules Dir = %mcp-dir% > MCP SpamAssassin Default Rules Dir = %mcp-dir% > MCP SpamAssassin Install Prefix = %mcp-dir% > Recipient MCP Report = %report-dir%/recipient.mcp.report.txt > Sender MCP Report = %report-dir%/sender.mcp.report.txt > > > My test mail: > > >From wilson@ftpmanager.com Tue May 29 10:19:42 2007 > Return-Path: > X-Original-To: wilson@ftpmanager.com > Delivered-To: wilson@ftpmanager.com > Received: from sdxp (unknown [192.168.0.1]) > by netserver.ftpmanager.com (Postfix) with SMTP id 1784D107F90 > for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) > Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" > X-Priority: 3 > X-MSMail-Priority: Normal > X-Mailer: Microsoft Outlook Express 6.00.2900.3028 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 > X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more > information > X-ftpmanagerbr_net-MailScanner: Found to be clean > X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, > requerido 1) > X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanager.com > X-Spam-Status: No > > This is a multi-part message in MIME format. > > ------=_NextPart_000_0005_01C7A1DA.CCACFD20 > Content-Type: text/plain; > charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > Block this t?o > > > My cf file: > > header MY_RULE_1 Subject =~ /block this phrase/i > score MY_RULE_1 100 > > body MY_RULE_2 /Block this too/i > score MY_RULE_2 100 > > body MY_RULE_3 /this\s*is\s*more\s*complicated/i > score MY_RULE_3 100 > > > body SAMPLE_RULE2 /this/i > describe SAMPLE_RULE2 Banned body text > score SAMPLE_RULE2 5 > > body LOCAL_DEMONSTRATION_RULE /test/ > score LOCAL_DEMONSTRATION_RULE 100 > describe LOCAL_DEMONSTRATION_RULE This is a simple test rule > > header LOCAL_DEMONSTRATION_SUBJECT Subject =~ /\btest\b/i > score LOCAL_DEMONSTRATION_SUBJECT 100 > > > The spamassassin test: > > spamassassin -C /etc/MailScanner/mcp -p > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < teste.mail > [15603] dbg: logger: adding facilities: all > [15603] dbg: logger: logging level is DBG > [15603] dbg: generic: SpamAssassin version 3.2.0 > [15603] dbg: config: score set 0 chosen. > [15603] dbg: util: running in taint mode? yes > [15603] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH > [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping > [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping > [15603] dbg: util: PATH included '/usr/local/sbin', keeping > [15603] dbg: util: PATH included '/usr/local/bin', keeping > [15603] dbg: util: PATH included '/sbin', keeping > [15603] dbg: util: PATH included '/bin', keeping > [15603] dbg: util: PATH included '/usr/sbin', keeping > [15603] dbg: util: PATH included '/usr/bin', keeping > [15603] dbg: util: PATH included '/root/bin', which doesn't exist, dropping > [15603] dbg: util: final PATH set to: > /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b > in:/usr/sbin:/usr/bin > [15603] dbg: dns: no ipv6 > [15603] dbg: dns: is Net::DNS::Resolver available? yes > [15603] dbg: dns: Net::DNS version: 0.59 > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre files > [15603] dbg: config: read file /etc/mail/spamassassin/init.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre > [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files > [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir > [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir > [15603] dbg: config: read file /etc/mail/spamassassin/local.cf > [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf > [15603] dbg: config: using "/root/.spamassassin" for user state dir > [15603] dbg: config: using > "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file > [15603] dbg: config: read file > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC > [15603] dbg: pyzor: network tests on, attempting Pyzor > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered > [15603] dbg: conf: finish parsing > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) > implements 'finish_parsing_end', priority 0 > [15603] dbg: replacetags: replacing tags > [15603] dbg: replacetags: done replacing tags > [15603] dbg: config: score set 1 chosen. > [15603] dbg: message: main message type: multipart/alternative > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) > implements 'check_start', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) > implements 'check_main', priority 0 > [15603] dbg: conf: trusted_networks are not configured; it is recommended > that you configure trusted_networks manually > [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp > by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= > msa=0 ] > [15603] dbg: received-header: 'from' 192.168.0.1 has private IP > [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes > msa? no > [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-Untrusted: > [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-External: > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'extract_metadata', priority 0 > [15603] dbg: metadata: X-Relay-Countries: > [15603] dbg: message: ---- MIME PARSER START ---- > [15603] dbg: message: parsing multipart, got boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: found part of type text/plain, boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: added part, type: text/plain > [15603] dbg: message: parsing normal part > [15603] dbg: message: ---- MIME PARSER END ---- > [15603] dbg: message: decoding quoted-printable > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) > implements 'parsed_metadata', priority 0 > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'parsed_metadata', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) > implements 'parsed_metadata', priority 0 > [15603] dbg: dns: dns_available set to yes in config file, skipping test > [15603] dbg: uridnsbl: domains to query: > [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups > [15603] dbg: check: running tests for priority: 0 > [15603] dbg: rules: running head tests; score so far=0 > [15603] dbg: rules: compiled head tests > [15603] dbg: rules: running body tests; score so far=0 > [15603] dbg: rules: compiled body tests > [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got hit: > "test" > [15603] dbg: rules: running uri tests; score so far=100 > [15603] dbg: rules: compiled uri tests > [15603] dbg: rules: running rawbody tests; score so far=100 > [15603] dbg: rules: compiled rawbody tests > [15603] dbg: rules: running full tests; score so far=100 > [15603] dbg: rules: compiled full tests > [15603] dbg: rules: running meta tests; score so far=100 > [15603] dbg: rules: compiled meta tests > [15603] dbg: check: is spam? score=100 required=5 > [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE > [15603] dbg: check: subtests= > >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 > Received: from localhost by netserver.ftpmanagerbr.net > with SpamAssassin (version 3.2.0); > Tue, 29 May 2007 10:28:40 -0300 > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on > netserver.ftpmanagerbr.net > MIME-Version: 1.0 > Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" > > This is a multi-part message in MIME format. > > ------------=_465C2A88.4A78356A > Content-Type: text/plain; charset=iso-8859-1 > Content-Disposition: inline > Content-Transfer-Encoding: 8bit > > (no report template found) > > > > ------------=_465C2A88.4A78356A > Content-Type: message/rfc822; x-spam-type=original > Content-Description: original message before SpamAssassin > Content-Disposition: attachment > Content-Transfer-Encoding: 8bit > > Return-Path: > X-Original-To: wilson@ftpmanagerbr.net > Delivered-To: wilson@ftpmanagerbr.net > Received: from sdxp (unknown [192.168.0.1]) > by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 > for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) > Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" > X-Priority: 3 > X-MSMail-Priority: Normal > X-Mailer: Microsoft Outlook Express 6.00.2900.3028 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 > X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more > information > X-ftpmanagerbr_net-MailScanner: Found to be clean > X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, > requerido 1) > X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net > X-Spam-Status: No > > This is a multi-part message in MIME format. > > ------=_NextPart_000_0005_01C7A1DA.CCACFD20 > Content-Type: text/plain; > charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > Block this too > > ------------=_465C2A88.4A78356A-- > > (no report template found) spamassassin -C /etc/MailScanner/mcp -p > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < teste.mail > [15603] dbg: logger: adding facilities: all > [15603] dbg: logger: logging level is DBG > [15603] dbg: generic: SpamAssassin version 3.2.0 > [15603] dbg: config: score set 0 chosen. > [15603] dbg: util: running in taint mode? yes > [15603] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH > [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping > [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping > [15603] dbg: util: PATH included '/usr/local/sbin', keeping > [15603] dbg: util: PATH included '/usr/local/bin', keeping > [15603] dbg: util: PATH included '/sbin', keeping > [15603] dbg: util: PATH included '/bin', keeping > [15603] dbg: util: PATH included '/usr/sbin', keeping > [15603] dbg: util: PATH included '/usr/bin', keeping > [15603] dbg: util: PATH included '/root/bin', which doesn't exist, dropping > [15603] dbg: util: final PATH set to: > /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b > in:/usr/sbin:/usr/bin > [15603] dbg: dns: no ipv6 > [15603] dbg: dns: is Net::DNS::Resolver available? yes > [15603] dbg: dns: Net::DNS version: 0.59 > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre files > [15603] dbg: config: read file /etc/mail/spamassassin/init.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre > [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files > [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir > [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir > [15603] dbg: config: read file /etc/mail/spamassassin/local.cf > [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf > [15603] dbg: config: using "/root/.spamassassin" for user state dir > [15603] dbg: config: using > "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file > [15603] dbg: config: read file > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC > [15603] dbg: pyzor: network tests on, attempting Pyzor > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered > [15603] dbg: conf: finish parsing > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) > implements 'finish_parsing_end', priority 0 > [15603] dbg: replacetags: replacing tags > [15603] dbg: replacetags: done replacing tags > [15603] dbg: config: score set 1 chosen. > [15603] dbg: message: main message type: multipart/alternative > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) > implements 'check_start', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) > implements 'check_main', priority 0 > [15603] dbg: conf: trusted_networks are not configured; it is recommended > that you configure trusted_networks manually > [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp > by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= > msa=0 ] > [15603] dbg: received-header: 'from' 192.168.0.1 has private IP > [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes > msa? no > [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-Untrusted: > [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-External: > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'extract_metadata', priority 0 > [15603] dbg: metadata: X-Relay-Countries: > [15603] dbg: message: ---- MIME PARSER START ---- > [15603] dbg: message: parsing multipart, got boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: found part of type text/plain, boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: added part, type: text/plain > [15603] dbg: message: parsing normal part > [15603] dbg: message: ---- MIME PARSER END ---- > [15603] dbg: message: decoding quoted-printable > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) > implements 'parsed_metadata', priority 0 > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'parsed_metadata', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) > implements 'parsed_metadata', priority 0 > [15603] dbg: dns: dns_available set to yes in config file, skipping test > [15603] dbg: uridnsbl: domains to query: > [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups > [15603] dbg: check: running tests for priority: 0 > [15603] dbg: rules: running head tests; score so far=0 > [15603] dbg: rules: compiled head tests > [15603] dbg: rules: running body tests; score so far=0 > [15603] dbg: rules: compiled body tests > [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got hit: > "test" > [15603] dbg: rules: running uri tests; score so far=100 > [15603] dbg: rules: compiled uri tests > [15603] dbg: rules: running rawbody tests; score so far=100 > [15603] dbg: rules: compiled rawbody tests > [15603] dbg: rules: running full tests; score so far=100 > [15603] dbg: rules: compiled full tests > [15603] dbg: rules: running meta tests; score so far=100 > [15603] dbg: rules: compiled meta tests > [15603] dbg: check: is spam? score=100 required=5 > [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE > [15603] dbg: check: subtests= > >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 > Received: from localhost by netserver.ftpmanagerbr.net > with SpamAssassin (version 3.2.0); > Tue, 29 May 2007 10:28:40 -0300 > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on > netserver.ftpmanagerbr.net > MIME-Version: 1.0 > Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" > > This is a multi-part message in MIME format. > > ------------=_465C2A88.4A78356A > Content-Type: text/plain; charset=iso-8859-1 > Content-Disposition: inline > Content-Transfer-Encoding: 8bit > > (no report template found) > > > > ------------=_465C2A88.4A78356A > Content-Type: message/rfc822; x-spam-type=original > Content-Description: original message before SpamAssassin > Content-Disposition: attachment > Content-Transfer-Encoding: 8bit > > Return-Path: > X-Original-To: wilson@ftpmanagerbr.net > Delivered-To: wilson@ftpmanagerbr.net > Received: from sdxp (unknown [192.168.0.1]) > by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 > for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) > Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" > X-Priority: 3 > X-MSMail-Priority: Normal > X-Mailer: Microsoft Outlook Express 6.00.2900.3028 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 > X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more > information > X-ftpmanagerbr_net-MailScanner: Found to be clean > X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, > requerido 1) > X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net > X-Spam-Status: No > > This is a multi-part message in MIME format. > > ------=_NextPart_000_0005_01C7A1DA.CCACFD20 > Content-Type: text/plain; > charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > Block this too > > ------------=_465C2A88.4A78356A-- > > (no report template found) > > > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Lasantha > Marian > Enviada em: ter?a-feira, 29 de maio de 2007 06:14 > Para: MailScanner discussion > Assunto: Re: RES: mcp help > > Dear Julian, > > I have been experiencing some strange behaviors in my MCP setup (SA 3.2.0/MS > 4.59.4) too, i.e. MCP setup works very fine when tested from command line so > does SpamAssassin setup (from both ends; command line and from MailScanner), > but MCP would not work properly from MailScanner. It would happily scan but > does not report against customized MCP rules. MCP rules are properly applied > and correct scores are shown when run from command line without any errors. > The very same MCP rules set works fine with earlier versions (SA 3.1.1/MS > 4.53.8). > > I think it is the same kind of problem that Wilson is experiencing in MCP. > It identifies MCP, but then may be a reporting problem ! > > Thanks and regards, > > Lasantha. > > > *-------- Original Message --------* > *Subject: * RES: mcp help > *Date: * Tue, 29/May/2007 4:39:25 AM +0550 > *From: * "Wilson A. Galafassi Jr." > *To: * "'MailScanner discussion'" > > > >> spamassassin --D --lint > >> > /tmp/sa.log 2>&1 > > > > >> This is the result. >> > > > > >> [root@netserver tmp]# cat sa.log >> > > >> [26391] dbg: logger: adding facilities: all >> > > >> [26391] dbg: logger: logging level is DBG >> > > >> [26391] dbg: generic: SpamAssassin version 3.2.0 >> > > >> [26391] dbg: config: score set 0 chosen. >> > > >> [26391] dbg: util: running in taint mode? yes >> > > >> [26391] dbg: util: taint mode: deleting unsafe environment >> > variables, > > >> resetting PATH >> > > > > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From wilson.galafassi at gmail.com Tue May 29 15:31:42 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Tue May 29 15:32:24 2007 Subject: RES: RES: mcp help In-Reply-To: <465BEEF0.6000505@gmail.com> References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> <465BEEF0.6000505@gmail.com> Message-ID: I found this error when performing mcp check. This error occours only when spamassassin perform mcp checks. When perform spam checks the error don?t occour. check: no loaded plugin implements 'check_main': cannot scan! at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin/PerMsgStatus.pm line 164. De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Lasantha Marian Enviada em: ter?a-feira, 29 de maio de 2007 06:14 Para: MailScanner discussion Assunto: Re: RES: mcp help Dear Julian, I have been experiencing some strange behaviors in my MCP setup (SA 3.2.0/MS 4.59.4) too, i.e. MCP setup works very fine when tested from command line so does SpamAssassin setup (from both ends; command line and from MailScanner), but MCP would not work properly from MailScanner. It would happily scan but does not report against customized MCP rules. MCP rules are properly applied and correct scores are shown when run from command line without any errors. The very same MCP rules set works fine with earlier versions (SA 3.1.1/MS 4.53.8). I think it is the same kind of problem that Wilson is experiencing in MCP. It identifies MCP, but then may be a reporting problem ! Thanks and regards, Lasantha. *-------- Original Message --------* *Subject: * RES: mcp help *Date: * Tue, 29/May/2007 4:39:25 AM +0550 *From: * "Wilson A. Galafassi Jr." *To: * "'MailScanner discussion'" > spamassassin --D --lint > /tmp/sa.log 2>&1 > > This is the result. > > [root@netserver tmp]# cat sa.log > [26391] dbg: logger: adding facilities: all > [26391] dbg: logger: logging level is DBG > [26391] dbg: generic: SpamAssassin version 3.2.0 > [26391] dbg: config: score set 0 chosen. > [26391] dbg: util: running in taint mode? yes > [26391] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070529/7c69669d/attachment.html From wilson.galafassi at gmail.com Tue May 29 15:53:11 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Tue May 29 15:53:28 2007 Subject: RES: RES: RES: mcp help In-Reply-To: <465C33C7.6040301@ecs.soton.ac.uk> References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> <465BEEF0.6000505@gmail.com> <465C33C7.60403 01@ecs.soton.ac.uk> Message-ID: I have changed in MailScanner.conf the setting: First Check = spam And the error: check: no loaded plugin implements 'check_main': cannot scan! at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin/PerMsgStatus.pm line 164 now the error occour at the end of log. I?m thinking this problem is related to mcp scan, because if First Check = mcp the error occour at begining of log and using the same rules in spam.assassin.pref.conf the rules are detected, but in mcp not. Thanks Wilson -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field Enviada em: ter?a-feira, 29 de maio de 2007 11:08 Para: MailScanner discussion Assunto: Re: RES: RES: mcp help Yes, but what about the setting MCP Checks = yes ? Remember MCP is off by default. Wilson A. Galafassi Jr. wrote: > I have something wrong... any help is very apreciated! > > Thanks > Wilson > > > My mailscanner.cf > > First Check = mcp > > # The rest of these options are clones of the equivalent spam options > MCP Required SpamAssassin Score = 1 > MCP High SpamAssassin Score = 10 > MCP Error Score = 1 > > MCP Header = X-%org-name%-MailScanner-MCPCheck: > Non MCP Actions = deliver > MCP Actions = store > High Scoring MCP Actions = store > Bounce MCP As Attachment = no > > MCP Modify Subject = start > MCP Subject Text = {MCP?} > High Scoring MCP Modify Subject = start > High Scoring MCP Subject Text = {MCP?} > > Is Definitely MCP = no > Is Definitely Not MCP = no > Definite MCP Is High Scoring = yes > Always Include MCP Report = yes > Detailed MCP Report = yes > Include Scores In MCP Report = yes > Log MCP = yes > > MCP Max SpamAssassin Timeouts = 20 > MCP Max SpamAssassin Size = 100k > MCP SpamAssassin Timeout = 10 > > MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf > MCP SpamAssassin User State Dir = /var/spool/MailScanner/mcp > MCP SpamAssassin Local Rules Dir = %mcp-dir% > MCP SpamAssassin Default Rules Dir = %mcp-dir% > MCP SpamAssassin Install Prefix = %mcp-dir% > Recipient MCP Report = %report-dir%/recipient.mcp.report.txt > Sender MCP Report = %report-dir%/sender.mcp.report.txt > > > My test mail: > > >From wilson@ftpmanager.com Tue May 29 10:19:42 2007 > Return-Path: > X-Original-To: wilson@ftpmanager.com > Delivered-To: wilson@ftpmanager.com > Received: from sdxp (unknown [192.168.0.1]) > by netserver.ftpmanager.com (Postfix) with SMTP id 1784D107F90 > for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) > Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" > X-Priority: 3 > X-MSMail-Priority: Normal > X-Mailer: Microsoft Outlook Express 6.00.2900.3028 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 > X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more > information > X-ftpmanagerbr_net-MailScanner: Found to be clean > X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, > requerido 1) > X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanager.com > X-Spam-Status: No > > This is a multi-part message in MIME format. > > ------=_NextPart_000_0005_01C7A1DA.CCACFD20 > Content-Type: text/plain; > charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > Block this t?o > > > My cf file: > > header MY_RULE_1 Subject =~ /block this phrase/i > score MY_RULE_1 100 > > body MY_RULE_2 /Block this too/i > score MY_RULE_2 100 > > body MY_RULE_3 /this\s*is\s*more\s*complicated/i > score MY_RULE_3 100 > > > body SAMPLE_RULE2 /this/i > describe SAMPLE_RULE2 Banned body text > score SAMPLE_RULE2 5 > > body LOCAL_DEMONSTRATION_RULE /test/ > score LOCAL_DEMONSTRATION_RULE 100 > describe LOCAL_DEMONSTRATION_RULE This is a simple test rule > > header LOCAL_DEMONSTRATION_SUBJECT Subject =~ /\btest\b/i > score LOCAL_DEMONSTRATION_SUBJECT 100 > > > The spamassassin test: > > spamassassin -C /etc/MailScanner/mcp -p > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < teste.mail > [15603] dbg: logger: adding facilities: all > [15603] dbg: logger: logging level is DBG > [15603] dbg: generic: SpamAssassin version 3.2.0 > [15603] dbg: config: score set 0 chosen. > [15603] dbg: util: running in taint mode? yes > [15603] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH > [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping > [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping > [15603] dbg: util: PATH included '/usr/local/sbin', keeping > [15603] dbg: util: PATH included '/usr/local/bin', keeping > [15603] dbg: util: PATH included '/sbin', keeping > [15603] dbg: util: PATH included '/bin', keeping > [15603] dbg: util: PATH included '/usr/sbin', keeping > [15603] dbg: util: PATH included '/usr/bin', keeping > [15603] dbg: util: PATH included '/root/bin', which doesn't exist, dropping > [15603] dbg: util: final PATH set to: > /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b > in:/usr/sbin:/usr/bin > [15603] dbg: dns: no ipv6 > [15603] dbg: dns: is Net::DNS::Resolver available? yes > [15603] dbg: dns: Net::DNS version: 0.59 > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre files > [15603] dbg: config: read file /etc/mail/spamassassin/init.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre > [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files > [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir > [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir > [15603] dbg: config: read file /etc/mail/spamassassin/local.cf > [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf > [15603] dbg: config: using "/root/.spamassassin" for user state dir > [15603] dbg: config: using > "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file > [15603] dbg: config: read file > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC > [15603] dbg: pyzor: network tests on, attempting Pyzor > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered > [15603] dbg: conf: finish parsing > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) > implements 'finish_parsing_end', priority 0 > [15603] dbg: replacetags: replacing tags > [15603] dbg: replacetags: done replacing tags > [15603] dbg: config: score set 1 chosen. > [15603] dbg: message: main message type: multipart/alternative > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) > implements 'check_start', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) > implements 'check_main', priority 0 > [15603] dbg: conf: trusted_networks are not configured; it is recommended > that you configure trusted_networks manually > [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp > by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= > msa=0 ] > [15603] dbg: received-header: 'from' 192.168.0.1 has private IP > [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes > msa? no > [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-Untrusted: > [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-External: > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'extract_metadata', priority 0 > [15603] dbg: metadata: X-Relay-Countries: > [15603] dbg: message: ---- MIME PARSER START ---- > [15603] dbg: message: parsing multipart, got boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: found part of type text/plain, boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: added part, type: text/plain > [15603] dbg: message: parsing normal part > [15603] dbg: message: ---- MIME PARSER END ---- > [15603] dbg: message: decoding quoted-printable > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) > implements 'parsed_metadata', priority 0 > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'parsed_metadata', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) > implements 'parsed_metadata', priority 0 > [15603] dbg: dns: dns_available set to yes in config file, skipping test > [15603] dbg: uridnsbl: domains to query: > [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups > [15603] dbg: check: running tests for priority: 0 > [15603] dbg: rules: running head tests; score so far=0 > [15603] dbg: rules: compiled head tests > [15603] dbg: rules: running body tests; score so far=0 > [15603] dbg: rules: compiled body tests > [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got hit: > "test" > [15603] dbg: rules: running uri tests; score so far=100 > [15603] dbg: rules: compiled uri tests > [15603] dbg: rules: running rawbody tests; score so far=100 > [15603] dbg: rules: compiled rawbody tests > [15603] dbg: rules: running full tests; score so far=100 > [15603] dbg: rules: compiled full tests > [15603] dbg: rules: running meta tests; score so far=100 > [15603] dbg: rules: compiled meta tests > [15603] dbg: check: is spam? score=100 required=5 > [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE > [15603] dbg: check: subtests= > >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 > Received: from localhost by netserver.ftpmanagerbr.net > with SpamAssassin (version 3.2.0); > Tue, 29 May 2007 10:28:40 -0300 > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on > netserver.ftpmanagerbr.net > MIME-Version: 1.0 > Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" > > This is a multi-part message in MIME format. > > ------------=_465C2A88.4A78356A > Content-Type: text/plain; charset=iso-8859-1 > Content-Disposition: inline > Content-Transfer-Encoding: 8bit > > (no report template found) > > > > ------------=_465C2A88.4A78356A > Content-Type: message/rfc822; x-spam-type=original > Content-Description: original message before SpamAssassin > Content-Disposition: attachment > Content-Transfer-Encoding: 8bit > > Return-Path: > X-Original-To: wilson@ftpmanagerbr.net > Delivered-To: wilson@ftpmanagerbr.net > Received: from sdxp (unknown [192.168.0.1]) > by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 > for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) > Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" > X-Priority: 3 > X-MSMail-Priority: Normal > X-Mailer: Microsoft Outlook Express 6.00.2900.3028 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 > X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more > information > X-ftpmanagerbr_net-MailScanner: Found to be clean > X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, > requerido 1) > X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net > X-Spam-Status: No > > This is a multi-part message in MIME format. > > ------=_NextPart_000_0005_01C7A1DA.CCACFD20 > Content-Type: text/plain; > charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > Block this too > > ------------=_465C2A88.4A78356A-- > > (no report template found) spamassassin -C /etc/MailScanner/mcp -p > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < teste.mail > [15603] dbg: logger: adding facilities: all > [15603] dbg: logger: logging level is DBG > [15603] dbg: generic: SpamAssassin version 3.2.0 > [15603] dbg: config: score set 0 chosen. > [15603] dbg: util: running in taint mode? yes > [15603] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH > [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping > [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping > [15603] dbg: util: PATH included '/usr/local/sbin', keeping > [15603] dbg: util: PATH included '/usr/local/bin', keeping > [15603] dbg: util: PATH included '/sbin', keeping > [15603] dbg: util: PATH included '/bin', keeping > [15603] dbg: util: PATH included '/usr/sbin', keeping > [15603] dbg: util: PATH included '/usr/bin', keeping > [15603] dbg: util: PATH included '/root/bin', which doesn't exist, dropping > [15603] dbg: util: final PATH set to: > /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b > in:/usr/sbin:/usr/bin > [15603] dbg: dns: no ipv6 > [15603] dbg: dns: is Net::DNS::Resolver available? yes > [15603] dbg: dns: Net::DNS version: 0.59 > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre files > [15603] dbg: config: read file /etc/mail/spamassassin/init.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre > [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files > [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir > [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir > [15603] dbg: config: read file /etc/mail/spamassassin/local.cf > [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf > [15603] dbg: config: using "/root/.spamassassin" for user state dir > [15603] dbg: config: using > "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file > [15603] dbg: config: read file > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC > [15603] dbg: pyzor: network tests on, attempting Pyzor > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered > [15603] dbg: conf: finish parsing > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) > implements 'finish_parsing_end', priority 0 > [15603] dbg: replacetags: replacing tags > [15603] dbg: replacetags: done replacing tags > [15603] dbg: config: score set 1 chosen. > [15603] dbg: message: main message type: multipart/alternative > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) > implements 'check_start', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) > implements 'check_main', priority 0 > [15603] dbg: conf: trusted_networks are not configured; it is recommended > that you configure trusted_networks manually > [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp > by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= > msa=0 ] > [15603] dbg: received-header: 'from' 192.168.0.1 has private IP > [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes > msa? no > [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-Untrusted: > [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-External: > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'extract_metadata', priority 0 > [15603] dbg: metadata: X-Relay-Countries: > [15603] dbg: message: ---- MIME PARSER START ---- > [15603] dbg: message: parsing multipart, got boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: found part of type text/plain, boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: added part, type: text/plain > [15603] dbg: message: parsing normal part > [15603] dbg: message: ---- MIME PARSER END ---- > [15603] dbg: message: decoding quoted-printable > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) > implements 'parsed_metadata', priority 0 > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'parsed_metadata', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) > implements 'parsed_metadata', priority 0 > [15603] dbg: dns: dns_available set to yes in config file, skipping test > [15603] dbg: uridnsbl: domains to query: > [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups > [15603] dbg: check: running tests for priority: 0 > [15603] dbg: rules: running head tests; score so far=0 > [15603] dbg: rules: compiled head tests > [15603] dbg: rules: running body tests; score so far=0 > [15603] dbg: rules: compiled body tests > [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got hit: > "test" > [15603] dbg: rules: running uri tests; score so far=100 > [15603] dbg: rules: compiled uri tests > [15603] dbg: rules: running rawbody tests; score so far=100 > [15603] dbg: rules: compiled rawbody tests > [15603] dbg: rules: running full tests; score so far=100 > [15603] dbg: rules: compiled full tests > [15603] dbg: rules: running meta tests; score so far=100 > [15603] dbg: rules: compiled meta tests > [15603] dbg: check: is spam? score=100 required=5 > [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE > [15603] dbg: check: subtests= > >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 > Received: from localhost by netserver.ftpmanagerbr.net > with SpamAssassin (version 3.2.0); > Tue, 29 May 2007 10:28:40 -0300 > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on > netserver.ftpmanagerbr.net > MIME-Version: 1.0 > Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" > > This is a multi-part message in MIME format. > > ------------=_465C2A88.4A78356A > Content-Type: text/plain; charset=iso-8859-1 > Content-Disposition: inline > Content-Transfer-Encoding: 8bit > > (no report template found) > > > > ------------=_465C2A88.4A78356A > Content-Type: message/rfc822; x-spam-type=original > Content-Description: original message before SpamAssassin > Content-Disposition: attachment > Content-Transfer-Encoding: 8bit > > Return-Path: > X-Original-To: wilson@ftpmanagerbr.net > Delivered-To: wilson@ftpmanagerbr.net > Received: from sdxp (unknown [192.168.0.1]) > by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 > for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) > Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" > X-Priority: 3 > X-MSMail-Priority: Normal > X-Mailer: Microsoft Outlook Express 6.00.2900.3028 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 > X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more > information > X-ftpmanagerbr_net-MailScanner: Found to be clean > X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, > requerido 1) > X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net > X-Spam-Status: No > > This is a multi-part message in MIME format. > > ------=_NextPart_000_0005_01C7A1DA.CCACFD20 > Content-Type: text/plain; > charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > Block this too > > ------------=_465C2A88.4A78356A-- > > (no report template found) > > > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Lasantha > Marian > Enviada em: ter?a-feira, 29 de maio de 2007 06:14 > Para: MailScanner discussion > Assunto: Re: RES: mcp help > > Dear Julian, > > I have been experiencing some strange behaviors in my MCP setup (SA 3.2.0/MS > 4.59.4) too, i.e. MCP setup works very fine when tested from command line so > does SpamAssassin setup (from both ends; command line and from MailScanner), > but MCP would not work properly from MailScanner. It would happily scan but > does not report against customized MCP rules. MCP rules are properly applied > and correct scores are shown when run from command line without any errors. > The very same MCP rules set works fine with earlier versions (SA 3.1.1/MS > 4.53.8). > > I think it is the same kind of problem that Wilson is experiencing in MCP. > It identifies MCP, but then may be a reporting problem ! > > Thanks and regards, > > Lasantha. > > > *-------- Original Message --------* > *Subject: * RES: mcp help > *Date: * Tue, 29/May/2007 4:39:25 AM +0550 > *From: * "Wilson A. Galafassi Jr." > *To: * "'MailScanner discussion'" > > > >> spamassassin --D --lint > >> > /tmp/sa.log 2>&1 > > > > >> This is the result. >> > > > > >> [root@netserver tmp]# cat sa.log >> > > >> [26391] dbg: logger: adding facilities: all >> > > >> [26391] dbg: logger: logging level is DBG >> > > >> [26391] dbg: generic: SpamAssassin version 3.2.0 >> > > >> [26391] dbg: config: score set 0 chosen. >> > > >> [26391] dbg: util: running in taint mode? yes >> > > >> [26391] dbg: util: taint mode: deleting unsafe environment >> > variables, > > >> resetting PATH >> > > > > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From johan.boye at latecoere.fr Tue May 29 15:59:56 2007 From: johan.boye at latecoere.fr (johan.boye@latecoere.fr) Date: Tue May 29 16:00:02 2007 Subject: Attachment Warning Filename Question Message-ID: I have to admit I'm quite lost ;) Let's restart from scratch, sorry : I did that : # I don't want to notify the sender when one of his email is blocked by the filename/filetype rules : Notify Senders = no Notify Senders Of Blocked Filenames Or Filetypes = no Notify Senders Of Other Blocked Content = no # Then, I want to notify the recipient when a filename/type has been blocked : Warning Is Attachment = yes Attachment Warning Filename = %report-dir%/stored.filename.message.txt But you told me to put that instead : Attachment Warning Filename = %org-name%-Attachment-Warning.txt Where should I put this file "mycompagny-tld-Attachment-Warning.txt" ? # I don't want to warn System Administrator : Send Notices = no Why that config, recipients don't receive any notification. What could be the problem ? Thanks ! Johan > >> Anyway, here is my question : > >> I'm using Mailscanner since a couple of week and it works great. I > >> just have a question regarding the "Attachment Warning Filename" > >> functionnality. > >> I wish send an email to the recipient when an email for him is > >> blocked, It activated that : > >> > >> Warning Is Attachment = yes > >> Attachment Warning Filename = > >> %report-dir%/stored.filename.message.txt > That option wants a filename to put into the delivered message, not the > contents of the file. Something like Attachment Warning Filename = %org-name%-Attachments-Read-Me.txt > would be a suitable setting IIRC. It's what the replacement attachment warning will be called, not what will go in it. If you can > come up with a better explanation than is currently in the MailScanner.conf file, then please let me know, as the current > explanation is far from ideal. > > If you want to set the text to go into the Attachments-Read-Me.txt, then you should be setting > # Set where to find the message text sent to users when one of their > # attachments has been deleted from a message. > # These can also be the filenames of rulesets. > Deleted Bad Content Message Report = %report-dir%/deleted.content.message.txt > Deleted Bad Filename Message Report = %report-dir%/deleted.filename.message.txt > Deleted Virus Message Report = %report-dir%/deleted.virus.message.txt > Deleted Size Message Report = %report-dir%/deleted.size.message.txt > > # Set where to find the message text sent to users when one of their > # attachments has been deleted from a message and stored in > the quarantine. > # These can also be the filenames of rulesets. > Stored Bad Content Message Report = %report-dir%/stored.content.message.txt > Stored Bad Filename Message Report = %report-dir%/stored.filename.message.txt > Stored Virus Message Report = %report-dir%/stored.virus.message.txt > Stored Size Message Report = %report-dir%/stored.size.message.txt > > >> > >> My default installation Mailscanner dir is : /opt/MailScanner/ > >> But this is not sending any email to the recipient, did i mist > >> something ? > >> > >> > >> Thanks by advance, > >> > >> Johan > > > > Likely what you have there is OK, just that you never instruct MS to > > actually use it:-). > > > > Check your "Silent Viruses" and "Still Deliver Silent Viruses" > > settings, and perhaps some more (attachment "actions" for > unacceptable attachment types etc). "Les informations contenues dans ce message electronique peuvent etre de nature confidentielles et soumises a une obligation de secret. Elles sont destinees a l'usage exclusif du reel destinataire. Si vous n'etes pas le reel destinataire, ou si vous recevez ce message par erreur, merci de le detruire immediatement et de le notifier a son emetteur." "The information contained in this e-mail may be privileged and confidential. It is intended for the exclusive use of the designated recipients named above. If you are not the intended recipient or if you receive this e-mail in error, please delete it and immediately notify the sender." From ssilva at sgvwater.com Tue May 29 16:42:55 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 29 16:43:30 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: <465C3376.2090300@ecs.soton.ac.uk> References: <418312.38090.qm@web26315.mail.ukl.yahoo.com> <465C3376.2090300@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 5/29/2007 7:06 AM: > Andrew MacLachlan wrote: >> Can it be added to existing MailScanner installations? >> > Yes. This is starting to be the 20 questions thread. Is it bigger than a breadbox? ;-) -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Tue May 29 17:00:06 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 29 17:00:28 2007 Subject: Question... In-Reply-To: <177594.7833.qm@web26315.mail.ukl.yahoo.com> References: <177594.7833.qm@web26315.mail.ukl.yahoo.com> Message-ID: Andrew MacLachlan spake the following on 5/28/2007 5:33 PM: > Fabio - Which country are you in? > I have had one of my users complaining that this isn't legal in Italy > (!) - Seem like a crazy law... > Can anyone clarify this? > > -Andy Just because a law seems crazy doesn't mean that a government won't pass it. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From alex at nkpanama.com Tue May 29 17:06:34 2007 From: alex at nkpanama.com (Alex Neuman) Date: Tue May 29 17:09:55 2007 Subject: Question... In-Reply-To: References: <177594.7833.qm@web26315.mail.ukl.yahoo.com> Message-ID: <465C4F8A.90007@nkpanama.com> In fact, the crazyness factor makes it more appealing to otherwise clue-challenged lawmakers... :-( ... you know, the "won't somebody *please* think of the children!" mentality... Scott Silva wrote: > Andrew MacLachlan spake the following on 5/28/2007 5:33 PM: > >> Fabio - Which country are you in? >> I have had one of my users complaining that this isn't legal in Italy >> (!) - Seem like a crazy law... >> Can anyone clarify this? >> >> -Andy >> > Just because a law seems crazy doesn't mean that a government won't pass it. > > From jan-peter at koopmann.eu Tue May 29 17:10:01 2007 From: jan-peter at koopmann.eu (Koopmann, Jan-Peter) Date: Tue May 29 17:10:12 2007 Subject: better blocking at MTA level (off-topic) In-Reply-To: References: <418312.38090.qm@web26315.mail.ukl.yahoo.com><465C3376.2090300@ecs.soton.ac.uk> Message-ID: On Tuesday, May 29, 2007 5:43 PM Scott Silva wrote: > This is starting to be the 20 questions thread. > Is it bigger than a breadbox? ;-) Depends on the server size you install it on. :-) From hvdkooij at vanderkooij.org Tue May 29 18:49:19 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue May 29 18:49:59 2007 Subject: Reject mail from invalid domains In-Reply-To: <465BD26A.6060105@halla.pt> References: <465B004F.1@halla.pt> <465BD26A.6060105@halla.pt> Message-ID: On Tue, 29 May 2007, Jorge Costinha wrote: > invalid domain, are domains that cannot be resolved by DNS. i belive it is a > good practice to reduce spam and workload of mailscanner and spamassassin if > mails coming from invalid domains are block. am i right? There are a few scenarios. You ask for the domain name but get a clear answer it does not exist ==> No need to receive it as it is bogus email You ask for the A and/or MX records and find that none of these exist ==> Again no ways to delivere them messages so why accept theirs? You ask for it but can not get an authorative answer ==> Tell them to get back later and try again. You can additional checks and see how well they hold out. Fighting spam is a balance of costs. Money is only part of the 'costs' one has to take into account. And not all of us value costs the same way so different persons may get to different results. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From hvdkooij at vanderkooij.org Tue May 29 19:00:17 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue May 29 19:00:56 2007 Subject: Question... In-Reply-To: References: <177594.7833.qm@web26315.mail.ukl.yahoo.com> Message-ID: On Tue, 29 May 2007, Scott Silva wrote: > Andrew MacLachlan spake the following on 5/28/2007 5:33 PM: >> Fabio - Which country are you in? >> I have had one of my users complaining that this isn't legal in Italy >> (!) - Seem like a crazy law... >> Can anyone clarify this? >> > Just because a law seems crazy doesn't mean that a government won't pass it. A law that does garantue that private (e)mail remains private? Is that a bad or crazy law? It must have come out of the dark ages for sure. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From Denis.Beauchemin at USherbrooke.ca Tue May 29 19:17:01 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Tue May 29 19:17:16 2007 Subject: Attachment Warning Filename Question In-Reply-To: References: Message-ID: <465C6E1D.2030009@USherbrooke.ca> johan.boye@latecoere.fr a ?crit : > I have to admit I'm quite lost ;) Let's restart from scratch, sorry : > > # Then, I want to notify the recipient when a filename/type has been > blocked : > Warning Is Attachment = yes > Attachment Warning Filename = > %report-dir%/stored.filename.message.txt > > But you told me to put that instead : > Attachment Warning Filename = %org-name%-Attachment-Warning.txt > This filename doesn't exist anywhere on your server. This is the name the attachment will use in your emails. The contents of the message will come from: Deleted Bad Filename Message Report = %report-dir%/deleted.filename.message.txt > Where should I put this file "mycompagny-tld-Attachment-Warning.txt" > ? > > # I don't want to warn System Administrator : > Send Notices = no > > > Why that config, recipients don't receive any notification. What could > be the problem ? > > Denis -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3595 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070529/e222b40b/smime.bin From itdept at fractalweb.com Tue May 29 20:30:48 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Tue May 29 20:30:56 2007 Subject: false positives on rule "FM_RATSIGN_1106" and what to do? Message-ID: <465C7F68.1020803@fractalweb.com> Hi, Suddenly, I'm seeing quite a number of false positives on the rule "FM_RATSIGN_1106" that gets a whopping 3.8 points. I've tried to figure out what exactly it's hitting on, but the only thing I found was: ##{ FM_RATSIGN_1106 meta FM_RATSIGN_1106 (__MSGID_VGA && __DATE_700) describe FM_RATSIGN_1106 Fingerprint seen in lots of spam. 11/2006 ##} FM_RATSIGN_1106 I think I need to set this rule down to 0.01 for now, or does someone have a better suggestion? Thanks From ssilva at sgvwater.com Tue May 29 20:45:26 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 29 20:45:45 2007 Subject: false positives on rule "FM_RATSIGN_1106" and what to do? In-Reply-To: <465C7F68.1020803@fractalweb.com> References: <465C7F68.1020803@fractalweb.com> Message-ID: Chris Yuzik spake the following on 5/29/2007 12:30 PM: > Hi, > > Suddenly, I'm seeing quite a number of false positives on the rule > "FM_RATSIGN_1106" that gets a whopping 3.8 points. I've tried to figure > out what exactly it's hitting on, but the only thing I found was: > > ##{ FM_RATSIGN_1106 > meta FM_RATSIGN_1106 (__MSGID_VGA && __DATE_700) > describe FM_RATSIGN_1106 Fingerprint seen in lots of spam. 11/2006 > ##} FM_RATSIGN_1106 > > I think I need to set this rule down to 0.01 for now, or does someone > have a better suggestion? > > Thanks > It looks at messages that hit both MSGID_VGA and DATE_700 Message-ID =~ /^<000001c[67]/ and date is -7 hours It is in 72_active.cf. So if you are getting false positives it might be that you deal with a lot of mail from a time zone that is 7 hours behind you. If it hits that much, you could score lower. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From mailscanner at ecs.soton.ac.uk Tue May 29 20:49:30 2007 From: mailscanner at ecs.soton.ac.uk (Julian Field) Date: Tue May 29 20:50:22 2007 Subject: ANNOUNCE: BarricadeMX is released Message-ID: <54C6E1F0-01FF-4365-A395-D00BFED6C980@ecs.soton.ac.uk> Fort Systems Limited is proud to introduce its newest flagship software, BarricadeMX. Featuring a new level of spam filtering which rejects most of the spam before it's even accepted for delivery, BarricadeMX is the top of the line anti-spam filtering application. BarricadeMX was designed to complement MailScanner and SpamAssassin for high volume sites and / or sites which require very accurate spam detection. BarricadeMX was jointly developed by Fort Systems Ltd and SnertSoft to more efficiently block spam at the MTA level during the initial SMTP conversation. BarricadeMX can be installed with MailScanner, any other MTA or placed in front of any existing anti- spam solution. Since this has been a very active recent topic on the MailScanner list we hope you will find this information to be useful. A quick overview of the product follows and more information regarding BarricadeMX can be found at www.fsl.com or www.snertsoft.com. BarricadeMX is a new lightweight, small footprint computer-based anti- spam application. It is designed as an SMTP port 25 proxy, filtering and forwarding mail to one or more local or remote mail transfer agents. BarricadeMX supports a variety of well blended anti-spam filtering tests that can be individually enabled or disabled according to the rigors of the postmaster's local filtering policy. Most of these tests are optional and several are configurable by Domain. BarricadeMX can also set limits on message size by sender, recipient, domain, IP address and IP address ranges. The application itself is a small (4 MB resident memory), lightweight, multi-threaded C program. Much more efficient than the typical MTA, it can gracefully handle many simultaneous incoming connections. A single CPU system has handled 1018 concurrent SMTP client connections without failing or losing any legitimate mail. Many servers that are in production routinely handle 200 to 300 incoming simultaneous connections while maintaining low CPU utilization. BarricadeMX may be configured to run on multiple gateways which share multicast or unicast caches. These caches provide a fast, simple, and efficient means to share cache updates across multiple gateways on the same network segment or back and forth to a set of remote hosts. Both the multicast and unicast caches use a broadcast-and-correct model and support IPv4 and IPv6. By rejecting messages with a 550 error at the MTA level during the initial SMTP conversation, valid senders should receive a rejection notice letting them know that their email was not accepted for delivery and the reason for the rejection. Since this notice is sent directly to the server trying to deliver the message, there is no chance this feature being used in a ?reflected spam? attack. The rejection notice may also be customized for individual sites to let the recipient of the bounce know who to contact to correct the problem. BarricadeMX is currently available only for Linux Red Hat and CentOS and OpenBSD operating systems. Ports to FreeBSD, SuSE and Solaris will be available soon with ports to Microsoft and Mac OS X in the planning stage. BarricadeMX is supplied as an rpm install for Linux and it is configured and managed using a simple web interface or by using text configuration files. For FreeBSD it is installed using pkg_add and configured by using text configuration files. And finally here are the results from one of our beta sites. Before installing BarricadeMX this site was running 15 very expensive PC anti-spam gateways which were barely able to handle the load. There were long delays caused by a load of approximately 2 million total messages per day for +1,800 domains. Peak connection attempts typically reached +100,000 connections per hour. The 15 PC gateways have now been replaced be three Sun 2100?s with single Dual-Core AMD Opteron 1210 processors and 4 GB of memory running the CentOS 4.x x86_64 operating system, BarricadeMX and a typical MailScanner anti-spam installation. Gateway 1 is running BarricadeMX, a typical MailScanner / SpamAssassin installation and MailWatch. It is also the Gateway cluster?s log host, web server and MailWatch database server. Gateways 2 and 3 are running BarricadeMX and a typical MailScanner / SpamAssassin installation. And here are recent statistics from this beta site: Gateway 1 Gateway 2 Gateway 3 Site Totals Delivery Attempts 4,052,718 15,067,573 3,719,411 22,839,702 Accepted messages 89,999 177,359 53,705 321,063 Accepted messages 2.22% 1.18% 1.44% 1.61% Connections per day 579,160 747,604 532,078 1,858,842 Max Simultaneous Connections 506 506 506 506 Process Age (seconds) 604,591 1,741,347 603,966 N.A. Connections per second 6.70 8.65 6.16 21.51 Connections per hour 24,132 31,150 22,170 77,452 Connections per Day 720,021 521,808 572,566 1,814,395 Daily Bandwidth savings (KB) 11,377,738 8,223,877 8,949,527 28,551,142 Load Average 1.0 to 2.0 1.0 to 2.0 0.5 to 1.5 under 2.0 This is a site that gets a massive amount of spam and is currently accurately rejecting over 98% of the spam at the MTA level. We have had less than ten sites that needed to be white listed as false positives in just over two months. We estimate that each of these servers can easily handle over 1,000,000 messages per day. After passing through BarricadeMX, MailScanner is only processing an average of 39,226 messages per day out of 1,814,395 average daily connection attempts, 1,940 (4.95%) of which are tagged as spam and 89 (0.23%) of which are quarantined as viruses. The client reports getting ?virtually no spam?. A white paper with more information and pricing is available at http://www.fsl.com . For more information and pricing please contact us off list at info@www.fsl.com . Julian Field, MEng CITP Chief Technology Officer Fort System Ltd. Steve Swaney President Fort Systems Ltd. Steve@fsl.com www.fsl.com -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070529/30a0b691/attachment.html From itdept at fractalweb.com Tue May 29 21:01:42 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Tue May 29 21:01:50 2007 Subject: false positives on rule "FM_RATSIGN_1106" and what to do? In-Reply-To: References: <465C7F68.1020803@fractalweb.com> Message-ID: <465C86A6.801@fractalweb.com> Scott Silva wrote: > It looks at messages that hit both MSGID_VGA and DATE_700 > Message-ID =~ /^<000001c[67]/ and date is -7 hours > > It is in 72_active.cf. > So if you are getting false positives it might be that you deal with a lot of > mail from a time zone that is 7 hours behind you. If it hits that much, you > could score lower. > Hi Scott, Thanks for the quick response. From what I can see, the message IDs on the false positives do indeed match the pattern you note above, but the date is a bit bizarre. We're on the west coast of North America, and because it's summer, everyone in this time zone is -0700. From what I can see in the header, the user's computer's clock does seem to be correct, and their time zone appears to be correct. I've attached a (censored) copy of a message header from a message that's getting hit on this: Return-Path: Received: from cma30pc (m11.domain3.com [208.18.05.15] (may be forged)) (authenticated bits=0) by devel.fractalweb.com (8.13.1/8.13.1) with ESMTP id l4TIkeXu024105 for ; Tue, 29 May 2007 11:46:44 -0700 From: "Jane Doe" To: Subject: Test Date: Tue, 29 May 2007 11:46:45 -0700 Message-ID: <000001c7a221$b74aedb0$820b0a0a@north.domain1.COM> MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0001_01C7A1E7.0AEC15B0" X-Mailer: Microsoft Office Outlook 11 Thread-Index: AceiIbTeqm6E92mrTWiQjXzemkXObw== X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 There is nothing suspicious in the message body, and based on your explanation of the rule, I don't think it's looking at the body anyways. Does this rule need to be rewritten? Chris From mike at tc3net.com Tue May 29 21:07:25 2007 From: mike at tc3net.com (Michael Baird) Date: Tue May 29 21:04:11 2007 Subject: ANNOUNCE: BarricadeMX is released In-Reply-To: <54C6E1F0-01FF-4365-A395-D00BFED6C980@ecs.soton.ac.uk> References: <54C6E1F0-01FF-4365-A395-D00BFED6C980@ecs.soton.ac.uk> Message-ID: <465C87FD.7090507@tc3net.com> The BarricadeMX demo link on fsl.com still presents info about the DefenderMX trial. http://www.fsl.com/register-new2.php Regards Michael Baird > Fort Systems Limited is proud to introduce its newest flagship software, > *BarricadeMX*. > > Featuring a new level of spam filtering which rejects most of the spam > before it's even accepted for delivery, *BarricadeMX* is the top of the > line anti-spam filtering application. > > BarricadeMX was designed to complement MailScanner and SpamAssassin for > high volume sites and / or sites which require very accurate spam > detection. BarricadeMX was jointly developed by Fort Systems Ltd and > SnertSoft to more efficiently block spam at the MTA level during the > initial SMTP conversation. BarricadeMX can be installed with > MailScanner, any other MTA or placed in front of any existing anti-spam > solution. > > Since this has been a very active recent topic on the MailScanner list > we hope you will find this information to be useful. A quick overview of > the product follows and more information regarding BarricadeMX can be > found at www.fsl.com or www.snertsoft.com > . > > BarricadeMX is a new lightweight, small footprint computer-based > anti-spam application. It is > designed as an SMTP port 25 proxy, filtering and forwarding mail to one > or more local or remote mail transfer agents. BarricadeMX supports a > variety of well blended anti-spam filtering tests that can be > individually enabled or disabled according to the rigors of the > postmaster's local filtering policy. Most of these tests are optional > and several are configurable by Domain. BarricadeMX can also set limits > on message size by sender, recipient, domain, IP address and IP address > ranges. > > The application itself is a small (4 MB resident memory), lightweight, > multi-threaded C program. Much more efficient than the typical MTA, it > can gracefully handle many simultaneous incoming connections. A single > CPU system has handled 1018 concurrent SMTP client connections without > failing or losing any legitimate mail. Many servers that are in > production routinely handle 200 to 300 incoming simultaneous connections > while maintaining low CPU utilization. > > BarricadeMX may be configured to run on multiple gateways which share > multicast or unicast caches. These caches provide a fast, simple, and > efficient means to share cache updates across multiple gateways on the > same network segment or back and forth to a set of remote hosts. Both > the multicast and unicast caches use a broadcast-and-correct model and > support IPv4 and IPv6. > > By rejecting messages with a 550 error at the MTA level during the > initial SMTP conversation, valid senders should receive a rejection > notice letting them know that their email was not accepted for delivery > and the reason for the rejection. Since this notice is sent directly to > the server trying to deliver the message, there is no chance this > feature being used in a ?reflected spam? attack. The rejection notice > may also be customized for individual sites to let the recipient of the > bounce know who to contact to correct the problem. > > BarricadeMX is currently available only for Linux Red Hat and CentOS and > OpenBSD operating systems. Ports to FreeBSD, SuSE and Solaris will be > available soon with ports to Microsoft and Mac OS X in the planning stage. > > BarricadeMX is supplied as an rpm install for Linux and it is configured > and managed using a simple web interface or by using text configuration > files. For FreeBSD it is installed using pkg_add and configured by using > text configuration files. > > And finally here are the results from one of our beta sites. Before > installing BarricadeMX this site was running 15 very expensive PC > anti-spam gateways which were barely able to handle the load. There were > long delays caused by a load of approximately 2 million total messages > per day for +1,800 domains. Peak connection attempts typically reached > +100,000 connections per hour. > > The 15 PC gateways have now been replaced be three Sun 2100?s with > single Dual-Core AMD Opteron 1210 processors and 4 GB of memory running > the CentOS 4.x x86_64 operating system, BarricadeMX and a typical > MailScanner anti-spam installation. Gateway 1 is running BarricadeMX, a > typical MailScanner / SpamAssassin installation and MailWatch. It is > also the Gateway cluster?s log host, web server and MailWatch database > server. Gateways 2 and 3 are running BarricadeMX and a typical > MailScanner / SpamAssassin installation. > > And here are recent statistics from this beta site: > > > > Gateway 1 > > > > Gateway 2 > > > > Gateway 3 > > > > Site Totals > > Delivery Attempts > > > > 4,052,718 > > > > 15,067,573 > > > > 3,719,411 > > > > 22,839,702 > > Accepted messages > > > > 89,999 > > > > 177,359 > > > > 53,705 > > > > 321,063 > > Accepted messages > > > > 2.22% > > > > 1.18% > > > > 1.44% > > > > 1.61% > > Connections per day > > > > 579,160 > > > > 747,604 > > > > 532,078 > > > > 1,858,842 > > Max Simultaneous Connections > > > > 506 > > > > 506 > > > > 506 > > > > 506 > > Process Age (seconds) > > > > 604,591 > > > > 1,741,347 > > > > 603,966 > > > > N.A. > > Connections per second > > > > 6.70 > > > > 8.65 > > > > 6.16 > > > > 21.51 > > Connections per hour > > > > 24,132 > > > > 31,150 > > > > 22,170 > > > > 77,452 > > Connections per Day > > > > 720,021 > > > > 521,808 > > > > 572,566 > > > > 1,814,395 > > Daily Bandwidth savings (KB) > > > > 11,377,738 > > > > 8,223,877 > > > > 8,949,527 > > > > 28,551,142 > > Load Average > > > > 1.0 to 2.0 > > > > 1.0 to 2.0 > > > > 0.5 to 1.5 > > > > under 2.0 > > > > This is a site that gets a massive amount of spam and is currently > accurately rejecting over 98% of the spam at the MTA level. We have had > less than ten sites that needed to be white listed as false positives in > just over two months. We estimate that each of these servers can easily > handle over 1,000,000 messages per day. > > After passing through BarricadeMX, MailScanner is only processing an > average of 39,226 messages per day out of 1,814,395 average daily > connection attempts, 1,940 (4.95%) of which are tagged as spam and 89 > (0.23%) of which are quarantined as viruses. > > The client reports getting ?virtually no spam?. > > A white paper with more information and pricing is available at > http://www.fsl.com . For more information and pricing please contact us > off list at info@www.fsl.com . > > Julian Field, MEng CITP > Chief Technology Officer > Fort System Ltd. > > Steve Swaney > President > Fort Systems Ltd. > Steve@fsl.com > www.fsl.com > > > -- > This message has been scanned for viruses and > dangerous content by *MailScanner* , and is > believed to be clean. > For all you IT requirements visit transtec Computers > . > From hvdkooij at vanderkooij.org Tue May 29 21:11:22 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Tue May 29 21:12:00 2007 Subject: false positives on rule "FM_RATSIGN_1106" and what to do? In-Reply-To: References: <465C7F68.1020803@fractalweb.com> Message-ID: On Tue, 29 May 2007, Scott Silva wrote: > Chris Yuzik spake the following on 5/29/2007 12:30 PM: >> Hi, >> >> Suddenly, I'm seeing quite a number of false positives on the rule >> "FM_RATSIGN_1106" that gets a whopping 3.8 points. I've tried to figure >> out what exactly it's hitting on, but the only thing I found was: >> >> ##{ FM_RATSIGN_1106 >> meta FM_RATSIGN_1106 (__MSGID_VGA && __DATE_700) >> describe FM_RATSIGN_1106 Fingerprint seen in lots of spam. 11/2006 >> ##} FM_RATSIGN_1106 >> >> I think I need to set this rule down to 0.01 for now, or does someone >> have a better suggestion? >> >> Thanks >> > It looks at messages that hit both MSGID_VGA and DATE_700 > Message-ID =~ /^<000001c[67]/ and date is -7 hours Just out of curiosity. What is the significance of this particular message ID or this difference in timezones? I have to admit I get a shitload of spam from the USA and some of the US states are -7 hours from my timezone. But I fail to see the logic of this construct at the moment. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From steve.swaney at fsl.com Tue May 29 21:36:06 2007 From: steve.swaney at fsl.com (Stephen Swaney) Date: Tue May 29 21:36:50 2007 Subject: ANNOUNCE: BarricadeMX is released In-Reply-To: <465C87FD.7090507@tc3net.com> References: <54C6E1F0-01FF-4365-A395-D00BFED6C980@ecs.soton.ac.uk> <465C87FD.7090507@tc3net.com> Message-ID: <447401c7a230$fbdd1b10$f3975130$@swaney@fsl.com> Michael, It looks like we're still working the kinks out of the new web site. Should be OK soon. Please send email to info@fsl.com if you have any questions or problems. Thanks, Steve Steve Swaney steve@fsl.com > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Michael Baird > Sent: Tuesday, May 29, 2007 4:07 PM > To: MailScanner discussion > Subject: Re: ANNOUNCE: BarricadeMX is released > > The BarricadeMX demo link on fsl.com still presents info about the > DefenderMX trial. > > http://www.fsl.com/register-new2.php > > Regards > Michael Baird > > > Fort Systems Limited is proud to introduce its newest flagship > software, > > *BarricadeMX*. > > > > Featuring a new level of spam filtering which rejects most of the > spam > > before it's even accepted for delivery, *BarricadeMX* is the top of > the > > line anti-spam filtering application. > > > > BarricadeMX was designed to complement MailScanner and SpamAssassin > for > > high volume sites and / or sites which require very accurate spam > > detection. BarricadeMX was jointly developed by Fort Systems Ltd and > > SnertSoft to more efficiently block spam at the MTA level during the > > initial SMTP conversation. BarricadeMX can be installed with > > MailScanner, any other MTA or placed in front of any existing anti- > spam > > solution. > > > > Since this has been a very active recent topic on the MailScanner > list > > we hope you will find this information to be useful. A quick overview > of > > the product follows and more information regarding BarricadeMX can be > > found at www.fsl.com or www.snertsoft.com > > . > > > > BarricadeMX is a new lightweight, small footprint computer-based > > anti-spam application. It is > > designed as an SMTP port 25 proxy, filtering and forwarding mail to > one > > or more local or remote mail transfer agents. BarricadeMX supports a > > variety of well blended anti-spam filtering tests that can be > > individually enabled or disabled according to the rigors of the > > postmaster's local filtering policy. Most of these tests are optional > > and several are configurable by Domain. BarricadeMX can also set > limits > > on message size by sender, recipient, domain, IP address and IP > address > > ranges. > > > > The application itself is a small (4 MB resident memory), > lightweight, > > multi-threaded C program. Much more efficient than the typical MTA, > it > > can gracefully handle many simultaneous incoming connections. A > single > > CPU system has handled 1018 concurrent SMTP client connections > without > > failing or losing any legitimate mail. Many servers that are in > > production routinely handle 200 to 300 incoming simultaneous > connections > > while maintaining low CPU utilization. > > > > BarricadeMX may be configured to run on multiple gateways which share > > multicast or unicast caches. These caches provide a fast, simple, and > > efficient means to share cache updates across multiple gateways on > the > > same network segment or back and forth to a set of remote hosts. Both > > the multicast and unicast caches use a broadcast-and-correct model > and > > support IPv4 and IPv6. > > > > By rejecting messages with a 550 error at the MTA level during the > > initial SMTP conversation, valid senders should receive a rejection > > notice letting them know that their email was not accepted for > delivery > > and the reason for the rejection. Since this notice is sent directly > to > > the server trying to deliver the message, there is no chance this > > feature being used in a "reflected spam" attack. The rejection notice > > may also be customized for individual sites to let the recipient of > the > > bounce know who to contact to correct the problem. > > > > BarricadeMX is currently available only for Linux Red Hat and CentOS > and > > OpenBSD operating systems. Ports to FreeBSD, SuSE and Solaris will be > > available soon with ports to Microsoft and Mac OS X in the planning > stage. > > > > BarricadeMX is supplied as an rpm install for Linux and it is > configured > > and managed using a simple web interface or by using text > configuration > > files. For FreeBSD it is installed using pkg_add and configured by > using > > text configuration files. > > > > And finally here are the results from one of our beta sites. Before > > installing BarricadeMX this site was running 15 very expensive PC > > anti-spam gateways which were barely able to handle the load. There > were > > long delays caused by a load of approximately 2 million total > messages > > per day for +1,800 domains. Peak connection attempts typically > reached > > +100,000 connections per hour. > > > > The 15 PC gateways have now been replaced be three Sun 2100's with > > single Dual-Core AMD Opteron 1210 processors and 4 GB of memory > running > > the CentOS 4.x x86_64 operating system, BarricadeMX and a typical > > MailScanner anti-spam installation. Gateway 1 is running BarricadeMX, > a > > typical MailScanner / SpamAssassin installation and MailWatch. It is > > also the Gateway cluster's log host, web server and MailWatch > database > > server. Gateways 2 and 3 are running BarricadeMX and a typical > > MailScanner / SpamAssassin installation. > > > > And here are recent statistics from this beta site: > > > > > > > > Gateway 1 > > > > > > > > Gateway 2 > > > > > > > > Gateway 3 > > > > > > > > Site Totals > > > > Delivery Attempts > > > > > > > > 4,052,718 > > > > > > > > 15,067,573 > > > > > > > > 3,719,411 > > > > > > > > 22,839,702 > > > > Accepted messages > > > > > > > > 89,999 > > > > > > > > 177,359 > > > > > > > > 53,705 > > > > > > > > 321,063 > > > > Accepted messages > > > > > > > > 2.22% > > > > > > > > 1.18% > > > > > > > > 1.44% > > > > > > > > 1.61% > > > > Connections per day > > > > > > > > 579,160 > > > > > > > > 747,604 > > > > > > > > 532,078 > > > > > > > > 1,858,842 > > > > Max Simultaneous Connections > > > > > > > > 506 > > > > > > > > 506 > > > > > > > > 506 > > > > > > > > 506 > > > > Process Age (seconds) > > > > > > > > 604,591 > > > > > > > > 1,741,347 > > > > > > > > 603,966 > > > > > > > > N.A. > > > > Connections per second > > > > > > > > 6.70 > > > > > > > > 8.65 > > > > > > > > 6.16 > > > > > > > > 21.51 > > > > Connections per hour > > > > > > > > 24,132 > > > > > > > > 31,150 > > > > > > > > 22,170 > > > > > > > > 77,452 > > > > Connections per Day > > > > > > > > 720,021 > > > > > > > > 521,808 > > > > > > > > 572,566 > > > > > > > > 1,814,395 > > > > Daily Bandwidth savings (KB) > > > > > > > > 11,377,738 > > > > > > > > 8,223,877 > > > > > > > > 8,949,527 > > > > > > > > 28,551,142 > > > > Load Average > > > > > > > > 1.0 to 2.0 > > > > > > > > 1.0 to 2.0 > > > > > > > > 0.5 to 1.5 > > > > > > > > under 2.0 > > > > > > > > This is a site that gets a massive amount of spam and is currently > > accurately rejecting over 98% of the spam at the MTA level. We have > had > > less than ten sites that needed to be white listed as false positives > in > > just over two months. We estimate that each of these servers can > easily > > handle over 1,000,000 messages per day. > > > > After passing through BarricadeMX, MailScanner is only processing an > > average of 39,226 messages per day out of 1,814,395 average daily > > connection attempts, 1,940 (4.95%) of which are tagged as spam and 89 > > (0.23%) of which are quarantined as viruses. > > > > The client reports getting "virtually no spam". > > > > A white paper with more information and pricing is available at > > http://www.fsl.com . For more information and pricing please contact > us > > off list at info@www.fsl.com . > > > > Julian Field, MEng CITP > > Chief Technology Officer > > Fort System Ltd. > > > > Steve Swaney > > President > > Fort Systems Ltd. > > Steve@fsl.com > > www.fsl.com > > > > > > -- > > This message has been scanned for viruses and > > dangerous content by *MailScanner* , > and is > > believed to be clean. > > For all you IT requirements visit transtec Computers > > . > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! From amaclach at yahoo.co.uk Tue May 29 21:50:36 2007 From: amaclach at yahoo.co.uk (Andrew MacLachlan) Date: Tue May 29 21:50:37 2007 Subject: ANNOUNCE: BarricadeMX is released Message-ID: <317039.15472.qm@web26313.mail.ukl.yahoo.com> The most important question though - how much does it cost? (very little in compute resources, but the real deal-breaker is the $$$...) -Andy ----- Original Message ---- From: Stephen Swaney To: MailScanner discussion Cc: robin@fsl.com; vince@deepbluecreative.com Sent: Tuesday, 29 May, 2007 9:36:06 PM Subject: RE: ANNOUNCE: BarricadeMX is released Michael, It looks like we're still working the kinks out of the new web site. Should be OK soon. Please send email to info@fsl.com if you have any questions or problems. Thanks, Steve Steve Swaney steve@fsl.com > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Michael Baird > Sent: Tuesday, May 29, 2007 4:07 PM > To: MailScanner discussion > Subject: Re: ANNOUNCE: BarricadeMX is released > > The BarricadeMX demo link on fsl.com still presents info about the > DefenderMX trial. > > http://www.fsl.com/register-new2.php > > Regards > Michael Baird > > > Fort Systems Limited is proud to introduce its newest flagship > software, > > *BarricadeMX*. > > > > Featuring a new level of spam filtering which rejects most of the > spam > > before it's even accepted for delivery, *BarricadeMX* is the top of > the > > line anti-spam filtering application. > > > > BarricadeMX was designed to complement MailScanner and SpamAssassin > for > > high volume sites and / or sites which require very accurate spam > > detection. BarricadeMX was jointly developed by Fort Systems Ltd and > > SnertSoft to more efficiently block spam at the MTA level during the > > initial SMTP conversation. BarricadeMX can be installed with > > MailScanner, any other MTA or placed in front of any existing anti- > spam > > solution. > > > > Since this has been a very active recent topic on the MailScanner > list > > we hope you will find this information to be useful. A quick overview > of > > the product follows and more information regarding BarricadeMX can be > > found at www.fsl.com or www.snertsoft.com > > . > > > > BarricadeMX is a new lightweight, small footprint computer-based > > anti-spam application. It is > > designed as an SMTP port 25 proxy, filtering and forwarding mail to > one > > or more local or remote mail transfer agents. BarricadeMX supports a > > variety of well blended anti-spam filtering tests that can be > > individually enabled or disabled according to the rigors of the > > postmaster's local filtering policy. Most of these tests are optional > > and several are configurable by Domain. BarricadeMX can also set > limits > > on message size by sender, recipient, domain, IP address and IP > address > > ranges. > > > > The application itself is a small (4 MB resident memory), > lightweight, > > multi-threaded C program. Much more efficient than the typical MTA, > it > > can gracefully handle many simultaneous incoming connections. A > single > > CPU system has handled 1018 concurrent SMTP client connections > without > > failing or losing any legitimate mail. Many servers that are in > > production routinely handle 200 to 300 incoming simultaneous > connections > > while maintaining low CPU utilization. > > > > BarricadeMX may be configured to run on multiple gateways which share > > multicast or unicast caches. These caches provide a fast, simple, and > > efficient means to share cache updates across multiple gateways on > the > > same network segment or back and forth to a set of remote hosts. Both > > the multicast and unicast caches use a broadcast-and-correct model > and > > support IPv4 and IPv6. > > > > By rejecting messages with a 550 error at the MTA level during the > > initial SMTP conversation, valid senders should receive a rejection > > notice letting them know that their email was not accepted for > delivery > > and the reason for the rejection. Since this notice is sent directly > to > > the server trying to deliver the message, there is no chance this > > feature being used in a "reflected spam" attack. The rejection notice > > may also be customized for individual sites to let the recipient of > the > > bounce know who to contact to correct the problem. > > > > BarricadeMX is currently available only for Linux Red Hat and CentOS > and > > OpenBSD operating systems. Ports to FreeBSD, SuSE and Solaris will be > > available soon with ports to Microsoft and Mac OS X in the planning > stage. > > > > BarricadeMX is supplied as an rpm install for Linux and it is > configured > > and managed using a simple web interface or by using text > configuration > > files. For FreeBSD it is installed using pkg_add and configured by > using > > text configuration files. > > > > And finally here are the results from one of our beta sites. Before > > installing BarricadeMX this site was running 15 very expensive PC > > anti-spam gateways which were barely able to handle the load. There > were > > long delays caused by a load of approximately 2 million total > messages > > per day for +1,800 domains. Peak connection attempts typically > reached > > +100,000 connections per hour. > > > > The 15 PC gateways have now been replaced be three Sun 2100's with > > single Dual-Core AMD Opteron 1210 processors and 4 GB of memory > running > > the CentOS 4.x x86_64 operating system, BarricadeMX and a typical > > MailScanner anti-spam installation. Gateway 1 is running BarricadeMX, > a > > typical MailScanner / SpamAssassin installation and MailWatch. It is > > also the Gateway cluster's log host, web server and MailWatch > database > > server. Gateways 2 and 3 are running BarricadeMX and a typical > > MailScanner / SpamAssassin installation. > > > > And here are recent statistics from this beta site: > > > > > > > > Gateway 1 > > > > > > > > Gateway 2 > > > > > > > > Gateway 3 > > > > > > > > Site Totals > > > > Delivery Attempts > > > > > > > > 4,052,718 > > > > > > > > 15,067,573 > > > > > > > > 3,719,411 > > > > > > > > 22,839,702 > > > > Accepted messages > > > > > > > > 89,999 > > > > > > > > 177,359 > > > > > > > > 53,705 > > > > > > > > 321,063 > > > > Accepted messages > > > > > > > > 2.22% > > > > > > > > 1.18% > > > > > > > > 1.44% > > > > > > > > 1.61% > > > > Connections per day > > > > > > > > 579,160 > > > > > > > > 747,604 > > > > > > > > 532,078 > > > > > > > > 1,858,842 > > > > Max Simultaneous Connections > > > > > > > > 506 > > > > > > > > 506 > > > > > > > > 506 > > > > > > > > 506 > > > > Process Age (seconds) > > > > > > > > 604,591 > > > > > > > > 1,741,347 > > > > > > > > 603,966 > > > > > > > > N.A. > > > > Connections per second > > > > > > > > 6.70 > > > > > > > > 8.65 > > > > > > > > 6.16 > > > > > > > > 21.51 > > > > Connections per hour > > > > > > > > 24,132 > > > > > > > > 31,150 > > > > > > > > 22,170 > > > > > > > > 77,452 > > > > Connections per Day > > > > > > > > 720,021 > > > > > > > > 521,808 > > > > > > > > 572,566 > > > > > > > > 1,814,395 > > > > Daily Bandwidth savings (KB) > > > > > > > > 11,377,738 > > > > > > > > 8,223,877 > > > > > > > > 8,949,527 > > > > > > > > 28,551,142 > > > > Load Average > > > > > > > > 1.0 to 2.0 > > > > > > > > 1.0 to 2.0 > > > > > > > > 0.5 to 1.5 > > > > > > > > under 2.0 > > > > > > > > This is a site that gets a massive amount of spam and is currently > > accurately rejecting over 98% of the spam at the MTA level. We have > had > > less than ten sites that needed to be white listed as false positives > in > > just over two months. We estimate that each of these servers can > easily > > handle over 1,000,000 messages per day. > > > > After passing through BarricadeMX, MailScanner is only processing an > > average of 39,226 messages per day out of 1,814,395 average daily > > connection attempts, 1,940 (4.95%) of which are tagged as spam and 89 > > (0.23%) of which are quarantined as viruses. > > > > The client reports getting "virtually no spam". > > > > A white paper with more information and pricing is available at > > http://www.fsl.com . For more information and pricing please contact > us > > off list at info@www.fsl.com . > > > > Julian Field, MEng CITP > > Chief Technology Officer > > Fort System Ltd. > > > > Steve Swaney > > President > > Fort Systems Ltd. > > Steve@fsl.com > > www.fsl.com > > > > > > -- > > This message has been scanned for viruses and > > dangerous content by *MailScanner* , > and is > > believed to be clean. > > For all you IT requirements visit transtec Computers > > . > > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From ms-list at alexb.ch Tue May 29 21:51:41 2007 From: ms-list at alexb.ch (Alex Broens) Date: Tue May 29 21:51:47 2007 Subject: false positives on rule "FM_RATSIGN_1106" and what to do? In-Reply-To: <465C7F68.1020803@fractalweb.com> References: <465C7F68.1020803@fractalweb.com> Message-ID: <465C925D.5030907@alexb.ch> On 5/29/2007 9:30 PM, Chris Yuzik wrote: > Hi, > > Suddenly, I'm seeing quite a number of false positives on the rule > "FM_RATSIGN_1106" that gets a whopping 3.8 points. I've tried to figure > out what exactly it's hitting on, but the only thing I found was: > > ##{ FM_RATSIGN_1106 > meta FM_RATSIGN_1106 (__MSGID_VGA && __DATE_700) > describe FM_RATSIGN_1106 Fingerprint seen in lots of spam. 11/2006 > ##} FM_RATSIGN_1106 > > I think I need to set this rule down to 0.01 for now, or does someone > have a better suggestion? > This is very strange http://ruleqa.spamassassin.org/ shows a score of 0.77 Why not submit as a "buglet"? Alex From ssilva at sgvwater.com Tue May 29 22:23:52 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Tue May 29 22:24:13 2007 Subject: false positives on rule "FM_RATSIGN_1106" and what to do? In-Reply-To: References: <465C7F68.1020803@fractalweb.com> Message-ID: Hugo van der Kooij spake the following on 5/29/2007 1:11 PM: > On Tue, 29 May 2007, Scott Silva wrote: > >> Chris Yuzik spake the following on 5/29/2007 12:30 PM: >>> Hi, >>> >>> Suddenly, I'm seeing quite a number of false positives on the rule >>> "FM_RATSIGN_1106" that gets a whopping 3.8 points. I've tried to figure >>> out what exactly it's hitting on, but the only thing I found was: >>> >>> ##{ FM_RATSIGN_1106 >>> meta FM_RATSIGN_1106 (__MSGID_VGA && __DATE_700) >>> describe FM_RATSIGN_1106 Fingerprint seen in lots of spam. 11/2006 >>> ##} FM_RATSIGN_1106 >>> >>> I think I need to set this rule down to 0.01 for now, or does someone >>> have a better suggestion? >>> >>> Thanks >>> >> It looks at messages that hit both MSGID_VGA and DATE_700 >> Message-ID =~ /^<000001c[67]/ and date is -7 hours > > Just out of curiosity. What is the significance of this particular > message ID or this difference in timezones? I have to admit I get a > shitload of spam from the USA and some of the US states are -7 hours > from my timezone. But I fail to see the logic of this construct at the > moment. > > Hugo. > I didn't write the rule, and have no idea what it is trying to do. I just grep'd through the rules and read the results. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From res at ausics.net Tue May 29 22:29:45 2007 From: res at ausics.net (Res) Date: Tue May 29 22:29:51 2007 Subject: ANNOUNCE: BarricadeMX is released In-Reply-To: <447401c7a230$fbdd1b10$f3975130$@swaney@fsl.com> References: <54C6E1F0-01FF-4365-A395-D00BFED6C980@ecs.soton.ac.uk> <465C87FD.7090507@tc3net.com> <447401c7a230$fbdd1b10$f3975130$@swaney@fsl.com> Message-ID: On Tue, 29 May 2007, Stephen Swaney wrote: > be OK soon. Please send email to info@fsl.com if you have any questions or > problems. > > Thanks, > > Steve Why only such limited distros? To protect your source code? You truly restrict yourself to those who may wish to try/use the product, very few networks in this part of the world use anything but slackware and debian, and about 70% of the network admins I know in the U.S are the same (with an equal high percent using FreeBSD and slowaris) -- Cheers Res From ka at pacific.net Tue May 29 22:43:23 2007 From: ka at pacific.net (Ken A) Date: Tue May 29 22:43:22 2007 Subject: ANNOUNCE: BarricadeMX is released In-Reply-To: <54C6E1F0-01FF-4365-A395-D00BFED6C980@ecs.soton.ac.uk> References: <54C6E1F0-01FF-4365-A395-D00BFED6C980@ecs.soton.ac.uk> Message-ID: <465C9E7B.9070404@pacific.net> Very impressive feature list. Good luck with the new product! Thanks, Ken Anderson Pacific.Net Julian Field wrote: > Fort Systems Limited is proud to introduce its newest flagship software, > BarricadeMX. > > Featuring a new level of spam filtering which rejects most of the spam > before it's even accepted for delivery, BarricadeMX is the top of the > line anti-spam filtering application. > > BarricadeMX was designed to complement MailScanner and SpamAssassin for > high volume sites and / or sites which require very accurate spam > detection. BarricadeMX was jointly developed by Fort Systems Ltd and > SnertSoft to more efficiently block spam at the MTA level during the > initial SMTP conversation. BarricadeMX can be installed with > MailScanner, any other MTA or placed in front of any existing anti-spam > solution. > > Since this has been a very active recent topic on the MailScanner list > we hope you will find this information to be useful. A quick overview of > the product follows and more information regarding BarricadeMX can be > found at www.fsl.com or www.snertsoft.com. > > BarricadeMX is a new lightweight, small footprint computer-based > anti-spam application. It is > designed as an SMTP port 25 proxy, filtering and forwarding mail to one > or more local or remote mail transfer agents. BarricadeMX supports a > variety of well blended anti-spam filtering tests that can be > individually enabled or disabled according to the rigors of the > postmaster's local filtering policy. Most of these tests are optional > and several are configurable by Domain. BarricadeMX can also set limits > on message size by sender, recipient, domain, IP address and IP address > ranges. > > The application itself is a small (4 MB resident memory), lightweight, > multi-threaded C program. Much more efficient than the typical MTA, it > can gracefully handle many simultaneous incoming connections. A single > CPU system has handled 1018 concurrent SMTP client connections without > failing or losing any legitimate mail. Many servers that are in > production routinely handle 200 to 300 incoming simultaneous connections > while maintaining low CPU utilization. > > BarricadeMX may be configured to run on multiple gateways which share > multicast or unicast caches. These caches provide a fast, simple, and > efficient means to share cache updates across multiple gateways on the > same network segment or back and forth to a set of remote hosts. Both > the multicast and unicast caches use a broadcast-and-correct model and > support IPv4 and IPv6. > > By rejecting messages with a 550 error at the MTA level during the > initial SMTP conversation, valid senders should receive a rejection > notice letting them know that their email was not accepted for delivery > and the reason for the rejection. Since this notice is sent directly to > the server trying to deliver the message, there is no chance this > feature being used in a ?reflected spam? attack. The rejection notice > may also be customized for individual sites to let the recipient of the > bounce know who to contact to correct the problem. > > BarricadeMX is currently available only for Linux Red Hat and CentOS and > OpenBSD operating systems. Ports to FreeBSD, SuSE and Solaris will be > available soon with ports to Microsoft and Mac OS X in the planning stage. > > BarricadeMX is supplied as an rpm install for Linux and it is configured > and managed using a simple web interface or by using text configuration > files. For FreeBSD it is installed using pkg_add and configured by using > text configuration files. > > And finally here are the results from one of our beta sites. Before > installing BarricadeMX this site was running 15 very expensive PC > anti-spam gateways which were barely able to handle the load. There were > long delays caused by a load of approximately 2 million total messages > per day for +1,800 domains. Peak connection attempts typically reached > +100,000 connections per hour. > > The 15 PC gateways have now been replaced be three Sun 2100?s with > single Dual-Core AMD Opteron 1210 processors and 4 GB of memory running > the CentOS 4.x x86_64 operating system, BarricadeMX and a typical > MailScanner anti-spam installation. Gateway 1 is running BarricadeMX, a > typical MailScanner / SpamAssassin installation and MailWatch. It is > also the Gateway cluster?s log host, web server and MailWatch database > server. Gateways 2 and 3 are running BarricadeMX and a typical > MailScanner / SpamAssassin installation. > > And here are recent statistics from this beta site: > > Gateway 1 > > Gateway 2 > > Gateway 3 > > Site Totals > > Delivery Attempts > > 4,052,718 > > 15,067,573 > > 3,719,411 > > 22,839,702 > > Accepted messages > > 89,999 > > 177,359 > > 53,705 > > 321,063 > > Accepted messages > > 2.22% > > 1.18% > > 1.44% > > 1.61% > > Connections per day > > 579,160 > > 747,604 > > 532,078 > > 1,858,842 > > Max Simultaneous Connections > > 506 > > 506 > > 506 > > 506 > > Process Age (seconds) > > 604,591 > > 1,741,347 > > 603,966 > > N.A. > > Connections per second > > 6.70 > > 8.65 > > 6.16 > > 21.51 > > Connections per hour > > 24,132 > > 31,150 > > 22,170 > > 77,452 > > Connections per Day > > 720,021 > > 521,808 > > 572,566 > > 1,814,395 > > Daily Bandwidth savings (KB) > > 11,377,738 > > 8,223,877 > > 8,949,527 > > 28,551,142 > > Load Average > > 1.0 to 2.0 > > 1.0 to 2.0 > > 0.5 to 1.5 > > under 2.0 > > > > This is a site that gets a massive amount of spam and is currently > accurately rejecting over 98% of the spam at the MTA level. We have had > less than ten sites that needed to be white listed as false positives in > just over two months. We estimate that each of these servers can easily > handle over 1,000,000 messages per day. > > After passing through BarricadeMX, MailScanner is only processing an > average of 39,226 messages per day out of 1,814,395 average daily > connection attempts, 1,940 (4.95%) of which are tagged as spam and 89 > (0.23%) of which are quarantined as viruses. > > The client reports getting ?virtually no spam?. > > A white paper with more information and pricing is available at > http://www.fsl.com . For more information and pricing please contact us > off list at info@www.fsl.com . > > Julian Field, MEng CITP > Chief Technology Officer > Fort System Ltd. > > Steve Swaney > President > Fort Systems Ltd. > Steve@fsl.com > www.fsl.com > > --This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- Ken Anderson Pacific.Net From wilson.galafassi at gmail.com Tue May 29 23:09:12 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Tue May 29 23:09:53 2007 Subject: RES: RES: RES: mcp help In-Reply-To: <465C33C7.6040301@ecs.soton.ac.uk> References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> <465BEEF0.6000505@gmail.com> <465C33C7.60403 01@ecs.soton.ac.uk> Message-ID: Any Idea to solve this problem? Very thanks to all, Wilson -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field Enviada em: ter?a-feira, 29 de maio de 2007 11:08 Para: MailScanner discussion Assunto: Re: RES: RES: mcp help Yes, but what about the setting MCP Checks = yes ? Remember MCP is off by default. Wilson A. Galafassi Jr. wrote: > I have something wrong... any help is very apreciated! > > Thanks > Wilson > > > My mailscanner.cf > > First Check = mcp > > # The rest of these options are clones of the equivalent spam options > MCP Required SpamAssassin Score = 1 > MCP High SpamAssassin Score = 10 > MCP Error Score = 1 > > MCP Header = X-%org-name%-MailScanner-MCPCheck: > Non MCP Actions = deliver > MCP Actions = store > High Scoring MCP Actions = store > Bounce MCP As Attachment = no > > MCP Modify Subject = start > MCP Subject Text = {MCP?} > High Scoring MCP Modify Subject = start > High Scoring MCP Subject Text = {MCP?} > > Is Definitely MCP = no > Is Definitely Not MCP = no > Definite MCP Is High Scoring = yes > Always Include MCP Report = yes > Detailed MCP Report = yes > Include Scores In MCP Report = yes > Log MCP = yes > > MCP Max SpamAssassin Timeouts = 20 > MCP Max SpamAssassin Size = 100k > MCP SpamAssassin Timeout = 10 > > MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf > MCP SpamAssassin User State Dir = /var/spool/MailScanner/mcp > MCP SpamAssassin Local Rules Dir = %mcp-dir% > MCP SpamAssassin Default Rules Dir = %mcp-dir% > MCP SpamAssassin Install Prefix = %mcp-dir% > Recipient MCP Report = %report-dir%/recipient.mcp.report.txt > Sender MCP Report = %report-dir%/sender.mcp.report.txt > > > My test mail: > > >From wilson@ftpmanager.com Tue May 29 10:19:42 2007 > Return-Path: > X-Original-To: wilson@ftpmanager.com > Delivered-To: wilson@ftpmanager.com > Received: from sdxp (unknown [192.168.0.1]) > by netserver.ftpmanager.com (Postfix) with SMTP id 1784D107F90 > for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) > Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" > X-Priority: 3 > X-MSMail-Priority: Normal > X-Mailer: Microsoft Outlook Express 6.00.2900.3028 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 > X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more > information > X-ftpmanagerbr_net-MailScanner: Found to be clean > X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, > requerido 1) > X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanager.com > X-Spam-Status: No > > This is a multi-part message in MIME format. > > ------=_NextPart_000_0005_01C7A1DA.CCACFD20 > Content-Type: text/plain; > charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > Block this t?o > > > My cf file: > > header MY_RULE_1 Subject =~ /block this phrase/i > score MY_RULE_1 100 > > body MY_RULE_2 /Block this too/i > score MY_RULE_2 100 > > body MY_RULE_3 /this\s*is\s*more\s*complicated/i > score MY_RULE_3 100 > > > body SAMPLE_RULE2 /this/i > describe SAMPLE_RULE2 Banned body text > score SAMPLE_RULE2 5 > > body LOCAL_DEMONSTRATION_RULE /test/ > score LOCAL_DEMONSTRATION_RULE 100 > describe LOCAL_DEMONSTRATION_RULE This is a simple test rule > > header LOCAL_DEMONSTRATION_SUBJECT Subject =~ /\btest\b/i > score LOCAL_DEMONSTRATION_SUBJECT 100 > > > The spamassassin test: > > spamassassin -C /etc/MailScanner/mcp -p > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < teste.mail > [15603] dbg: logger: adding facilities: all > [15603] dbg: logger: logging level is DBG > [15603] dbg: generic: SpamAssassin version 3.2.0 > [15603] dbg: config: score set 0 chosen. > [15603] dbg: util: running in taint mode? yes > [15603] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH > [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping > [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping > [15603] dbg: util: PATH included '/usr/local/sbin', keeping > [15603] dbg: util: PATH included '/usr/local/bin', keeping > [15603] dbg: util: PATH included '/sbin', keeping > [15603] dbg: util: PATH included '/bin', keeping > [15603] dbg: util: PATH included '/usr/sbin', keeping > [15603] dbg: util: PATH included '/usr/bin', keeping > [15603] dbg: util: PATH included '/root/bin', which doesn't exist, dropping > [15603] dbg: util: final PATH set to: > /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b > in:/usr/sbin:/usr/bin > [15603] dbg: dns: no ipv6 > [15603] dbg: dns: is Net::DNS::Resolver available? yes > [15603] dbg: dns: Net::DNS version: 0.59 > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre files > [15603] dbg: config: read file /etc/mail/spamassassin/init.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre > [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files > [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir > [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir > [15603] dbg: config: read file /etc/mail/spamassassin/local.cf > [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf > [15603] dbg: config: using "/root/.spamassassin" for user state dir > [15603] dbg: config: using > "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file > [15603] dbg: config: read file > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC > [15603] dbg: pyzor: network tests on, attempting Pyzor > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered > [15603] dbg: conf: finish parsing > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) > implements 'finish_parsing_end', priority 0 > [15603] dbg: replacetags: replacing tags > [15603] dbg: replacetags: done replacing tags > [15603] dbg: config: score set 1 chosen. > [15603] dbg: message: main message type: multipart/alternative > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) > implements 'check_start', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) > implements 'check_main', priority 0 > [15603] dbg: conf: trusted_networks are not configured; it is recommended > that you configure trusted_networks manually > [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp > by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= > msa=0 ] > [15603] dbg: received-header: 'from' 192.168.0.1 has private IP > [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes > msa? no > [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-Untrusted: > [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-External: > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'extract_metadata', priority 0 > [15603] dbg: metadata: X-Relay-Countries: > [15603] dbg: message: ---- MIME PARSER START ---- > [15603] dbg: message: parsing multipart, got boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: found part of type text/plain, boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: added part, type: text/plain > [15603] dbg: message: parsing normal part > [15603] dbg: message: ---- MIME PARSER END ---- > [15603] dbg: message: decoding quoted-printable > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) > implements 'parsed_metadata', priority 0 > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'parsed_metadata', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) > implements 'parsed_metadata', priority 0 > [15603] dbg: dns: dns_available set to yes in config file, skipping test > [15603] dbg: uridnsbl: domains to query: > [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups > [15603] dbg: check: running tests for priority: 0 > [15603] dbg: rules: running head tests; score so far=0 > [15603] dbg: rules: compiled head tests > [15603] dbg: rules: running body tests; score so far=0 > [15603] dbg: rules: compiled body tests > [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got hit: > "test" > [15603] dbg: rules: running uri tests; score so far=100 > [15603] dbg: rules: compiled uri tests > [15603] dbg: rules: running rawbody tests; score so far=100 > [15603] dbg: rules: compiled rawbody tests > [15603] dbg: rules: running full tests; score so far=100 > [15603] dbg: rules: compiled full tests > [15603] dbg: rules: running meta tests; score so far=100 > [15603] dbg: rules: compiled meta tests > [15603] dbg: check: is spam? score=100 required=5 > [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE > [15603] dbg: check: subtests= > >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 > Received: from localhost by netserver.ftpmanagerbr.net > with SpamAssassin (version 3.2.0); > Tue, 29 May 2007 10:28:40 -0300 > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on > netserver.ftpmanagerbr.net > MIME-Version: 1.0 > Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" > > This is a multi-part message in MIME format. > > ------------=_465C2A88.4A78356A > Content-Type: text/plain; charset=iso-8859-1 > Content-Disposition: inline > Content-Transfer-Encoding: 8bit > > (no report template found) > > > > ------------=_465C2A88.4A78356A > Content-Type: message/rfc822; x-spam-type=original > Content-Description: original message before SpamAssassin > Content-Disposition: attachment > Content-Transfer-Encoding: 8bit > > Return-Path: > X-Original-To: wilson@ftpmanagerbr.net > Delivered-To: wilson@ftpmanagerbr.net > Received: from sdxp (unknown [192.168.0.1]) > by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 > for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) > Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" > X-Priority: 3 > X-MSMail-Priority: Normal > X-Mailer: Microsoft Outlook Express 6.00.2900.3028 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 > X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more > information > X-ftpmanagerbr_net-MailScanner: Found to be clean > X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, > requerido 1) > X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net > X-Spam-Status: No > > This is a multi-part message in MIME format. > > ------=_NextPart_000_0005_01C7A1DA.CCACFD20 > Content-Type: text/plain; > charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > Block this too > > ------------=_465C2A88.4A78356A-- > > (no report template found) spamassassin -C /etc/MailScanner/mcp -p > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < teste.mail > [15603] dbg: logger: adding facilities: all > [15603] dbg: logger: logging level is DBG > [15603] dbg: generic: SpamAssassin version 3.2.0 > [15603] dbg: config: score set 0 chosen. > [15603] dbg: util: running in taint mode? yes > [15603] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH > [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping > [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping > [15603] dbg: util: PATH included '/usr/local/sbin', keeping > [15603] dbg: util: PATH included '/usr/local/bin', keeping > [15603] dbg: util: PATH included '/sbin', keeping > [15603] dbg: util: PATH included '/bin', keeping > [15603] dbg: util: PATH included '/usr/sbin', keeping > [15603] dbg: util: PATH included '/usr/bin', keeping > [15603] dbg: util: PATH included '/root/bin', which doesn't exist, dropping > [15603] dbg: util: final PATH set to: > /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b > in:/usr/sbin:/usr/bin > [15603] dbg: dns: no ipv6 > [15603] dbg: dns: is Net::DNS::Resolver available? yes > [15603] dbg: dns: Net::DNS version: 0.59 > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre files > [15603] dbg: config: read file /etc/mail/spamassassin/init.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre > [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files > [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir > [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir > [15603] dbg: config: read file /etc/mail/spamassassin/local.cf > [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf > [15603] dbg: config: using "/root/.spamassassin" for user state dir > [15603] dbg: config: using > "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file > [15603] dbg: config: read file > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC > [15603] dbg: pyzor: network tests on, attempting Pyzor > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered > [15603] dbg: conf: finish parsing > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) > implements 'finish_parsing_end', priority 0 > [15603] dbg: replacetags: replacing tags > [15603] dbg: replacetags: done replacing tags > [15603] dbg: config: score set 1 chosen. > [15603] dbg: message: main message type: multipart/alternative > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) > implements 'check_start', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) > implements 'check_main', priority 0 > [15603] dbg: conf: trusted_networks are not configured; it is recommended > that you configure trusted_networks manually > [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp > by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= > msa=0 ] > [15603] dbg: received-header: 'from' 192.168.0.1 has private IP > [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes > msa? no > [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-Untrusted: > [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-External: > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'extract_metadata', priority 0 > [15603] dbg: metadata: X-Relay-Countries: > [15603] dbg: message: ---- MIME PARSER START ---- > [15603] dbg: message: parsing multipart, got boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: found part of type text/plain, boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: added part, type: text/plain > [15603] dbg: message: parsing normal part > [15603] dbg: message: ---- MIME PARSER END ---- > [15603] dbg: message: decoding quoted-printable > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) > implements 'parsed_metadata', priority 0 > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'parsed_metadata', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) > implements 'parsed_metadata', priority 0 > [15603] dbg: dns: dns_available set to yes in config file, skipping test > [15603] dbg: uridnsbl: domains to query: > [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups > [15603] dbg: check: running tests for priority: 0 > [15603] dbg: rules: running head tests; score so far=0 > [15603] dbg: rules: compiled head tests > [15603] dbg: rules: running body tests; score so far=0 > [15603] dbg: rules: compiled body tests > [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got hit: > "test" > [15603] dbg: rules: running uri tests; score so far=100 > [15603] dbg: rules: compiled uri tests > [15603] dbg: rules: running rawbody tests; score so far=100 > [15603] dbg: rules: compiled rawbody tests > [15603] dbg: rules: running full tests; score so far=100 > [15603] dbg: rules: compiled full tests > [15603] dbg: rules: running meta tests; score so far=100 > [15603] dbg: rules: compiled meta tests > [15603] dbg: check: is spam? score=100 required=5 > [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE > [15603] dbg: check: subtests= > >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 > Received: from localhost by netserver.ftpmanagerbr.net > with SpamAssassin (version 3.2.0); > Tue, 29 May 2007 10:28:40 -0300 > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on > netserver.ftpmanagerbr.net > MIME-Version: 1.0 > Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" > > This is a multi-part message in MIME format. > > ------------=_465C2A88.4A78356A > Content-Type: text/plain; charset=iso-8859-1 > Content-Disposition: inline > Content-Transfer-Encoding: 8bit > > (no report template found) > > > > ------------=_465C2A88.4A78356A > Content-Type: message/rfc822; x-spam-type=original > Content-Description: original message before SpamAssassin > Content-Disposition: attachment > Content-Transfer-Encoding: 8bit > > Return-Path: > X-Original-To: wilson@ftpmanagerbr.net > Delivered-To: wilson@ftpmanagerbr.net > Received: from sdxp (unknown [192.168.0.1]) > by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 > for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) > Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" > X-Priority: 3 > X-MSMail-Priority: Normal > X-Mailer: Microsoft Outlook Express 6.00.2900.3028 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 > X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more > information > X-ftpmanagerbr_net-MailScanner: Found to be clean > X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, > requerido 1) > X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net > X-Spam-Status: No > > This is a multi-part message in MIME format. > > ------=_NextPart_000_0005_01C7A1DA.CCACFD20 > Content-Type: text/plain; > charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > Block this too > > ------------=_465C2A88.4A78356A-- > > (no report template found) > > > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Lasantha > Marian > Enviada em: ter?a-feira, 29 de maio de 2007 06:14 > Para: MailScanner discussion > Assunto: Re: RES: mcp help > > Dear Julian, > > I have been experiencing some strange behaviors in my MCP setup (SA 3.2.0/MS > 4.59.4) too, i.e. MCP setup works very fine when tested from command line so > does SpamAssassin setup (from both ends; command line and from MailScanner), > but MCP would not work properly from MailScanner. It would happily scan but > does not report against customized MCP rules. MCP rules are properly applied > and correct scores are shown when run from command line without any errors. > The very same MCP rules set works fine with earlier versions (SA 3.1.1/MS > 4.53.8). > > I think it is the same kind of problem that Wilson is experiencing in MCP. > It identifies MCP, but then may be a reporting problem ! > > Thanks and regards, > > Lasantha. > > > *-------- Original Message --------* > *Subject: * RES: mcp help > *Date: * Tue, 29/May/2007 4:39:25 AM +0550 > *From: * "Wilson A. Galafassi Jr." > *To: * "'MailScanner discussion'" > > > >> spamassassin --D --lint > >> > /tmp/sa.log 2>&1 > > > > >> This is the result. >> > > > > >> [root@netserver tmp]# cat sa.log >> > > >> [26391] dbg: logger: adding facilities: all >> > > >> [26391] dbg: logger: logging level is DBG >> > > >> [26391] dbg: generic: SpamAssassin version 3.2.0 >> > > >> [26391] dbg: config: score set 0 chosen. >> > > >> [26391] dbg: util: running in taint mode? yes >> > > >> [26391] dbg: util: taint mode: deleting unsafe environment >> > variables, > > >> resetting PATH >> > > > > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From steve.freegard at fsl.com Tue May 29 23:21:16 2007 From: steve.freegard at fsl.com (Steve Freegard) Date: Tue May 29 23:21:14 2007 Subject: ANNOUNCE: BarricadeMX is released In-Reply-To: References: <54C6E1F0-01FF-4365-A395-D00BFED6C980@ecs.soton.ac.uk> <465C87FD.7090507@tc3net.com> <447401c7a230$fbdd1b10$f3975130$@swaney@fsl.com> Message-ID: <465CA75C.3020906@fsl.com> Res wrote: > Why only such limited distros? We will release the product for other distros - but this is driven by customer demand as writing and updating packages for every distro whether you have customers using it not does not scale well due to the number of different package formats. All of our existing customers use either CentOS/RHEL, FreeBSD or Solaris so these were the obvious places to start. If you want to try this on Slackware or any other OS, then let me know and I'll try and put something together for you. Kind regards, Steve. -- Steve Freegard Development Director Fort Systems Ltd. From wilson.galafassi at gmail.com Tue May 29 23:54:33 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Tue May 29 23:55:01 2007 Subject: RES: RES: RES: mcp help In-Reply-To: <465C33C7.6040301@ecs.soton.ac.uk> References: <20070528115436.731854e0@uxbod.splatnix.net> <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> <465BEEF0.6000505@gmail.com> <465C33C7.60403 01@ecs.soton.ac.uk> Message-ID: I have tried to upgrade to latest beta version and the error in mcp checks persist. check: no loaded plugin implements 'check_main': cannot scan! at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin/PerMsgStatus.pm line 164. Any help is apreciated. Thanks, Wilson -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field Enviada em: ter?a-feira, 29 de maio de 2007 11:08 Para: MailScanner discussion Assunto: Re: RES: RES: mcp help Yes, but what about the setting MCP Checks = yes ? Remember MCP is off by default. Wilson A. Galafassi Jr. wrote: > I have something wrong... any help is very apreciated! > > Thanks > Wilson > > > My mailscanner.cf > > First Check = mcp > > # The rest of these options are clones of the equivalent spam options > MCP Required SpamAssassin Score = 1 > MCP High SpamAssassin Score = 10 > MCP Error Score = 1 > > MCP Header = X-%org-name%-MailScanner-MCPCheck: > Non MCP Actions = deliver > MCP Actions = store > High Scoring MCP Actions = store > Bounce MCP As Attachment = no > > MCP Modify Subject = start > MCP Subject Text = {MCP?} > High Scoring MCP Modify Subject = start > High Scoring MCP Subject Text = {MCP?} > > Is Definitely MCP = no > Is Definitely Not MCP = no > Definite MCP Is High Scoring = yes > Always Include MCP Report = yes > Detailed MCP Report = yes > Include Scores In MCP Report = yes > Log MCP = yes > > MCP Max SpamAssassin Timeouts = 20 > MCP Max SpamAssassin Size = 100k > MCP SpamAssassin Timeout = 10 > > MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf > MCP SpamAssassin User State Dir = /var/spool/MailScanner/mcp > MCP SpamAssassin Local Rules Dir = %mcp-dir% > MCP SpamAssassin Default Rules Dir = %mcp-dir% > MCP SpamAssassin Install Prefix = %mcp-dir% > Recipient MCP Report = %report-dir%/recipient.mcp.report.txt > Sender MCP Report = %report-dir%/sender.mcp.report.txt > > > My test mail: > > >From wilson@ftpmanager.com Tue May 29 10:19:42 2007 > Return-Path: > X-Original-To: wilson@ftpmanager.com > Delivered-To: wilson@ftpmanager.com > Received: from sdxp (unknown [192.168.0.1]) > by netserver.ftpmanager.com (Postfix) with SMTP id 1784D107F90 > for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) > Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" > X-Priority: 3 > X-MSMail-Priority: Normal > X-Mailer: Microsoft Outlook Express 6.00.2900.3028 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 > X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more > information > X-ftpmanagerbr_net-MailScanner: Found to be clean > X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, > requerido 1) > X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanager.com > X-Spam-Status: No > > This is a multi-part message in MIME format. > > ------=_NextPart_000_0005_01C7A1DA.CCACFD20 > Content-Type: text/plain; > charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > Block this t?o > > > My cf file: > > header MY_RULE_1 Subject =~ /block this phrase/i > score MY_RULE_1 100 > > body MY_RULE_2 /Block this too/i > score MY_RULE_2 100 > > body MY_RULE_3 /this\s*is\s*more\s*complicated/i > score MY_RULE_3 100 > > > body SAMPLE_RULE2 /this/i > describe SAMPLE_RULE2 Banned body text > score SAMPLE_RULE2 5 > > body LOCAL_DEMONSTRATION_RULE /test/ > score LOCAL_DEMONSTRATION_RULE 100 > describe LOCAL_DEMONSTRATION_RULE This is a simple test rule > > header LOCAL_DEMONSTRATION_SUBJECT Subject =~ /\btest\b/i > score LOCAL_DEMONSTRATION_SUBJECT 100 > > > The spamassassin test: > > spamassassin -C /etc/MailScanner/mcp -p > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < teste.mail > [15603] dbg: logger: adding facilities: all > [15603] dbg: logger: logging level is DBG > [15603] dbg: generic: SpamAssassin version 3.2.0 > [15603] dbg: config: score set 0 chosen. > [15603] dbg: util: running in taint mode? yes > [15603] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH > [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping > [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping > [15603] dbg: util: PATH included '/usr/local/sbin', keeping > [15603] dbg: util: PATH included '/usr/local/bin', keeping > [15603] dbg: util: PATH included '/sbin', keeping > [15603] dbg: util: PATH included '/bin', keeping > [15603] dbg: util: PATH included '/usr/sbin', keeping > [15603] dbg: util: PATH included '/usr/bin', keeping > [15603] dbg: util: PATH included '/root/bin', which doesn't exist, dropping > [15603] dbg: util: final PATH set to: > /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b > in:/usr/sbin:/usr/bin > [15603] dbg: dns: no ipv6 > [15603] dbg: dns: is Net::DNS::Resolver available? yes > [15603] dbg: dns: Net::DNS version: 0.59 > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre files > [15603] dbg: config: read file /etc/mail/spamassassin/init.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre > [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files > [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir > [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir > [15603] dbg: config: read file /etc/mail/spamassassin/local.cf > [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf > [15603] dbg: config: using "/root/.spamassassin" for user state dir > [15603] dbg: config: using > "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file > [15603] dbg: config: read file > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC > [15603] dbg: pyzor: network tests on, attempting Pyzor > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered > [15603] dbg: conf: finish parsing > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) > implements 'finish_parsing_end', priority 0 > [15603] dbg: replacetags: replacing tags > [15603] dbg: replacetags: done replacing tags > [15603] dbg: config: score set 1 chosen. > [15603] dbg: message: main message type: multipart/alternative > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) > implements 'check_start', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) > implements 'check_main', priority 0 > [15603] dbg: conf: trusted_networks are not configured; it is recommended > that you configure trusted_networks manually > [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp > by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= > msa=0 ] > [15603] dbg: received-header: 'from' 192.168.0.1 has private IP > [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes > msa? no > [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-Untrusted: > [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-External: > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'extract_metadata', priority 0 > [15603] dbg: metadata: X-Relay-Countries: > [15603] dbg: message: ---- MIME PARSER START ---- > [15603] dbg: message: parsing multipart, got boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: found part of type text/plain, boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: added part, type: text/plain > [15603] dbg: message: parsing normal part > [15603] dbg: message: ---- MIME PARSER END ---- > [15603] dbg: message: decoding quoted-printable > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) > implements 'parsed_metadata', priority 0 > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'parsed_metadata', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) > implements 'parsed_metadata', priority 0 > [15603] dbg: dns: dns_available set to yes in config file, skipping test > [15603] dbg: uridnsbl: domains to query: > [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups > [15603] dbg: check: running tests for priority: 0 > [15603] dbg: rules: running head tests; score so far=0 > [15603] dbg: rules: compiled head tests > [15603] dbg: rules: running body tests; score so far=0 > [15603] dbg: rules: compiled body tests > [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got hit: > "test" > [15603] dbg: rules: running uri tests; score so far=100 > [15603] dbg: rules: compiled uri tests > [15603] dbg: rules: running rawbody tests; score so far=100 > [15603] dbg: rules: compiled rawbody tests > [15603] dbg: rules: running full tests; score so far=100 > [15603] dbg: rules: compiled full tests > [15603] dbg: rules: running meta tests; score so far=100 > [15603] dbg: rules: compiled meta tests > [15603] dbg: check: is spam? score=100 required=5 > [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE > [15603] dbg: check: subtests= > >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 > Received: from localhost by netserver.ftpmanagerbr.net > with SpamAssassin (version 3.2.0); > Tue, 29 May 2007 10:28:40 -0300 > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on > netserver.ftpmanagerbr.net > MIME-Version: 1.0 > Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" > > This is a multi-part message in MIME format. > > ------------=_465C2A88.4A78356A > Content-Type: text/plain; charset=iso-8859-1 > Content-Disposition: inline > Content-Transfer-Encoding: 8bit > > (no report template found) > > > > ------------=_465C2A88.4A78356A > Content-Type: message/rfc822; x-spam-type=original > Content-Description: original message before SpamAssassin > Content-Disposition: attachment > Content-Transfer-Encoding: 8bit > > Return-Path: > X-Original-To: wilson@ftpmanagerbr.net > Delivered-To: wilson@ftpmanagerbr.net > Received: from sdxp (unknown [192.168.0.1]) > by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 > for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) > Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" > X-Priority: 3 > X-MSMail-Priority: Normal > X-Mailer: Microsoft Outlook Express 6.00.2900.3028 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 > X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more > information > X-ftpmanagerbr_net-MailScanner: Found to be clean > X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, > requerido 1) > X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net > X-Spam-Status: No > > This is a multi-part message in MIME format. > > ------=_NextPart_000_0005_01C7A1DA.CCACFD20 > Content-Type: text/plain; > charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > Block this too > > ------------=_465C2A88.4A78356A-- > > (no report template found) spamassassin -C /etc/MailScanner/mcp -p > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < teste.mail > [15603] dbg: logger: adding facilities: all > [15603] dbg: logger: logging level is DBG > [15603] dbg: generic: SpamAssassin version 3.2.0 > [15603] dbg: config: score set 0 chosen. > [15603] dbg: util: running in taint mode? yes > [15603] dbg: util: taint mode: deleting unsafe environment variables, > resetting PATH > [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping > [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping > [15603] dbg: util: PATH included '/usr/local/sbin', keeping > [15603] dbg: util: PATH included '/usr/local/bin', keeping > [15603] dbg: util: PATH included '/sbin', keeping > [15603] dbg: util: PATH included '/bin', keeping > [15603] dbg: util: PATH included '/usr/sbin', keeping > [15603] dbg: util: PATH included '/usr/bin', keeping > [15603] dbg: util: PATH included '/root/bin', which doesn't exist, dropping > [15603] dbg: util: final PATH set to: > /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b > in:/usr/sbin:/usr/bin > [15603] dbg: dns: no ipv6 > [15603] dbg: dns: is Net::DNS::Resolver available? yes > [15603] dbg: dns: Net::DNS version: 0.59 > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre files > [15603] dbg: config: read file /etc/mail/spamassassin/init.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre > [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre > [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files > [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir > [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf > [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir > [15603] dbg: config: read file /etc/mail/spamassassin/local.cf > [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf > [15603] dbg: config: using "/root/.spamassassin" for user state dir > [15603] dbg: config: using > "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file > [15603] dbg: config: read file > /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC > [15603] dbg: pyzor: network tests on, attempting Pyzor > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject > from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from > @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from > @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC > [15603] dbg: razor2: razor2 is not available > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered > [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC > [15603] dbg: plugin: did not register > Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered > [15603] dbg: conf: finish parsing > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) > implements 'finish_parsing_end', priority 0 > [15603] dbg: replacetags: replacing tags > [15603] dbg: replacetags: done replacing tags > [15603] dbg: config: score set 1 chosen. > [15603] dbg: message: main message type: multipart/alternative > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) > implements 'check_start', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) > implements 'check_main', priority 0 > [15603] dbg: conf: trusted_networks are not configured; it is recommended > that you configure trusted_networks manually > [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp > by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= > msa=0 ] > [15603] dbg: received-header: 'from' 192.168.0.1 has private IP > [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes > msa? no > [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-Untrusted: > [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= > helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 > id=1784D107F90 auth= msa=0 ] > [15603] dbg: metadata: X-Spam-Relays-External: > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'extract_metadata', priority 0 > [15603] dbg: metadata: X-Relay-Countries: > [15603] dbg: message: ---- MIME PARSER START ---- > [15603] dbg: message: parsing multipart, got boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: found part of type text/plain, boundary: > ----=_NextPart_000_0005_01C7A1DA.CCACFD20 > [15603] dbg: message: added part, type: text/plain > [15603] dbg: message: parsing normal part > [15603] dbg: message: ---- MIME PARSER END ---- > [15603] dbg: message: decoding quoted-printable > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) > implements 'parsed_metadata', priority 0 > [15603] dbg: plugin: > Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements > 'parsed_metadata', priority 0 > [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) > implements 'parsed_metadata', priority 0 > [15603] dbg: dns: dns_available set to yes in config file, skipping test > [15603] dbg: uridnsbl: domains to query: > [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups > [15603] dbg: check: running tests for priority: 0 > [15603] dbg: rules: running head tests; score so far=0 > [15603] dbg: rules: compiled head tests > [15603] dbg: rules: running body tests; score so far=0 > [15603] dbg: rules: compiled body tests > [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got hit: > "test" > [15603] dbg: rules: running uri tests; score so far=100 > [15603] dbg: rules: compiled uri tests > [15603] dbg: rules: running rawbody tests; score so far=100 > [15603] dbg: rules: compiled rawbody tests > [15603] dbg: rules: running full tests; score so far=100 > [15603] dbg: rules: compiled full tests > [15603] dbg: rules: running meta tests; score so far=100 > [15603] dbg: rules: compiled meta tests > [15603] dbg: check: is spam? score=100 required=5 > [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE > [15603] dbg: check: subtests= > >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 > Received: from localhost by netserver.ftpmanagerbr.net > with SpamAssassin (version 3.2.0); > Tue, 29 May 2007 10:28:40 -0300 > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on > netserver.ftpmanagerbr.net > MIME-Version: 1.0 > Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" > > This is a multi-part message in MIME format. > > ------------=_465C2A88.4A78356A > Content-Type: text/plain; charset=iso-8859-1 > Content-Disposition: inline > Content-Transfer-Encoding: 8bit > > (no report template found) > > > > ------------=_465C2A88.4A78356A > Content-Type: message/rfc822; x-spam-type=original > Content-Description: original message before SpamAssassin > Content-Disposition: attachment > Content-Transfer-Encoding: 8bit > > Return-Path: > X-Original-To: wilson@ftpmanagerbr.net > Delivered-To: wilson@ftpmanagerbr.net > Received: from sdxp (unknown [192.168.0.1]) > by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 > for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) > Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> > From: "Wilson - FTP" > To: > Subject: teste > Date: Tue, 29 May 2007 10:19:11 -0300 > MIME-Version: 1.0 > Content-Type: multipart/alternative; > boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" > X-Priority: 3 > X-MSMail-Priority: Normal > X-Mailer: Microsoft Outlook Express 6.00.2900.3028 > X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 > X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more > information > X-ftpmanagerbr_net-MailScanner: Found to be clean > X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, > requerido 1) > X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net > X-Spam-Status: No > > This is a multi-part message in MIME format. > > ------=_NextPart_000_0005_01C7A1DA.CCACFD20 > Content-Type: text/plain; > charset="iso-8859-1" > Content-Transfer-Encoding: quoted-printable > > Block this too > > ------------=_465C2A88.4A78356A-- > > (no report template found) > > > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Lasantha > Marian > Enviada em: ter?a-feira, 29 de maio de 2007 06:14 > Para: MailScanner discussion > Assunto: Re: RES: mcp help > > Dear Julian, > > I have been experiencing some strange behaviors in my MCP setup (SA 3.2.0/MS > 4.59.4) too, i.e. MCP setup works very fine when tested from command line so > does SpamAssassin setup (from both ends; command line and from MailScanner), > but MCP would not work properly from MailScanner. It would happily scan but > does not report against customized MCP rules. MCP rules are properly applied > and correct scores are shown when run from command line without any errors. > The very same MCP rules set works fine with earlier versions (SA 3.1.1/MS > 4.53.8). > > I think it is the same kind of problem that Wilson is experiencing in MCP. > It identifies MCP, but then may be a reporting problem ! > > Thanks and regards, > > Lasantha. > > > *-------- Original Message --------* > *Subject: * RES: mcp help > *Date: * Tue, 29/May/2007 4:39:25 AM +0550 > *From: * "Wilson A. Galafassi Jr." > *To: * "'MailScanner discussion'" > > > >> spamassassin --D --lint > >> > /tmp/sa.log 2>&1 > > > > >> This is the result. >> > > > > >> [root@netserver tmp]# cat sa.log >> > > >> [26391] dbg: logger: adding facilities: all >> > > >> [26391] dbg: logger: logging level is DBG >> > > >> [26391] dbg: generic: SpamAssassin version 3.2.0 >> > > >> [26391] dbg: config: score set 0 chosen. >> > > >> [26391] dbg: util: running in taint mode? yes >> > > >> [26391] dbg: util: taint mode: deleting unsafe environment >> > variables, > > >> resetting PATH >> > > > > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From steve.swaney at fsl.com Wed May 30 00:46:23 2007 From: steve.swaney at fsl.com (Stephen Swaney) Date: Wed May 30 00:47:06 2007 Subject: ANNOUNCE: BarricadeMX is released In-Reply-To: References: <54C6E1F0-01FF-4365-A395-D00BFED6C980@ecs.soton.ac.uk> <465C87FD.7090507@tc3net.com> <447401c7a230$fbdd1b10$f3975130$@swaney@fsl.com> Message-ID: <456601c7a24b$9104db50$b30e91f0$@swaney@fsl.com> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Res > Sent: Tuesday, May 29, 2007 5:30 PM > To: MailScanner discussion > Subject: RE: ANNOUNCE: BarricadeMX is released > > On Tue, 29 May 2007, Stephen Swaney wrote: > > > be OK soon. Please send email to info@fsl.com if you have any > questions or > > problems. > > > > Thanks, > > > > Steve > > Why only such limited distros? To protect your source code? > You truly restrict yourself to those who may wish to try/use > the product, very few networks in this part of the world use > anything but slackware and debian, and about 70% of the network > admins I know in the U.S are the same (with an equal high percent > using FreeBSD and slowaris) Res, It's a question of getting the most popular distributions out first. SuSE FreeBSD and Solaris will be out shortly. Porting is not terrible difficult but we're working very hard to package each distribution so that installation and upgrading is very, very simple :) Best regards, Steve Steve Swaney steve@fsl.com From alex at nkpanama.com Wed May 30 01:13:53 2007 From: alex at nkpanama.com (Alex Neuman) Date: Wed May 30 01:14:30 2007 Subject: Question... In-Reply-To: References: <177594.7833.qm@web26315.mail.ukl.yahoo.com> Message-ID: <465CC1C1.70605@nkpanama.com> While I agree with the line of reasoning you're using, I don't think I've ever considered anything you write down (or type up) to be private. You can only make it (trivially|reasonably|strongly) difficult for a third party to get to (for example, using encryption), but in the end the moment you express your thoughts in writing, "the cat's out of the bag". I think there's even something in the bible about secrets being "like putting a burning oil lamp under the bed" or something. It kind of parallels the situation of Jews who avoid writing the name of God on something perishable, out of respect for God. That being said, I agree that what you consider "private communication" should remain private unless there is proper reason to lift the protection of privacy that one would expect (or have a right to, depending on jurisdiction). Even so, I also believe there is merit in letting the users know that unless you properly protect (again, through whatever technological means are available) the content of your communication, there is always the possibility that someone will be able to intercept or alter it. Hugo van der Kooij wrote: > On Tue, 29 May 2007, Scott Silva wrote: > >> Andrew MacLachlan spake the following on 5/28/2007 5:33 PM: >>> Fabio - Which country are you in? >>> I have had one of my users complaining that this isn't legal in Italy >>> (!) - Seem like a crazy law... >>> Can anyone clarify this? >>> >> Just because a law seems crazy doesn't mean that a government won't >> pass it. > > A law that does garantue that private (e)mail remains private? Is that > a bad or crazy law? It must have come out of the dark ages for sure. > > Hugo. > From writetoashok at gmail.com Wed May 30 06:15:07 2007 From: writetoashok at gmail.com (ashok Kumar) Date: Wed May 30 06:15:11 2007 Subject: Forcing processing of mails in incomming queue In-Reply-To: <465C198F.3030103@nkpanama.com> References: <465C198F.3030103@nkpanama.com> Message-ID: > > I'm guessing it could be done using sendmail -v -qRexample.com -O > QueueDirectory=/var/spool/mqueue.in > ... > Thanks. That was exactly what i needed. Actually my purpose was to deliver some urgent mails of a particular domain, instead of waiting in the incoming queue for a long time to be processed. But i think here the mail is not being processed by MailScanner and is directly delivered by sendmail. Anyway the purpose is served. -- regards, Ashok. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070530/b52e2ac3/attachment.html From Jason at SYO.Com Wed May 30 09:40:18 2007 From: Jason at SYO.Com (Jason Gottschalk) Date: Wed May 30 09:39:34 2007 Subject: Approve/Deny outgoing e-mail ? In-Reply-To: <464372AA.2090906@ecs.soton.ac.uk> References: <1503721294.20070510094401@SYO.Com> <464372AA.2090906@ecs.soton.ac.uk> Message-ID: <1859700602.20070530044018@SYO.Com> Hello Julian, Looking for someone who can implement this for me. I have been trying for two weeks and cannot make it work. I've added a rule to archive.rules that successfully appends the messages in question to a mbox file, but it still delivers the message. It has become a real thorn in my side! Jason Thursday, May 10, 2007, 3:29:46 PM, you wrote: Julian> -----BEGIN PGP SIGNED MESSAGE----- Julian> Hash: SHA1 Julian> You could do this with a little ruleset and an external script that Julian> would show the admin each mail message and move it into the outgoing Julian> queue if it's 'approved'. Julian> Just use a ruleset that says that mail going to domains other than your Julian> own should go into /var/spool/mqueue.approval. Mail going to your domain Julian> goes straight into /var/spool/mqueue. Julian> The script would then show the messages in mqueue.approval to the admin, Julian> then if they are approved they are moved into mqueue (from where the MTA Julian> will then deliver them). Julian> Jason Gottschalk wrote: >> I know mailscanner can scan outgoing mail (when the user uses the host >> as his smtp server). Is there any mechanism in mailscanner to hold an >> outgoing message until it is reviewed by an administrator who would >> approve/deny the message and then release it? >> >> >> >> Julian> Jules Julian> - -- Julian> Julian Field MEng CITP Julian> www.MailScanner.info Julian> Buy the MailScanner book at www.MailScanner.info/store Julian> MailScanner customisation, or any advanced system administration help? Julian> Contact me at Jules@Jules.FM Julian> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 Julian> For all your IT requirements visit www.transtec.co.uk Julian> -----BEGIN PGP SIGNATURE----- Julian> Version: PGP Desktop 9.6.1 (Build 1012) Julian> Charset: ISO-8859-1 Julian> wj8DBQFGQ3OsEfZZRxQVtlQRAhWgAKDRMCFbCSWzncvbV1zsHnoxFN/cGQCdEyVp Julian> IUyhZgOVoITi/cvvX6l7zTw= Julian> =JBJd Julian> -----END PGP SIGNATURE----- Julian> -- Julian> This message has been scanned for viruses and Julian> dangerous content by MailScanner, and is Julian> believed to be clean. Julian> For all your IT requirements visit www.transtec.co.uk -- Best regards, Jason Gottschalk mailto:Jason@SYO.Com SYO Computer Engineering Services, Inc. 586-286-2557 From R.Sterenborg at netsourcing.nl Wed May 30 09:27:02 2007 From: R.Sterenborg at netsourcing.nl (Rob Sterenborg) Date: Wed May 30 09:59:35 2007 Subject: Denial of Service reports Message-ID: <74ACEB3E6A055643A89B8CEC74C7BF2488E04A@WISENT.dcyb.net> Hi all, Since last Weekend we're receiving numerous Denial of Service email-reports from Mailscanner (still 4.58) on legitimate email from and to our customers. When searching about this I found something with still_deliver_silent_viruses.rules containing "Virus: /Denial.of.Service/ yes" but I'm not really sure of what it does. Can someone please tell me: what exactly is triggering a Denial of Service? If I cannot avoid this from happening, is there a to turn this off? Thanks! Rob From MailScanner at ecs.soton.ac.uk Wed May 30 10:08:12 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 30 10:12:02 2007 Subject: RES: RES: RES: mcp help In-Reply-To: References: <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> <465BEEF0.6000505@gmail.com> <465C33C7.60403 01@ecs.soton.ac.uk> Message-ID: <465D3EFC.80300@ecs.soton.ac.uk> Copy over the *.pre files into the mcp directory. It's missing some LoadPlugin lines from the looks of it. Wilson A. Galafassi Jr. wrote: > I have tried to upgrade to latest beta version and the error in mcp checks > persist. > > check: no loaded plugin implements 'check_main': cannot scan! at > /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin/PerMsgStatus.pm line 164. > > > Any help is apreciated. > > Thanks, > > Wilson > > -----Mensagem original----- > De: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field > Enviada em: ter?a-feira, 29 de maio de 2007 11:08 > Para: MailScanner discussion > Assunto: Re: RES: RES: mcp help > > Yes, but what about the setting > MCP Checks = yes > ? > Remember MCP is off by default. > > Wilson A. Galafassi Jr. wrote: > >> I have something wrong... any help is very apreciated! >> >> Thanks >> Wilson >> >> >> My mailscanner.cf >> >> First Check = mcp >> >> # The rest of these options are clones of the equivalent spam options >> MCP Required SpamAssassin Score = 1 >> MCP High SpamAssassin Score = 10 >> MCP Error Score = 1 >> >> MCP Header = X-%org-name%-MailScanner-MCPCheck: >> Non MCP Actions = deliver >> MCP Actions = store >> High Scoring MCP Actions = store >> Bounce MCP As Attachment = no >> >> MCP Modify Subject = start >> MCP Subject Text = {MCP?} >> High Scoring MCP Modify Subject = start >> High Scoring MCP Subject Text = {MCP?} >> >> Is Definitely MCP = no >> Is Definitely Not MCP = no >> Definite MCP Is High Scoring = yes >> Always Include MCP Report = yes >> Detailed MCP Report = yes >> Include Scores In MCP Report = yes >> Log MCP = yes >> >> MCP Max SpamAssassin Timeouts = 20 >> MCP Max SpamAssassin Size = 100k >> MCP SpamAssassin Timeout = 10 >> >> MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf >> MCP SpamAssassin User State Dir = /var/spool/MailScanner/mcp >> MCP SpamAssassin Local Rules Dir = %mcp-dir% >> MCP SpamAssassin Default Rules Dir = %mcp-dir% >> MCP SpamAssassin Install Prefix = %mcp-dir% >> Recipient MCP Report = %report-dir%/recipient.mcp.report.txt >> Sender MCP Report = %report-dir%/sender.mcp.report.txt >> >> >> My test mail: >> >> >From wilson@ftpmanager.com Tue May 29 10:19:42 2007 >> Return-Path: >> X-Original-To: wilson@ftpmanager.com >> Delivered-To: wilson@ftpmanager.com >> Received: from sdxp (unknown [192.168.0.1]) >> by netserver.ftpmanager.com (Postfix) with SMTP id 1784D107F90 >> for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) >> Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> >> From: "Wilson - FTP" >> To: >> Subject: teste >> Date: Tue, 29 May 2007 10:19:11 -0300 >> MIME-Version: 1.0 >> Content-Type: multipart/alternative; >> boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" >> X-Priority: 3 >> X-MSMail-Priority: Normal >> X-Mailer: Microsoft Outlook Express 6.00.2900.3028 >> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 >> X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for >> > more > >> information >> X-ftpmanagerbr_net-MailScanner: Found to be clean >> X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, >> requerido 1) >> X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanager.com >> X-Spam-Status: No >> >> This is a multi-part message in MIME format. >> >> ------=_NextPart_000_0005_01C7A1DA.CCACFD20 >> Content-Type: text/plain; >> charset="iso-8859-1" >> Content-Transfer-Encoding: quoted-printable >> >> Block this t?o >> >> >> My cf file: >> >> header MY_RULE_1 Subject =~ /block this phrase/i >> score MY_RULE_1 100 >> >> body MY_RULE_2 /Block this too/i >> score MY_RULE_2 100 >> >> body MY_RULE_3 /this\s*is\s*more\s*complicated/i >> score MY_RULE_3 100 >> >> >> body SAMPLE_RULE2 /this/i >> describe SAMPLE_RULE2 Banned body text >> score SAMPLE_RULE2 5 >> >> body LOCAL_DEMONSTRATION_RULE /test/ >> score LOCAL_DEMONSTRATION_RULE 100 >> describe LOCAL_DEMONSTRATION_RULE This is a simple test rule >> >> header LOCAL_DEMONSTRATION_SUBJECT Subject =~ /\btest\b/i >> score LOCAL_DEMONSTRATION_SUBJECT 100 >> >> >> The spamassassin test: >> >> spamassassin -C /etc/MailScanner/mcp -p >> /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < >> > teste.mail > >> [15603] dbg: logger: adding facilities: all >> [15603] dbg: logger: logging level is DBG >> [15603] dbg: generic: SpamAssassin version 3.2.0 >> [15603] dbg: config: score set 0 chosen. >> [15603] dbg: util: running in taint mode? yes >> [15603] dbg: util: taint mode: deleting unsafe environment variables, >> resetting PATH >> [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping >> [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping >> [15603] dbg: util: PATH included '/usr/local/sbin', keeping >> [15603] dbg: util: PATH included '/usr/local/bin', keeping >> [15603] dbg: util: PATH included '/sbin', keeping >> [15603] dbg: util: PATH included '/bin', keeping >> [15603] dbg: util: PATH included '/usr/sbin', keeping >> [15603] dbg: util: PATH included '/usr/bin', keeping >> [15603] dbg: util: PATH included '/root/bin', which doesn't exist, >> > dropping > >> [15603] dbg: util: final PATH set to: >> >> > /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b > >> in:/usr/sbin:/usr/bin >> [15603] dbg: dns: no ipv6 >> [15603] dbg: dns: is Net::DNS::Resolver available? yes >> [15603] dbg: dns: Net::DNS version: 0.59 >> [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre >> > files > >> [15603] dbg: config: read file /etc/mail/spamassassin/init.pre >> [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre >> [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre >> [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre >> [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files >> [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir >> [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf >> [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir >> [15603] dbg: config: read file /etc/mail/spamassassin/local.cf >> [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf >> [15603] dbg: config: using "/root/.spamassassin" for user state dir >> [15603] dbg: config: using >> "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file >> [15603] dbg: config: read file >> /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >> @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >> [15603] dbg: razor2: razor2 is not available >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC >> [15603] dbg: pyzor: network tests on, attempting Pyzor >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >> [15603] dbg: razor2: razor2 is not available >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC >> [15603] dbg: plugin: loading >> > Mail::SpamAssassin::Plugin::AutoLearnThreshold > >> from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject >> from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from >> @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from >> @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >> @INC >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already >> > registered > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >> > @INC > >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch >> > from > >> @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from >> @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >> @INC >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already >> > registered > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >> > @INC > >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >> [15603] dbg: razor2: razor2 is not available >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered >> [15603] dbg: conf: finish parsing >> [15603] dbg: plugin: >> > Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) > >> implements 'finish_parsing_end', priority 0 >> [15603] dbg: replacetags: replacing tags >> [15603] dbg: replacetags: done replacing tags >> [15603] dbg: config: score set 1 chosen. >> [15603] dbg: message: main message type: multipart/alternative >> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) >> implements 'check_start', priority 0 >> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) >> implements 'check_main', priority 0 >> [15603] dbg: conf: trusted_networks are not configured; it is recommended >> that you configure trusted_networks manually >> [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp >> by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= >> msa=0 ] >> [15603] dbg: received-header: 'from' 192.168.0.1 has private IP >> [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes >> msa? no >> [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= >> helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 >> id=1784D107F90 auth= msa=0 ] >> [15603] dbg: metadata: X-Spam-Relays-Untrusted: >> [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= >> helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 >> id=1784D107F90 auth= msa=0 ] >> [15603] dbg: metadata: X-Spam-Relays-External: >> [15603] dbg: plugin: >> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements >> 'extract_metadata', priority 0 >> [15603] dbg: metadata: X-Relay-Countries: >> [15603] dbg: message: ---- MIME PARSER START ---- >> [15603] dbg: message: parsing multipart, got boundary: >> ----=_NextPart_000_0005_01C7A1DA.CCACFD20 >> [15603] dbg: message: found part of type text/plain, boundary: >> ----=_NextPart_000_0005_01C7A1DA.CCACFD20 >> [15603] dbg: message: added part, type: text/plain >> [15603] dbg: message: parsing normal part >> [15603] dbg: message: ---- MIME PARSER END ---- >> [15603] dbg: message: decoding quoted-printable >> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) >> implements 'parsed_metadata', priority 0 >> [15603] dbg: plugin: >> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements >> 'parsed_metadata', priority 0 >> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) >> implements 'parsed_metadata', priority 0 >> [15603] dbg: dns: dns_available set to yes in config file, skipping test >> [15603] dbg: uridnsbl: domains to query: >> [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups >> [15603] dbg: check: running tests for priority: 0 >> [15603] dbg: rules: running head tests; score so far=0 >> [15603] dbg: rules: compiled head tests >> [15603] dbg: rules: running body tests; score so far=0 >> [15603] dbg: rules: compiled body tests >> [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got >> > hit: > >> "test" >> [15603] dbg: rules: running uri tests; score so far=100 >> [15603] dbg: rules: compiled uri tests >> [15603] dbg: rules: running rawbody tests; score so far=100 >> [15603] dbg: rules: compiled rawbody tests >> [15603] dbg: rules: running full tests; score so far=100 >> [15603] dbg: rules: compiled full tests >> [15603] dbg: rules: running meta tests; score so far=100 >> [15603] dbg: rules: compiled meta tests >> [15603] dbg: check: is spam? score=100 required=5 >> [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE >> [15603] dbg: check: subtests= >> >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 >> Received: from localhost by netserver.ftpmanagerbr.net >> with SpamAssassin (version 3.2.0); >> Tue, 29 May 2007 10:28:40 -0300 >> From: "Wilson - FTP" >> To: >> Subject: teste >> Date: Tue, 29 May 2007 10:19:11 -0300 >> Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> >> X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on >> netserver.ftpmanagerbr.net >> MIME-Version: 1.0 >> Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" >> >> This is a multi-part message in MIME format. >> >> ------------=_465C2A88.4A78356A >> Content-Type: text/plain; charset=iso-8859-1 >> Content-Disposition: inline >> Content-Transfer-Encoding: 8bit >> >> (no report template found) >> >> >> >> ------------=_465C2A88.4A78356A >> Content-Type: message/rfc822; x-spam-type=original >> Content-Description: original message before SpamAssassin >> Content-Disposition: attachment >> Content-Transfer-Encoding: 8bit >> >> Return-Path: >> X-Original-To: wilson@ftpmanagerbr.net >> Delivered-To: wilson@ftpmanagerbr.net >> Received: from sdxp (unknown [192.168.0.1]) >> by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 >> for ; Tue, 29 May 2007 10:19:27 -0300 >> > (BRT) > >> Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> >> From: "Wilson - FTP" >> To: >> Subject: teste >> Date: Tue, 29 May 2007 10:19:11 -0300 >> MIME-Version: 1.0 >> Content-Type: multipart/alternative; >> boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" >> X-Priority: 3 >> X-MSMail-Priority: Normal >> X-Mailer: Microsoft Outlook Express 6.00.2900.3028 >> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 >> X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for >> > more > >> information >> X-ftpmanagerbr_net-MailScanner: Found to be clean >> X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, >> requerido 1) >> X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net >> X-Spam-Status: No >> >> This is a multi-part message in MIME format. >> >> ------=_NextPart_000_0005_01C7A1DA.CCACFD20 >> Content-Type: text/plain; >> charset="iso-8859-1" >> Content-Transfer-Encoding: quoted-printable >> >> Block this too >> >> ------------=_465C2A88.4A78356A-- >> >> (no report template found) spamassassin -C /etc/MailScanner/mcp -p >> /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < >> > teste.mail > >> [15603] dbg: logger: adding facilities: all >> [15603] dbg: logger: logging level is DBG >> [15603] dbg: generic: SpamAssassin version 3.2.0 >> [15603] dbg: config: score set 0 chosen. >> [15603] dbg: util: running in taint mode? yes >> [15603] dbg: util: taint mode: deleting unsafe environment variables, >> resetting PATH >> [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping >> [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping >> [15603] dbg: util: PATH included '/usr/local/sbin', keeping >> [15603] dbg: util: PATH included '/usr/local/bin', keeping >> [15603] dbg: util: PATH included '/sbin', keeping >> [15603] dbg: util: PATH included '/bin', keeping >> [15603] dbg: util: PATH included '/usr/sbin', keeping >> [15603] dbg: util: PATH included '/usr/bin', keeping >> [15603] dbg: util: PATH included '/root/bin', which doesn't exist, >> > dropping > >> [15603] dbg: util: final PATH set to: >> >> > /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b > >> in:/usr/sbin:/usr/bin >> [15603] dbg: dns: no ipv6 >> [15603] dbg: dns: is Net::DNS::Resolver available? yes >> [15603] dbg: dns: Net::DNS version: 0.59 >> [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre >> > files > >> [15603] dbg: config: read file /etc/mail/spamassassin/init.pre >> [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre >> [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre >> [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre >> [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files >> [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir >> [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf >> [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir >> [15603] dbg: config: read file /etc/mail/spamassassin/local.cf >> [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf >> [15603] dbg: config: using "/root/.spamassassin" for user state dir >> [15603] dbg: config: using >> "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file >> [15603] dbg: config: read file >> /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >> @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >> [15603] dbg: razor2: razor2 is not available >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC >> [15603] dbg: pyzor: network tests on, attempting Pyzor >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >> [15603] dbg: razor2: razor2 is not available >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC >> [15603] dbg: plugin: loading >> > Mail::SpamAssassin::Plugin::AutoLearnThreshold > >> from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject >> from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from >> @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from >> @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >> @INC >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already >> > registered > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >> > @INC > >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch >> > from > >> @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from >> @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from >> > @INC > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >> @INC >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already >> > registered > >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >> > @INC > >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >> [15603] dbg: razor2: razor2 is not available >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered >> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >> [15603] dbg: plugin: did not register >> Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered >> [15603] dbg: conf: finish parsing >> [15603] dbg: plugin: >> > Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) > >> implements 'finish_parsing_end', priority 0 >> [15603] dbg: replacetags: replacing tags >> [15603] dbg: replacetags: done replacing tags >> [15603] dbg: config: score set 1 chosen. >> [15603] dbg: message: main message type: multipart/alternative >> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) >> implements 'check_start', priority 0 >> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) >> implements 'check_main', priority 0 >> [15603] dbg: conf: trusted_networks are not configured; it is recommended >> that you configure trusted_networks manually >> [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp >> by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= >> msa=0 ] >> [15603] dbg: received-header: 'from' 192.168.0.1 has private IP >> [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes >> msa? no >> [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= >> helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 >> id=1784D107F90 auth= msa=0 ] >> [15603] dbg: metadata: X-Spam-Relays-Untrusted: >> [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= >> helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 >> id=1784D107F90 auth= msa=0 ] >> [15603] dbg: metadata: X-Spam-Relays-External: >> [15603] dbg: plugin: >> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements >> 'extract_metadata', priority 0 >> [15603] dbg: metadata: X-Relay-Countries: >> [15603] dbg: message: ---- MIME PARSER START ---- >> [15603] dbg: message: parsing multipart, got boundary: >> ----=_NextPart_000_0005_01C7A1DA.CCACFD20 >> [15603] dbg: message: found part of type text/plain, boundary: >> ----=_NextPart_000_0005_01C7A1DA.CCACFD20 >> [15603] dbg: message: added part, type: text/plain >> [15603] dbg: message: parsing normal part >> [15603] dbg: message: ---- MIME PARSER END ---- >> [15603] dbg: message: decoding quoted-printable >> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) >> implements 'parsed_metadata', priority 0 >> [15603] dbg: plugin: >> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements >> 'parsed_metadata', priority 0 >> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) >> implements 'parsed_metadata', priority 0 >> [15603] dbg: dns: dns_available set to yes in config file, skipping test >> [15603] dbg: uridnsbl: domains to query: >> [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups >> [15603] dbg: check: running tests for priority: 0 >> [15603] dbg: rules: running head tests; score so far=0 >> [15603] dbg: rules: compiled head tests >> [15603] dbg: rules: running body tests; score so far=0 >> [15603] dbg: rules: compiled body tests >> [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got >> > hit: > >> "test" >> [15603] dbg: rules: running uri tests; score so far=100 >> [15603] dbg: rules: compiled uri tests >> [15603] dbg: rules: running rawbody tests; score so far=100 >> [15603] dbg: rules: compiled rawbody tests >> [15603] dbg: rules: running full tests; score so far=100 >> [15603] dbg: rules: compiled full tests >> [15603] dbg: rules: running meta tests; score so far=100 >> [15603] dbg: rules: compiled meta tests >> [15603] dbg: check: is spam? score=100 required=5 >> [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE >> [15603] dbg: check: subtests= >> >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 >> Received: from localhost by netserver.ftpmanagerbr.net >> with SpamAssassin (version 3.2.0); >> Tue, 29 May 2007 10:28:40 -0300 >> From: "Wilson - FTP" >> To: >> Subject: teste >> Date: Tue, 29 May 2007 10:19:11 -0300 >> Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> >> X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on >> netserver.ftpmanagerbr.net >> MIME-Version: 1.0 >> Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" >> >> This is a multi-part message in MIME format. >> >> ------------=_465C2A88.4A78356A >> Content-Type: text/plain; charset=iso-8859-1 >> Content-Disposition: inline >> Content-Transfer-Encoding: 8bit >> >> (no report template found) >> >> >> >> ------------=_465C2A88.4A78356A >> Content-Type: message/rfc822; x-spam-type=original >> Content-Description: original message before SpamAssassin >> Content-Disposition: attachment >> Content-Transfer-Encoding: 8bit >> >> Return-Path: >> X-Original-To: wilson@ftpmanagerbr.net >> Delivered-To: wilson@ftpmanagerbr.net >> Received: from sdxp (unknown [192.168.0.1]) >> by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 >> for ; Tue, 29 May 2007 10:19:27 -0300 >> > (BRT) > >> Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> >> From: "Wilson - FTP" >> To: >> Subject: teste >> Date: Tue, 29 May 2007 10:19:11 -0300 >> MIME-Version: 1.0 >> Content-Type: multipart/alternative; >> boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" >> X-Priority: 3 >> X-MSMail-Priority: Normal >> X-Mailer: Microsoft Outlook Express 6.00.2900.3028 >> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 >> X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for >> > more > >> information >> X-ftpmanagerbr_net-MailScanner: Found to be clean >> X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, >> requerido 1) >> X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net >> X-Spam-Status: No >> >> This is a multi-part message in MIME format. >> >> ------=_NextPart_000_0005_01C7A1DA.CCACFD20 >> Content-Type: text/plain; >> charset="iso-8859-1" >> Content-Transfer-Encoding: quoted-printable >> >> Block this too >> >> ------------=_465C2A88.4A78356A-- >> >> (no report template found) >> >> >> De: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Lasantha >> Marian >> Enviada em: ter?a-feira, 29 de maio de 2007 06:14 >> Para: MailScanner discussion >> Assunto: Re: RES: mcp help >> >> Dear Julian, >> >> I have been experiencing some strange behaviors in my MCP setup (SA >> > 3.2.0/MS > >> 4.59.4) too, i.e. MCP setup works very fine when tested from command line >> > so > >> does SpamAssassin setup (from both ends; command line and from >> > MailScanner), > >> but MCP would not work properly from MailScanner. It would happily scan >> > but > >> does not report against customized MCP rules. MCP rules are properly >> > applied > >> and correct scores are shown when run from command line without any >> > errors. > >> The very same MCP rules set works fine with earlier versions (SA 3.1.1/MS >> 4.53.8). >> >> I think it is the same kind of problem that Wilson is experiencing in MCP. >> It identifies MCP, but then may be a reporting problem ! >> >> Thanks and regards, >> >> Lasantha. >> >> >> *-------- Original Message --------* >> *Subject: * RES: mcp help >> *Date: * Tue, 29/May/2007 4:39:25 AM +0550 >> *From: * "Wilson A. Galafassi Jr." >> *To: * "'MailScanner discussion'" >> >> >> >> >>> spamassassin --D --lint > >>> >>> >> /tmp/sa.log 2>&1 >> >> >> >> >> >>> This is the result. >>> >>> >> >> >> >> >>> [root@netserver tmp]# cat sa.log >>> >>> >> >> >>> [26391] dbg: logger: adding facilities: all >>> >>> >> >> >>> [26391] dbg: logger: logging level is DBG >>> >>> >> >> >>> [26391] dbg: generic: SpamAssassin version 3.2.0 >>> >>> >> >> >>> [26391] dbg: config: score set 0 chosen. >>> >>> >> >> >>> [26391] dbg: util: running in taint mode? yes >>> >>> >> >> >>> [26391] dbg: util: taint mode: deleting unsafe environment >>> >>> >> variables, >> >> >> >>> resetting PATH >>> >>> >> >> >> >> >> > > Jules > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070530/85cc642e/attachment.html From a.peacock at chime.ucl.ac.uk Wed May 30 10:25:17 2007 From: a.peacock at chime.ucl.ac.uk (Anthony Peacock) Date: Wed May 30 10:25:51 2007 Subject: RES: RES: RES: mcp help In-Reply-To: <465D3EFC.80300@ecs.soton.ac.uk> References: <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> <465BEEF0.6000505@gmail.com> <465C33C7.60403 01@ecs.soton.ac.uk> <465D3EFC.80300@ecs.soton.ac.uk> Message-ID: <465D42FD.60603@chime.ucl.ac.uk> Hi, Julian Field wrote: > Copy over the *.pre files into the mcp directory. It's missing some > LoadPlugin lines from the looks of it. > > Wilson A. Galafassi Jr. wrote: >> I have tried to upgrade to latest beta version and the error in mcp checks >> persist. >> >> check: no loaded plugin implements 'check_main': cannot scan! at >> /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin/PerMsgStatus.pm line 164. Specifically, you need to copy over v320.pre. The error you are seeing looks to me like you have upgraded to SA 3.2.0. As the check_main routine is now loaded as a plugin. If you are missing the load plugin line then the check_main routine will not be available. -- Anthony Peacock CHIME, Royal Free & University College Medical School WWW: http://www.chime.ucl.ac.uk/~rmhiajp/ "A CAT scan should take less time than a PET scan. For a CAT scan, they're only looking for one thing, whereas a PET scan could result in a lot of things." - Carl Princi, 2002/07/19 From r.berber at computer.org Wed May 30 11:04:35 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Wed May 30 11:05:07 2007 Subject: Denial of Service reports In-Reply-To: <74ACEB3E6A055643A89B8CEC74C7BF2488E04A@WISENT.dcyb.net> References: <74ACEB3E6A055643A89B8CEC74C7BF2488E04A@WISENT.dcyb.net> Message-ID: Rob Sterenborg wrote: [snip] > Can someone please tell me: what exactly is triggering a Denial of > Service? The anti virus timeouts. The mail log should be very explicit about what is happening. > If I cannot avoid this from happening, is there a to turn this > off? Fix your configuration... Guessing that you are using clamav, for instance changing from clamscan to clamdscan or the clamav perl module should improve performance. Or just use a larger timeout. -- Ren? Berber From x72m35 at gmail.com Wed May 30 11:34:32 2007 From: x72m35 at gmail.com (Lasantha Marian) Date: Wed May 30 11:31:48 2007 Subject: RES: RES: RES: mcp help In-Reply-To: <465D3EFC.80300@ecs.soton.ac.uk> References: <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> <465BEEF0.6000505@gmail.com> <465C33C7.60403 01@ecs.soton.ac.uk> <465D3EFC.80300@ecs.soton.ac.uk> Message-ID: <465D5338.2080608@gmail.com> Dear Julian, I too had the same problem, now it works perfect with just copying *.pre files. Thanks for the support. Best regards, Lasantha. *-------- Original Message --------* *Subject: * RES: RES: RES: mcp help *Date: * Wed, 30/May/2007 2:38:12 PM +0550 *From: * Julian Field *To: * MailScanner discussion > Copy over the *.pre files into the mcp directory. It's missing some > LoadPlugin lines from the looks of it. > > Wilson A. Galafassi Jr. wrote: >> I have tried to upgrade to latest beta version and the error in mcp checks >> persist. >> >> check: no loaded plugin implements 'check_main': cannot scan! at >> /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin/PerMsgStatus.pm line 164. >> >> >> Any help is apreciated. >> >> Thanks, >> >> Wilson >> >> -----Mensagem original----- >> De: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field >> Enviada em: ter?a-feira, 29 de maio de 2007 11:08 >> Para: MailScanner discussion >> Assunto: Re: RES: RES: mcp help >> >> Yes, but what about the setting >> MCP Checks = yes >> ? >> Remember MCP is off by default. >> >> Wilson A. Galafassi Jr. wrote: >> >>> I have something wrong... any help is very apreciated! >>> >>> Thanks >>> Wilson >>> >>> >>> My mailscanner.cf >>> >>> First Check = mcp >>> >>> # The rest of these options are clones of the equivalent spam options >>> MCP Required SpamAssassin Score = 1 >>> MCP High SpamAssassin Score = 10 >>> MCP Error Score = 1 >>> >>> MCP Header = X-%org-name%-MailScanner-MCPCheck: >>> Non MCP Actions = deliver >>> MCP Actions = store >>> High Scoring MCP Actions = store >>> Bounce MCP As Attachment = no >>> >>> MCP Modify Subject = start >>> MCP Subject Text = {MCP?} >>> High Scoring MCP Modify Subject = start >>> High Scoring MCP Subject Text = {MCP?} >>> >>> Is Definitely MCP = no >>> Is Definitely Not MCP = no >>> Definite MCP Is High Scoring = yes >>> Always Include MCP Report = yes >>> Detailed MCP Report = yes >>> Include Scores In MCP Report = yes >>> Log MCP = yes >>> >>> MCP Max SpamAssassin Timeouts = 20 >>> MCP Max SpamAssassin Size = 100k >>> MCP SpamAssassin Timeout = 10 >>> >>> MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf >>> MCP SpamAssassin User State Dir = /var/spool/MailScanner/mcp >>> MCP SpamAssassin Local Rules Dir = %mcp-dir% >>> MCP SpamAssassin Default Rules Dir = %mcp-dir% >>> MCP SpamAssassin Install Prefix = %mcp-dir% >>> Recipient MCP Report = %report-dir%/recipient.mcp.report.txt >>> Sender MCP Report = %report-dir%/sender.mcp.report.txt >>> >>> >>> My test mail: >>> >>> >From wilson@ftpmanager.com Tue May 29 10:19:42 2007 >>> Return-Path: >>> X-Original-To: wilson@ftpmanager.com >>> Delivered-To: wilson@ftpmanager.com >>> Received: from sdxp (unknown [192.168.0.1]) >>> by netserver.ftpmanager.com (Postfix) with SMTP id 1784D107F90 >>> for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) >>> Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> >>> From: "Wilson - FTP" >>> To: >>> Subject: teste >>> Date: Tue, 29 May 2007 10:19:11 -0300 >>> MIME-Version: 1.0 >>> Content-Type: multipart/alternative; >>> boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" >>> X-Priority: 3 >>> X-MSMail-Priority: Normal >>> X-Mailer: Microsoft Outlook Express 6.00.2900.3028 >>> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 >>> X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for >>> >> more >> >>> information >>> X-ftpmanagerbr_net-MailScanner: Found to be clean >>> X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, >>> requerido 1) >>> X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanager.com >>> X-Spam-Status: No >>> >>> This is a multi-part message in MIME format. >>> >>> ------=_NextPart_000_0005_01C7A1DA.CCACFD20 >>> Content-Type: text/plain; >>> charset="iso-8859-1" >>> Content-Transfer-Encoding: quoted-printable >>> >>> Block this t?o >>> >>> >>> My cf file: >>> >>> header MY_RULE_1 Subject =~ /block this phrase/i >>> score MY_RULE_1 100 >>> >>> body MY_RULE_2 /Block this too/i >>> score MY_RULE_2 100 >>> >>> body MY_RULE_3 /this\s*is\s*more\s*complicated/i >>> score MY_RULE_3 100 >>> >>> >>> body SAMPLE_RULE2 /this/i >>> describe SAMPLE_RULE2 Banned body text >>> score SAMPLE_RULE2 5 >>> >>> body LOCAL_DEMONSTRATION_RULE /test/ >>> score LOCAL_DEMONSTRATION_RULE 100 >>> describe LOCAL_DEMONSTRATION_RULE This is a simple test rule >>> >>> header LOCAL_DEMONSTRATION_SUBJECT Subject =~ /\btest\b/i >>> score LOCAL_DEMONSTRATION_SUBJECT 100 >>> >>> >>> The spamassassin test: >>> >>> spamassassin -C /etc/MailScanner/mcp -p >>> /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < >>> >> teste.mail >> >>> [15603] dbg: logger: adding facilities: all >>> [15603] dbg: logger: logging level is DBG >>> [15603] dbg: generic: SpamAssassin version 3.2.0 >>> [15603] dbg: config: score set 0 chosen. >>> [15603] dbg: util: running in taint mode? yes >>> [15603] dbg: util: taint mode: deleting unsafe environment variables, >>> resetting PATH >>> [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping >>> [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping >>> [15603] dbg: util: PATH included '/usr/local/sbin', keeping >>> [15603] dbg: util: PATH included '/usr/local/bin', keeping >>> [15603] dbg: util: PATH included '/sbin', keeping >>> [15603] dbg: util: PATH included '/bin', keeping >>> [15603] dbg: util: PATH included '/usr/sbin', keeping >>> [15603] dbg: util: PATH included '/usr/bin', keeping >>> [15603] dbg: util: PATH included '/root/bin', which doesn't exist, >>> >> dropping >> >>> [15603] dbg: util: final PATH set to: >>> >>> >> /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b >> >>> in:/usr/sbin:/usr/bin >>> [15603] dbg: dns: no ipv6 >>> [15603] dbg: dns: is Net::DNS::Resolver available? yes >>> [15603] dbg: dns: Net::DNS version: 0.59 >>> [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre >>> >> files >> >>> [15603] dbg: config: read file /etc/mail/spamassassin/init.pre >>> [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre >>> [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre >>> [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre >>> [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files >>> [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir >>> [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf >>> [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir >>> [15603] dbg: config: read file /etc/mail/spamassassin/local.cf >>> [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf >>> [15603] dbg: config: using "/root/.spamassassin" for user state dir >>> [15603] dbg: config: using >>> "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file >>> [15603] dbg: config: read file >>> /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >>> @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >>> [15603] dbg: razor2: razor2 is not available >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC >>> [15603] dbg: pyzor: network tests on, attempting Pyzor >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >>> [15603] dbg: razor2: razor2 is not available >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC >>> [15603] dbg: plugin: loading >>> >> Mail::SpamAssassin::Plugin::AutoLearnThreshold >> >>> from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject >>> from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from >>> @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from >>> @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >>> @INC >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already >>> >> registered >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >>> >> @INC >> >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch >>> >> from >> >>> @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from >>> @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >>> @INC >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already >>> >> registered >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >>> >> @INC >> >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >>> [15603] dbg: razor2: razor2 is not available >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered >>> [15603] dbg: conf: finish parsing >>> [15603] dbg: plugin: >>> >> Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) >> >>> implements 'finish_parsing_end', priority 0 >>> [15603] dbg: replacetags: replacing tags >>> [15603] dbg: replacetags: done replacing tags >>> [15603] dbg: config: score set 1 chosen. >>> [15603] dbg: message: main message type: multipart/alternative >>> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) >>> implements 'check_start', priority 0 >>> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) >>> implements 'check_main', priority 0 >>> [15603] dbg: conf: trusted_networks are not configured; it is recommended >>> that you configure trusted_networks manually >>> [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp >>> by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= >>> msa=0 ] >>> [15603] dbg: received-header: 'from' 192.168.0.1 has private IP >>> [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes >>> msa? no >>> [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= >>> helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 >>> id=1784D107F90 auth= msa=0 ] >>> [15603] dbg: metadata: X-Spam-Relays-Untrusted: >>> [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= >>> helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 >>> id=1784D107F90 auth= msa=0 ] >>> [15603] dbg: metadata: X-Spam-Relays-External: >>> [15603] dbg: plugin: >>> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements >>> 'extract_metadata', priority 0 >>> [15603] dbg: metadata: X-Relay-Countries: >>> [15603] dbg: message: ---- MIME PARSER START ---- >>> [15603] dbg: message: parsing multipart, got boundary: >>> ----=_NextPart_000_0005_01C7A1DA.CCACFD20 >>> [15603] dbg: message: found part of type text/plain, boundary: >>> ----=_NextPart_000_0005_01C7A1DA.CCACFD20 >>> [15603] dbg: message: added part, type: text/plain >>> [15603] dbg: message: parsing normal part >>> [15603] dbg: message: ---- MIME PARSER END ---- >>> [15603] dbg: message: decoding quoted-printable >>> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) >>> implements 'parsed_metadata', priority 0 >>> [15603] dbg: plugin: >>> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements >>> 'parsed_metadata', priority 0 >>> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) >>> implements 'parsed_metadata', priority 0 >>> [15603] dbg: dns: dns_available set to yes in config file, skipping test >>> [15603] dbg: uridnsbl: domains to query: >>> [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups >>> [15603] dbg: check: running tests for priority: 0 >>> [15603] dbg: rules: running head tests; score so far=0 >>> [15603] dbg: rules: compiled head tests >>> [15603] dbg: rules: running body tests; score so far=0 >>> [15603] dbg: rules: compiled body tests >>> [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got >>> >> hit: >> >>> "test" >>> [15603] dbg: rules: running uri tests; score so far=100 >>> [15603] dbg: rules: compiled uri tests >>> [15603] dbg: rules: running rawbody tests; score so far=100 >>> [15603] dbg: rules: compiled rawbody tests >>> [15603] dbg: rules: running full tests; score so far=100 >>> [15603] dbg: rules: compiled full tests >>> [15603] dbg: rules: running meta tests; score so far=100 >>> [15603] dbg: rules: compiled meta tests >>> [15603] dbg: check: is spam? score=100 required=5 >>> [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE >>> [15603] dbg: check: subtests= >>> >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 >>> Received: from localhost by netserver.ftpmanagerbr.net >>> with SpamAssassin (version 3.2.0); >>> Tue, 29 May 2007 10:28:40 -0300 >>> From: "Wilson - FTP" >>> To: >>> Subject: teste >>> Date: Tue, 29 May 2007 10:19:11 -0300 >>> Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> >>> X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on >>> netserver.ftpmanagerbr.net >>> MIME-Version: 1.0 >>> Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" >>> >>> This is a multi-part message in MIME format. >>> >>> ------------=_465C2A88.4A78356A >>> Content-Type: text/plain; charset=iso-8859-1 >>> Content-Disposition: inline >>> Content-Transfer-Encoding: 8bit >>> >>> (no report template found) >>> >>> >>> >>> ------------=_465C2A88.4A78356A >>> Content-Type: message/rfc822; x-spam-type=original >>> Content-Description: original message before SpamAssassin >>> Content-Disposition: attachment >>> Content-Transfer-Encoding: 8bit >>> >>> Return-Path: >>> X-Original-To: wilson@ftpmanagerbr.net >>> Delivered-To: wilson@ftpmanagerbr.net >>> Received: from sdxp (unknown [192.168.0.1]) >>> by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 >>> for ; Tue, 29 May 2007 10:19:27 -0300 >>> >> (BRT) >> >>> Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> >>> From: "Wilson - FTP" >>> To: >>> Subject: teste >>> Date: Tue, 29 May 2007 10:19:11 -0300 >>> MIME-Version: 1.0 >>> Content-Type: multipart/alternative; >>> boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" >>> X-Priority: 3 >>> X-MSMail-Priority: Normal >>> X-Mailer: Microsoft Outlook Express 6.00.2900.3028 >>> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 >>> X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for >>> >> more >> >>> information >>> X-ftpmanagerbr_net-MailScanner: Found to be clean >>> X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, >>> requerido 1) >>> X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net >>> X-Spam-Status: No >>> >>> This is a multi-part message in MIME format. >>> >>> ------=_NextPart_000_0005_01C7A1DA.CCACFD20 >>> Content-Type: text/plain; >>> charset="iso-8859-1" >>> Content-Transfer-Encoding: quoted-printable >>> >>> Block this too >>> >>> ------------=_465C2A88.4A78356A-- >>> >>> (no report template found) spamassassin -C /etc/MailScanner/mcp -p >>> /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < >>> >> teste.mail >> >>> [15603] dbg: logger: adding facilities: all >>> [15603] dbg: logger: logging level is DBG >>> [15603] dbg: generic: SpamAssassin version 3.2.0 >>> [15603] dbg: config: score set 0 chosen. >>> [15603] dbg: util: running in taint mode? yes >>> [15603] dbg: util: taint mode: deleting unsafe environment variables, >>> resetting PATH >>> [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping >>> [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping >>> [15603] dbg: util: PATH included '/usr/local/sbin', keeping >>> [15603] dbg: util: PATH included '/usr/local/bin', keeping >>> [15603] dbg: util: PATH included '/sbin', keeping >>> [15603] dbg: util: PATH included '/bin', keeping >>> [15603] dbg: util: PATH included '/usr/sbin', keeping >>> [15603] dbg: util: PATH included '/usr/bin', keeping >>> [15603] dbg: util: PATH included '/root/bin', which doesn't exist, >>> >> dropping >> >>> [15603] dbg: util: final PATH set to: >>> >>> >> /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b >> >>> in:/usr/sbin:/usr/bin >>> [15603] dbg: dns: no ipv6 >>> [15603] dbg: dns: is Net::DNS::Resolver available? yes >>> [15603] dbg: dns: Net::DNS version: 0.59 >>> [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre >>> >> files >> >>> [15603] dbg: config: read file /etc/mail/spamassassin/init.pre >>> [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre >>> [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre >>> [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre >>> [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files >>> [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir >>> [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf >>> [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir >>> [15603] dbg: config: read file /etc/mail/spamassassin/local.cf >>> [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf >>> [15603] dbg: config: using "/root/.spamassassin" for user state dir >>> [15603] dbg: config: using >>> "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file >>> [15603] dbg: config: read file >>> /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >>> @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >>> [15603] dbg: razor2: razor2 is not available >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC >>> [15603] dbg: pyzor: network tests on, attempting Pyzor >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >>> [15603] dbg: razor2: razor2 is not available >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC >>> [15603] dbg: plugin: loading >>> >> Mail::SpamAssassin::Plugin::AutoLearnThreshold >> >>> from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject >>> from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from >>> @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from >>> @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >>> @INC >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already >>> >> registered >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >>> >> @INC >> >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch >>> >> from >> >>> @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from >>> @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from >>> >> @INC >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >>> @INC >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already >>> >> registered >> >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >>> >> @INC >> >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >>> [15603] dbg: razor2: razor2 is not available >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered >>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >>> [15603] dbg: plugin: did not register >>> Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered >>> [15603] dbg: conf: finish parsing >>> [15603] dbg: plugin: >>> >> Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) >> >>> implements 'finish_parsing_end', priority 0 >>> [15603] dbg: replacetags: replacing tags >>> [15603] dbg: replacetags: done replacing tags >>> [15603] dbg: config: score set 1 chosen. >>> [15603] dbg: message: main message type: multipart/alternative >>> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) >>> implements 'check_start', priority 0 >>> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) >>> implements 'check_main', priority 0 >>> [15603] dbg: conf: trusted_networks are not configured; it is recommended >>> that you configure trusted_networks manually >>> [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp >>> by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= >>> msa=0 ] >>> [15603] dbg: received-header: 'from' 192.168.0.1 has private IP >>> [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes >>> msa? no >>> [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= >>> helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 >>> id=1784D107F90 auth= msa=0 ] >>> [15603] dbg: metadata: X-Spam-Relays-Untrusted: >>> [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= >>> helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 >>> id=1784D107F90 auth= msa=0 ] >>> [15603] dbg: metadata: X-Spam-Relays-External: >>> [15603] dbg: plugin: >>> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements >>> 'extract_metadata', priority 0 >>> [15603] dbg: metadata: X-Relay-Countries: >>> [15603] dbg: message: ---- MIME PARSER START ---- >>> [15603] dbg: message: parsing multipart, got boundary: >>> ----=_NextPart_000_0005_01C7A1DA.CCACFD20 >>> [15603] dbg: message: found part of type text/plain, boundary: >>> ----=_NextPart_000_0005_01C7A1DA.CCACFD20 >>> [15603] dbg: message: added part, type: text/plain >>> [15603] dbg: message: parsing normal part >>> [15603] dbg: message: ---- MIME PARSER END ---- >>> [15603] dbg: message: decoding quoted-printable >>> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) >>> implements 'parsed_metadata', priority 0 >>> [15603] dbg: plugin: >>> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements >>> 'parsed_metadata', priority 0 >>> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) >>> implements 'parsed_metadata', priority 0 >>> [15603] dbg: dns: dns_available set to yes in config file, skipping test >>> [15603] dbg: uridnsbl: domains to query: >>> [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups >>> [15603] dbg: check: running tests for priority: 0 >>> [15603] dbg: rules: running head tests; score so far=0 >>> [15603] dbg: rules: compiled head tests >>> [15603] dbg: rules: running body tests; score so far=0 >>> [15603] dbg: rules: compiled body tests >>> [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got >>> >> hit: >> >>> "test" >>> [15603] dbg: rules: running uri tests; score so far=100 >>> [15603] dbg: rules: compiled uri tests >>> [15603] dbg: rules: running rawbody tests; score so far=100 >>> [15603] dbg: rules: compiled rawbody tests >>> [15603] dbg: rules: running full tests; score so far=100 >>> [15603] dbg: rules: compiled full tests >>> [15603] dbg: rules: running meta tests; score so far=100 >>> [15603] dbg: rules: compiled meta tests >>> [15603] dbg: check: is spam? score=100 required=5 >>> [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE >>> [15603] dbg: check: subtests= >>> >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 >>> Received: from localhost by netserver.ftpmanagerbr.net >>> with SpamAssassin (version 3.2.0); >>> Tue, 29 May 2007 10:28:40 -0300 >>> From: "Wilson - FTP" >>> To: >>> Subject: teste >>> Date: Tue, 29 May 2007 10:19:11 -0300 >>> Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> >>> X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on >>> netserver.ftpmanagerbr.net >>> MIME-Version: 1.0 >>> Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" >>> >>> This is a multi-part message in MIME format. >>> >>> ------------=_465C2A88.4A78356A >>> Content-Type: text/plain; charset=iso-8859-1 >>> Content-Disposition: inline >>> Content-Transfer-Encoding: 8bit >>> >>> (no report template found) >>> >>> >>> >>> ------------=_465C2A88.4A78356A >>> Content-Type: message/rfc822; x-spam-type=original >>> Content-Description: original message before SpamAssassin >>> Content-Disposition: attachment >>> Content-Transfer-Encoding: 8bit >>> >>> Return-Path: >>> X-Original-To: wilson@ftpmanagerbr.net >>> Delivered-To: wilson@ftpmanagerbr.net >>> Received: from sdxp (unknown [192.168.0.1]) >>> by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 >>> for ; Tue, 29 May 2007 10:19:27 -0300 >>> >> (BRT) >> >>> Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> >>> From: "Wilson - FTP" >>> To: >>> Subject: teste >>> Date: Tue, 29 May 2007 10:19:11 -0300 >>> MIME-Version: 1.0 >>> Content-Type: multipart/alternative; >>> boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" >>> X-Priority: 3 >>> X-MSMail-Priority: Normal >>> X-Mailer: Microsoft Outlook Express 6.00.2900.3028 >>> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 >>> X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for >>> >> more >> >>> information >>> X-ftpmanagerbr_net-MailScanner: Found to be clean >>> X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, >>> requerido 1) >>> X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net >>> X-Spam-Status: No >>> >>> This is a multi-part message in MIME format. >>> >>> ------=_NextPart_000_0005_01C7A1DA.CCACFD20 >>> Content-Type: text/plain; >>> charset="iso-8859-1" >>> Content-Transfer-Encoding: quoted-printable >>> >>> Block this too >>> >>> ------------=_465C2A88.4A78356A-- >>> >>> (no report template found) >>> >>> >>> De: mailscanner-bounces@lists.mailscanner.info >>> [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Lasantha >>> Marian >>> Enviada em: ter?a-feira, 29 de maio de 2007 06:14 >>> Para: MailScanner discussion >>> Assunto: Re: RES: mcp help >>> >>> Dear Julian, >>> >>> I have been experiencing some strange behaviors in my MCP setup (SA >>> >> 3.2.0/MS >> >>> 4.59.4) too, i.e. MCP setup works very fine when tested from command line >>> >> so >> >>> does SpamAssassin setup (from both ends; command line and from >>> >> MailScanner), >> >>> but MCP would not work properly from MailScanner. It would happily scan >>> >> but >> >>> does not report against customized MCP rules. MCP rules are properly >>> >> applied >> >>> and correct scores are shown when run from command line without any >>> >> errors. >> >>> The very same MCP rules set works fine with earlier versions (SA 3.1.1/MS >>> 4.53.8). >>> >>> I think it is the same kind of problem that Wilson is experiencing in MCP. >>> It identifies MCP, but then may be a reporting problem ! >>> >>> Thanks and regards, >>> >>> Lasantha. >>> >>> >>> *-------- Original Message --------* >>> *Subject: * RES: mcp help >>> *Date: * Tue, 29/May/2007 4:39:25 AM +0550 >>> *From: * "Wilson A. Galafassi Jr." >>> *To: * "'MailScanner discussion'" >>> >>> >>> >>> >>>> spamassassin --D --lint > >>>> >>>> >>> /tmp/sa.log 2>&1 >>> >>> >>> >>> >>> >>>> This is the result. >>>> >>>> >>> >>> >>> >>> >>>> [root@netserver tmp]# cat sa.log >>>> >>>> >>> >>> >>>> [26391] dbg: logger: adding facilities: all >>>> >>>> >>> >>> >>>> [26391] dbg: logger: logging level is DBG >>>> >>>> >>> >>> >>>> [26391] dbg: generic: SpamAssassin version 3.2.0 >>>> >>>> >>> >>> >>>> [26391] dbg: config: score set 0 chosen. >>>> >>>> >>> >>> >>>> [26391] dbg: util: running in taint mode? yes >>>> >>>> >>> >>> >>>> [26391] dbg: util: taint mode: deleting unsafe environment >>>> >>>> >>> variables, >>> >>> >>> >>>> resetting PATH >>>> >>>> >>> >>> >>> >>> >> >> Jules >> >> > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > -- > This message has been scanned for viruses and > dangerous content by *MailScanner* , and is > believed to be clean. > For all you IT requirements visit transtec Computers > . -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070530/5dd198a0/attachment.html From wilson.galafassi at gmail.com Wed May 30 11:42:00 2007 From: wilson.galafassi at gmail.com (Wilson A. Galafassi Jr.) Date: Wed May 30 11:43:33 2007 Subject: RES: RES: RES: RES: mcp help In-Reply-To: <465D3EFC.80300@ecs.soton.ac.uk> References: <465AE999.8040005@ecs.soton.ac.uk> <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> <465BEEF0.6000505@gmail.com> <465C33C7.60403 01@ecs.soton.ac.uk> <465D3EFC.80300@ecs.so ton.ac.uk> Message-ID: Very thanks Julian now is working. Thanks alot. You are the man!!!! Wilson De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field Enviada em: quarta-feira, 30 de maio de 2007 06:08 Para: MailScanner discussion Assunto: Re: RES: RES: RES: mcp help Copy over the *.pre files into the mcp directory. It's missing some LoadPlugin lines from the looks of it. Wilson A. Galafassi Jr. wrote: I have tried to upgrade to latest beta version and the error in mcp checks persist. check: no loaded plugin implements 'check_main': cannot scan! at /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin/PerMsgStatus.pm line 164. Any help is apreciated. Thanks, Wilson -----Mensagem original----- De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field Enviada em: ter?a-feira, 29 de maio de 2007 11:08 Para: MailScanner discussion Assunto: Re: RES: RES: mcp help Yes, but what about the setting MCP Checks = yes ? Remember MCP is off by default. Wilson A. Galafassi Jr. wrote: I have something wrong... any help is very apreciated! Thanks Wilson My mailscanner.cf First Check = mcp # The rest of these options are clones of the equivalent spam options MCP Required SpamAssassin Score = 1 MCP High SpamAssassin Score = 10 MCP Error Score = 1 MCP Header = X-%org-name%-MailScanner-MCPCheck: Non MCP Actions = deliver MCP Actions = store High Scoring MCP Actions = store Bounce MCP As Attachment = no MCP Modify Subject = start MCP Subject Text = {MCP?} High Scoring MCP Modify Subject = start High Scoring MCP Subject Text = {MCP?} Is Definitely MCP = no Is Definitely Not MCP = no Definite MCP Is High Scoring = yes Always Include MCP Report = yes Detailed MCP Report = yes Include Scores In MCP Report = yes Log MCP = yes MCP Max SpamAssassin Timeouts = 20 MCP Max SpamAssassin Size = 100k MCP SpamAssassin Timeout = 10 MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf MCP SpamAssassin User State Dir = /var/spool/MailScanner/mcp MCP SpamAssassin Local Rules Dir = %mcp-dir% MCP SpamAssassin Default Rules Dir = %mcp-dir% MCP SpamAssassin Install Prefix = %mcp-dir% Recipient MCP Report = %report-dir%/recipient.mcp.report.txt Sender MCP Report = %report-dir%/sender.mcp.report.txt My test mail: >From wilson@ftpmanager.com Tue May 29 10:19:42 2007 Return-Path: X-Original-To: wilson@ftpmanager.com Delivered-To: wilson@ftpmanager.com Received: from sdxp (unknown [192.168.0.1]) by netserver.ftpmanager.com (Postfix) with SMTP id 1784D107F90 for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> From: "Wilson - FTP" To: Subject: teste Date: Tue, 29 May 2007 10:19:11 -0300 MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2900.3028 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more information X-ftpmanagerbr_net-MailScanner: Found to be clean X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, requerido 1) X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanager.com X-Spam-Status: No This is a multi-part message in MIME format. ------=_NextPart_000_0005_01C7A1DA.CCACFD20 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Block this t?o My cf file: header MY_RULE_1 Subject =~ /block this phrase/i score MY_RULE_1 100 body MY_RULE_2 /Block this too/i score MY_RULE_2 100 body MY_RULE_3 /this\s*is\s*more\s*complicated/i score MY_RULE_3 100 body SAMPLE_RULE2 /this/i describe SAMPLE_RULE2 Banned body text score SAMPLE_RULE2 5 body LOCAL_DEMONSTRATION_RULE /test/ score LOCAL_DEMONSTRATION_RULE 100 describe LOCAL_DEMONSTRATION_RULE This is a simple test rule header LOCAL_DEMONSTRATION_SUBJECT Subject =~ /\btest\b/i score LOCAL_DEMONSTRATION_SUBJECT 100 The spamassassin test: spamassassin -C /etc/MailScanner/mcp -p /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < teste.mail [15603] dbg: logger: adding facilities: all [15603] dbg: logger: logging level is DBG [15603] dbg: generic: SpamAssassin version 3.2.0 [15603] dbg: config: score set 0 chosen. [15603] dbg: util: running in taint mode? yes [15603] dbg: util: taint mode: deleting unsafe environment variables, resetting PATH [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping [15603] dbg: util: PATH included '/usr/local/sbin', keeping [15603] dbg: util: PATH included '/usr/local/bin', keeping [15603] dbg: util: PATH included '/sbin', keeping [15603] dbg: util: PATH included '/bin', keeping [15603] dbg: util: PATH included '/usr/sbin', keeping [15603] dbg: util: PATH included '/usr/bin', keeping [15603] dbg: util: PATH included '/root/bin', which doesn't exist, dropping [15603] dbg: util: final PATH set to: /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b in:/usr/sbin:/usr/bin [15603] dbg: dns: no ipv6 [15603] dbg: dns: is Net::DNS::Resolver available? yes [15603] dbg: dns: Net::DNS version: 0.59 [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre files [15603] dbg: config: read file /etc/mail/spamassassin/init.pre [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir [15603] dbg: config: read file /etc/mail/spamassassin/local.cf [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf [15603] dbg: config: using "/root/.spamassassin" for user state dir [15603] dbg: config: using "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file [15603] dbg: config: read file /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [15603] dbg: razor2: razor2 is not available [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC [15603] dbg: pyzor: network tests on, attempting Pyzor [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [15603] dbg: razor2: razor2 is not available [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [15603] dbg: razor2: razor2 is not available [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered [15603] dbg: conf: finish parsing [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) implements 'finish_parsing_end', priority 0 [15603] dbg: replacetags: replacing tags [15603] dbg: replacetags: done replacing tags [15603] dbg: config: score set 1 chosen. [15603] dbg: message: main message type: multipart/alternative [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) implements 'check_start', priority 0 [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) implements 'check_main', priority 0 [15603] dbg: conf: trusted_networks are not configured; it is recommended that you configure trusted_networks manually [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= msa=0 ] [15603] dbg: received-header: 'from' 192.168.0.1 has private IP [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes msa? no [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 id=1784D107F90 auth= msa=0 ] [15603] dbg: metadata: X-Spam-Relays-Untrusted: [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 id=1784D107F90 auth= msa=0 ] [15603] dbg: metadata: X-Spam-Relays-External: [15603] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements 'extract_metadata', priority 0 [15603] dbg: metadata: X-Relay-Countries: [15603] dbg: message: ---- MIME PARSER START ---- [15603] dbg: message: parsing multipart, got boundary: ----=_NextPart_000_0005_01C7A1DA.CCACFD20 [15603] dbg: message: found part of type text/plain, boundary: ----=_NextPart_000_0005_01C7A1DA.CCACFD20 [15603] dbg: message: added part, type: text/plain [15603] dbg: message: parsing normal part [15603] dbg: message: ---- MIME PARSER END ---- [15603] dbg: message: decoding quoted-printable [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) implements 'parsed_metadata', priority 0 [15603] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements 'parsed_metadata', priority 0 [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) implements 'parsed_metadata', priority 0 [15603] dbg: dns: dns_available set to yes in config file, skipping test [15603] dbg: uridnsbl: domains to query: [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups [15603] dbg: check: running tests for priority: 0 [15603] dbg: rules: running head tests; score so far=0 [15603] dbg: rules: compiled head tests [15603] dbg: rules: running body tests; score so far=0 [15603] dbg: rules: compiled body tests [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got hit: "test" [15603] dbg: rules: running uri tests; score so far=100 [15603] dbg: rules: compiled uri tests [15603] dbg: rules: running rawbody tests; score so far=100 [15603] dbg: rules: compiled rawbody tests [15603] dbg: rules: running full tests; score so far=100 [15603] dbg: rules: compiled full tests [15603] dbg: rules: running meta tests; score so far=100 [15603] dbg: rules: compiled meta tests [15603] dbg: check: is spam? score=100 required=5 [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE [15603] dbg: check: subtests= >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 Received: from localhost by netserver.ftpmanagerbr.net with SpamAssassin (version 3.2.0); Tue, 29 May 2007 10:28:40 -0300 From: "Wilson - FTP" To: Subject: teste Date: Tue, 29 May 2007 10:19:11 -0300 Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on netserver.ftpmanagerbr.net MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" This is a multi-part message in MIME format. ------------=_465C2A88.4A78356A Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit (no report template found) ------------=_465C2A88.4A78356A Content-Type: message/rfc822; x-spam-type=original Content-Description: original message before SpamAssassin Content-Disposition: attachment Content-Transfer-Encoding: 8bit Return-Path: X-Original-To: wilson@ftpmanagerbr.net Delivered-To: wilson@ftpmanagerbr.net Received: from sdxp (unknown [192.168.0.1]) by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> From: "Wilson - FTP" To: Subject: teste Date: Tue, 29 May 2007 10:19:11 -0300 MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2900.3028 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more information X-ftpmanagerbr_net-MailScanner: Found to be clean X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, requerido 1) X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net X-Spam-Status: No This is a multi-part message in MIME format. ------=_NextPart_000_0005_01C7A1DA.CCACFD20 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Block this too ------------=_465C2A88.4A78356A-- (no report template found) spamassassin -C /etc/MailScanner/mcp -p /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < teste.mail [15603] dbg: logger: adding facilities: all [15603] dbg: logger: logging level is DBG [15603] dbg: generic: SpamAssassin version 3.2.0 [15603] dbg: config: score set 0 chosen. [15603] dbg: util: running in taint mode? yes [15603] dbg: util: taint mode: deleting unsafe environment variables, resetting PATH [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping [15603] dbg: util: PATH included '/usr/local/sbin', keeping [15603] dbg: util: PATH included '/usr/local/bin', keeping [15603] dbg: util: PATH included '/sbin', keeping [15603] dbg: util: PATH included '/bin', keeping [15603] dbg: util: PATH included '/usr/sbin', keeping [15603] dbg: util: PATH included '/usr/bin', keeping [15603] dbg: util: PATH included '/root/bin', which doesn't exist, dropping [15603] dbg: util: final PATH set to: /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b in:/usr/sbin:/usr/bin [15603] dbg: dns: no ipv6 [15603] dbg: dns: is Net::DNS::Resolver available? yes [15603] dbg: dns: Net::DNS version: 0.59 [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre files [15603] dbg: config: read file /etc/mail/spamassassin/init.pre [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir [15603] dbg: config: read file /etc/mail/spamassassin/local.cf [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf [15603] dbg: config: using "/root/.spamassassin" for user state dir [15603] dbg: config: using "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file [15603] dbg: config: read file /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [15603] dbg: razor2: razor2 is not available [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC [15603] dbg: pyzor: network tests on, attempting Pyzor [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [15603] dbg: razor2: razor2 is not available [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AutoLearnThreshold from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from @INC [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC [15603] dbg: razor2: razor2 is not available [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC [15603] dbg: plugin: did not register Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered [15603] dbg: conf: finish parsing [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) implements 'finish_parsing_end', priority 0 [15603] dbg: replacetags: replacing tags [15603] dbg: replacetags: done replacing tags [15603] dbg: config: score set 1 chosen. [15603] dbg: message: main message type: multipart/alternative [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) implements 'check_start', priority 0 [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) implements 'check_main', priority 0 [15603] dbg: conf: trusted_networks are not configured; it is recommended that you configure trusted_networks manually [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= msa=0 ] [15603] dbg: received-header: 'from' 192.168.0.1 has private IP [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes msa? no [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 id=1784D107F90 auth= msa=0 ] [15603] dbg: metadata: X-Spam-Relays-Untrusted: [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 id=1784D107F90 auth= msa=0 ] [15603] dbg: metadata: X-Spam-Relays-External: [15603] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements 'extract_metadata', priority 0 [15603] dbg: metadata: X-Relay-Countries: [15603] dbg: message: ---- MIME PARSER START ---- [15603] dbg: message: parsing multipart, got boundary: ----=_NextPart_000_0005_01C7A1DA.CCACFD20 [15603] dbg: message: found part of type text/plain, boundary: ----=_NextPart_000_0005_01C7A1DA.CCACFD20 [15603] dbg: message: added part, type: text/plain [15603] dbg: message: parsing normal part [15603] dbg: message: ---- MIME PARSER END ---- [15603] dbg: message: decoding quoted-printable [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) implements 'parsed_metadata', priority 0 [15603] dbg: plugin: Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements 'parsed_metadata', priority 0 [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) implements 'parsed_metadata', priority 0 [15603] dbg: dns: dns_available set to yes in config file, skipping test [15603] dbg: uridnsbl: domains to query: [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups [15603] dbg: check: running tests for priority: 0 [15603] dbg: rules: running head tests; score so far=0 [15603] dbg: rules: compiled head tests [15603] dbg: rules: running body tests; score so far=0 [15603] dbg: rules: compiled body tests [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got hit: "test" [15603] dbg: rules: running uri tests; score so far=100 [15603] dbg: rules: compiled uri tests [15603] dbg: rules: running rawbody tests; score so far=100 [15603] dbg: rules: compiled rawbody tests [15603] dbg: rules: running full tests; score so far=100 [15603] dbg: rules: compiled full tests [15603] dbg: rules: running meta tests; score so far=100 [15603] dbg: rules: compiled meta tests [15603] dbg: check: is spam? score=100 required=5 [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE [15603] dbg: check: subtests= >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 Received: from localhost by netserver.ftpmanagerbr.net with SpamAssassin (version 3.2.0); Tue, 29 May 2007 10:28:40 -0300 From: "Wilson - FTP" To: Subject: teste Date: Tue, 29 May 2007 10:19:11 -0300 Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on netserver.ftpmanagerbr.net MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" This is a multi-part message in MIME format. ------------=_465C2A88.4A78356A Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit (no report template found) ------------=_465C2A88.4A78356A Content-Type: message/rfc822; x-spam-type=original Content-Description: original message before SpamAssassin Content-Disposition: attachment Content-Transfer-Encoding: 8bit Return-Path: X-Original-To: wilson@ftpmanagerbr.net Delivered-To: wilson@ftpmanagerbr.net Received: from sdxp (unknown [192.168.0.1]) by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> From: "Wilson - FTP" To: Subject: teste Date: Tue, 29 May 2007 10:19:11 -0300 MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2900.3028 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for more information X-ftpmanagerbr_net-MailScanner: Found to be clean X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, requerido 1) X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net X-Spam-Status: No This is a multi-part message in MIME format. ------=_NextPart_000_0005_01C7A1DA.CCACFD20 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Block this too ------------=_465C2A88.4A78356A-- (no report template found) De: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Lasantha Marian Enviada em: ter?a-feira, 29 de maio de 2007 06:14 Para: MailScanner discussion Assunto: Re: RES: mcp help Dear Julian, I have been experiencing some strange behaviors in my MCP setup (SA 3.2.0/MS 4.59.4) too, i.e. MCP setup works very fine when tested from command line so does SpamAssassin setup (from both ends; command line and from MailScanner), but MCP would not work properly from MailScanner. It would happily scan but does not report against customized MCP rules. MCP rules are properly applied and correct scores are shown when run from command line without any errors. The very same MCP rules set works fine with earlier versions (SA 3.1.1/MS 4.53.8). I think it is the same kind of problem that Wilson is experiencing in MCP. It identifies MCP, but then may be a reporting problem ! Thanks and regards, Lasantha. *-------- Original Message --------* *Subject: * RES: mcp help *Date: * Tue, 29/May/2007 4:39:25 AM +0550 *From: * "Wilson A. Galafassi Jr." *To: * "'MailScanner discussion'" spamassassin --D --lint > /tmp/sa.log 2>&1 This is the result. [root@netserver tmp]# cat sa.log [26391] dbg: logger: adding facilities: all [26391] dbg: logger: logging level is DBG [26391] dbg: generic: SpamAssassin version 3.2.0 [26391] dbg: config: score set 0 chosen. [26391] dbg: util: running in taint mode? yes [26391] dbg: util: taint mode: deleting unsafe environment variables, resetting PATH Jules Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all you IT requirements visit transtec Computers. -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070530/a2034c3e/attachment-0001.html From MailScanner at ecs.soton.ac.uk Wed May 30 11:42:44 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 30 11:44:30 2007 Subject: RES: RES: RES: mcp help In-Reply-To: <465D5338.2080608@gmail.com> References: <465AF0F9.3030504@ecs.soton.ac.uk> <20070528172421.68cb5c01@uxbod.splatnix.net> <20070528204135.045a9d5a@uxbod.splatnix.net> <465BEEF0.6000505@gmail.com> <465C33C7.60403 01@ecs.soton.ac.uk> <465D3EFC.80300@ecs.soton.ac.uk> <465D5338.2080608@gmail.com> Message-ID: <465D5524.1030204@ecs.soton.ac.uk> I have added the v320.pre file to the distribution, with just the loadplugin line for the main checker. Lasantha Marian wrote: > Dear Julian, > > I too had the same problem, now it works perfect with just copying > *.pre files. > > Thanks for the support. > > Best regards, > > Lasantha. > > *-------- Original Message --------* > *Subject: * RES: RES: RES: mcp help > *Date: * Wed, 30/May/2007 2:38:12 PM +0550 > *From: * Julian Field > *To: * MailScanner discussion > > >> Copy over the *.pre files into the mcp directory. It's missing some >> LoadPlugin lines from the looks of it. >> >> Wilson A. Galafassi Jr. wrote: >>> I have tried to upgrade to latest beta version and the error in mcp checks >>> persist. >>> >>> check: no loaded plugin implements 'check_main': cannot scan! at >>> /usr/lib/perl5/site_perl/5.8.8/Mail/SpamAssassin/PerMsgStatus.pm line 164. >>> >>> >>> Any help is apreciated. >>> >>> Thanks, >>> >>> Wilson >>> >>> -----Mensagem original----- >>> De: mailscanner-bounces@lists.mailscanner.info >>> [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Julian Field >>> Enviada em: ter?a-feira, 29 de maio de 2007 11:08 >>> Para: MailScanner discussion >>> Assunto: Re: RES: RES: mcp help >>> >>> Yes, but what about the setting >>> MCP Checks = yes >>> ? >>> Remember MCP is off by default. >>> >>> Wilson A. Galafassi Jr. wrote: >>> >>>> I have something wrong... any help is very apreciated! >>>> >>>> Thanks >>>> Wilson >>>> >>>> >>>> My mailscanner.cf >>>> >>>> First Check = mcp >>>> >>>> # The rest of these options are clones of the equivalent spam options >>>> MCP Required SpamAssassin Score = 1 >>>> MCP High SpamAssassin Score = 10 >>>> MCP Error Score = 1 >>>> >>>> MCP Header = X-%org-name%-MailScanner-MCPCheck: >>>> Non MCP Actions = deliver >>>> MCP Actions = store >>>> High Scoring MCP Actions = store >>>> Bounce MCP As Attachment = no >>>> >>>> MCP Modify Subject = start >>>> MCP Subject Text = {MCP?} >>>> High Scoring MCP Modify Subject = start >>>> High Scoring MCP Subject Text = {MCP?} >>>> >>>> Is Definitely MCP = no >>>> Is Definitely Not MCP = no >>>> Definite MCP Is High Scoring = yes >>>> Always Include MCP Report = yes >>>> Detailed MCP Report = yes >>>> Include Scores In MCP Report = yes >>>> Log MCP = yes >>>> >>>> MCP Max SpamAssassin Timeouts = 20 >>>> MCP Max SpamAssassin Size = 100k >>>> MCP SpamAssassin Timeout = 10 >>>> >>>> MCP SpamAssassin Prefs File = %mcp-dir%/mcp.spam.assassin.prefs.conf >>>> MCP SpamAssassin User State Dir = /var/spool/MailScanner/mcp >>>> MCP SpamAssassin Local Rules Dir = %mcp-dir% >>>> MCP SpamAssassin Default Rules Dir = %mcp-dir% >>>> MCP SpamAssassin Install Prefix = %mcp-dir% >>>> Recipient MCP Report = %report-dir%/recipient.mcp.report.txt >>>> Sender MCP Report = %report-dir%/sender.mcp.report.txt >>>> >>>> >>>> My test mail: >>>> >>>> >From wilson@ftpmanager.com Tue May 29 10:19:42 2007 >>>> Return-Path: >>>> X-Original-To: wilson@ftpmanager.com >>>> Delivered-To: wilson@ftpmanager.com >>>> Received: from sdxp (unknown [192.168.0.1]) >>>> by netserver.ftpmanager.com (Postfix) with SMTP id 1784D107F90 >>>> for ; Tue, 29 May 2007 10:19:27 -0300 (BRT) >>>> Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> >>>> From: "Wilson - FTP" >>>> To: >>>> Subject: teste >>>> Date: Tue, 29 May 2007 10:19:11 -0300 >>>> MIME-Version: 1.0 >>>> Content-Type: multipart/alternative; >>>> boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" >>>> X-Priority: 3 >>>> X-MSMail-Priority: Normal >>>> X-Mailer: Microsoft Outlook Express 6.00.2900.3028 >>>> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 >>>> X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for >>>> >>> more >>> >>>> information >>>> X-ftpmanagerbr_net-MailScanner: Found to be clean >>>> X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, >>>> requerido 1) >>>> X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanager.com >>>> X-Spam-Status: No >>>> >>>> This is a multi-part message in MIME format. >>>> >>>> ------=_NextPart_000_0005_01C7A1DA.CCACFD20 >>>> Content-Type: text/plain; >>>> charset="iso-8859-1" >>>> Content-Transfer-Encoding: quoted-printable >>>> >>>> Block this t?o >>>> >>>> >>>> My cf file: >>>> >>>> header MY_RULE_1 Subject =~ /block this phrase/i >>>> score MY_RULE_1 100 >>>> >>>> body MY_RULE_2 /Block this too/i >>>> score MY_RULE_2 100 >>>> >>>> body MY_RULE_3 /this\s*is\s*more\s*complicated/i >>>> score MY_RULE_3 100 >>>> >>>> >>>> body SAMPLE_RULE2 /this/i >>>> describe SAMPLE_RULE2 Banned body text >>>> score SAMPLE_RULE2 5 >>>> >>>> body LOCAL_DEMONSTRATION_RULE /test/ >>>> score LOCAL_DEMONSTRATION_RULE 100 >>>> describe LOCAL_DEMONSTRATION_RULE This is a simple test rule >>>> >>>> header LOCAL_DEMONSTRATION_SUBJECT Subject =~ /\btest\b/i >>>> score LOCAL_DEMONSTRATION_SUBJECT 100 >>>> >>>> >>>> The spamassassin test: >>>> >>>> spamassassin -C /etc/MailScanner/mcp -p >>>> /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < >>>> >>> teste.mail >>> >>>> [15603] dbg: logger: adding facilities: all >>>> [15603] dbg: logger: logging level is DBG >>>> [15603] dbg: generic: SpamAssassin version 3.2.0 >>>> [15603] dbg: config: score set 0 chosen. >>>> [15603] dbg: util: running in taint mode? yes >>>> [15603] dbg: util: taint mode: deleting unsafe environment variables, >>>> resetting PATH >>>> [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping >>>> [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping >>>> [15603] dbg: util: PATH included '/usr/local/sbin', keeping >>>> [15603] dbg: util: PATH included '/usr/local/bin', keeping >>>> [15603] dbg: util: PATH included '/sbin', keeping >>>> [15603] dbg: util: PATH included '/bin', keeping >>>> [15603] dbg: util: PATH included '/usr/sbin', keeping >>>> [15603] dbg: util: PATH included '/usr/bin', keeping >>>> [15603] dbg: util: PATH included '/root/bin', which doesn't exist, >>>> >>> dropping >>> >>>> [15603] dbg: util: final PATH set to: >>>> >>>> >>> /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b >>> >>>> in:/usr/sbin:/usr/bin >>>> [15603] dbg: dns: no ipv6 >>>> [15603] dbg: dns: is Net::DNS::Resolver available? yes >>>> [15603] dbg: dns: Net::DNS version: 0.59 >>>> [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre >>>> >>> files >>> >>>> [15603] dbg: config: read file /etc/mail/spamassassin/init.pre >>>> [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre >>>> [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre >>>> [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre >>>> [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files >>>> [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir >>>> [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf >>>> [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir >>>> [15603] dbg: config: read file /etc/mail/spamassassin/local.cf >>>> [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf >>>> [15603] dbg: config: using "/root/.spamassassin" for user state dir >>>> [15603] dbg: config: using >>>> "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file >>>> [15603] dbg: config: read file >>>> /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >>>> @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >>>> [15603] dbg: razor2: razor2 is not available >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC >>>> [15603] dbg: pyzor: network tests on, attempting Pyzor >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >>>> [15603] dbg: razor2: razor2 is not available >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC >>>> [15603] dbg: plugin: loading >>>> >>> Mail::SpamAssassin::Plugin::AutoLearnThreshold >>> >>>> from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject >>>> from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from >>>> @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from >>>> @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >>>> @INC >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already >>>> >>> registered >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch >>>> >>> from >>> >>>> @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from >>>> @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >>>> @INC >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already >>>> >>> registered >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >>>> [15603] dbg: razor2: razor2 is not available >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered >>>> [15603] dbg: conf: finish parsing >>>> [15603] dbg: plugin: >>>> >>> Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) >>> >>>> implements 'finish_parsing_end', priority 0 >>>> [15603] dbg: replacetags: replacing tags >>>> [15603] dbg: replacetags: done replacing tags >>>> [15603] dbg: config: score set 1 chosen. >>>> [15603] dbg: message: main message type: multipart/alternative >>>> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) >>>> implements 'check_start', priority 0 >>>> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) >>>> implements 'check_main', priority 0 >>>> [15603] dbg: conf: trusted_networks are not configured; it is recommended >>>> that you configure trusted_networks manually >>>> [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp >>>> by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= >>>> msa=0 ] >>>> [15603] dbg: received-header: 'from' 192.168.0.1 has private IP >>>> [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes >>>> msa? no >>>> [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= >>>> helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 >>>> id=1784D107F90 auth= msa=0 ] >>>> [15603] dbg: metadata: X-Spam-Relays-Untrusted: >>>> [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= >>>> helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 >>>> id=1784D107F90 auth= msa=0 ] >>>> [15603] dbg: metadata: X-Spam-Relays-External: >>>> [15603] dbg: plugin: >>>> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements >>>> 'extract_metadata', priority 0 >>>> [15603] dbg: metadata: X-Relay-Countries: >>>> [15603] dbg: message: ---- MIME PARSER START ---- >>>> [15603] dbg: message: parsing multipart, got boundary: >>>> ----=_NextPart_000_0005_01C7A1DA.CCACFD20 >>>> [15603] dbg: message: found part of type text/plain, boundary: >>>> ----=_NextPart_000_0005_01C7A1DA.CCACFD20 >>>> [15603] dbg: message: added part, type: text/plain >>>> [15603] dbg: message: parsing normal part >>>> [15603] dbg: message: ---- MIME PARSER END ---- >>>> [15603] dbg: message: decoding quoted-printable >>>> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) >>>> implements 'parsed_metadata', priority 0 >>>> [15603] dbg: plugin: >>>> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements >>>> 'parsed_metadata', priority 0 >>>> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) >>>> implements 'parsed_metadata', priority 0 >>>> [15603] dbg: dns: dns_available set to yes in config file, skipping test >>>> [15603] dbg: uridnsbl: domains to query: >>>> [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups >>>> [15603] dbg: check: running tests for priority: 0 >>>> [15603] dbg: rules: running head tests; score so far=0 >>>> [15603] dbg: rules: compiled head tests >>>> [15603] dbg: rules: running body tests; score so far=0 >>>> [15603] dbg: rules: compiled body tests >>>> [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got >>>> >>> hit: >>> >>>> "test" >>>> [15603] dbg: rules: running uri tests; score so far=100 >>>> [15603] dbg: rules: compiled uri tests >>>> [15603] dbg: rules: running rawbody tests; score so far=100 >>>> [15603] dbg: rules: compiled rawbody tests >>>> [15603] dbg: rules: running full tests; score so far=100 >>>> [15603] dbg: rules: compiled full tests >>>> [15603] dbg: rules: running meta tests; score so far=100 >>>> [15603] dbg: rules: compiled meta tests >>>> [15603] dbg: check: is spam? score=100 required=5 >>>> [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE >>>> [15603] dbg: check: subtests= >>>> >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 >>>> Received: from localhost by netserver.ftpmanagerbr.net >>>> with SpamAssassin (version 3.2.0); >>>> Tue, 29 May 2007 10:28:40 -0300 >>>> From: "Wilson - FTP" >>>> To: >>>> Subject: teste >>>> Date: Tue, 29 May 2007 10:19:11 -0300 >>>> Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> >>>> X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on >>>> netserver.ftpmanagerbr.net >>>> MIME-Version: 1.0 >>>> Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" >>>> >>>> This is a multi-part message in MIME format. >>>> >>>> ------------=_465C2A88.4A78356A >>>> Content-Type: text/plain; charset=iso-8859-1 >>>> Content-Disposition: inline >>>> Content-Transfer-Encoding: 8bit >>>> >>>> (no report template found) >>>> >>>> >>>> >>>> ------------=_465C2A88.4A78356A >>>> Content-Type: message/rfc822; x-spam-type=original >>>> Content-Description: original message before SpamAssassin >>>> Content-Disposition: attachment >>>> Content-Transfer-Encoding: 8bit >>>> >>>> Return-Path: >>>> X-Original-To: wilson@ftpmanagerbr.net >>>> Delivered-To: wilson@ftpmanagerbr.net >>>> Received: from sdxp (unknown [192.168.0.1]) >>>> by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 >>>> for ; Tue, 29 May 2007 10:19:27 -0300 >>>> >>> (BRT) >>> >>>> Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> >>>> From: "Wilson - FTP" >>>> To: >>>> Subject: teste >>>> Date: Tue, 29 May 2007 10:19:11 -0300 >>>> MIME-Version: 1.0 >>>> Content-Type: multipart/alternative; >>>> boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" >>>> X-Priority: 3 >>>> X-MSMail-Priority: Normal >>>> X-Mailer: Microsoft Outlook Express 6.00.2900.3028 >>>> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 >>>> X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for >>>> >>> more >>> >>>> information >>>> X-ftpmanagerbr_net-MailScanner: Found to be clean >>>> X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, >>>> requerido 1) >>>> X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net >>>> X-Spam-Status: No >>>> >>>> This is a multi-part message in MIME format. >>>> >>>> ------=_NextPart_000_0005_01C7A1DA.CCACFD20 >>>> Content-Type: text/plain; >>>> charset="iso-8859-1" >>>> Content-Transfer-Encoding: quoted-printable >>>> >>>> Block this too >>>> >>>> ------------=_465C2A88.4A78356A-- >>>> >>>> (no report template found) spamassassin -C /etc/MailScanner/mcp -p >>>> /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf --mbox -t -D < >>>> >>> teste.mail >>> >>>> [15603] dbg: logger: adding facilities: all >>>> [15603] dbg: logger: logging level is DBG >>>> [15603] dbg: generic: SpamAssassin version 3.2.0 >>>> [15603] dbg: config: score set 0 chosen. >>>> [15603] dbg: util: running in taint mode? yes >>>> [15603] dbg: util: taint mode: deleting unsafe environment variables, >>>> resetting PATH >>>> [15603] dbg: util: PATH included '/usr/kerberos/sbin', keeping >>>> [15603] dbg: util: PATH included '/usr/kerberos/bin', keeping >>>> [15603] dbg: util: PATH included '/usr/local/sbin', keeping >>>> [15603] dbg: util: PATH included '/usr/local/bin', keeping >>>> [15603] dbg: util: PATH included '/sbin', keeping >>>> [15603] dbg: util: PATH included '/bin', keeping >>>> [15603] dbg: util: PATH included '/usr/sbin', keeping >>>> [15603] dbg: util: PATH included '/usr/bin', keeping >>>> [15603] dbg: util: PATH included '/root/bin', which doesn't exist, >>>> >>> dropping >>> >>>> [15603] dbg: util: final PATH set to: >>>> >>>> >>> /usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/b >>> >>>> in:/usr/sbin:/usr/bin >>>> [15603] dbg: dns: no ipv6 >>>> [15603] dbg: dns: is Net::DNS::Resolver available? yes >>>> [15603] dbg: dns: Net::DNS version: 0.59 >>>> [15603] dbg: config: using "/etc/mail/spamassassin" for site rules pre >>>> >>> files >>> >>>> [15603] dbg: config: read file /etc/mail/spamassassin/init.pre >>>> [15603] dbg: config: read file /etc/mail/spamassassin/v310.pre >>>> [15603] dbg: config: read file /etc/mail/spamassassin/v312.pre >>>> [15603] dbg: config: read file /etc/mail/spamassassin/v320.pre >>>> [15603] dbg: config: using "/etc/MailScanner/mcp" for sys rules pre files >>>> [15603] dbg: config: using "/etc/MailScanner/mcp" for default rules dir >>>> [15603] dbg: config: read file /etc/MailScanner/mcp/digital.cf >>>> [15603] dbg: config: using "/etc/mail/spamassassin" for site rules dir >>>> [15603] dbg: config: read file /etc/mail/spamassassin/local.cf >>>> [15603] dbg: config: read file /etc/mail/spamassassin/mailscanner.cf >>>> [15603] dbg: config: using "/root/.spamassassin" for user state dir >>>> [15603] dbg: config: using >>>> "/etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf" for user prefs file >>>> [15603] dbg: config: read file >>>> /etc/MailScanner/mcp/mcp.spam.assassin.prefs.conf >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Hashcash from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >>>> @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >>>> [15603] dbg: razor2: razor2 is not available >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Pyzor from @INC >>>> [15603] dbg: pyzor: network tests on, attempting Pyzor >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >>>> [15603] dbg: razor2: razor2 is not available >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::Razor2=HASH(0x921ab8c), already registered >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::AWL from @INC >>>> [15603] dbg: plugin: loading >>>> >>> Mail::SpamAssassin::Plugin::AutoLearnThreshold >>> >>>> from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WhiteListSubject >>>> from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEHeader from >>>> @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ReplaceTags from >>>> @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >>>> @INC >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x93863c8), already >>>> >>> registered >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::SPF=HASH(0x921ad48), already registered >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x92ea180), already registered >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::ASN=HASH(0x925f2ac), already registered >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Check from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTTPSMismatch >>>> >>> from >>> >>>> @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDetail from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Bayes from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::BodyEval from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::DNSEval from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HTMLEval from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::HeaderEval from >>>> @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::MIMEEval from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayEval from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIEval from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::WLBLEval from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::VBounce from @INC >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ImageInfo from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::RelayCountry from >>>> @INC >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x953093c), already >>>> >>> registered >>> >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::SPF from @INC >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::SPF=HASH(0x921b240), already registered >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::URIDNSBL from >>>> >>> @INC >>> >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x93868e4), already registered >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::Razor2 from @INC >>>> [15603] dbg: razor2: razor2 is not available >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::Razor2=HASH(0x9386a88), already registered >>>> [15603] dbg: plugin: loading Mail::SpamAssassin::Plugin::ASN from @INC >>>> [15603] dbg: plugin: did not register >>>> Mail::SpamAssassin::Plugin::ASN=HASH(0x9334ac8), already registered >>>> [15603] dbg: conf: finish parsing >>>> [15603] dbg: plugin: >>>> >>> Mail::SpamAssassin::Plugin::ReplaceTags=HASH(0x9386344) >>> >>>> implements 'finish_parsing_end', priority 0 >>>> [15603] dbg: replacetags: replacing tags >>>> [15603] dbg: replacetags: done replacing tags >>>> [15603] dbg: config: score set 1 chosen. >>>> [15603] dbg: message: main message type: multipart/alternative >>>> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::DNSEval=HASH(0x941cf78) >>>> implements 'check_start', priority 0 >>>> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::Check=HASH(0x93d2508) >>>> implements 'check_main', priority 0 >>>> [15603] dbg: conf: trusted_networks are not configured; it is recommended >>>> that you configure trusted_networks manually >>>> [15603] dbg: received-header: parsed as [ ip=192.168.0.1 rdns= helo=sdxp >>>> by=netserver.ftpmanagerbr.net ident= envfrom= intl=0 id=1784D107F90 auth= >>>> msa=0 ] >>>> [15603] dbg: received-header: 'from' 192.168.0.1 has private IP >>>> [15603] dbg: received-header: relay 192.168.0.1 trusted? yes internal? yes >>>> msa? no >>>> [15603] dbg: metadata: X-Spam-Relays-Trusted: [ ip=192.168.0.1 rdns= >>>> helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 >>>> id=1784D107F90 auth= msa=0 ] >>>> [15603] dbg: metadata: X-Spam-Relays-Untrusted: >>>> [15603] dbg: metadata: X-Spam-Relays-Internal: [ ip=192.168.0.1 rdns= >>>> helo=sdxp by=netserver.ftpmanagerbr.net ident= envfrom= intl=1 >>>> id=1784D107F90 auth= msa=0 ] >>>> [15603] dbg: metadata: X-Spam-Relays-External: >>>> [15603] dbg: plugin: >>>> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements >>>> 'extract_metadata', priority 0 >>>> [15603] dbg: metadata: X-Relay-Countries: >>>> [15603] dbg: message: ---- MIME PARSER START ---- >>>> [15603] dbg: message: parsing multipart, got boundary: >>>> ----=_NextPart_000_0005_01C7A1DA.CCACFD20 >>>> [15603] dbg: message: found part of type text/plain, boundary: >>>> ----=_NextPart_000_0005_01C7A1DA.CCACFD20 >>>> [15603] dbg: message: added part, type: text/plain >>>> [15603] dbg: message: parsing normal part >>>> [15603] dbg: message: ---- MIME PARSER END ---- >>>> [15603] dbg: message: decoding quoted-printable >>>> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::URIDNSBL=HASH(0x925efb8) >>>> implements 'parsed_metadata', priority 0 >>>> [15603] dbg: plugin: >>>> Mail::SpamAssassin::Plugin::RelayCountry=HASH(0x92c9644) implements >>>> 'parsed_metadata', priority 0 >>>> [15603] dbg: plugin: Mail::SpamAssassin::Plugin::ASN=HASH(0x93133ac) >>>> implements 'parsed_metadata', priority 0 >>>> [15603] dbg: dns: dns_available set to yes in config file, skipping test >>>> [15603] dbg: uridnsbl: domains to query: >>>> [15603] dbg: asn: no asn_lookup configured, skipping ASN lookups >>>> [15603] dbg: check: running tests for priority: 0 >>>> [15603] dbg: rules: running head tests; score so far=0 >>>> [15603] dbg: rules: compiled head tests >>>> [15603] dbg: rules: running body tests; score so far=0 >>>> [15603] dbg: rules: compiled body tests >>>> [15603] dbg: rules: ran body rule LOCAL_DEMONSTRATION_RULE ======> got >>>> >>> hit: >>> >>>> "test" >>>> [15603] dbg: rules: running uri tests; score so far=100 >>>> [15603] dbg: rules: compiled uri tests >>>> [15603] dbg: rules: running rawbody tests; score so far=100 >>>> [15603] dbg: rules: compiled rawbody tests >>>> [15603] dbg: rules: running full tests; score so far=100 >>>> [15603] dbg: rules: compiled full tests >>>> [15603] dbg: rules: running meta tests; score so far=100 >>>> [15603] dbg: rules: compiled meta tests >>>> [15603] dbg: check: is spam? score=100 required=5 >>>> [15603] dbg: check: tests=LOCAL_DEMONSTRATION_RULE >>>> [15603] dbg: check: subtests= >>>> >From wilson@ftpmanagerbr.net Tue May 29 10:19:42 2007 >>>> Received: from localhost by netserver.ftpmanagerbr.net >>>> with SpamAssassin (version 3.2.0); >>>> Tue, 29 May 2007 10:28:40 -0300 >>>> From: "Wilson - FTP" >>>> To: >>>> Subject: teste >>>> Date: Tue, 29 May 2007 10:19:11 -0300 >>>> Message-Id: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> >>>> X-Spam-Checker-Version: SpamAssassin 3.2.0 (2007-05-01) on >>>> netserver.ftpmanagerbr.net >>>> MIME-Version: 1.0 >>>> Content-Type: multipart/mixed; boundary="----------=_465C2A88.4A78356A" >>>> >>>> This is a multi-part message in MIME format. >>>> >>>> ------------=_465C2A88.4A78356A >>>> Content-Type: text/plain; charset=iso-8859-1 >>>> Content-Disposition: inline >>>> Content-Transfer-Encoding: 8bit >>>> >>>> (no report template found) >>>> >>>> >>>> >>>> ------------=_465C2A88.4A78356A >>>> Content-Type: message/rfc822; x-spam-type=original >>>> Content-Description: original message before SpamAssassin >>>> Content-Disposition: attachment >>>> Content-Transfer-Encoding: 8bit >>>> >>>> Return-Path: >>>> X-Original-To: wilson@ftpmanagerbr.net >>>> Delivered-To: wilson@ftpmanagerbr.net >>>> Received: from sdxp (unknown [192.168.0.1]) >>>> by netserver.ftpmanagerbr.net (Postfix) with SMTP id 1784D107F90 >>>> for ; Tue, 29 May 2007 10:19:27 -0300 >>>> >>> (BRT) >>> >>>> Message-ID: <000801c7a1f3$f2253cc0$0100a8c0@sdxp> >>>> From: "Wilson - FTP" >>>> To: >>>> Subject: teste >>>> Date: Tue, 29 May 2007 10:19:11 -0300 >>>> MIME-Version: 1.0 >>>> Content-Type: multipart/alternative; >>>> boundary="----=_NextPart_000_0005_01C7A1DA.CCACFD20" >>>> X-Priority: 3 >>>> X-MSMail-Priority: Normal >>>> X-Mailer: Microsoft Outlook Express 6.00.2900.3028 >>>> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028 >>>> X-ftpmanagerbr_net-MailScanner-Information: Please contact the ISP for >>>> >>> more >>> >>>> information >>>> X-ftpmanagerbr_net-MailScanner: Found to be clean >>>> X-ftpmanagerbr_net-MailScanner-MCPCheck: MCP-Limpo, MCP-Checa (escore=0, >>>> requerido 1) >>>> X-ftpmanagerbr_net-MailScanner-From: wilson@ftpmanagerbr.net >>>> X-Spam-Status: No >>>> >>>> This is a multi-part message in MIME format. >>>> >>>> ------=_NextPart_000_0005_01C7A1DA.CCACFD20 >>>> Content-Type: text/plain; >>>> charset="iso-8859-1" >>>> Content-Transfer-Encoding: quoted-printable >>>> >>>> Block this too >>>> >>>> ------------=_465C2A88.4A78356A-- >>>> >>>> (no report template found) >>>> >>>> >>>> De: mailscanner-bounces@lists.mailscanner.info >>>> [mailto:mailscanner-bounces@lists.mailscanner.info] Em nome de Lasantha >>>> Marian >>>> Enviada em: ter?a-feira, 29 de maio de 2007 06:14 >>>> Para: MailScanner discussion >>>> Assunto: Re: RES: mcp help >>>> >>>> Dear Julian, >>>> >>>> I have been experiencing some strange behaviors in my MCP setup (SA >>>> >>> 3.2.0/MS >>> >>>> 4.59.4) too, i.e. MCP setup works very fine when tested from command line >>>> >>> so >>> >>>> does SpamAssassin setup (from both ends; command line and from >>>> >>> MailScanner), >>> >>>> but MCP would not work properly from MailScanner. It would happily scan >>>> >>> but >>> >>>> does not report against customized MCP rules. MCP rules are properly >>>> >>> applied >>> >>>> and correct scores are shown when run from command line without any >>>> >>> errors. >>> >>>> The very same MCP rules set works fine with earlier versions (SA 3.1.1/MS >>>> 4.53.8). >>>> >>>> I think it is the same kind of problem that Wilson is experiencing in MCP. >>>> It identifies MCP, but then may be a reporting problem ! >>>> >>>> Thanks and regards, >>>> >>>> Lasantha. >>>> >>>> >>>> *-------- Original Message --------* >>>> *Subject: * RES: mcp help >>>> *Date: * Tue, 29/May/2007 4:39:25 AM +0550 >>>> *From: * "Wilson A. Galafassi Jr." >>>> *To: * "'MailScanner discussion'" >>>> >>>> >>>> >>>> >>>>> spamassassin --D --lint > >>>>> >>>>> >>>> /tmp/sa.log 2>&1 >>>> >>>> >>>> >>>> >>>> >>>>> This is the result. >>>>> >>>>> >>>> >>>> >>>> >>>> >>>>> [root@netserver tmp]# cat sa.log >>>>> >>>>> >>>> >>>> >>>>> [26391] dbg: logger: adding facilities: all >>>>> >>>>> >>>> >>>> >>>>> [26391] dbg: logger: logging level is DBG >>>>> >>>>> >>>> >>>> >>>>> [26391] dbg: generic: SpamAssassin version 3.2.0 >>>>> >>>>> >>>> >>>> >>>>> [26391] dbg: config: score set 0 chosen. >>>>> >>>>> >>>> >>>> >>>>> [26391] dbg: util: running in taint mode? yes >>>>> >>>>> >>>> >>>> >>>>> [26391] dbg: util: taint mode: deleting unsafe environment >>>>> >>>>> >>>> variables, >>>> >>>> >>>> >>>>> resetting PATH >>>>> >>>>> >>>> >>>> >>>> >>> >>> Jules >>> >>> >> >> Jules >> >> -- >> Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> MailScanner customisation, or any advanced system administration help? >> Contact me at Jules@Jules.FM >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> For all your IT requirements visit www.transtec.co.uk >> >> >> -- >> This message has been scanned for viruses and >> dangerous content by *MailScanner* , >> and is >> believed to be clean. >> For all you IT requirements visit transtec Computers >> . Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070530/4754252f/attachment.html From johan.boye at latecoere.fr Wed May 30 12:06:31 2007 From: johan.boye at latecoere.fr (johan.boye@latecoere.fr) Date: Wed May 30 12:06:34 2007 Subject: Attachment Warning Filename Question Message-ID: > > # Then, I want to notify the recipient when a filename/type has been blocked : > > Warning Is Attachment = yes > > Attachment Warning Filename = %report-dir%/stored.filename.message.txt > > > > But you told me to put that instead : > > Attachment Warning Filename = %org-name%-Attachment-Warning.txt > > > This filename doesn't exist anywhere on your server. This is > the name the attachment will use in your emails. The > contents of the message will come from: > Deleted Bad Filename Message Report = %report-dir%/deleted.filename.message.txt Ok, so now, i have this : Warning Is Attachment = yes Attachment Warning Filename = %org-name%-Attachment-Warning.txt And Stored Bad Content Message Report = %report-dir%/stored.content.message.txt Stored Bad Filename Message Report = %report-dir%/stored.filename.message.txt Stored Virus Message Report = %report-dir%/stored.virus.message.txt But it still not notify any recipient... Did i mist something somewhere ? Thanks, Johan "Les informations contenues dans ce message electronique peuvent etre de nature confidentielles et soumises a une obligation de secret. Elles sont destinees a l'usage exclusif du reel destinataire. Si vous n'etes pas le reel destinataire, ou si vous recevez ce message par erreur, merci de le detruire immediatement et de le notifier a son emetteur." "The information contained in this e-mail may be privileged and confidential. It is intended for the exclusive use of the designated recipients named above. If you are not the intended recipient or if you receive this e-mail in error, please delete it and immediately notify the sender." From itdept at fractalweb.com Wed May 30 13:39:40 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Wed May 30 13:39:53 2007 Subject: false positives on rule "FM_RATSIGN_1106" and what to do? In-Reply-To: References: <465C7F68.1020803@fractalweb.com> Message-ID: <465D708C.9090304@fractalweb.com> Hugo van der Kooij wrote: > Just out of curiosity. What is the significance of this particular > message ID or this difference in timezones? I have to admit I get a > shitload of spam from the USA and some of the US states are -7 hours > from my timezone. But I fail to see the logic of this construct at the > moment. Hugo, I agree with you. Why is spam being tagged based on the time zone of the sender and part of the message ID? How exactly does this become part of the fingerprint in the first place? Chris From glenn.steen at gmail.com Wed May 30 14:08:49 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed May 30 14:08:52 2007 Subject: false positives on rule "FM_RATSIGN_1106" and what to do? In-Reply-To: <465D708C.9090304@fractalweb.com> References: <465C7F68.1020803@fractalweb.com> <465D708C.9090304@fractalweb.com> Message-ID: <223f97700705300608q7d7859b6p593181d1831ca6cf@mail.gmail.com> On 30/05/07, Chris Yuzik wrote: > Hugo van der Kooij wrote: > > Just out of curiosity. What is the significance of this particular > > message ID or this difference in timezones? I have to admit I get a > > shitload of spam from the USA and some of the US states are -7 hours > > from my timezone. But I fail to see the logic of this construct at the > > moment. > Hugo, > > I agree with you. Why is spam being tagged based on the time zone of the > sender and part of the message ID? How exactly does this become part of > the fingerprint in the first place? > > Chris I'm in no way responsible for that rule (not even remotely:-), but I can well guess that someone very frustrated noticed that all that untagged spam was a) from the american west coast (or is that just "off the coast" normally? .cx etc?), and b) seemed to have similar, possibly forged, Message-IDs... Perhaps not reflecting over the amount of computers in that part of the world (huge) and the amount of less than well maintained Windoze boxes in that area (still huge, I reckon:-). So ... that way you could easily end up with rules that are more or less insane:-D. Especially insane to use if one happen to be in that area:P. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From ka at pacific.net Wed May 30 16:34:56 2007 From: ka at pacific.net (Ken A) Date: Wed May 30 16:34:56 2007 Subject: false positives on rule "FM_RATSIGN_1106" and what to do? In-Reply-To: <223f97700705300608q7d7859b6p593181d1831ca6cf@mail.gmail.com> References: <465C7F68.1020803@fractalweb.com> <465D708C.9090304@fractalweb.com> <223f97700705300608q7d7859b6p593181d1831ca6cf@mail.gmail.com> Message-ID: <465D99A0.6040504@pacific.net> Glenn Steen wrote: > On 30/05/07, Chris Yuzik wrote: >> Hugo van der Kooij wrote: >> > Just out of curiosity. What is the significance of this particular >> > message ID or this difference in timezones? I have to admit I get a >> > shitload of spam from the USA and some of the US states are -7 hours >> > from my timezone. But I fail to see the logic of this construct at the >> > moment. >> Hugo, >> >> I agree with you. Why is spam being tagged based on the time zone of the >> sender and part of the message ID? How exactly does this become part of >> the fingerprint in the first place? >> >> Chris > > I'm in no way responsible for that rule (not even remotely:-), but I > can well guess that someone very frustrated noticed that all that > untagged spam was a) from the american west coast (or is that just > "off the coast" normally? .cx etc?), I'm currently in -0700, left coast, USA (pacific daylight time), and a quick check of local spools shows quite a few FPs on this rule. Setting score to 0. (it was only 0.25 btw). Thanks, Ken Anderson Pacific.Net and b) seemed to have similar, > possibly forged, Message-IDs... Perhaps not reflecting over the amount > of computers in that part of the world (huge) and the amount of less > than well maintained Windoze boxes in that area (still huge, I > reckon:-). > > So ... that way you could easily end up with rules that are more or > less insane:-D. Especially insane to use if one happen to be in that > area:P. > > Cheers -- Ken Anderson Pacific.Net From itdept at fractalweb.com Wed May 30 16:55:35 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Wed May 30 16:55:46 2007 Subject: false positives on rule "FM_RATSIGN_1106" and what to do? In-Reply-To: <465D99A0.6040504@pacific.net> References: <465C7F68.1020803@fractalweb.com> <465D708C.9090304@fractalweb.com> <223f97700705300608q7d7859b6p593181d1831ca6cf@mail.gmail.com> <465D99A0.6040504@pacific.net> Message-ID: <465D9E77.6010501@fractalweb.com> Ken A wrote: > > I'm currently in -0700, left coast, USA (pacific daylight time), and a > quick check of local spools shows quite a few FPs on this rule. > Setting score to 0. (it was only 0.25 btw). Ken, Odd that your installation was set to 0.25, while mine (3.20 on Centos 4.4) was at the default of 3.8 points. Are you also on 3.20? Cheers From ka at pacific.net Wed May 30 17:15:37 2007 From: ka at pacific.net (Ken A) Date: Wed May 30 17:15:37 2007 Subject: false positives on rule "FM_RATSIGN_1106" and what to do? In-Reply-To: <465D9E77.6010501@fractalweb.com> References: <465C7F68.1020803@fractalweb.com> <465D708C.9090304@fractalweb.com> <223f97700705300608q7d7859b6p593181d1831ca6cf@mail.gmail.com> <465D99A0.6040504@pacific.net> <465D9E77.6010501@fractalweb.com> Message-ID: <465DA329.10406@pacific.net> Chris Yuzik wrote: > Ken A wrote: >> >> I'm currently in -0700, left coast, USA (pacific daylight time), and a >> quick check of local spools shows quite a few FPs on this rule. >> Setting score to 0. (it was only 0.25 btw). > > Ken, > > Odd that your installation was set to 0.25, while mine (3.20 on Centos > 4.4) was at the default of 3.8 points. Are you also on 3.20? > > Cheers > Yes, I am, but we aren't using bayes here, so we hit the 2nd score rather than the 4th. Interesting. # grep FM_RATSIGN_1106 * 50_scores.cf:score FM_RATSIGN_1106 1.700 0.250 3.492 3.799 # n=2 Ken -- Ken Anderson Pacific.Net From mcrider at hoecoop.org Wed May 30 17:19:45 2007 From: mcrider at hoecoop.org (Michael Crider) Date: Wed May 30 17:19:48 2007 Subject: Attachments messed up going to Exchange Message-ID: <465DA421.5080104@hoecoop.org> We migrated from a hosted mail server to an in-house server one month ago, running CentOS 4.4, MailScanner 4.59.4, Postfix 2.2.10, ClamAV and SpamAssassin 3.1.7, initially installed from the howto at hughesjr.com, then fine tuned with the awesome info in FSL's manual and the mail list archives. Today is the first day with a problem that I haven't seen covered (may have overlooked). One of our users is trying to send an attachment to the USDA. She has tried both xls and pdf files. In both cases the person receiving it says he is only getting a .dat file. According to his email headers, he is using Exchange 6.0, and our user is using Thunderbird 2.0. She can email them to other users without a problem (have tested both local users and my home email account). His replies have all come back with the original email inline (no headers or attachments), so I can't tell where the problem is. She had emailed attachments to him as recently as April 3 through the hosted server without a problem, but I have no idea how it was configured (I know it ran SpamAssassin, but nothing beyond that). Has anyone else seen anything like this, or have suggestions on what I should look for? I don't know how computer literate he is, so I don't know how much to ask him (and Washington DC is a long way from Missouri for me to run over and look myself :). Thanks for any advice. Michael -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From alex at nkpanama.com Wed May 30 17:39:47 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Wed May 30 17:40:27 2007 Subject: Attachments messed up going to Exchange In-Reply-To: <465DA421.5080104@hoecoop.org> References: <465DA421.5080104@hoecoop.org> Message-ID: <465DA8D3.6010506@nkpanama.com> Michael Crider wrote: > We migrated from a hosted mail server to an in-house server one month > ago, running CentOS 4.4, MailScanner 4.59.4, Postfix 2.2.10, ClamAV > and SpamAssassin 3.1.7, initially installed from the howto at > hughesjr.com, then fine tuned with the awesome info in FSL's manual > and the mail list archives. Today is the first day with a problem that > I haven't seen covered (may have overlooked). One of our users is > trying to send an attachment to the USDA. She has tried both xls and > pdf files. In both cases the person receiving it says he is only > getting a .dat file. According to his email headers, he is using > Exchange 6.0, and our user is using Thunderbird 2.0. She can email > them to other users without a problem (have tested both local users > and my home email account). His replies have all come back with the > original email inline (no headers or attachments), so I can't tell > where the problem is. She had emailed attachments to him as recently > as April 3 through the hosted server without a problem, but I have no > idea how it was configured (I know it ran SpamAssassin, but nothing > beyond that). Has anyone else seen anything like this, or have > suggestions on what I should look for? I don't know how computer > literate he is, so I don't know how much to ask him (and Washington DC > is a long way from Missouri for me to run over and look myself :). > > Thanks for any advice. > Michael > You need to set the format to "HTML" or "Plain Text" instead of "Rich Text", at least on the client - and preferably tell Exchange not to mess with it either, since Exchange will (depending on your settings) reformat it using RTF. RTF is a PITA. When you *do* get the messages that "look" blank (no attachments, etc.), look at the message source. You'll see a WINMAIL.DAT that's been uuencoded or something. By taking the message source, running it through a UUDECODEr, and running the resulting WINMAIL.DAT through a de-RTFer, you should get the original message and/or attachments. From hvdkooij at vanderkooij.org Wed May 30 17:47:16 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Wed May 30 17:47:54 2007 Subject: Attachments messed up going to Exchange In-Reply-To: <465DA421.5080104@hoecoop.org> References: <465DA421.5080104@hoecoop.org> Message-ID: On Wed, 30 May 2007, Michael Crider wrote: > We migrated from a hosted mail server to an in-house server one month ago, > running CentOS 4.4, MailScanner 4.59.4, Postfix 2.2.10, ClamAV and > SpamAssassin 3.1.7, initially installed from the howto at hughesjr.com, then > fine tuned with the awesome info in FSL's manual and the mail list archives. > Today is the first day with a problem that I haven't seen covered (may have > overlooked). One of our users is trying to send an attachment to the USDA. > She has tried both xls and pdf files. In both cases the person receiving it > says he is only getting a .dat file. According to his email headers, he is > using Exchange 6.0, and our user is using Thunderbird 2.0. She can email them > to other users without a problem (have tested both local users and my home > email account). His replies have all come back with the original email inline > (no headers or attachments), so I can't tell where the problem is. She had > emailed attachments to him as recently as April 3 through the hosted server > without a problem, but I have no idea how it was configured (I know it ran > SpamAssassin, but nothing beyond that). Has anyone else seen anything like > this, or have suggestions on what I should look for? I don't know how > computer literate he is, so I don't know how much to ask him (and Washington > DC is a long way from Missouri for me to run over and look myself :). Use tcpdump to check the inbound and outbound packets. With a smart filter you should just get both and should be able to tell in which format the message is received and in which format the message is send. If you still send it ok it is a SEP and you can take the evening of. That is how I tackle issues like this. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From dyioulos at firstbhph.com Wed May 30 17:57:56 2007 From: dyioulos at firstbhph.com (Dimitri Yioulos) Date: Wed May 30 17:58:38 2007 Subject: Attachments messed up going to Exchange In-Reply-To: References: <465DA421.5080104@hoecoop.org> Message-ID: <200705301257.56400.dyioulos@firstbhph.com> On Wednesday 30 May 2007 12:47 pm, Hugo van der Kooij wrote: > On Wed, 30 May 2007, Michael Crider wrote: > > We migrated from a hosted mail server to an in-house server one month > > ago, running CentOS 4.4, MailScanner 4.59.4, Postfix 2.2.10, ClamAV and > > SpamAssassin 3.1.7, initially installed from the howto at hughesjr.com, > > then fine tuned with the awesome info in FSL's manual and the mail list > > archives. Today is the first day with a problem that I haven't seen > > covered (may have overlooked). One of our users is trying to send an > > attachment to the USDA. She has tried both xls and pdf files. In both > > cases the person receiving it says he is only getting a .dat file. > > According to his email headers, he is using Exchange 6.0, and our user is > > using Thunderbird 2.0. She can email them to other users without a > > problem (have tested both local users and my home email account). His > > replies have all come back with the original email inline (no headers or > > attachments), so I can't tell where the problem is. She had emailed > > attachments to him as recently as April 3 through the hosted server > > without a problem, but I have no idea how it was configured (I know it > > ran SpamAssassin, but nothing beyond that). Has anyone else seen anything > > like this, or have suggestions on what I should look for? I don't know > > how computer literate he is, so I don't know how much to ask him (and > > Washington DC is a long way from Missouri for me to run over and look > > myself :). > > Use tcpdump to check the inbound and outbound packets. With a smart filter > you should just get both and should be able to tell in which format the > message is received and in which format the message is send. > > If you still send it ok it is a SEP and you can take the evening of. > > That is how I tackle issues like this. > > Hugo. > > -- > hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ > This message is using 100% recycled electrons. > Isn't that due to a Microsoft/TNEF issue? I seem to recall that it was discussed here a while ago. I look through the archives night be helpful. Dimitri -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From ssilva at sgvwater.com Wed May 30 18:02:30 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed May 30 18:02:58 2007 Subject: Attachments messed up going to Exchange In-Reply-To: <465DA8D3.6010506@nkpanama.com> References: <465DA421.5080104@hoecoop.org> <465DA8D3.6010506@nkpanama.com> Message-ID: Alex Neuman van der Hans spake the following on 5/30/2007 9:39 AM: > Michael Crider wrote: >> We migrated from a hosted mail server to an in-house server one month >> ago, running CentOS 4.4, MailScanner 4.59.4, Postfix 2.2.10, ClamAV >> and SpamAssassin 3.1.7, initially installed from the howto at >> hughesjr.com, then fine tuned with the awesome info in FSL's manual >> and the mail list archives. Today is the first day with a problem that >> I haven't seen covered (may have overlooked). One of our users is >> trying to send an attachment to the USDA. She has tried both xls and >> pdf files. In both cases the person receiving it says he is only >> getting a .dat file. According to his email headers, he is using >> Exchange 6.0, and our user is using Thunderbird 2.0. She can email >> them to other users without a problem (have tested both local users >> and my home email account). His replies have all come back with the >> original email inline (no headers or attachments), so I can't tell >> where the problem is. She had emailed attachments to him as recently >> as April 3 through the hosted server without a problem, but I have no >> idea how it was configured (I know it ran SpamAssassin, but nothing >> beyond that). Has anyone else seen anything like this, or have >> suggestions on what I should look for? I don't know how computer >> literate he is, so I don't know how much to ask him (and Washington DC >> is a long way from Missouri for me to run over and look myself :). >> >> Thanks for any advice. >> Michael >> > You need to set the format to "HTML" or "Plain Text" instead of "Rich > Text", at least on the client - and preferably tell Exchange not to mess > with it either, since Exchange will (depending on your settings) > reformat it using RTF. RTF is a PITA. > > When you *do* get the messages that "look" blank (no attachments, etc.), > look at the message source. You'll see a WINMAIL.DAT that's been > uuencoded or something. By taking the message source, running it through > a UUDECODEr, and running the resulting WINMAIL.DAT through a de-RTFer, > you should get the original message and/or attachments. Sender is using Thunderbird, receiver is using Outbroke (outlook), so Rich text is not the issue. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From pravin.rane at gmail.com Wed May 30 18:04:45 2007 From: pravin.rane at gmail.com (Pravin Rane) Date: Wed May 30 18:04:47 2007 Subject: Attachments messed up going to Exchange In-Reply-To: References: <465DA421.5080104@hoecoop.org> Message-ID: <13c021a90705301004o1c523624rb70aa4b4c7d530de@mail.gmail.com> What is the size of .dat file which is recieved by the recpient. Is it nearly matching with the attachment size? When recpient does, view message source what he is getting. On 5/30/07, Hugo van der Kooij wrote: > > On Wed, 30 May 2007, Michael Crider wrote: > > > We migrated from a hosted mail server to an in-house server one month > ago, > > running CentOS 4.4, MailScanner 4.59.4, Postfix 2.2.10, ClamAV and > > SpamAssassin 3.1.7, initially installed from the howto at hughesjr.com, > then > > fine tuned with the awesome info in FSL's manual and the mail list > archives. > > Today is the first day with a problem that I haven't seen covered (may > have > > overlooked). One of our users is trying to send an attachment to the > USDA. > > She has tried both xls and pdf files. In both cases the person receiving > it > > says he is only getting a .dat file. According to his email headers, he > is > > using Exchange 6.0, and our user is using Thunderbird 2.0. She can email > them > > to other users without a problem (have tested both local users and my > home > > email account). His replies have all come back with the original email > inline > > (no headers or attachments), so I can't tell where the problem is. She > had > > emailed attachments to him as recently as April 3 through the hosted > server > > without a problem, but I have no idea how it was configured (I know it > ran > > SpamAssassin, but nothing beyond that). Has anyone else seen anything > like > > this, or have suggestions on what I should look for? I don't know how > > computer literate he is, so I don't know how much to ask him (and > Washington > > DC is a long way from Missouri for me to run over and look myself :). > > Use tcpdump to check the inbound and outbound packets. With a smart filter > you should just get both and should be able to tell in which format the > message is received and in which format the message is send. > > If you still send it ok it is a SEP and you can take the evening of. > > That is how I tackle issues like this. > > Hugo. > > -- > hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ > This message is using 100% recycled electrons. > > Some men see computers as they are and say "Windows" > I use computers with Linux and say "Why Windows?" > (Thanks JFK, for the insight.) > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > -- Regards Pravin -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070530/c48aedb5/attachment.html From ssilva at sgvwater.com Wed May 30 18:05:36 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed May 30 18:10:14 2007 Subject: Attachments messed up going to Exchange In-Reply-To: <465DA421.5080104@hoecoop.org> References: <465DA421.5080104@hoecoop.org> Message-ID: Michael Crider spake the following on 5/30/2007 9:19 AM: > We migrated from a hosted mail server to an in-house server one month > ago, running CentOS 4.4, MailScanner 4.59.4, Postfix 2.2.10, ClamAV and > SpamAssassin 3.1.7, initially installed from the howto at hughesjr.com, > then fine tuned with the awesome info in FSL's manual and the mail list > archives. Today is the first day with a problem that I haven't seen > covered (may have overlooked). One of our users is trying to send an > attachment to the USDA. She has tried both xls and pdf files. In both > cases the person receiving it says he is only getting a .dat file. > According to his email headers, he is using Exchange 6.0, and our user > is using Thunderbird 2.0. She can email them to other users without a > problem (have tested both local users and my home email account). His > replies have all come back with the original email inline (no headers or > attachments), so I can't tell where the problem is. She had emailed > attachments to him as recently as April 3 through the hosted server > without a problem, but I have no idea how it was configured (I know it > ran SpamAssassin, but nothing beyond that). Has anyone else seen > anything like this, or have suggestions on what I should look for? I > don't know how computer literate he is, so I don't know how much to ask > him (and Washington DC is a long way from Missouri for me to run over > and look myself :). > > Thanks for any advice. > Michael > Have the sender try to zip the file first if you can walk them through that. It sounds like receiver's postmaster might have tweaked something on their Exchange server. You can also try and send the same attachment from a free mail account like yahoo or Gmail and see if the receiver has the same problem. That way you can see if you can eliminate your server from the equation. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From alex at nkpanama.com Wed May 30 18:09:54 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Wed May 30 18:13:32 2007 Subject: Attachments messed up going to Exchange In-Reply-To: References: <465DA421.5080104@hoecoop.org> <465DA8D3.6010506@nkpanama.com> Message-ID: <465DAFE2.6040004@nkpanama.com> Scott Silva wrote: > Alex Neuman van der Hans spake the following on 5/30/2007 9:39 AM: > > Sender is using Thunderbird, receiver is using Outbroke (outlook), so Rich > text is not the issue. > > Then M-Sexchange is... From ssilva at sgvwater.com Wed May 30 18:22:00 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed May 30 18:22:19 2007 Subject: Attachments messed up going to Exchange In-Reply-To: <465DAFE2.6040004@nkpanama.com> References: <465DA421.5080104@hoecoop.org> <465DA8D3.6010506@nkpanama.com> <465DAFE2.6040004@nkpanama.com> Message-ID: Alex Neuman van der Hans spake the following on 5/30/2007 10:09 AM: > Scott Silva wrote: >> Alex Neuman van der Hans spake the following on 5/30/2007 9:39 AM: >> Sender is using Thunderbird, receiver is using Outbroke (outlook), >> so Rich >> text is not the issue. >> >> > Then M-Sexchange is... > "If it isn't broke, it isn't Exchange!" -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From jon at radel.com Wed May 30 18:29:58 2007 From: jon at radel.com (Jon Radel) Date: Wed May 30 18:30:11 2007 Subject: Attachments messed up going to Exchange In-Reply-To: References: <465DA421.5080104@hoecoop.org> <465DA8D3.6010506@nkpanama.com> Message-ID: <465DB496.9060208@radel.com> Scott Silva wrote: > Sender is using Thunderbird, receiver is using Outbroke (outlook), so Rich > text is not the issue. > Not an unknown issue here (assuming it's the same one--it sounds very familiar), though I've not yet had time to track down the details. I use Thunderbird 2.0.0. My boss uses Outlook. Ever since the IT dept (of which I'm not part, actually) upgraded to the latest version of Exchange, every attachment I send him has been completely invisible to him in Outlook. If he goes to the Exchange web access, there all the attachments are, complete and healthy. I suggest seeing if the gov't contact has web access; most agencies appear to provide that. --Jon Radel -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 2890 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070530/0e4da69f/smime.bin From alex at nkpanama.com Wed May 30 18:34:27 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Wed May 30 18:35:06 2007 Subject: Attachments messed up going to Exchange In-Reply-To: <465DB496.9060208@radel.com> References: <465DA421.5080104@hoecoop.org> <465DA8D3.6010506@nkpanama.com> <465DB496.9060208@radel.com> Message-ID: <465DB5A3.1050804@nkpanama.com> Jon Radel wrote: > > Not an unknown issue here (assuming it's the same one--it sounds very > familiar), though I've not yet had time to track down the details. I > use Thunderbird 2.0.0. My boss uses Outlook. Ever since the IT dept > (of which I'm not part, actually) upgraded to the latest version of > Exchange, every attachment I send him has been completely invisible to > him in Outlook. If he goes to the Exchange web access, there all the > attachments are, complete and healthy. > > They need to make sure that Exchange isn't converting everything to RTF/Winmail.dat - and that their Outlook clients have all the latest patches/updates/fixes/etc. > I suggest seeing if the gov't contact has web access; most agencies > appear to provide that. > > --Jon Radel > From alex at nkpanama.com Wed May 30 18:36:44 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Wed May 30 18:37:22 2007 Subject: %rules-dir%/spam.whitelist.rules Message-ID: <465DB62C.3040002@nkpanama.com> I'd like to know if, like in: From: 1.2.3. yes # Whitelist everything that *begins with* 1.2.3. in its IP Address one could: From: *.blableble.com yes # ... do the same with everything that reverse-resolves to something.blableble.com or From: .blableble.com yes # or this way... From ssilva at sgvwater.com Wed May 30 19:09:58 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Wed May 30 19:15:20 2007 Subject: %rules-dir%/spam.whitelist.rules In-Reply-To: <465DB62C.3040002@nkpanama.com> References: <465DB62C.3040002@nkpanama.com> Message-ID: Alex Neuman van der Hans spake the following on 5/30/2007 10:36 AM: > I'd like to know if, like in: > > From: 1.2.3. yes # Whitelist everything that *begins with* 1.2.3. in > its IP Address > > one could: > > From: *.blableble.com yes # ... do the same with everything > that reverse-resolves to something.blableble.com > or > From: .blableble.com yes # or this way... Should work, but will open you up to every spam mail that pretends to come from that domain. But I think the above will only match sub-domains of blableble.com, like server1.blableble.com or otherserver.blableble.com -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From alex at nkpanama.com Wed May 30 19:26:16 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Wed May 30 19:26:55 2007 Subject: %rules-dir%/spam.whitelist.rules In-Reply-To: References: <465DB62C.3040002@nkpanama.com> Message-ID: <465DC1C8.6010702@nkpanama.com> Scott Silva wrote: > Alex Neuman van der Hans spake the following on 5/30/2007 10:36 AM: > >> I'd like to know if, like in: >> >> From: 1.2.3. yes # Whitelist everything that *begins with* 1.2.3. in >> its IP Address >> >> one could: >> >> From: *.blableble.com yes # ... do the same with everything >> that reverse-resolves to something.blableble.com >> or >> From: .blableble.com yes # or this way... >> > Should work, but will open you up to every spam mail that pretends to come > from that domain. But I think the above will only match sub-domains of > blableble.com, like server1.blableble.com or otherserver.blableble.com > > True, but I'd like to match the reverse DNS and not the HELO, the SMTP sender, or the Envelope Sender. Makes it harder to supplant .blableble.com since you'd have to have control of the PTR record for your IP. This I'd like to do mostly for e-mail coming from blackberries and such that use someone else's server. SPF is already set up this way, but I'd like to take it one step further. From MailScanner at ecs.soton.ac.uk Wed May 30 19:43:23 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 30 19:44:10 2007 Subject: %rules-dir%/spam.whitelist.rules In-Reply-To: References: <465DB62C.3040002@nkpanama.com> Message-ID: <465DC5CB.8070407@ecs.soton.ac.uk> Scott Silva wrote: > Alex Neuman van der Hans spake the following on 5/30/2007 10:36 AM: > >> I'd like to know if, like in: >> >> From: 1.2.3. yes # Whitelist everything that *begins with* 1.2.3. in >> its IP Address >> That will test the IP address of the host sending out the SMTP. >> one could: >> >> From: *.blableble.com yes # ... do the same with everything >> that reverse-resolves to something.blableble.com >> or >> From: .blableble.com yes # or this way... >> That will match against the sender address in the message envelope, nothing to do with the IP address that is sending the SMTP. If you want to match against the SMTP client IP address, you have to use the numeric format in your first example. > Should work, but will open you up to every spam mail that pretends to come > from that domain. But I think the above will only match sub-domains of > blableble.com, like server1.blableble.com or otherserver.blableble.com > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070530/d08dda91/attachment.html From MailScanner at ecs.soton.ac.uk Wed May 30 19:49:03 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Wed May 30 19:50:12 2007 Subject: Beta release 4.60.7 Message-ID: <465DC71F.2080303@ecs.soton.ac.uk> This release includes a patch to the new Postfix code in 4.60. If you are using Postfix versions 2.3 or 2.4, please upgrade to this version to test it for me. Download as usual from www.mailscanner.info. The full Change Log for this version is: * New Features and Improvements * 1 Improved Sophos.install script so that it sets up /etc/ld.so.conf ready for installation of Perl-SAVI module required for "sophossavi" virus scanner. 1 Custom Functions can now receive parameters not only to their Init and End functions, but also to their run-time calculation functions (i.e. the real custom function itself used when processing each message). The Custom Function is now passed not only the message, but also a ref to a list of parameters specified in the MailScanner.conf file. 1 Improvement to phishing net. 1 'clamavmodule' scanner no longer detects encrypted zips/rars as viruses, leaving MailScanner to do the check later in the dangerous content scanning. The consequence is that MailWatch will allow them to be released from quarantine. 2 Updated a whole load of Perl modules in the pre-requisites lists for both MailScanner and SpamAssassin. 2 Added a "--nomodules" command-line option to the MailScanner install.sh script to skip installing required Perl modules. 2-2 Fixed bugs introduced by 4.60.2 in generic installer. Only affects 'other Linux and non-Linux' installer. 2-4 Fixed more non-Linux installer problems. 4 Added more modules to the list output by "MailScanner --version". 4 Improved phishing net detection of HTML tags, courtesy of snifer_@hotmail.com. 4 Added patches to provide full "p record" support in Postfix 2.3 and 2.4, courtesy of Glenn Steen . 5 Added a new feature, to compress all the attachments in a message and replace them with a single zip file. Set "Zip Attachments = yes" (no by default), and set "Attachments Zip Filename = MessageAttachments.zip" 6 Added 2 new configuration options for the "Zip Attachments" feature: Attachments Min Total Size To Zip = 100k Attachment Extensions Not To Zip = .zip .rar .tgz .gz .mpg .mpeg .mp3 .rpm Hopefully these are fairly self-explanatory. * Fixes * 1 Phishing net now correctly handles HTML tags inside links. 1 Deprecated clamscan flag replaced with supported one to stop it printing the summary. 1 Added '-b' to nod32-1.99 command-line options in SweepViruses.pm to stop scanner producing licensing details. Thanks to UxBoD. 1 Removed test in RPM distribution's test for RedHat 6 as it will clash with RHEL 6 and Fedora. Anyone still running RedHat 6 has bigger problems! :-) 1 Worked round Perl bug in returning number of RBLs hit by a message. 1 Fixed problem causing some password-protected RAR archives to be missed. 3 Fixed bug introduced in earlier beta in RBL code. 6-2 Patch to Exim to handle named ACL variables as well as numbered ones. Courtesy of Maarten Vink. 7 Added v320.pre to mcp directory. 7 Postfix 2.3/2.4 patch fix. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From Denis.Beauchemin at USherbrooke.ca Wed May 30 20:11:12 2007 From: Denis.Beauchemin at USherbrooke.ca (Denis Beauchemin) Date: Wed May 30 20:11:24 2007 Subject: Attachment Warning Filename Question In-Reply-To: References: Message-ID: <465DCC50.7060903@USherbrooke.ca> johan.boye@latecoere.fr a ?crit : >>> # Then, I want to notify the recipient when a filename/type has been >>> > blocked : > >>> Warning Is Attachment = yes >>> Attachment Warning Filename = >>> > %report-dir%/stored.filename.message.txt > >>> But you told me to put that instead : >>> Attachment Warning Filename = %org-name%-Attachment-Warning.txt >>> >>> >> This filename doesn't exist anywhere on your server. This is >> the name the attachment will use in your emails. The >> contents of the message will come from: >> Deleted Bad Filename Message Report = >> > %report-dir%/deleted.filename.message.txt > > Ok, so now, i have this : > Warning Is Attachment = yes > Attachment Warning Filename = %org-name%-Attachment-Warning.txt > And > Stored Bad Content Message Report = > %report-dir%/stored.content.message.txt > Stored Bad Filename Message Report = > %report-dir%/stored.filename.message.txt > Stored Virus Message Report = %report-dir%/stored.virus.message.txt > > But it still not notify any recipient... > > Did i mist something somewhere ? > > Strange... it's working fine here. I just sent myself a zero byte test.exe file (we block all EXE files) and I received the email with the stored.filename.message.txt text. I even received a second email sent to the sender because I have "Notify Senders = yes". The only option I can think of that could be causing this is: "Deliver Cleaned Messages = yes". Is yours set to "yes"? Denis PS: I didn't ask earlier but you are restarting/reloading MS after your changes to MailScanner.conf, right? -- _ ?v? Denis Beauchemin, analyste /(_)\ Universit? de Sherbrooke, S.T.I. ^ ^ T: 819.821.8000x62252 F: 819.821.8045 -------------- next part -------------- A non-text attachment was scrubbed... Name: smime.p7s Type: application/x-pkcs7-signature Size: 3595 bytes Desc: S/MIME Cryptographic Signature Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070530/5de0214e/smime.bin From rcooper at dwford.com Wed May 30 20:27:58 2007 From: rcooper at dwford.com (Rick Cooper) Date: Wed May 30 20:28:05 2007 Subject: Clamd Daemon Scanning Patches Message-ID: <024e01c7a2f0$a1d85ab0$0301a8c0@SAHOMELT> Julian, I have attached the patches for adding direct clamd daemon support to MailScanner. I have patched against the 4.60.6 beta. I can't run a plain vanilla MailScanner setup long as it screws up some reporting scripts as well as does away with my ArchivedFileName and ArchivedFileType rules and these are important to a lot of people. But my quick tests didn't show any issues and the code has been used on six servers for awhile now. IIRC dropping clamavmodule and talking directly to the daemon reduces the MS memory footprint by 28mg per child. It's adding the code to a pristine copy of MS and patching from there that isn't well tested. If you can get it into a beta soon It would be nice, I plan to fully patch (which my other patches) and build a 4.60.6 build either this evening or tomorrow. Feel free to redo what ever trips your trigger, but it shouldn't need any form of auto update scripting, or file watching as freshclam will reload clamd, or clamd will check on it's own depending on the system's clamd.conf Selfcheck setting. In fact one should be able to update ClamAV without restarting MailScanner and, unless they make huge changes in the clamd API any clam updates shouldn't affect the code at all. It's also likely that the clamav user problems that occurred using clamdscan shouldn't happen either unless the defaults (for dropping privilege) are changed. Last two items that should probably be asked of the group: I am assuming that the clamd init scripts are creating lock files, as most do, (usually /var/lock/subsys/clamd) but if that is not the case I should remove the check, I am PINGing clamd anyway but if the lock file isn't there I can short circuit the whole connect process. I am not using the threaded daemon model (MULTISCAN) but a config parameter such as "Clamd Use Threads" could be added so clamd can take advantage of threading on SMP hosts. Rick Cooper -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. -------------- next part -------------- A non-text attachment was scrubbed... Name: virus.scanners.conf.diff Type: application/octet-stream Size: 611 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070530/4b538fb9/virus.scanners.conf-0001.obj -------------- next part -------------- A non-text attachment was scrubbed... Name: ConfigDefs.pl.diff Type: application/octet-stream Size: 586 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070530/4b538fb9/ConfigDefs.pl-0001.obj -------------- next part -------------- A non-text attachment was scrubbed... Name: MailScanner.conf.diff Type: application/octet-stream Size: 706 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070530/4b538fb9/MailScanner.conf-0001.obj -------------- next part -------------- A non-text attachment was scrubbed... Name: SweepViruses.pm.diff Type: application/octet-stream Size: 8581 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070530/4b538fb9/SweepViruses.pm-0001.obj From jimc at laridian.com Wed May 30 20:30:43 2007 From: jimc at laridian.com (Jim Coates) Date: Wed May 30 20:33:08 2007 Subject: Slightly OT: mta.sh problem Message-ID: <070f01c7a2f1$03bdd8e0$6501a8c0@zorak> My ISP was working on implementing a DaemonPortOption today for a multihomed machine. When they went to restart sendmail (for use with MailScanner) using the mta.sh script, they got a "recipient not specified" error. It appears that they can start sendmail using sendmail's regular startup script, but when they try to run multiple instances for use with MailScanner, it bombs out with the error message. They of course say that they didn't change anything else and have backed out the DaemonPortOption line that they added. Any ideas what might be going on? Thank you, Jim Coates -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070530/c384c796/attachment.html From rcooper at dwford.com Wed May 30 20:35:36 2007 From: rcooper at dwford.com (Rick Cooper) Date: Wed May 30 20:35:39 2007 Subject: Clamd Daemon Scanning Patches In-Reply-To: <024e01c7a2f0$a1d85ab0$0301a8c0@SAHOMELT> References: <024e01c7a2f0$a1d85ab0$0301a8c0@SAHOMELT> Message-ID: <025b01c7a2f1$b26cc7c0$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Rick Cooper > Sent: Wednesday, May 30, 2007 3:28 PM > To: MailScanner List > Subject: Clamd Daemon Scanning Patches > > Julian, > > I have attached the patches for adding direct clamd daemon support to > MailScanner. I have patched against the 4.60.6 beta. I can't > run a plain > vanilla MailScanner setup long as it screws up some reporting > scripts as > well as does away with my ArchivedFileName and > ArchivedFileType rules and > these are important to a lot of people. But my quick tests > didn't show any [..] Julian, I forgot to add the requires for IO::Socket::INET and IO::Socket::UNIX, I call them by the long form so it shouldn't hurt and I would think most systems have them installed as few people actually use the core Sockets module anymore but you might want to make note and add the require IO::Socket::INET/IO::Socket::UNIX statements to SweepViruses.pm Sorry about that. Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From glenn.steen at gmail.com Wed May 30 21:45:37 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed May 30 21:46:04 2007 Subject: Beta release 4.60.7 In-Reply-To: <465DC71F.2080303@ecs.soton.ac.uk> References: <465DC71F.2080303@ecs.soton.ac.uk> Message-ID: <223f97700705301345m272832au1f3fd87d1706465d@mail.gmail.com> On 30/05/07, Julian Field wrote: > This release includes a patch to the new Postfix code in 4.60. If you > are using Postfix versions 2.3 or 2.4, please upgrade to this version to > test it for me. Actually that bug affected all versions of Postfix.... not good. So please all that have tried this for us (me and Jules), even if you are using PF version < 2.3, do test this one. Cheers -- -- Glenn (who is off to bed.... finally:-) email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Wed May 30 22:01:14 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Wed May 30 22:07:43 2007 Subject: Clamd Daemon Scanning Patches In-Reply-To: <024e01c7a2f0$a1d85ab0$0301a8c0@SAHOMELT> References: <024e01c7a2f0$a1d85ab0$0301a8c0@SAHOMELT> Message-ID: <223f97700705301401w7b65de2y86341513dac77a92@mail.gmail.com> On 30/05/07, Rick Cooper wrote: > Julian, > > I have attached the patches for adding direct clamd daemon support to > MailScanner. I have patched against the 4.60.6 beta. I can't run a plain > vanilla MailScanner setup long as it screws up some reporting scripts as > well as does away with my ArchivedFileName and ArchivedFileType rules and > these are important to a lot of people. But my quick tests didn't show any > issues and the code has been used on six servers for awhile now. IIRC > dropping clamavmodule and talking directly to the daemon reduces the MS > memory footprint by 28mg per child. It's adding the code to a pristine copy > of MS and patching from there that isn't well tested. If you can get it into > a beta soon It would be nice, I plan to fully patch (which my other patches) > and build a 4.60.6 build either this evening or tomorrow. > > Feel free to redo what ever trips your trigger, but it shouldn't need any > form of auto update scripting, or file watching as freshclam will reload > clamd, or clamd will check on it's own depending on the system's clamd.conf > Selfcheck setting. In fact one should be able to update ClamAV without > restarting MailScanner and, unless they make huge changes in the clamd API > any clam updates shouldn't affect the code at all. It's also likely that the > clamav user problems that occurred using clamdscan shouldn't happen either > unless the defaults (for dropping privilege) are changed. > > Last two items that should probably be asked of the group: > > I am assuming that the clamd init scripts are creating lock files, as most > do, (usually /var/lock/subsys/clamd) but if that is not the case I should > remove the check, I am PINGing clamd anyway but if the lock file isn't there > I can short circuit the whole connect process. Perhaps do this as a config thing too? If "Clamd Lock File" is empty, do the ping unconditionally, else check whatever it points to...? > I am not using the threaded daemon model (MULTISCAN) but a config parameter > such as "Clamd Use Threads" could be added so clamd can take advantage of > threading on SMP hosts. Should work. How far away is Config Option Number 400, Jules?:-) Awesome stuff, can't wait to see it in a new beta (Yeah, I'm feeling lazy today:-). When you tested this Rick, did you notice how this affected startup time of MS compared to clamavmodule? I boticed that using clamavmodule adds a hefty time for reading in the signatures... (rather irritating while debugging that p-record patch ... start debug, wait a couple of minutes, see some errors whizz by, fiddle with code, redo... sigh.:-)... Yeah, not that important, I know...:) Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From hvdkooij at vanderkooij.org Wed May 30 22:45:10 2007 From: hvdkooij at vanderkooij.org (Hugo van der Kooij) Date: Wed May 30 22:45:47 2007 Subject: Kaspersky version? Message-ID: Hi, >From the Kaspersky wrapper it seems the highest suppported version is 5.0 I have been testing higher versions but these seem to be more trouble then it is worth to me. Hugo. -- hvdkooij@vanderkooij.org http://hugo.vanderkooij.org/ This message is using 100% recycled electrons. Some men see computers as they are and say "Windows" I use computers with Linux and say "Why Windows?" (Thanks JFK, for the insight.) From alex at nkpanama.com Wed May 30 22:50:58 2007 From: alex at nkpanama.com (Alex Neuman) Date: Wed May 30 22:51:08 2007 Subject: %rules-dir%/spam.whitelist.rules In-Reply-To: <465DC5CB.8070407@ecs.soton.ac.uk> References: <465DB62C.3040002@nkpanama.com> <465DC5CB.8070407@ecs.soton.ac.uk> Message-ID: <1552.201.226.170.130.1180561858.squirrel@nkpanama.com> Would we have to do some sort of custom function in order to whitelist by PTR instead of IP? I know it's "expensive" from the networking point of view because a reverse lookup would have to be done every time, but it could be combined with an "and" so that it only happens under certain circumstances, I guess. > > > Scott Silva wrote: >> Alex Neuman van der Hans spake the following on 5/30/2007 10:36 AM: >> >>> I'd like to know if, like in: >>> >>> From: 1.2.3. yes # Whitelist everything that *begins with* 1.2.3. >>> in >>> its IP Address >>> > That will test the IP address of the host sending out the SMTP. >>> one could: >>> >>> From: *.blableble.com yes # ... do the same with everything >>> that reverse-resolves to something.blableble.com >>> or >>> From: .blableble.com yes # or this way... >>> > That will match against the sender address in the message envelope, > nothing to do with the IP address that is sending the SMTP. > > If you want to match against the SMTP client IP address, you have to use > the numeric format in your first example. >> Should work, but will open you up to every spam mail that pretends to >> come >> from that domain. But I think the above will only match sub-domains of >> blableble.com, like server1.blableble.com or otherserver.blableble.com >> >> > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From rcooper at dwford.com Wed May 30 23:12:56 2007 From: rcooper at dwford.com (Rick Cooper) Date: Wed May 30 23:13:01 2007 Subject: Clamd Daemon Scanning Patches In-Reply-To: <223f97700705301401w7b65de2y86341513dac77a92@mail.gmail.com> References: <024e01c7a2f0$a1d85ab0$0301a8c0@SAHOMELT> <223f97700705301401w7b65de2y86341513dac77a92@mail.gmail.com> Message-ID: <02aa01c7a307$ad21a3b0$0301a8c0@SAHOMELT> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > Of Glenn Steen > Sent: Wednesday, May 30, 2007 5:01 PM > To: MailScanner discussion > Subject: Re: Clamd Daemon Scanning Patches > [..] > > Last two items that should probably be asked of the group: > > > > I am assuming that the clamd init scripts are creating lock > files, as most > > do, (usually /var/lock/subsys/clamd) but if that is not the > case I should > > remove the check, I am PINGing clamd anyway but if the lock > file isn't there > > I can short circuit the whole connect process. > > Perhaps do this as a config thing too? If "Clamd Lock File" is empty, > do the ping unconditionally, else check whatever it points to...? > Yeah, in retrospect I think it should have gone that way and not made assumptions. Right now if the lock file isn't there it's assumed that clamd isn't running. Easy fix > > I am not using the threaded daemon model (MULTISCAN) but a > config parameter > > such as "Clamd Use Threads" could be added so clamd can > take advantage of > > threading on SMP hosts. > > Should work. How far away is Config Option Number 400, Jules?:-) > I don't know how helpful this option is as I don't have a SMP host to test on and I kept to the per file scanning model, although the tests I did didn't have an appreciable difference between scanning entire dir verses one file at a time since the connection to the daemon is open anyway. > Awesome stuff, can't wait to see it in a new beta (Yeah, I'm feeling > lazy today:-). > When you tested this Rick, did you notice how this affected startup > time of MS compared to clamavmodule? I boticed that using clamavmodule > adds a hefty time for reading in the signatures... (rather irritating > while debugging that p-record patch ... start debug, wait a couple of > minutes, see some errors whizz by, fiddle with code, redo... > sigh.:-)... Yeah, not that important, I know...:) > Didn't really time it but bear in mind MS doesn't load anything. It simply makes the socket (UNIX/TCP) connection and asks the daemon to scan something when required (no persistent connection). If you already use clamd then there is no impact on resources (no signatures loaded, etc). And it appears to be at least as fast as clamavmodule but I didn't do any high resolution timing or huge file, huge number of files. What ever overhead there is involved with clamavmodule is gone, including checking for changed files, loading DBs, etc. and the system overhead of clamdscan is also gone. Now of course you have to set some options in the clamd.conf that were set in MailScanner, such as flagging password protected files as viruses. Rick -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From lists at jfworks.net Thu May 31 02:03:33 2007 From: lists at jfworks.net (James) Date: Thu May 31 02:03:44 2007 Subject: Slightly OT: mta.sh problem In-Reply-To: <070f01c7a2f1$03bdd8e0$6501a8c0@zorak> References: <070f01c7a2f1$03bdd8e0$6501a8c0@zorak> Message-ID: <465E1EE5.3060007@jfworks.net> Jim Coates wrote: > My ISP was working on implementing a DaemonPortOption today for a > multihomed machine. When they went to restart sendmail (for use with > MailScanner) using the mta.sh script, they got a "recipient not > specified" error. > > It appears that they can start sendmail using sendmail's regular > startup script, but when they try to run multiple instances for use > with MailScanner, it bombs out with the error message. > > They of course say that they didn't change anything else and have > backed out the DaemonPortOption line that they added. > > Any ideas what might be going on? > > Thank you, > Jim Coates > Not sure how they are doing things, but I have added an additional port for users with problems on port 25. Here is the relevant part in my sendmail.mc. This works just fine with the MailScanner script that handles sendmail startup/shutdown. Listens on both port 25 and 99. DAEMON_OPTIONS(`Name=MTA')dnl DAEMON_OPTIONS(`Port=999, Name=MSA, M=E')dnl HTH James From jimc at laridian.com Thu May 31 02:44:33 2007 From: jimc at laridian.com (Jim Coates) Date: Thu May 31 02:47:17 2007 Subject: Slightly OT: mta.sh problem In-Reply-To: <465E1EE5.3060007@jfworks.net> Message-ID: <009401c7a325$429336d0$6501a8c0@zorak> James, Thanks... we actually found the problem. Turned out they had upgraded MailScanner, but hadn't yet configured the mta.sh script. It was working fine, because it hadn't been restarted, but once they did it failed. We got the script configured and all is well now. I do however still have one issue... I used the DaemonPortOption that binds outbound IPs to the same one used for inbound. This works great, except for mail submitted by things such as php mail, because it uses 127.0.0.1/localhost. Sendmail complains that it can't bind to that address for outbound mail (which I understand). How can I tell Sendmail to use a different outbound IP for the localhost mail? Thanks, Jim > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of James > Sent: Wednesday, May 30, 2007 8:04 PM > To: MailScanner discussion > Subject: Re: Slightly OT: mta.sh problem > > > Jim Coates wrote: > > My ISP was working on implementing a DaemonPortOption today for a > > multihomed machine. When they went to restart sendmail > (for use with > > MailScanner) using the mta.sh script, they got a "recipient not > > specified" error. > > > > It appears that they can start sendmail using sendmail's regular > > startup script, but when they try to run multiple instances for use > > with MailScanner, it bombs out with the error message. > > > > They of course say that they didn't change anything else and have > > backed out the DaemonPortOption line that they added. > > > > Any ideas what might be going on? > > > > Thank you, > > Jim Coates > > > Not sure how they are doing things, but I have added an > additional port > for users with problems on port 25. Here is the relevant part in my > sendmail.mc. This works just fine with the MailScanner script that > handles sendmail startup/shutdown. Listens on both port 25 and 99. > > > DAEMON_OPTIONS(`Name=MTA')dnl > DAEMON_OPTIONS(`Port=999, Name=MSA, M=E')dnl > > > HTH > > James > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From lists at jfworks.net Thu May 31 03:21:29 2007 From: lists at jfworks.net (James) Date: Thu May 31 03:21:36 2007 Subject: Slightly OT: mta.sh problem In-Reply-To: <009401c7a325$429336d0$6501a8c0@zorak> References: <009401c7a325$429336d0$6501a8c0@zorak> Message-ID: <465E3129.3020708@jfworks.net> Jim Coates wrote: > James, > > Thanks... we actually found the problem. Turned out they had upgraded > MailScanner, but hadn't yet configured the mta.sh script. It was working > fine, because it hadn't been restarted, but once they did it failed. > > We got the script configured and all is well now. > > I do however still have one issue... I used the DaemonPortOption that binds > outbound IPs to the same one used for inbound. This works great, except for > mail submitted by things such as php mail, because it uses > 127.0.0.1/localhost. Sendmail complains that it can't bind to that address > for outbound mail (which I understand). > > How can I tell Sendmail to use a different outbound IP for the localhost > mail? > > Thanks, > Jim > > Good question. So far I haven't needed to bind sendmail to IP's the way you have. Can you post what your DaemonPortOptions are and I can try and experiment? James From jimc at laridian.com Thu May 31 03:32:59 2007 From: jimc at laridian.com (Jim Coates) Date: Thu May 31 03:35:31 2007 Subject: Slightly OT: mta.sh problem In-Reply-To: <465E3129.3020708@jfworks.net> Message-ID: <00a101c7a32c$01424fc0$6501a8c0@zorak> > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of James > Sent: Wednesday, May 30, 2007 9:21 PM > To: MailScanner discussion > Subject: Re: Slightly OT: mta.sh problem > > > Jim Coates wrote: > > James, > > > > Thanks... we actually found the problem. Turned out they > had upgraded > > MailScanner, but hadn't yet configured the mta.sh script. It was > > working fine, because it hadn't been restarted, but once > they did it > > failed. > > > > We got the script configured and all is well now. > > > > I do however still have one issue... I used the > DaemonPortOption that > > binds outbound IPs to the same one used for inbound. This works > > great, except for mail submitted by things such as php > mail, because > > it uses 127.0.0.1/localhost. Sendmail complains that it > can't bind to > > that address for outbound mail (which I understand). > > > > How can I tell Sendmail to use a different outbound IP for the > > localhost mail? > > > > Thanks, > > Jim > > > > > > Good question. So far I haven't needed to bind sendmail to > IP's the way > you have. Can you post what your DaemonPortOptions are and I > can try and > experiment? > > James > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > Here is the string: DAEMON_OPTIONS(`Name=IPv4, Family=inet, Modifiers=bh') connections made from 123.123.123.1 go out 123.123.123.1 - great! connections made from 123.123.123.2 go out 123.123.123.2 - great! connections from 127.0.0.1 get lost because they can't get out of the machine Thanks, Jim From mark at mcselec.com Thu May 31 09:12:23 2007 From: mark at mcselec.com (Mark Alberts) Date: Thu May 31 09:13:32 2007 Subject: inodes problem Message-ID: <2007531101223.631487@pcn> Hi all, I am using the mailscanner as an end user without much knowledge since it was installed for me. I have a VPS and i saw inodes getting to 100%. I searched this list and found an old issue from 2002, but that was fixed long time ago. var/ spool/ MailScanner/ incoming/ get full of directories and they are not cleaned/removed. And i do suppose that these are all temp files. So the Q, is this a bug, or a configuration, or better does somebody know a fix? I am running 2.53 of Mailscanner. best regards Mark Alberts From r.berber at computer.org Thu May 31 09:46:09 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Thu May 31 09:46:26 2007 Subject: inodes problem In-Reply-To: <2007531101223.631487@pcn> References: <2007531101223.631487@pcn> Message-ID: Mark Alberts wrote: > I am using the mailscanner as an end user without much knowledge since > it was installed for me. > I have a VPS and i saw inodes getting to 100%. > I searched this list and found an old issue from 2002, but that was > fixed long time ago. > var/ spool/ MailScanner/ incoming/ get full of directories and they > are not cleaned/removed. And i do suppose that these are all temp > files. > So the Q, is this a bug, or a configuration, or better does somebody > know a fix? > I am running 2.53 of Mailscanner. There is in MailScanner's bin directory a script called "clean_incoming", just run it using cron once a day. -- Ren? Berber From uxbod at splatnix.net Thu May 31 09:58:31 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Thu May 31 09:59:51 2007 Subject: inodes problem In-Reply-To: <2007531101223.631487@pcn> References: <2007531101223.631487@pcn> Message-ID: 2.53 ! I would certainly recommend having your installation upgraded as the current stable version is 4.59.4-2. On Thu, 31 May 2007 10:12:23 +0200, Mark Alberts wrote: > Hi all, > > I am using the mailscanner as an end user without much knowledge since > it was installed for me. > I have a VPS and i saw inodes getting to 100%. > I searched this list and found an old issue from 2002, but that was > fixed long time ago. > var/ spool/ MailScanner/ incoming/ get full of directories and they > are not cleaned/removed. And i do suppose that these are all temp > files. > So the Q, is this a bug, or a configuration, or better does somebody > know a fix? > I am running 2.53 of Mailscanner. > > best regards > Mark Alberts > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From paul at blacknight.ie Thu May 31 10:07:31 2007 From: paul at blacknight.ie (Paul Kelly :: Blacknight Solutions) Date: Thu May 31 10:05:06 2007 Subject: inodes problem In-Reply-To: <2007531101223.631487@pcn> References: <2007531101223.631487@pcn> Message-ID: <465E9053.9010203@blacknight.ie> Mark Alberts wrote: > Hi all, > > I am using the mailscanner as an end user without much knowledge since > it was installed for me. > I have a VPS and i saw inodes getting to 100%. > I searched this list and found an old issue from 2002, but that was > fixed long time ago. > var/ spool/ MailScanner/ incoming/ get full of directories and they > are not cleaned/removed. And i do suppose that these are all temp > files. > So the Q, is this a bug, or a configuration, or better does somebody > know a fix? > I am running 2.53 of Mailscanner. > If you are storing spam, in /var/spool/MailScanner/quarantine/ can get full. We've a couple of boxes keeping 30 days worth of quarantine and now and again they run out of inodes. They block around 1m spams a day though, so it's not a typical setup. Paul > best regards > Mark Alberts > -- Paul Kelly Technical Director Blacknight Internet Solutions ltd Hosting, Colocation, Dedicated servers IP Transit Services Lo-call: 1850 929 929 DDI: 059 9183091 e-mail: paul@blacknight.ie web: http://www.blacknight.ie Blacknight Internet Solutions Ltd, Unit 12A,Barrowside Business Park, Sleaty Road, Graiguecullen, Carlow, Ireland Company No.: 370845 From glenn.steen at gmail.com Thu May 31 10:08:49 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu May 31 10:08:51 2007 Subject: Clamd Daemon Scanning Patches In-Reply-To: <02aa01c7a307$ad21a3b0$0301a8c0@SAHOMELT> References: <024e01c7a2f0$a1d85ab0$0301a8c0@SAHOMELT> <223f97700705301401w7b65de2y86341513dac77a92@mail.gmail.com> <02aa01c7a307$ad21a3b0$0301a8c0@SAHOMELT> Message-ID: <223f97700705310208se944248m137a40ed315558f4@mail.gmail.com> On 31/05/07, Rick Cooper wrote: > > > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf > > Of Glenn Steen > > Sent: Wednesday, May 30, 2007 5:01 PM > > To: MailScanner discussion > > Subject: Re: Clamd Daemon Scanning Patches > > (snip) > > > I am not using the threaded daemon model (MULTISCAN) but a > > config parameter > > > such as "Clamd Use Threads" could be added so clamd can > > take advantage of > > > threading on SMP hosts. > > > > Should work. How far away is Config Option Number 400, Jules?:-) > > > > I don't know how helpful this option is as I don't have a SMP host to test > on and I kept to the per file scanning model, although the tests I did > didn't have an appreciable difference between scanning entire dir verses one > file at a time since the connection to the daemon is open anyway. > Makes sense. The question is whether a "normal" MailScanner batch will be large enough for the threading to have any appreciable effect at all. I don't have any SMP host available for that type of test either though:-(. > > > Awesome stuff, can't wait to see it in a new beta (Yeah, I'm feeling > > lazy today:-). > > When you tested this Rick, did you notice how this affected startup > > time of MS compared to clamavmodule? I boticed that using clamavmodule > > adds a hefty time for reading in the signatures... (rather irritating > > while debugging that p-record patch ... start debug, wait a couple of > > minutes, see some errors whizz by, fiddle with code, redo... > > sigh.:-)... Yeah, not that important, I know...:) > > > > Didn't really time it but bear in mind MS doesn't load anything. It simply > makes the socket (UNIX/TCP) connection and asks the daemon to scan something > when required (no persistent connection). If you already use clamd then > there is no impact on resources (no signatures loaded, etc). And it appears > to be at least as fast as clamavmodule but I didn't do any high resolution > timing or huge file, huge number of files. What ever overhead there is > involved with clamavmodule is gone, including checking for changed files, > loading DBs, etc. and the system overhead of clamdscan is also gone. Now of > course you have to set some options in the clamd.conf that were set in > MailScanner, such as flagging password protected files as viruses. Exactly. Should be a pleasant experience to use:-)... i don't see any huge problem (other than a slight risk of confusion on what to set where:-) with having to set some options in the clamd.conf file. > Rick Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From glenn.steen at gmail.com Thu May 31 10:20:02 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu May 31 10:20:06 2007 Subject: Slightly OT: mta.sh problem In-Reply-To: <00a101c7a32c$01424fc0$6501a8c0@zorak> References: <465E3129.3020708@jfworks.net> <00a101c7a32c$01424fc0$6501a8c0@zorak> Message-ID: <223f97700705310220k45be42a1n4c525a614ae42167@mail.gmail.com> On 31/05/07, Jim Coates wrote: > > -----Original Message----- > > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of James > > Sent: Wednesday, May 30, 2007 9:21 PM > > To: MailScanner discussion > > Subject: Re: Slightly OT: mta.sh problem > > > > > > Jim Coates wrote: > > > James, > > > > > > Thanks... we actually found the problem. Turned out they > > had upgraded > > > MailScanner, but hadn't yet configured the mta.sh script. It was > > > working fine, because it hadn't been restarted, but once > > they did it > > > failed. > > > > > > We got the script configured and all is well now. > > > > > > I do however still have one issue... I used the > > DaemonPortOption that > > > binds outbound IPs to the same one used for inbound. This works > > > great, except for mail submitted by things such as php > > mail, because > > > it uses 127.0.0.1/localhost. Sendmail complains that it > > can't bind to > > > that address for outbound mail (which I understand). > > > > > > How can I tell Sendmail to use a different outbound IP for the > > > localhost mail? > > > > > > Thanks, > > > Jim > > > > > > > > > > Good question. So far I haven't needed to bind sendmail to > > IP's the way > > you have. Can you post what your DaemonPortOptions are and I > > can try and > > experiment? > > > > James > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > Here is the string: > > DAEMON_OPTIONS(`Name=IPv4, Family=inet, Modifiers=bh') > > connections made from 123.123.123.1 go out 123.123.123.1 - great! > connections made from 123.123.123.2 go out 123.123.123.2 - great! > connections from 127.0.0.1 get lost because they can't get out of the > machine > > > Thanks, > Jim > A workaround, but not really a solution, would be to use something that doesn't rely on 127.0.0.1 and/or the sendmail command. For PHP, you could instruct mail factory (PEAR, if you use it) to talk to one of the IF addresses instead of the loopback/localhost one. Perhaps also use Jef Poskanzer's mini_sendmail (http://www.acme.com/software/mini_sendmail/) instead of the sendmail command .... # mini_sendmail -h usage: mini_sendmail [-f] [-t] [-s] [-p] [-T] [-v] [address ...] # ... As you can see, you can specify server/IP address to connect to etc. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From johan.boye at latecoere.fr Thu May 31 10:24:19 2007 From: johan.boye at latecoere.fr (johan.boye@latecoere.fr) Date: Thu May 31 10:24:21 2007 Subject: Attachment Warning Filename Question Message-ID: > -----Message d'origine----- > De : mailscanner-bounces@lists.mailscanner.info > [mailto:mailscanner-bounces@lists.mailscanner.info] De la > part de Denis Beauchemin > Envoy? : mercredi 30 mai 2007 21:11 > ? : MailScanner discussion > Objet : Re: Attachment Warning Filename Question > > johan.boye@latecoere.fr a ?crit : > >>> # Then, I want to notify the recipient when a > filename/type has been > >>> > > blocked : > > > >>> Warning Is Attachment = yes > >>> Attachment Warning Filename = > >>> > > %report-dir%/stored.filename.message.txt > > > >>> But you told me to put that instead : > >>> Attachment Warning Filename = > %org-name%-Attachment-Warning.txt > >>> > >>> > >> This filename doesn't exist anywhere on your server. This is the > >> name the attachment will use in your emails. The contents of the > >> message will come from: > >> Deleted Bad Filename Message Report = > >> > > %report-dir%/deleted.filename.message.txt > > > > Ok, so now, i have this : > > Warning Is Attachment = yes > > Attachment Warning Filename = %org-name%-Attachment-Warning.txt > > And > > Stored Bad Content Message Report = > > %report-dir%/stored.content.message.txt > > Stored Bad Filename Message Report = > > %report-dir%/stored.filename.message.txt > > Stored Virus Message Report = > > %report-dir%/stored.virus.message.txt > > > > But it still not notify any recipient... > > > > Did i mist something somewhere ? > > > > > > Strange... it's working fine here. I just sent myself a > zero byte test.exe file (we block all EXE files) and I > received the email with the stored.filename.message.txt text. > I even received a second email sent to the sender because I > have "Notify Senders = yes". > > The only option I can think of that could be causing this is: > "Deliver Cleaned Messages = yes". Is yours set to "yes"? That's the point ! I set "Deliver Cleaned Messages" to yes and it works. Thanks > Denis > PS: I didn't ask earlier but you are restarting/reloading MS > after your changes to MailScanner.conf, right? Right ;) =============================== HERE IS THE SOLUTION FOR PEOPLE WHO WILL LOOK INTO THIS ML LATER : Warning Is Attachment = yes <= Important Attachment Warning Filename = %org-name%-Attachment-Warning.txt <= Just to format the name of the future attached file The content of the attached file will be defined in a bunch of variables like this : Stored Bad Content Message Report = %report-dir%/stored.content.message.txt Stored Bad Filename Message Report = %report-dir%/stored.filename.message.txt Stored Virus Message Report = %report-dir%/stored.virus.message.txt Check your "%report-dir%" at the beginning of the MailScanner.conf to see the content of the files. And : set "Deliver Cleaned Messages" to yes Then, restart Mailscanner ;) Thanks a LOT See you "Les informations contenues dans ce message ?lectronique peuvent ?tre de nature confidentielles et soumises ? une obligation de secret. Elles sont destin?es ? l'usage exclusif du r?el destinataire. Si vous n'?tes pas le r?el destinataire, ou si vous recevez ce message par erreur, merci de le d?truire imm?diatement et de le notifier ? son ?metteur." "The information contained in this e-mail may be privileged and confidential. It is intended for the exclusive use of the designated recipients named above. If you are not the intended recipient or if you receive this e-mail in error, please delete it and immediately notify the sender." From glenn.steen at gmail.com Thu May 31 10:26:32 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu May 31 10:26:35 2007 Subject: inodes problem In-Reply-To: <2007531101223.631487@pcn> References: <2007531101223.631487@pcn> Message-ID: <223f97700705310226v7d232b76s321f627950f538c4@mail.gmail.com> On 31/05/07, Mark Alberts wrote: > Hi all, > > I am using the mailscanner as an end user without much knowledge since > it was installed for me. > I have a VPS and i saw inodes getting to 100%. > I searched this list and found an old issue from 2002, but that was > fixed long time ago. > var/ spool/ MailScanner/ incoming/ get full of directories and they > are not cleaned/removed. And i do suppose that these are all temp > files. > So the Q, is this a bug, or a configuration, or better does somebody > know a fix? > I am running 2.53 of Mailscanner. > > best regards > Mark Alberts > What MTA do you use? There used to be a bug that cased Postfix-using systems to gradually fill up incoming that way (but then the "Restart Every..." option took care of things every X:th hour, IIRC). With an install as old as you say, you might very well be afflicted by that... Or any number of other bugs. If you do MailScanner -V does that show the version, or does it carp about "-V" not being a correct option? If this really is 2.53, contract someone (if you don't feel up to it:-) to do an upgrade as soon as humanely possible. Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From mark at mcselec.com Thu May 31 10:27:02 2007 From: mark at mcselec.com (Mark Alberts) Date: Thu May 31 10:29:06 2007 Subject: inodes problem In-Reply-To: Message-ID: <200753111272.635256@pcn> Hi Thanks for your anwer. in my frontend i see : Current:v2.53 New:v2.56. But not 4.59.4-2 Could it be the case we talk about different things? Maybe the number i see is for the package? this soft was installed by a third party and i do not know all ins and outs. I do not know where to look to determine the version? best regards Mark On Thu, 31 May 2007 09:58:31 +0100, --[ UxBoD ]-- wrote: > 2.53 ! I would certainly recommend having your installation upgraded as the > current stable version is 4.59.4-2. > > On Thu, 31 May 2007 10:12:23 +0200, Mark Alberts wrote: >> Hi all, >> >> I am using the mailscanner as an end user without much knowledge since >> it was installed for me. >> I have a VPS and i saw inodes getting to 100%. >> I searched this list and found an old issue from 2002, but that was >> fixed long time ago. >> var/ spool/ MailScanner/ incoming/ get full of directories and they >> are not cleaned/removed. And i do suppose that these are all temp >> files. >> So the Q, is this a bug, or a configuration, or better does somebody >> know a fix? >> I am running 2.53 of Mailscanner. >> >> best regards >> Mark Alberts >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> > -- > --[ UxBoD ]-- > // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" > // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 > // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 > // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net > > > -- > This message has been scanned for viruses and dangerous content by MailScanner, and is > believed to be clean. From mark at mcselec.com Thu May 31 10:31:47 2007 From: mark at mcselec.com (Mark Alberts) Date: Thu May 31 10:33:54 2007 Subject: inodes problem In-Reply-To: Message-ID: <2007531113147.229886@pcn> Hi Thanks for your reply. > There is in MailScanner's bin directory a script called "clean_incoming", just > run it using cron once a day. I found : clean.SA.cache and clean.quarantine not the clean_incoming I looked in : usr/ mailscanner/ bin/ Then there is a cron subdir : Which has these files : clean.quarantine.cron clean.SA.cache.cron Is one of these files the script that should run? Or do i look at the wrong place? best regards Mark From waytotheweb at googlemail.com Thu May 31 10:34:58 2007 From: waytotheweb at googlemail.com (Sarah Trayser) Date: Thu May 31 10:35:01 2007 Subject: inodes problem In-Reply-To: <2007531101223.631487@pcn> References: <2007531101223.631487@pcn> Message-ID: > I am using the mailscanner as an end user without much knowledge since > it was installed for me. > I have a VPS and i saw inodes getting to 100%. > I searched this list and found an old issue from 2002, but that was > fixed long time ago. > var/ spool/ MailScanner/ incoming/ get full of directories and they > are not cleaned/removed. And i do suppose that these are all temp > files. > So the Q, is this a bug, or a configuration, or better does somebody > know a fix? > I am running 2.53 of Mailscanner. It's not actually version 2.53 of MailScanner, it's version 2.53 of our installer script for MailScanner on cPanel servers. The version of MailScanner he's using would be v4.58.9. I directed him to post his question to this list as we do not know what the answer is. Temporary empty directories seem to be building up in the directory /var/spool/MailScanner/incoming/. They are not quarantine files. He's using exim as the MTA. Shouldn't these directories be getting deleted automatically on a regular basis? -- Regards, Sarah Trayser Way to the Web Ltd Server Management Services: http://www.configserver.com Web Hosting: http://www.waytotheweb.com From MailScanner at ecs.soton.ac.uk Thu May 31 10:33:11 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 31 10:38:16 2007 Subject: Clamd Daemon Scanning Patches In-Reply-To: <223f97700705301401w7b65de2y86341513dac77a92@mail.gmail.com> References: <024e01c7a2f0$a1d85ab0$0301a8c0@SAHOMELT> <223f97700705301401w7b65de2y86341513dac77a92@mail.gmail.com> Message-ID: <465E9657.50301@ecs.soton.ac.uk> Glenn Steen wrote: > On 30/05/07, Rick Cooper wrote: >> Julian, >> >> I have attached the patches for adding direct clamd daemon support to >> MailScanner. I have patched against the 4.60.6 beta. I can't run a plain >> vanilla MailScanner setup long as it screws up some reporting scripts as >> well as does away with my ArchivedFileName and ArchivedFileType rules >> and >> these are important to a lot of people. But my quick tests didn't >> show any >> issues and the code has been used on six servers for awhile now. IIRC >> dropping clamavmodule and talking directly to the daemon reduces the MS >> memory footprint by 28mg per child. It's adding the code to a >> pristine copy >> of MS and patching from there that isn't well tested. If you can get >> it into >> a beta soon It would be nice, I plan to fully patch (which my other >> patches) >> and build a 4.60.6 build either this evening or tomorrow. >> >> Feel free to redo what ever trips your trigger, but it shouldn't need >> any >> form of auto update scripting, or file watching as freshclam will reload >> clamd, or clamd will check on it's own depending on the system's >> clamd.conf >> Selfcheck setting. In fact one should be able to update ClamAV without >> restarting MailScanner and, unless they make huge changes in the >> clamd API >> any clam updates shouldn't affect the code at all. It's also likely >> that the >> clamav user problems that occurred using clamdscan shouldn't happen >> either >> unless the defaults (for dropping privilege) are changed. >> >> Last two items that should probably be asked of the group: >> >> I am assuming that the clamd init scripts are creating lock files, as >> most >> do, (usually /var/lock/subsys/clamd) but if that is not the case I >> should >> remove the check, I am PINGing clamd anyway but if the lock file >> isn't there >> I can short circuit the whole connect process. > > Perhaps do this as a config thing too? If "Clamd Lock File" is empty, > do the ping unconditionally, else check whatever it points to...? > >> I am not using the threaded daemon model (MULTISCAN) but a config >> parameter >> such as "Clamd Use Threads" could be added so clamd can take >> advantage of >> threading on SMP hosts. > > Should work. How far away is Config Option Number 400, Jules?:-) > > Awesome stuff, can't wait to see it in a new beta (Yeah, I'm feeling > lazy today:-). I want to put out a new stable release tomorrow (1st June). This patch has really come a bit late to make that release. However, I'll put out a first beta of the next release very soon afterwards, which will have this code in it. Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From MailScanner at ecs.soton.ac.uk Thu May 31 10:35:48 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 31 10:38:23 2007 Subject: Clamd Daemon Scanning Patches In-Reply-To: <02aa01c7a307$ad21a3b0$0301a8c0@SAHOMELT> References: <024e01c7a2f0$a1d85ab0$0301a8c0@SAHOMELT> <223f97700705301401w7b65de2y86341513dac77a92@mail.gmail.com> <02aa01c7a307$ad21a3b0$0301a8c0@SAHOMELT> Message-ID: <465E96F4.903@ecs.soton.ac.uk> Rick Cooper wrote: > > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info >> [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf >> Of Glenn Steen >> Sent: Wednesday, May 30, 2007 5:01 PM >> To: MailScanner discussion >> Subject: Re: Clamd Daemon Scanning Patches >> >> > [..] > >>> Last two items that should probably be asked of the group: >>> >>> I am assuming that the clamd init scripts are creating lock >>> >> files, as most >> >>> do, (usually /var/lock/subsys/clamd) but if that is not the >>> >> case I should >> >>> remove the check, I am PINGing clamd anyway but if the lock >>> >> file isn't there >> >>> I can short circuit the whole connect process. >>> >> Perhaps do this as a config thing too? If "Clamd Lock File" is empty, >> do the ping unconditionally, else check whatever it points to...? >> >> > > Yeah, in retrospect I think it should have gone that way and not made > assumptions. Right now if the lock file isn't there it's assumed that clamd > isn't running. Easy fix > Work out a new set of patches and send me them, and they'll go in the first beta of the next version 4.61. > >>> I am not using the threaded daemon model (MULTISCAN) but a >>> >> config parameter >> >>> such as "Clamd Use Threads" could be added so clamd can >>> >> take advantage of >> >>> threading on SMP hosts. >>> >> Should work. How far away is Config Option Number 400, Jules?:-) >> >> > > I don't know how helpful this option is as I don't have a SMP host to test > on and I kept to the per file scanning model, although the tests I did > didn't have an appreciable difference between scanning entire dir verses one > file at a time since the connection to the daemon is open anyway. > > > >> Awesome stuff, can't wait to see it in a new beta (Yeah, I'm feeling >> lazy today:-). >> When you tested this Rick, did you notice how this affected startup >> time of MS compared to clamavmodule? I boticed that using clamavmodule >> adds a hefty time for reading in the signatures... (rather irritating >> while debugging that p-record patch ... start debug, wait a couple of >> minutes, see some errors whizz by, fiddle with code, redo... >> sigh.:-)... Yeah, not that important, I know...:) >> >> > > Didn't really time it but bear in mind MS doesn't load anything. It simply > makes the socket (UNIX/TCP) connection and asks the daemon to scan something > when required (no persistent connection). If you already use clamd then > there is no impact on resources (no signatures loaded, etc). And it appears > to be at least as fast as clamavmodule but I didn't do any high resolution > timing or huge file, huge number of files. What ever overhead there is > involved with clamavmodule is gone, including checking for changed files, > loading DBs, etc. and the system overhead of clamdscan is also gone. Now of > course you have to set some options in the clamd.conf that were set in > MailScanner, such as flagging password protected files as viruses. > > Rick > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070531/f8f0e739/attachment-0001.html From mark at mcselec.com Thu May 31 10:38:04 2007 From: mark at mcselec.com (Mark Alberts) Date: Thu May 31 10:40:13 2007 Subject: inodes problem In-Reply-To: <465E9053.9010203@blacknight.ie> Message-ID: <200753111384.121066@pcn> hi > If you are storing spam, in /var/spool/MailScanner/quarantine/ can get > full. We've a couple of boxes keeping 30 days worth of quarantine and > now and again they run out of inodes. yes, i find a lot of dirs and files there. var/ spool/ MailScanner/ But i do not need to store the spam. i have the frontend configured that it deletes all spam. These seems all ClamAV folders/files. Some are old. Is there a way to remove all these files and change a setting somewhere so that i do not end up with all these files? thanks ! best regards Mark > > -- > Paul Kelly > Technical Director > Blacknight Internet Solutions ltd > Hosting, Colocation, Dedicated servers > IP Transit Services > Lo-call: 1850 929 929 > DDI: 059 9183091 > > e-mail: paul@blacknight.ie > web: http://www.blacknight.ie > > Blacknight Internet Solutions Ltd, > Unit 12A,Barrowside Business Park, > Sleaty Road, > Graiguecullen, > Carlow, > Ireland > > Company No.: 370845 From MailScanner at ecs.soton.ac.uk Thu May 31 10:39:02 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 31 10:43:17 2007 Subject: inodes problem In-Reply-To: References: <2007531101223.631487@pcn> Message-ID: <465E97B6.1080505@ecs.soton.ac.uk> I knew there were still a few version 3 installs out there running, but I never dreamed there were still some version 2 systems as well! --[ UxBoD ]-- wrote: > 2.53 ! I would certainly recommend having your installation upgraded as the > current stable version is 4.59.4-2. > > On Thu, 31 May 2007 10:12:23 +0200, Mark Alberts wrote: > >> Hi all, >> >> I am using the mailscanner as an end user without much knowledge since >> it was installed for me. >> I have a VPS and i saw inodes getting to 100%. >> I searched this list and found an old issue from 2002, but that was >> fixed long time ago. >> var/ spool/ MailScanner/ incoming/ get full of directories and they >> are not cleaned/removed. And i do suppose that these are all temp >> files. >> So the Q, is this a bug, or a configuration, or better does somebody >> know a fix? >> I am running 2.53 of Mailscanner. >> >> best regards >> Mark Alberts >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> >> >> Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From uxbod at splatnix.net Thu May 31 10:48:14 2007 From: uxbod at splatnix.net (--[ UxBoD ]--) Date: Thu May 31 10:49:15 2007 Subject: inodes problem In-Reply-To: References: Message-ID: <80d9ea01f76920f0506fde48e0fba92b@62.49.223.244> The directories are based on the PID of each running MS process. From my own installation I was under the impression that when MS was restarted manually, or the process restart themselves then their associated incoming work directory would be removed. Could it be pointing to a issue when the PID is actually just dying, and leaving remnants behind ? On Thu, 31 May 2007 10:34:58 +0100, "Sarah Trayser" wrote: >> I am using the mailscanner as an end user without much knowledge since >> it was installed for me. >> I have a VPS and i saw inodes getting to 100%. >> I searched this list and found an old issue from 2002, but that was >> fixed long time ago. >> var/ spool/ MailScanner/ incoming/ get full of directories and they >> are not cleaned/removed. And i do suppose that these are all temp >> files. >> So the Q, is this a bug, or a configuration, or better does somebody >> know a fix? >> I am running 2.53 of Mailscanner. > > It's not actually version 2.53 of MailScanner, it's version 2.53 of > our installer script for MailScanner on cPanel servers. The version of > MailScanner he's using would be v4.58.9. I directed him to post his > question to this list as we do not know what the answer is. Temporary > empty directories seem to be building up in the directory > /var/spool/MailScanner/incoming/. They are not quarantine files. He's > using exim as the MTA. Shouldn't these directories be getting deleted > automatically on a regular basis? > > -- > Regards, > Sarah Trayser > > Way to the Web Ltd > Server Management Services: > http://www.configserver.com > Web Hosting: > http://www.waytotheweb.com > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > > -- > This message has been scanned for viruses and dangerous content by > MailScanner, and is > believed to be clean. -- --[ UxBoD ]-- // PGP Key: "curl -s http://www.splatnix.net/uxbod.asc | gpg --import" // Fingerprint: 543A E778 7F2D 98F1 3E50 9C1F F190 93E0 E8E8 0CF8 // Keyserver: www.keyserver.net Key-ID: 0xE8E80CF8 // Phone: +44 (0) 845 869 2749 SIP: uxbod@sip.splatnix.net -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. From r.berber at computer.org Thu May 31 10:54:24 2007 From: r.berber at computer.org (=?ISO-8859-1?Q?Ren=E9_Berber?=) Date: Thu May 31 10:54:47 2007 Subject: inodes problem In-Reply-To: <2007531113147.229886@pcn> References: <2007531113147.229886@pcn> Message-ID: Mark Alberts wrote: > I found : clean.SA.cache > and clean.quarantine > not the clean_incoming > I looked in : usr/ mailscanner/ bin/ > > Then there is a cron subdir : > Which has these files : > clean.quarantine.cron > clean.SA.cache.cron > > Is one of these files the script that should run? > Or do i look at the wrong place? No, sorry I was wrong, the script is one I made; attached if you like to use it. -- Ren? Berber -------------- next part -------------- #!/bin/bash # # Copyright (c) 2003 LegoSoft. All rights reserved. # This program is free software; you can redistribute it and/or modify it # under the terms of the GNU Public Licence. incoming_dir=/var/spool/MailScanner/incoming safetime=7 find $incoming_dir -type d -mtime +$safetime -exec rm -rf {} \; #EOF From Paul.Bijnens at xplanation.com Thu May 31 11:29:52 2007 From: Paul.Bijnens at xplanation.com (Paul Bijnens) Date: Thu May 31 11:29:58 2007 Subject: Attachments messed up going to Exchange In-Reply-To: References: <465DA421.5080104@hoecoop.org> <465DA8D3.6010506@nkpanama.com> Message-ID: <465EA3A0.4010108@xplanation.com> On 2007-05-30 19:02, Scott Silva wrote: > Sender is using Thunderbird, receiver is using Outbroke (outlook), so Rich > text is not the issue. > If the LookOut receiver sees the filenames of the attachment only as ".dat" files, instead of the original name, then you problaby run into: http://kb.mozillazine.org/Attachments_renamed The explanation there is about thunderbird 1.5. I'm using thunderbird 2.0 and the default setting for that parameter is "3", which seems to solve the problem for Outlook and Thunderbird receipients at the same time, by adding mimeheaders so that both are picking up the right name. If you're too lazy to read/understand the article, then do in thunderbird: Preferences -> Advanced -> Config Editor... find parameter "mail.strictly_mime.parm_folding" and set the value to "0" instead of "2". If the value is "3", you're already using Thunderbird 2.0, which does not generate the problem the LookOut lusers. -- Paul Bijnens, xplanation Technology Services Tel +32 16 397.511 Technologielaan 21 bus 2, B-3001 Leuven, BELGIUM Fax +32 16 397.512 http://www.xplanation.com/ email: Paul.Bijnens@xplanation.com *********************************************************************** * I think I've got the hang of it now: exit, ^D, ^C, ^\, ^Z, ^Q, ^^, * * F6, quit, ZZ, :q, :q!, M-Z, ^X^C, logoff, logout, close, bye, /bye, * * stop, end, F3, ~., ^]c, +++ ATH, disconnect, halt, abort, hangup, * * PF4, F20, ^X^X, :D::D, KJOB, F14-f-e, F8-e, kill -1 $$, shutdown, * * init 0, kill -9 1, Alt-F4, Ctrl-Alt-Del, AltGr-NumLock, Stop-A, ... * * ... "Are you sure?" ... YES ... Phew ... I'm out * *********************************************************************** From mark at mcselec.com Thu May 31 11:39:15 2007 From: mark at mcselec.com (Mark Alberts) Date: Thu May 31 11:41:21 2007 Subject: inodes problem In-Reply-To: Message-ID: <2007531123915.023534@pcn> Hi Thanks ! I will try this script. Thanks everybody for their time and help. best regards Mark On Thu, 31 May 2007 04:54:24 -0500, René Berber wrote: > Mark Alberts wrote: > >> I found : clean.SA.cache >> and clean.quarantine >> not the clean_incoming >> I looked in : usr/ mailscanner/ bin/ >> >> Then there is a cron subdir : >> Which has these files : >> clean.quarantine.cron >> clean.SA.cache.cron >> >> Is one of these files the script that should run? >> Or do i look at the wrong place? > > No, sorry I was wrong, the script is one I made; attached if you like to use it. From glenn.steen at gmail.com Thu May 31 11:48:29 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu May 31 11:48:33 2007 Subject: inodes problem In-Reply-To: References: <2007531101223.631487@pcn> Message-ID: <223f97700705310348tace1deewc734ed9be77581db@mail.gmail.com> On 31/05/07, Sarah Trayser wrote: > > I am using the mailscanner as an end user without much knowledge since > > it was installed for me. > > I have a VPS and i saw inodes getting to 100%. > > I searched this list and found an old issue from 2002, but that was > > fixed long time ago. > > var/ spool/ MailScanner/ incoming/ get full of directories and they > > are not cleaned/removed. And i do suppose that these are all temp > > files. > > So the Q, is this a bug, or a configuration, or better does somebody > > know a fix? > > I am running 2.53 of Mailscanner. > > It's not actually version 2.53 of MailScanner, it's version 2.53 of > our installer script for MailScanner on cPanel servers. The version of > MailScanner he's using would be v4.58.9. I directed him to post his > question to this list as we do not know what the answer is. Temporary > empty directories seem to be building up in the directory > /var/spool/MailScanner/incoming/. They are not quarantine files. He's > using exim as the MTA. Shouldn't these directories be getting deleted > automatically on a regular basis? > Ah. That explains that. Perhaps you should look at incorporating the MS version somewhere visible too:-). On to the error... Yes, these should be cleared out. The directories go when the processes (children) are cleaned up and restarted, the individual directories for each message of a batch should be cleaned when the batch is ended. The Postfix bug I mentioned was in the latter case. Is the directories (/var/spool/MailScanner/incoming/) empty? Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From waytotheweb at googlemail.com Thu May 31 12:15:44 2007 From: waytotheweb at googlemail.com (Sarah Trayser) Date: Thu May 31 12:15:47 2007 Subject: inodes problem In-Reply-To: <223f97700705310348tace1deewc734ed9be77581db@mail.gmail.com> References: <2007531101223.631487@pcn> <223f97700705310348tace1deewc734ed9be77581db@mail.gmail.com> Message-ID: > > question to this list as we do not know what the answer is. Temporary > > empty directories seem to be building up in the directory > > /var/spool/MailScanner/incoming/. They are not quarantine files. He's > > using exim as the MTA. Shouldn't these directories be getting deleted > > automatically on a regular basis? > > > Ah. That explains that. Perhaps you should look at incorporating the > MS version somewhere visible too:-). Good point. :-) > On to the error... Yes, these should be cleared out. > The directories go when the processes (children) are cleaned up > and restarted, the individual directories for each message of a batch > should be cleaned when the batch is ended. The Postfix bug I mentioned > was in the latter case. > Is the directories (/var/spool/MailScanner/incoming/) empty? They are empty except when the MailScanner process of that PID is actually scanning mail. All the old ones are empty. We're seeing this on our own cPanel/exim servers as well, there are empty directories going back to December on one of them. -- Regards, Sarah Trayser Way to the Web Ltd Server Management Services: http://www.configserver.com Web Hosting: http://www.waytotheweb.com From mark at mcselec.com Thu May 31 12:49:46 2007 From: mark at mcselec.com (Mark Alberts) Date: Thu May 31 12:51:52 2007 Subject: inodes problem In-Reply-To: <223f97700705310348tace1deewc734ed9be77581db@mail.gmail.com> Message-ID: <2007531134946.808677@pcn> Hi > Ah. That explains that. Perhaps you should look at incorporating the > MS version somewhere visible too:-). I did not read it careful enough. It actual says package : "A new version of the MailScanner Package (Current:v2.53 New:v2.56) is available." But yes, when it would show the mailscanner version too it would be convenient to know what changed in the new mailscanner. > On to the error... Yes, these should be cleared out. > The directories go when the processes (children) are cleaned up > and restarted, the individual directories for each message of a batch > should be cleaned when the batch is ended. The Postfix bug I mentioned > was in the latter case. > Is the directories (/var/spool/MailScanner/incoming/) empty? Yes, they are all empty. user : mailnull group : mail permissons : drwx------ And there are lot of these dirs. best regards mark From rgreen at trayerproducts.com Thu May 31 13:55:46 2007 From: rgreen at trayerproducts.com (Rodney Green) Date: Thu May 31 13:55:50 2007 Subject: OT: VMware Message-ID: <31e7748d0705310555y6b25c9d5u81d3141f09f1c680@mail.gmail.com> Hello, I've seen VMware mentioned in a recent thread. What are the benefits of using such a solution for an e-mail server? I'm downloading VMware Server; the "free" version. Is this what you guys are using? Is it indeed free? I just never thought of using virtualization for an e-mail server. It's an interesting idea and would like to hear from people already doing it. Thanks, Rod -- 2GB of FREE online safe and secure data backups. Check out Mozy at: https://mozy.com/?ref=5R3XB1 -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070531/abeec83b/attachment.html From q at snj.ca Thu May 31 13:57:26 2007 From: q at snj.ca (Quintin Giesbrecht) Date: Thu May 31 13:57:33 2007 Subject: Email Addresses Get Stripped... Message-ID: <2BE78592B3B1824F97A2685E96221F627B0031@mail.snj.mb.ca> Has anyone seen this happen? I checked the corresponding email on the mailscanner server, and the email addresses are in tact. Once the message gets to our exchange server, an email that is sent to multiple recipients, contains only the name of the person, and not the email address...so, if you want to "reply to all", no one has a valid address. This is intermittent...it only happens with a couple of senders that I know of... Has anyone ever seen this? Is this something wrong on the mailscanner server? Or is it an Exchange 2003 problem? Thanks! _____________________ Quintin Giesbrecht IT Manager Smith Neufeld Jodoin LLP http://snj.ca q@snj.ca -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070531/9f1ed66f/attachment.html From MailScanner at ecs.soton.ac.uk Thu May 31 14:03:31 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 31 14:08:52 2007 Subject: OT: VMware In-Reply-To: <31e7748d0705310555y6b25c9d5u81d3141f09f1c680@mail.gmail.com> References: <31e7748d0705310555y6b25c9d5u81d3141f09f1c680@mail.gmail.com> Message-ID: <465EC7A3.7040705@ecs.soton.ac.uk> I just use it for testing, particularly odd operating systems and installation scripts. On my Macs I use Parallels for running Windows apps on a Mac, but I don't run any production mail servers with virtualisation. I need every last ounce of power for handling the mail, I can't afford the overhead caused by having VMware in the way. Rodney Green wrote: > Hello, > > I've seen VMware mentioned in a recent thread. What are the benefits > of using such a solution for an e-mail server? > I'm downloading VMware Server; the "free" version. Is this what you > guys are using? Is it indeed free? > > I just never thought of using virtualization for an e-mail server. > It's an interesting idea and would like to hear from > people already doing it. > > Thanks, > Rod > > -- > 2GB of FREE online safe and secure data backups. > Check out Mozy at: https://mozy.com/?ref=5R3XB1 Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From raymond at prolocation.net Thu May 31 14:20:05 2007 From: raymond at prolocation.net (Raymond Dijkxhoorn) Date: Thu May 31 14:20:04 2007 Subject: Email Addresses Get Stripped... In-Reply-To: <2BE78592B3B1824F97A2685E96221F627B0031@mail.snj.mb.ca> References: <2BE78592B3B1824F97A2685E96221F627B0031@mail.snj.mb.ca> Message-ID: Hi! > Has anyone seen this happen? I checked the corresponding email on the > mailscanner server, and the email addresses are in tact. > > Once the message gets to our exchange server, an email that is sent to > multiple recipients, contains only the name of the person, and not the > email address...so, if you want to "reply to all", no one has a valid > address. > > Has anyone ever seen this? Is this something wrong on the mailscanner > server? Or is it an Exchange 2003 problem? This can happen with badly configured or migrated exchange servers. The adres books and so contain links to bad adresses most likely. Outlook checks your addres book and links to one you have there, or one you have used recently. 99% thats your issue. Bye, Raymond. From remy at unix-asp.com Thu May 31 14:20:48 2007 From: remy at unix-asp.com (Remy de Ruysscher) Date: Thu May 31 14:22:05 2007 Subject: OT: VMware In-Reply-To: References: <31e7748d0705310555y6b25c9d5u81d3141f09f1c680@mail.gmail.com> Message-ID: <200705311322.l4VDM45b026519@safir.blacknight.ie> We are investigating VM Virtual Infrastructure 3.0 (not free) with a FC SAN. This allows you to dynamically adjust resources, with Virtual SMP you could cluster your servers into one pool and allocate 80% of the pool to one virtual machine. Offcourse VMWare won't make the server any faster but with a large pool you can easily benefit of VSMP. Regards, Remy. BTW It can also dynamically auto adjust your resources with DRS. -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian Field Sent: donderdag 31 mei 2007 15:04 To: MailScanner discussion Subject: Re: OT: VMware I just use it for testing, particularly odd operating systems and installation scripts. On my Macs I use Parallels for running Windows apps on a Mac, but I don't run any production mail servers with virtualisation. I need every last ounce of power for handling the mail, I can't afford the overhead caused by having VMware in the way. Rodney Green wrote: > Hello, > > I've seen VMware mentioned in a recent thread. What are the benefits > of using such a solution for an e-mail server? > I'm downloading VMware Server; the "free" version. Is this what you > guys are using? Is it indeed free? > > I just never thought of using virtualization for an e-mail server. > It's an interesting idea and would like to hear from > people already doing it. > > Thanks, > Rod > > -- > 2GB of FREE online safe and secure data backups. > Check out Mozy at: https://mozy.com/?ref=5R3XB1 Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From wick at bobwickline.com Thu May 31 16:27:18 2007 From: wick at bobwickline.com (Bob Wickline) Date: Thu May 31 16:27:46 2007 Subject: OT: VMware In-Reply-To: <31e7748d0705310555y6b25c9d5u81d3141f09f1c680@mail.gmail.com> References: <31e7748d0705310555y6b25c9d5u81d3141f09f1c680@mail.gmail.com> Message-ID: <20070531152000.M92749@wickline.cc> I'm not using VMWare but I am running mail servers under Solaris Zones. I have about 10 different customers (zones) running on a Dell 2-way server with 2G of memory. Virus scanning is the CPU killer and at 40M a pop for the Mailscanner process I can't run more than two threads a customer but it keeps up. ---------- Original Message ----------- From: "Rodney Green" To: "MailScanner discussion" Sent: Thu, 31 May 2007 08:55:46 -0400 Subject: OT: VMware > Hello, > > I've seen VMware mentioned in a recent thread. What are the benefits of > using such a solution for an e-mail server? > I'm downloading VMware Server; the "free" version. Is this what you > guys are using? Is it indeed free? > > I just never thought of using virtualization for an e-mail server. > It's an interesting idea and would like to hear from people already > doing it. > > Thanks, > Rod > > -- > 2GB of FREE online safe and secure data backups. > Check out Mozy at: https://mozy.com/?ref=5R3XB1 ------- End of Original Message ------- From glenn.steen at gmail.com Thu May 31 16:49:24 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu May 31 16:49:28 2007 Subject: inodes problem In-Reply-To: References: <2007531101223.631487@pcn> <223f97700705310348tace1deewc734ed9be77581db@mail.gmail.com> Message-ID: <223f97700705310849s47b6694cx74f148147d051d87@mail.gmail.com> On 31/05/07, Sarah Trayser wrote: > > > question to this list as we do not know what the answer is. Temporary > > > empty directories seem to be building up in the directory > > > /var/spool/MailScanner/incoming/. They are not quarantine files. He's > > > using exim as the MTA. Shouldn't these directories be getting deleted > > > automatically on a regular basis? > > > > > Ah. That explains that. Perhaps you should look at incorporating the > > MS version somewhere visible too:-). > > Good point. :-) > > > On to the error... Yes, these should be cleared out. > > The directories go when the processes (children) are cleaned up > > and restarted, the individual directories for each message of a batch > > should be cleaned when the batch is ended. The Postfix bug I mentioned > > was in the latter case. > > Is the directories (/var/spool/MailScanner/incoming/) empty? > > They are empty except when the MailScanner process of that PID is > actually scanning mail. All the old ones are empty. We're seeing this > on our own cPanel/exim servers as well, there are empty directories > going back to December on one of them. > Hm. So for some reason MailScanner isn't cleaning up at restart, or (as Phil rightly points out) is exiting abnormally. You see nothing indicative in your logs? Or if you run it in debug (MailScanner --debug)? -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From ssilva at sgvwater.com Thu May 31 16:47:46 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 31 16:50:09 2007 Subject: OT: Spam King Arrested! Message-ID: http://www.networkworld.com/news/2007/053107-spam-king-arrested-in.html?nlhtsec=0528securityalert4& One down --- thousands to go! -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From glenn.steen at gmail.com Thu May 31 16:57:58 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu May 31 16:58:01 2007 Subject: OT: Spam King Arrested! In-Reply-To: References: Message-ID: <223f97700705310857p6cab31d8h1b4ecb1a675c4664@mail.gmail.com> On 31/05/07, Scott Silva wrote: > http://www.networkworld.com/news/2007/053107-spam-king-arrested-in.html?nlhtsec=0528securityalert4& > > > One down --- thousands to go! > Amen! Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From alex at nkpanama.com Thu May 31 17:20:56 2007 From: alex at nkpanama.com (Alex Neuman) Date: Thu May 31 17:21:36 2007 Subject: OT: Spam King Arrested! In-Reply-To: <223f97700705310857p6cab31d8h1b4ecb1a675c4664@mail.gmail.com> References: <223f97700705310857p6cab31d8h1b4ecb1a675c4664@mail.gmail.com> Message-ID: <465EF5E8.5000107@nkpanama.com> I'm still waiting for "naked upside-down crucifixion of spammer to be televised worldwide"... :-) Glenn Steen wrote: > On 31/05/07, Scott Silva wrote: >> http://www.networkworld.com/news/2007/053107-spam-king-arrested-in.html?nlhtsec=0528securityalert4& >> >> >> >> One down --- thousands to go! >> > Amen! > Cheers From j.ede at birchenallhowden.co.uk Thu May 31 17:35:30 2007 From: j.ede at birchenallhowden.co.uk (Jason Ede) Date: Thu May 31 17:36:06 2007 Subject: SpamCheck report In-Reply-To: <465ABD96.1020706@ecs.soton.ac.uk> References: <462304A8.6030103@ddihealth.com><46230EAC.5070600@ddihealth.com><46231A7E.4080003@netmagicsolutions.com><462498A6.2020507@ddihealth.com><03203FB5-AC29-4B0B-BFB3-F9802A419917@elec.ucl.ac.be><77F6B238A9BA7847840CFF3DFDC46E190BB0FE@server03.BHL2.local> <024CA64E-2F65-4219-9D66-EBCE566BB31F@elec.ucl.ac.be><77F6B238A9BA7847840CFF3DFDC46E1905204B@server03.BHL2.local> <465ABD96.1020706@ecs.soton.ac.uk> Message-ID: <77F6B238A9BA7847840CFF3DFDC46E190BB1F3@server03.BHL2.local> X-BHL-MailScanner- Spamcheck: Authenticated X-BHL-MailScanner-Information: Please contact the ISP for more information X-BHL-MailScanner: Found to be clean X-BHL-MailScanner-SpamCheck: X-BHL-MailScanner-From: j.ede@birchenallhowden.co.uk X-Spam-Status: No Ok, I've found the custom ruleset from function file... I think I can see roughly what's going on, but I've a couple of questions... The $option is the external name of the config option... I can't seem to work out what this should be... (I'm using the custom function on the 'Spam Checks' config option, but that doesn't comply with what $option should be How do I then specify what ruleset is then used? Jason > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- > bounces@lists.mailscanner.info] On Behalf Of Julian Field > Sent: 28 May 2007 12:32 > To: MailScanner discussion > Subject: Re: SpamCheck report > > > > Jason Ede wrote: > > Hmmm.... Simple, but neat :-) > > > > Can you use a custom function and a ruleset at the same time? > Yes. Take a look in the example in the > /usr/lib/MailScanner/MailScanner/CustomFunctions directory. > > i.e. using the authenticated header check along with an ordinary > > ruleset containing a list of whitelisted addresses? > > > > Jason > > > > --------------------------------------------------------------------- > --- > > *From:* mailscanner-bounces@lists.mailscanner.info on behalf of > Pascal > > Maes > > *Sent:* Sun 27/05/2007 19:26 > > *To:* MailScanner discussion > > *Subject:* Re: SpamCheck report > > > > > > Le 27 mai 07 ? 15:51, Jason Ede a ?crit : > > > > > Hi, > > > > > > I don't suppose you'd be willing to share that custom function? > We'd > > > like to do the same, but the only way I can see to do that so far > > > is to > > > have postfix include the SASL login username in the header which > I'm > > > loathe to do if I can really avoid it. > > > > > > Jason > > > > > > Why not ? > > The first idea comes from the list so I could post it again. > > But first, thanks to Julian for his quick answer. > > > > ------8<------8<------8<------8<------8<------8<------8<------8<----- > -8< > > ------8<------ > > > > package MailScanner::CustomConfig; > > > > use strict 'vars'; > > use strict 'refs'; > > no strict 'subs'; # Allow bare words for parameter %'s > > > > use vars qw($VERSION); > > > > ### The package version, both in 1.23 style *and* usable by > MakeMaker: > > $VERSION = substr q$Revision: 2331 $, 10; > > > > sub InitCheckSMTPAuth > > { > > # Empty > > } > > > > sub EndCheckSMTPAuth > > { > > # Empty > > } > > > > sub CheckSMTPAuth > > { > > my ($message) = @_; > > return 1 unless $message; > > > > foreach (@{$message->{headers}}) > > { > > if (/PUT HERE THE STRING ABOUT THE AUTHENTICATION/) > > { > > MailScanner::Log::InfoLog("Message %s from (%s) is > > authenticated ($1)", $message->{id}, $message->{ > > fromuser}); > > $global::MS->{mta}->AddHeader($message, 'X-MailScanner- > > Spamcheck:', 'Authenticated'); > > return 0; > > } > > } > > return 1; > > } > > > > 1; > > > > ------8<------8<------8<------8<------8<------8<------8<------8<----- > -8< > > ------8<------ > > > > > > -- > > Pascal > > > > -- > > MailScanner mailing list > > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > > > Before posting, read http://wiki.mailscanner.info/posting > > > > Support MailScanner development - buy the book off the website! > > > > > > ----------------------------------------------------------- > > The information in this e-mail and any attachments is confidential. > It > > is intended solely for the attention and use of the named > > addressee(s). If you are not the intended recipient, or person > > responsible for delivering this information to the intended > recipient, > > please notify the sender or email postmaster@birchenallhowden.co.uk > > and delete it from your computer systems. Unless you are the intended > > recipient or his/her representative you are not authorised to, and > > must not, read, copy, distribute, use or retain this message or any > > part of it. All messages are scanned by Mailscanner and are believed > > to be clean. Recipients are advised to apply their own virus checks > to > > any message on delivery. No liability is accepted by BirchenallHowden > > Ltd for any losses caused by viruses contracted during transit over > > the internet or present in any receiving system. BirchenallHowden > Ltd, > > 233 Edmund Road, Sheffield S2 4EL. > > ----- *BirchenallHowden* > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > For all your IT requirements visit www.transtec.co.uk > > > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! ----------------------------------------------------------- The information in this e-mail and any attachments is confidential. It is intended solely for the attention and use of the named addressee(s). If you are not the intended recipient, or person responsible for delivering this information to the intended recipient, please notify the sender or email postmaster@birchenallhowden.co.uk and delete it from your computer systems. Unless you are the intended recipient or his/her representative you are not authorised to, and must not, read, copy, distribute, use or retain this message or any part of it. All messages are scanned by Mailscanner and are believed to be clean. Recipients are advised to apply their own virus checks to any message on delivery. No liability is accepted by BirchenallHowden Ltd for any losses caused by viruses contracted during transit over the internet or present in any receiving system. BirchenallHowden Ltd, 233 Edmund Road, Sheffield, S2 4EL From MailScanner at ecs.soton.ac.uk Thu May 31 17:47:05 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 31 17:47:53 2007 Subject: SpamCheck report In-Reply-To: <77F6B238A9BA7847840CFF3DFDC46E190BB1F3@server03.BHL2.local> References: <462304A8.6030103@ddihealth.com><46230EAC.5070600@ddihealth.com><46231A7E.4080003@netmagicsolutions.com><462498A6.2020507@ddihealth.com><03203FB5-AC29-4B0B-BFB3-F9802A419917@elec.ucl.ac.be><77F6B238A9BA7847840CFF3DFDC46E190BB0FE@server03.BHL2.local> <024CA64E-2F65-4219-9D66-EBCE566BB31F@elec.ucl.ac.be><77F6B238A9BA7847840CFF3DFDC46E1905204B@server03.BHL2.local> <465ABD96.1020706@ecs.soton.ac.uk> <77F6B238A9BA7847840CFF3DFDC46E190BB1F3@server03.BHL2.local> Message-ID: <465EFC09.9010808@ecs.soton.ac.uk> Jason Ede wrote: > X-BHL-MailScanner- Spamcheck: Authenticated > X-BHL-MailScanner-Information: Please contact the ISP for more information > X-BHL-MailScanner: Found to be clean > X-BHL-MailScanner-SpamCheck: > X-BHL-MailScanner-From: j.ede@birchenallhowden.co.uk > X-Spam-Status: No > > Ok, I've found the custom ruleset from function file... I think I can see roughly what's going on, but I've a couple of questions... > > The $option is the external name of the config option... I can't seem to work out what this should be... (I'm using the custom function on the 'Spam Checks' config option, but that doesn't comply with what $option should be > > How do I then specify what ruleset is then used? > The External name is the same as the MailScanner.conf name but with all in lowercase, with all spaces and punctuation removed, so in your case it's just "spamchecks". > Jason > > >> -----Original Message----- >> From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner- >> bounces@lists.mailscanner.info] On Behalf Of Julian Field >> Sent: 28 May 2007 12:32 >> To: MailScanner discussion >> Subject: Re: SpamCheck report >> >> >> >> Jason Ede wrote: >> >>> Hmmm.... Simple, but neat :-) >>> >>> Can you use a custom function and a ruleset at the same time? >>> >> Yes. Take a look in the example in the >> /usr/lib/MailScanner/MailScanner/CustomFunctions directory. >> >>> i.e. using the authenticated header check along with an ordinary >>> ruleset containing a list of whitelisted addresses? >>> >>> Jason >>> >>> --------------------------------------------------------------------- >>> >> --- >> >>> *From:* mailscanner-bounces@lists.mailscanner.info on behalf of >>> >> Pascal >> >>> Maes >>> *Sent:* Sun 27/05/2007 19:26 >>> *To:* MailScanner discussion >>> *Subject:* Re: SpamCheck report >>> >>> >>> Le 27 mai 07 ? 15:51, Jason Ede a ?crit : >>> >>> >>>> Hi, >>>> >>>> I don't suppose you'd be willing to share that custom function? >>>> >> We'd >> >>>> like to do the same, but the only way I can see to do that so far >>>> is to >>>> have postfix include the SASL login username in the header which >>>> >> I'm >> >>>> loathe to do if I can really avoid it. >>>> >>>> Jason >>>> >>> Why not ? >>> The first idea comes from the list so I could post it again. >>> But first, thanks to Julian for his quick answer. >>> >>> ------8<------8<------8<------8<------8<------8<------8<------8<----- >>> >> -8< >> >>> ------8<------ >>> >>> package MailScanner::CustomConfig; >>> >>> use strict 'vars'; >>> use strict 'refs'; >>> no strict 'subs'; # Allow bare words for parameter %'s >>> >>> use vars qw($VERSION); >>> >>> ### The package version, both in 1.23 style *and* usable by >>> >> MakeMaker: >> >>> $VERSION = substr q$Revision: 2331 $, 10; >>> >>> sub InitCheckSMTPAuth >>> { >>> # Empty >>> } >>> >>> sub EndCheckSMTPAuth >>> { >>> # Empty >>> } >>> >>> sub CheckSMTPAuth >>> { >>> my ($message) = @_; >>> return 1 unless $message; >>> >>> foreach (@{$message->{headers}}) >>> { >>> if (/PUT HERE THE STRING ABOUT THE AUTHENTICATION/) >>> { >>> MailScanner::Log::InfoLog("Message %s from (%s) is >>> authenticated ($1)", $message->{id}, $message->{ >>> fromuser}); >>> $global::MS->{mta}->AddHeader($message, 'X-MailScanner- >>> Spamcheck:', 'Authenticated'); >>> return 0; >>> } >>> } >>> return 1; >>> } >>> >>> 1; >>> >>> ------8<------8<------8<------8<------8<------8<------8<------8<----- >>> >> -8< >> >>> ------8<------ >>> >>> >>> -- >>> Pascal >>> >>> -- >>> MailScanner mailing list >>> mailscanner@lists.mailscanner.info >>> http://lists.mailscanner.info/mailman/listinfo/mailscanner >>> >>> Before posting, read http://wiki.mailscanner.info/posting >>> >>> Support MailScanner development - buy the book off the website! >>> >>> >>> ----------------------------------------------------------- >>> The information in this e-mail and any attachments is confidential. >>> >> It >> >>> is intended solely for the attention and use of the named >>> addressee(s). If you are not the intended recipient, or person >>> responsible for delivering this information to the intended >>> >> recipient, >> >>> please notify the sender or email postmaster@birchenallhowden.co.uk >>> and delete it from your computer systems. Unless you are the intended >>> recipient or his/her representative you are not authorised to, and >>> must not, read, copy, distribute, use or retain this message or any >>> part of it. All messages are scanned by Mailscanner and are believed >>> to be clean. Recipients are advised to apply their own virus checks >>> >> to >> >>> any message on delivery. No liability is accepted by BirchenallHowden >>> Ltd for any losses caused by viruses contracted during transit over >>> the internet or present in any receiving system. BirchenallHowden >>> >> Ltd, >> >>> 233 Edmund Road, Sheffield S2 4EL. >>> ----- *BirchenallHowden* >>> >> Jules >> >> -- >> Julian Field MEng CITP >> www.MailScanner.info >> Buy the MailScanner book at www.MailScanner.info/store >> >> MailScanner customisation, or any advanced system administration help? >> Contact me at Jules@Jules.FM >> >> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 >> For all your IT requirements visit www.transtec.co.uk >> >> >> >> >> -- >> This message has been scanned for viruses and >> dangerous content by MailScanner, and is >> believed to be clean. >> For all your IT requirements visit www.transtec.co.uk >> >> -- >> MailScanner mailing list >> mailscanner@lists.mailscanner.info >> http://lists.mailscanner.info/mailman/listinfo/mailscanner >> >> Before posting, read http://wiki.mailscanner.info/posting >> >> Support MailScanner development - buy the book off the website! >> > > ----------------------------------------------------------- > The information in this e-mail and any attachments is confidential. It is intended solely for the attention and use of the named addressee(s). If you are not the intended recipient, or person responsible for delivering this information to the intended recipient, please notify the sender or email postmaster@birchenallhowden.co.uk and delete it from your computer systems. Unless you are the intended recipient or his/her representative you are not authorised to, and must not, read, copy, distribute, use or retain this message or any part of it. All messages are scanned by Mailscanner and are believed to be clean. Recipients are advised to apply their own virus checks to any message on delivery. No liability is accepted by BirchenallHowden Ltd for any losses caused by viruses contracted during transit over the internet or present in any receiving system. BirchenallHowden Ltd, 233 Edmund Road, Sheffield, S2 4EL > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070531/edca9cff/attachment.html From rob at dido.ca Thu May 31 17:50:29 2007 From: rob at dido.ca (Rob Morin) Date: Thu May 31 17:50:35 2007 Subject: SA whitelist not working?? Message-ID: <465EFCD5.10701@dido.ca> Hello all... I just added a new email in the white list, i restarted SA and tested the email , however it still comes through as normal email and not as whitelisted, it still gets knocked out as spam?? I have other emails in the list that work fine still.... i made sure i used tabs rather than spaces... it simply looks like this... FromOrTo: bloddy_ceaser@hotmail.com yes and yet it will get deleted if i send it with reconized spam stuff in it.... I rechecked the file for bad characters, and i see nothing, i used VI to be safe... linting SA comes back ok Any ideas? I am using MS 4.53 from tarball install, everything is in /opt as per default install I am confused.. Thanks.. -- Rob Morin Dido InterNet Inc. Montreal, Canada Http://www.dido.ca 514-990-4444 From stinkybob at gmail.com Thu May 31 17:52:08 2007 From: stinkybob at gmail.com (Eugene MacDougal) Date: Thu May 31 17:52:11 2007 Subject: Solaris Syslog Fix Message-ID: <2579c6b20705310952v1fe81edcga132d1371df747ea@mail.gmail.com> Skipped content of type multipart/alternative-------------- next part -------------- A non-text attachment was scrubbed... Name: solaris_syslog_Log_pm.patch Type: application/octet-stream Size: 382 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070531/536510aa/solaris_syslog_Log_pm.obj From painethom at gmail.com Thu May 31 17:53:01 2007 From: painethom at gmail.com (Thom Paine) Date: Thu May 31 17:53:04 2007 Subject: OT: Spam King Arrested! In-Reply-To: <465EF5E8.5000107@nkpanama.com> References: <223f97700705310857p6cab31d8h1b4ecb1a675c4664@mail.gmail.com> <465EF5E8.5000107@nkpanama.com> Message-ID: <9e1340d20705310953p4e0a7f30n814a61c25f7208e7@mail.gmail.com> I'm waiting for each of those spam emails to be printed out, then put in a pile, with a big crucifix in the middle, him strung up, and burned at the stake. Maybe I watch too much tv....... -- -=/>Thom From glenn.steen at gmail.com Thu May 31 18:06:00 2007 From: glenn.steen at gmail.com (Glenn Steen) Date: Thu May 31 18:06:03 2007 Subject: SA whitelist not working?? In-Reply-To: <465EFCD5.10701@dido.ca> References: <465EFCD5.10701@dido.ca> Message-ID: <223f97700705311006k65af8086u2de530488ce7a8df@mail.gmail.com> On 31/05/07, Rob Morin wrote: > Hello all... > > I just added a new email in the white list, i restarted SA and tested > the email , however it still comes through as normal email and not as > whitelisted, it still gets knocked out as spam?? > > I have other emails in the list that work fine still.... i made sure i > used tabs rather than spaces... it simply looks like this... > > FromOrTo: bloddy_ceaser@hotmail.com yes Um, this is an MS rule, not an SA rule. Whitelisting like that (email address) is generally a bad idea, but that aside... Is that the _envelope_ sender/recipient? Are you sure it is your system removing it? > and yet it will get deleted if i send it with reconized spam stuff in it.... > > I rechecked the file for bad characters, and i see nothing, i used VI to > be safe... > > linting SA comes back ok And if you do MailScanner --lint .... that gives...? > Any ideas? > > I am using MS 4.53 from tarball install, everything is in /opt as per > default install > > I am confused.. > > Thanks.. > Cheers -- -- Glenn email: glenn < dot > steen < at > gmail < dot > com work: glenn < dot > steen < at > ap1 < dot > se From ssilva at sgvwater.com Thu May 31 18:10:33 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 31 18:11:03 2007 Subject: inodes problem In-Reply-To: References: <2007531101223.631487@pcn> Message-ID: Sarah Trayser spake the following on 5/31/2007 2:34 AM: >> I am using the mailscanner as an end user without much knowledge since >> it was installed for me. >> I have a VPS and i saw inodes getting to 100%. >> I searched this list and found an old issue from 2002, but that was >> fixed long time ago. >> var/ spool/ MailScanner/ incoming/ get full of directories and they >> are not cleaned/removed. And i do suppose that these are all temp >> files. >> So the Q, is this a bug, or a configuration, or better does somebody >> know a fix? >> I am running 2.53 of Mailscanner. > > It's not actually version 2.53 of MailScanner, it's version 2.53 of > our installer script for MailScanner on cPanel servers. The version of > MailScanner he's using would be v4.58.9. I directed him to post his > question to this list as we do not know what the answer is. Temporary > empty directories seem to be building up in the directory > /var/spool/MailScanner/incoming/. They are not quarantine files. He's > using exim as the MTA. Shouldn't these directories be getting deleted > automatically on a regular basis? > A little off topic, but MailScanner systems get a big performance boost by running the /var/spool/MailScanner/incoming/ directory in tmpfs. You would need to make sure that it didn't fill up, and it might be a permission problem in your setups. The bug that was mentioned is several years old, and should be long gone. Do you have reports of other people with your setup having the same problem? -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ABartlett at ablenetworking.com Thu May 31 18:11:48 2007 From: ABartlett at ablenetworking.com (Aaron Bartlett) Date: Thu May 31 18:12:24 2007 Subject: VMware References: <31e7748d0705310555y6b25c9d5u81d3141f09f1c680@mail.gmail.com> Message-ID: <7C1069709E330840B1CBA1D812D1EEB8048258@server1.anc.local> Virtualization can be a viable production tool depending on your environment and workload. Services that are relatively low-impact (particularly for disk I/O) can do very well on VMware Server (free version) as long as you don't try to run more than a few virtual machines (VM's) simultaneously. For higher VM counts and/or stress loads, the free version doesn't scale well... you would be better suited to running a dedicated box or purchasing VMware ESX Server. I have around 50-60 SMB customers running production VM's under VMware Server 1.x (free version). Most of the VM's are dedicated to running MailScanner, DNS and other public-facing services. It provides a quick solution for deploying secured services on MS Windows servers (i.e. Linux/xBSD for DNS, postfix mail bastions, etc) without exposing the Windows server to the outside. I also have a few other customers running fairly large production environments on ESX Servers (50+ VM's) with HA, FC SAN, etc. Even with ESX, we still keep the heavy loads (SQL, file I/O, etc) on dedicated, physical machines for better performance. Best regards, Aaron Bartlett -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info on behalf of Rodney Green Sent: Thu 5/31/2007 7:55 AM To: MailScanner discussion Subject: OT: VMware Hello, I've seen VMware mentioned in a recent thread. What are the benefits of using such a solution for an e-mail server? I'm downloading VMware Server; the "free" version. Is this what you guys are using? Is it indeed free? I just never thought of using virtualization for an e-mail server. It's an interesting idea and would like to hear from people already doing it. Thanks, Rod -- 2GB of FREE online safe and secure data backups. Check out Mozy at: https://mozy.com/?ref=5R3XB1 ---- This message was scanned by ESVA and is believed to be clean. -- This message was scanned by ESVA and is believed to be clean. -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/ms-tnef Size: 3515 bytes Desc: not available Url : http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070531/a05a33a4/attachment-0001.bin From ssilva at sgvwater.com Thu May 31 18:17:40 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 31 18:17:57 2007 Subject: New Clamav 0.90.3 Message-ID: New version of Clamav out. I'm already seeing upgrade warnings in the updates. Latest ClamAV? stable release is: 0.90.3 Total number of signatures: 121037 ClamAV Virus Databases: main.cvd ver. 43 released on 11 Apr 2007 00:14 +0200 daily.cvd ver. 3335 released on 31 May 2007 10:16 +0000 -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From q at snj.ca Thu May 31 18:23:17 2007 From: q at snj.ca (Quintin Giesbrecht) Date: Thu May 31 18:23:24 2007 Subject: Email Addresses Get Stripped... In-Reply-To: References: <2BE78592B3B1824F97A2685E96221F627B0031@mail.snj.mb.ca> Message-ID: <2BE78592B3B1824F97A2685E96221F627B003D@mail.snj.mb.ca> I am using "mailwatch", and if I "release" the message (the exact message that was in question) from the quarantine, the message contains all the right address info...doesn't that seem strange? Q -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto:mailscanner-bounces@lists.mailscanner.info] On Behalf Of Raymond Dijkxhoorn Sent: Thursday, May 31, 2007 8:20 AM To: MailScanner discussion Subject: Re: Email Addresses Get Stripped... Hi! > Has anyone seen this happen? I checked the corresponding email on the > mailscanner server, and the email addresses are in tact. > > Once the message gets to our exchange server, an email that is sent to > multiple recipients, contains only the name of the person, and not the > email address...so, if you want to "reply to all", no one has a valid > address. > > Has anyone ever seen this? Is this something wrong on the mailscanner > server? Or is it an Exchange 2003 problem? This can happen with badly configured or migrated exchange servers. The adres books and so contain links to bad adresses most likely. Outlook checks your addres book and links to one you have there, or one you have used recently. 99% thats your issue. Bye, Raymond. -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! From waytotheweb at googlemail.com Thu May 31 18:39:09 2007 From: waytotheweb at googlemail.com (Sarah Trayser) Date: Thu May 31 18:39:13 2007 Subject: inodes problem In-Reply-To: <223f97700705310849s47b6694cx74f148147d051d87@mail.gmail.com> References: <2007531101223.631487@pcn> <223f97700705310348tace1deewc734ed9be77581db@mail.gmail.com> <223f97700705310849s47b6694cx74f148147d051d87@mail.gmail.com> Message-ID: On 31/05/07, Glenn Steen wrote: > Hm. So for some reason MailScanner isn't cleaning up at restart, or > (as Phil rightly points out) is exiting abnormally. You see nothing > indicative in your logs? Or if you run it in debug (MailScanner > --debug)? I see "MailScanner child dying of old age" entries regularly in the maillog. When I run MailScanner in debug, here's what I get: In Debugging mode, not forking... Ignore errors about failing to find EOCD signature Stopping now as you are debugging me. commit ineffective with AutoCommit enabled at /usr/mailscanner/lib/MailScanner/MailWatch.pm line 94, line 297. It scanned the messages in the queue without problems during the debug run. -- Regards, Sarah Trayser Way to the Web Ltd Server Management Services: http://www.configserver.com Web Hosting: http://www.waytotheweb.com From MailScanner at ecs.soton.ac.uk Thu May 31 18:41:05 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 31 18:41:53 2007 Subject: New Clamav 0.90.3 In-Reply-To: References: Message-ID: <465F08B1.2060009@ecs.soton.ac.uk> I have just updated my easy-to-install Clam+SA package to this latest release. Download from www.mailscanner.info as usual. Scott Silva wrote: > New version of Clamav out. I'm already seeing upgrade warnings in the updates. > > Latest ClamAV? stable release is: 0.90.3 > Total number of signatures: 121037 > ClamAV Virus Databases: > main.cvd ver. 43 released on 11 Apr 2007 00:14 +0200 > daily.cvd ver. 3335 released on 31 May 2007 10:16 +0000 > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From waytotheweb at googlemail.com Thu May 31 18:47:32 2007 From: waytotheweb at googlemail.com (Sarah Trayser) Date: Thu May 31 18:47:35 2007 Subject: inodes problem In-Reply-To: References: <2007531101223.631487@pcn> Message-ID: On 31/05/07, Scott Silva wrote: > A little off topic, but MailScanner systems get a big performance boost by > running the /var/spool/MailScanner/incoming/ directory in tmpfs. You would > need to make sure that it didn't fill up, and it might be a permission problem > in your setups. This often cannot be done on a VPS which is why we do not configure it that way in our setups. > The bug that was mentioned is several years old, and should be > long gone. > Do you have reports of other people with your setup having the same problem? No, we have not come across this as a problem before. On one of our own servers there are 700 of these old empty directories, on another 350, and on another only 150. I just had a look to see if I could find any pattern and it does look like these are being left behind *primarily* at the time of the nightly cPanel software update, so that at least gives us a clue. MailScanner would be restarted following this update. -- Regards, Sarah Trayser Way to the Web Ltd Server Management Services: http://www.configserver.com Web Hosting: http://www.waytotheweb.com From Jason at SYO.Com Thu May 31 18:51:38 2007 From: Jason at SYO.Com (Jason Gottschalk) Date: Thu May 31 18:51:40 2007 Subject: How to store and delete a message Message-ID: <451805095.20070531135138@SYO.Com> Hello MailScanner, I am trying to store (archive) and delete a message. I am using this rule in the archive.rules ruleset -- FromOrTo: Me@mydomain.Com Delete /sites/mysite/mail/archive/mbox The message is being archived correctly, but not deleted, it is still being delivered. Is my syntax wrong? -- Best regards, Jason Gottschalk mailto:Jason@SYO.Com SYO Computer Engineering Services, Inc. SYO - Servicing Your Organization 586-286-2557 From MailScanner at ecs.soton.ac.uk Thu May 31 19:28:49 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 31 19:29:52 2007 Subject: How to store and delete a message In-Reply-To: <451805095.20070531135138@SYO.Com> References: <451805095.20070531135138@SYO.Com> Message-ID: <465F13E1.3060001@ecs.soton.ac.uk> What configuration option are you attaching this ruleset to? Jason Gottschalk wrote: > Hello MailScanner, > > I am trying to store (archive) and delete a message. > > I am using this rule in the archive.rules ruleset > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From ssilva at sgvwater.com Thu May 31 19:40:40 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 31 19:41:20 2007 Subject: inodes problem In-Reply-To: References: <2007531101223.631487@pcn> Message-ID: Sarah Trayser spake the following on 5/31/2007 10:47 AM: > On 31/05/07, Scott Silva wrote: > >> A little off topic, but MailScanner systems get a big performance >> boost by >> running the /var/spool/MailScanner/incoming/ directory in tmpfs. You >> would >> need to make sure that it didn't fill up, and it might be a permission >> problem >> in your setups. > > This often cannot be done on a VPS which is why we do not configure it > that way in our setups. > >> The bug that was mentioned is several years old, and should be >> long gone. >> Do you have reports of other people with your setup having the same >> problem? > > No, we have not come across this as a problem before. On one of our > own servers there are 700 of these old empty directories, on another > 350, and on another only 150. I just had a look to see if I could > find any pattern and it does look like these are being left behind > *primarily* at the time of the nightly cPanel software update, so that > at least gives us a clue. MailScanner would be restarted following > this update. > Sometimes mailscanner benefits from a sleep of 10 or so seconds between a stop and a start. It gives the children some time to finish dying off. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Thu May 31 19:42:51 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 31 19:45:10 2007 Subject: OT: Spam King Arrested! In-Reply-To: <9e1340d20705310953p4e0a7f30n814a61c25f7208e7@mail.gmail.com> References: <223f97700705310857p6cab31d8h1b4ecb1a675c4664@mail.gmail.com> <465EF5E8.5000107@nkpanama.com> <9e1340d20705310953p4e0a7f30n814a61c25f7208e7@mail.gmail.com> Message-ID: Thom Paine spake the following on 5/31/2007 9:53 AM: > I'm waiting for each of those spam emails to be printed out, then put > in a pile, with a big crucifix in the middle, him strung up, and > burned at the stake. > > Maybe I watch too much tv....... > The body would be ashes before all the paper could finish burning! -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Thu May 31 19:48:48 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 31 19:50:14 2007 Subject: How to store and delete a message In-Reply-To: <451805095.20070531135138@SYO.Com> References: <451805095.20070531135138@SYO.Com> Message-ID: Jason Gottschalk spake the following on 5/31/2007 10:51 AM: > Hello MailScanner, > > I am trying to store (archive) and delete a message. > > I am using this rule in the archive.rules ruleset AFAIR you can't delete from the archive rules. You need to not deliver from the spam/notspam rules or functions. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From Jason at SYO.Com Thu May 31 19:53:11 2007 From: Jason at SYO.Com (Jason Gottschalk) Date: Thu May 31 19:53:13 2007 Subject: How to store and delete a message In-Reply-To: <465F13E1.3060001@ecs.soton.ac.uk> References: <451805095.20070531135138@SYO.Com> <465F13E1.3060001@ecs.soton.ac.uk> Message-ID: <621104333.20070531145311@SYO.Com> Hello Julian, Maybe that is the problem, I do not know what you mean by that. I just added the line below to the archive.rules FromOrTo: me@mydomain.com delete /sites/mysite/mail/archive/mbox The mbox writing is working, but the message is still being delivered. Thursday, May 31, 2007, 2:28:49 PM, you wrote: Julian> What configuration option are you attaching this ruleset to? Julian> Jason Gottschalk wrote: >> Hello MailScanner, >> >> I am trying to store (archive) and delete a message. >> >> I am using this rule in the archive.rules ruleset >> Julian> Jules Julian> -- Julian> Julian Field MEng CITP Julian> www.MailScanner.info Julian> Buy the MailScanner book at www.MailScanner.info/store Julian> MailScanner customisation, or any advanced system administration help? Julian> Contact me at Jules@Jules.FM Julian> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 Julian> For all your IT requirements visit www.transtec.co.uk Julian> -- Julian> This message has been scanned for viruses and Julian> dangerous content by MailScanner, and is Julian> believed to be clean. Julian> For all your IT requirements visit www.transtec.co.uk -- Best regards, Jason Gottschalk mailto:Jason@SYO.Com SYO Computer Engineering Services, Inc. 586-286-2557 From ssilva at sgvwater.com Thu May 31 19:46:41 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 31 19:55:10 2007 Subject: New Clamav 0.90.3 In-Reply-To: <465F08B1.2060009@ecs.soton.ac.uk> References: <465F08B1.2060009@ecs.soton.ac.uk> Message-ID: Julian Field spake the following on 5/31/2007 10:41 AM: > I have just updated my easy-to-install Clam+SA package to this latest > release. > Download from www.mailscanner.info as usual. > By the speed at which you are getting things out, it is hard to believe that your health was any less than good! Here's to your continued recovery!!!!! -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From alex at nkpanama.com Thu May 31 19:59:04 2007 From: alex at nkpanama.com (Alex Neuman) Date: Thu May 31 19:59:43 2007 Subject: New Clamav 0.90.3 In-Reply-To: References: <465F08B1.2060009@ecs.soton.ac.uk> Message-ID: <465F1AF8.7010709@nkpanama.com> You could almost say his response time *improved*! :-) Scott Silva wrote: > Julian Field spake the following on 5/31/2007 10:41 AM: > >> I have just updated my easy-to-install Clam+SA package to this latest >> release. >> Download from www.mailscanner.info as usual. >> >> > By the speed at which you are getting things out, it is hard to believe that > your health was any less than good! > > Here's to your continued recovery!!!!! > > From Jason at SYO.Com Thu May 31 20:05:53 2007 From: Jason at SYO.Com (Jason Gottschalk) Date: Thu May 31 20:05:55 2007 Subject: How to store and delete a message In-Reply-To: References: <451805095.20070531135138@SYO.Com> Message-ID: <1566947004.20070531150553@SYO.Com> Hello Scott, Can I write to a mbox from the spam rules? or do I need half of my goal in the spam ruleset and the other half of my gola in the archive ruleset. And if it is split, will the archive process before the spam? Thursday, May 31, 2007, 2:48:48 PM, you wrote: Scott> Jason Gottschalk spake the following on 5/31/2007 10:51 AM: >> Hello MailScanner, >> >> I am trying to store (archive) and delete a message. >> >> I am using this rule in the archive.rules ruleset Scott> AFAIR you can't delete from the archive rules. You need to not deliver from Scott> the spam/notspam rules or functions. Scott> -- Scott> MailScanner is like deodorant... Scott> You hope everybody uses it, and Scott> you notice quickly if they don't!!!! -- Best regards, Jason Gottschalk mailto:Jason@SYO.Com SYO Computer Engineering Services, Inc. 586-286-2557 From MailScanner at ecs.soton.ac.uk Thu May 31 20:04:26 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 31 20:08:18 2007 Subject: inodes problem In-Reply-To: References: <2007531101223.631487@pcn> Message-ID: <465F1C3A.5090803@ecs.soton.ac.uk> Scott Silva wrote: > Sarah Trayser spake the following on 5/31/2007 10:47 AM: > >> On 31/05/07, Scott Silva wrote: >> >> >>> A little off topic, but MailScanner systems get a big performance >>> boost by >>> running the /var/spool/MailScanner/incoming/ directory in tmpfs. You >>> would >>> need to make sure that it didn't fill up, and it might be a permission >>> problem >>> in your setups. >>> >> This often cannot be done on a VPS which is why we do not configure it >> that way in our setups. >> >> >>> The bug that was mentioned is several years old, and should be >>> long gone. >>> Do you have reports of other people with your setup having the same >>> problem? >>> >> No, we have not come across this as a problem before. On one of our >> own servers there are 700 of these old empty directories, on another >> 350, and on another only 150. I just had a look to see if I could >> find any pattern and it does look like these are being left behind >> *primarily* at the time of the nightly cPanel software update, so that >> at least gives us a clue. MailScanner would be restarted following >> this update. >> >> > Sometimes mailscanner benefits from a sleep of 10 or so seconds between a stop > and a start. It gives the children some time to finish dying off. > > I wonder if it's killing it, waiting for a couple of seconds for it to die and then 'kill -9' it, without giving it long enough to clear up. My init.d script gives is 30 seconds to clear up. Funnily enough, there's a reason for that. If the cpanel authors think they know better, then what can I say? Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070531/66b4880b/attachment.html From edwardbruce at sbcglobal.net Thu May 31 20:08:50 2007 From: edwardbruce at sbcglobal.net (Ed Bruce) Date: Thu May 31 20:09:01 2007 Subject: Beta release 4.60.7 In-Reply-To: <465DC71F.2080303@ecs.soton.ac.uk> References: <465DC71F.2080303@ecs.soton.ac.uk> Message-ID: <465F1D42.2030705@sbcglobal.net> -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Julian Field wrote: > This release includes a patch to the new Postfix code in 4.60. If you > are using Postfix versions 2.3 or 2.4, please upgrade to this version to > test it for me. > > Download as usual from www.mailscanner.info. > > Just confused myself. I downloaded 4.60.7 yesterday (and forgot). So clicked on the link today and it download 4.60.6-2? So which one is really the latest beta? -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (Cygwin) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFGXx1CpdNaP9x3McgRAsrXAJwPrnsfpSQA7gQ8hzimeSUHojdiHQCff7oh E6IGERCoDtjqL3XRMCtQJfs= =Jieg -----END PGP SIGNATURE----- From MailScanner at ecs.soton.ac.uk Thu May 31 20:08:14 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 31 20:09:14 2007 Subject: How to store and delete a message In-Reply-To: <621104333.20070531145311@SYO.Com> References: <451805095.20070531135138@SYO.Com> <465F13E1.3060001@ecs.soton.ac.uk> <621104333.20070531145311@SYO.Com> Message-ID: <465F1D1E.6040709@ecs.soton.ac.uk> Jason Gottschalk wrote: > Hello Julian, > > Maybe that is the problem, I do not know what you mean by that. > Every ruleset has to be attached to a configuration option for it to do anything. There must somewhere be a line in your MailScanner.conf saying Config Option Name Here = %rules-dir%/archive.rules And remember that the only place you can use the "delete" keyword is in these config options: spam actions non-spam actions high scoring spam actions > I just added the line below to the archive.rules > > FromOrTo: me@mydomain.com delete /sites/mysite/mail/archive/mbox > > The mbox writing is working, but the message is still being delivered. > > > Thursday, May 31, 2007, 2:28:49 PM, you wrote: > Julian> What configuration option are you attaching this ruleset to? > > Julian> Jason Gottschalk wrote: > >>> Hello MailScanner, >>> >>> I am trying to store (archive) and delete a message. >>> >>> I am using this rule in the archive.rules ruleset >>> >>> > > Julian> Jules > > Julian> -- > Julian> Julian Field MEng CITP > Julian> www.MailScanner.info > Julian> Buy the MailScanner book at www.MailScanner.info/store > > Julian> MailScanner customisation, or any advanced system administration help? > Julian> Contact me at Jules@Jules.FM > > Julian> PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 > Julian> For all your IT requirements visit www.transtec.co.uk > > > > Julian> -- > Julian> This message has been scanned for viruses and > Julian> dangerous content by MailScanner, and is > Julian> believed to be clean. > Julian> For all your IT requirements visit www.transtec.co.uk > > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070531/ae55509d/attachment.html From MailScanner at ecs.soton.ac.uk Thu May 31 20:27:36 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 31 20:28:21 2007 Subject: Beta release 4.60.7 In-Reply-To: <465F1D42.2030705@sbcglobal.net> References: <465DC71F.2080303@ecs.soton.ac.uk> <465F1D42.2030705@sbcglobal.net> Message-ID: <465F21A8.7040807@ecs.soton.ac.uk> Sorry! I screwed up when putting up the page listing ClamAV 0.90.3 and uploaded an old version listing an out-of-date beta release in it. Forgot to 'svn update' first :-( Fixed now. The latest is 4.60.7-1 as you would expect. Jules. Ed Bruce wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Julian Field wrote: > >> This release includes a patch to the new Postfix code in 4.60. If you >> are using Postfix versions 2.3 or 2.4, please upgrade to this version to >> test it for me. >> >> Download as usual from www.mailscanner.info. >> >> >> > > Just confused myself. I downloaded 4.60.7 yesterday (and forgot). So > clicked on the link today and it download 4.60.6-2? So which one is > really the latest beta? > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.5 (Cygwin) > Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org > > iD8DBQFGXx1CpdNaP9x3McgRAsrXAJwPrnsfpSQA7gQ8hzimeSUHojdiHQCff7oh > E6IGERCoDtjqL3XRMCtQJfs= > =Jieg > -----END PGP SIGNATURE----- > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070531/992906da/attachment.html From Jason at SYO.Com Thu May 31 20:30:54 2007 From: Jason at SYO.Com (Jason Gottschalk) Date: Thu May 31 20:30:56 2007 Subject: How to store and delete a message In-Reply-To: <465F1D1E.6040709@ecs.soton.ac.uk> References: <451805095.20070531135138@SYO.Com> <465F13E1.3060001@ecs.soton.ac.uk> <621104333.20070531145311@SYO.Com> <465F1D1E.6040709@ecs.soton.ac.uk> Message-ID: <61045624.20070531153054@SYO.Com> Hello Julian, I see: spam.action.rules spamhigh.action.rules but not nonspam.action.rules Which ruleset that allows delete will run when a message is non spam or whitelisted? Do I have to add this to my .conf? nonspam = %rules-dir%/nonspam.action.rules If so, how does MS know that the delete keyword will apply? Thursday, May 31, 2007, 3:08:14 PM, you wrote: Julian> And remember that the only place you can use the "delete" keyword is in Julian> these config options: Julian> spam actions Julian> non-spam actions Julian> high scoring spam actions -- Best regards, Jason Gottschalk mailto:Jason@SYO.Com SYO Computer Engineering Services, Inc. 586-286-2557 From MailScanner at ecs.soton.ac.uk Thu May 31 20:45:39 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 31 20:46:27 2007 Subject: How to store and delete a message In-Reply-To: <61045624.20070531153054@SYO.Com> References: <451805095.20070531135138@SYO.Com> <465F13E1.3060001@ecs.soton.ac.uk> <621104333.20070531145311@SYO.Com> <465F1D1E.6040709@ecs.soton.ac.uk> <61045624.20070531153054@SYO.Com> Message-ID: <465F25E3.9030108@ecs.soton.ac.uk> You need to understand the relationship between the MailScaner.conf file and any *.rules files you may happen to have. You need to get your head round this (it's really very simple, just look at the MailScanner.conf file and search for mentions of a few of your rulesets). Or you won't get anywhere. MailScanner has to know how to calculate the value of every configuration option for every message. Most things are just simple values such as a number, a filename, a yes/no value, whateve. And then there are rulesets which produce a different value depending on the message properties (the From and/or To address). Jason Gottschalk wrote: > Hello Julian, > > I see: > spam.action.rules > spamhigh.action.rules > > but not nonspam.action.rules > > Which ruleset that allows delete will run when a message is non spam > or whitelisted? > > > Do I have to add this to my .conf? > nonspam = %rules-dir%/nonspam.action.rules > > If so, how does MS know that the delete keyword will apply? > > Thursday, May 31, 2007, 3:08:14 PM, you wrote: > Julian> And remember that the only place you can use the "delete" keyword is in > Julian> these config options: > Julian> spam actions > Julian> non-spam actions > Julian> high scoring spam actions > > > Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From stinkybob at gmail.com Thu May 31 20:52:57 2007 From: stinkybob at gmail.com (Eugene MacDougal) Date: Thu May 31 20:53:00 2007 Subject: Default Virus Actions Message-ID: <2579c6b20705311252m6bbfede5qf88b8f9918d1a041@mail.gmail.com> Is it possible to change the virus actions to be similar to spam? I would like to quarantine the virus messages that come through and not deliver them to the users. Is this possible with MailScanner or does it only remove the virus from the original messge? Thanks in advance, -Eugene -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070531/07bc387d/attachment.html From holger at noefer.org Thu May 31 20:54:57 2007 From: holger at noefer.org (Holger =?iso-8859-1?b?TvZmZXI=?=) Date: Thu May 31 20:55:04 2007 Subject: New ClamAV version Message-ID: <20070531215457.6jqiy2kuc3s4sck4@www.noefer.org> Hi all, a new version of clamav is out, 0.90.3 Here the changes http://sourceforge.net/project/shownotes.php?release_id=512356&group_id=86638 Some security and stability bugs have been fixed. I have not tested it. Best regards, Holger From MailScanner at ecs.soton.ac.uk Thu May 31 20:59:35 2007 From: MailScanner at ecs.soton.ac.uk (Julian Field) Date: Thu May 31 21:00:44 2007 Subject: Default Virus Actions In-Reply-To: <2579c6b20705311252m6bbfede5qf88b8f9918d1a041@mail.gmail.com> References: <2579c6b20705311252m6bbfede5qf88b8f9918d1a041@mail.gmail.com> Message-ID: <465F2927.1000100@ecs.soton.ac.uk> Eugene MacDougal wrote: > Is it possible to change the virus actions to be similar to spam? I > would like to quarantine the virus messages that come through and not > deliver them to the users. Is this possible with MailScanner or does > it only remove the virus from the original messge? Take a look at "Deliver Cleaned Messages", and the "Quarantine" options. > > Thanks in advance, > -Eugene Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk From stinkybob at gmail.com Thu May 31 21:08:48 2007 From: stinkybob at gmail.com (Eugene MacDougal) Date: Thu May 31 21:08:53 2007 Subject: Default Virus Actions Message-ID: <2579c6b20705311308o37a4ca14u97197e50049083cd@mail.gmail.com> Thanks for pointing that out. That option was right in my face and I missed it. I appreciate you not flaming me like other lists may have. -Eugene -----Original Message----- From: mailscanner-bounces@lists.mailscanner.info [mailto: mailscanner-bounces@lists.mailscanner.info] On Behalf Of Julian Field Sent: Thursday, May 31, 2007 3:00 PM To: MailScanner discussion Subject: Re: Default Virus Actions Eugene MacDougal wrote: > Is it possible to change the virus actions to be similar to spam? I > would like to quarantine the virus messages that come through and not > deliver them to the users. Is this possible with MailScanner or does > it only remove the virus from the original messge? Take a look at "Deliver Cleaned Messages", and the "Quarantine" options. > > Thanks in advance, > -Eugene Jules -- Julian Field MEng CITP www.MailScanner.info Buy the MailScanner book at www.MailScanner.info/store MailScanner customisation, or any advanced system administration help? Contact me at Jules@Jules.FM PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For all your IT requirements visit www.transtec.co.uk -- This message has been scanned for viruses and dangerous content by MailScanner, and is believed to be clean. For all your IT requirements visit www.transtec.co.uk -- MailScanner mailing list mailscanner@lists.mailscanner.info http://lists.mailscanner.info/mailman/listinfo/mailscanner Before posting, read http://wiki.mailscanner.info/posting Support MailScanner development - buy the book off the website! -------------- next part -------------- An HTML attachment was scrubbed... URL: http://lists.mailscanner.info/pipermail/mailscanner/attachments/20070531/73af5a1e/attachment.html From rob at dido.ca Thu May 31 21:09:42 2007 From: rob at dido.ca (Rob Morin) Date: Thu May 31 21:09:47 2007 Subject: SA whitelist not working?? In-Reply-To: <223f97700705311006k65af8086u2de530488ce7a8df@mail.gmail.com> References: <465EFCD5.10701@dido.ca> <223f97700705311006k65af8086u2de530488ce7a8df@mail.gmail.com> Message-ID: <465F2B86.1080703@dido.ca> I have always been using that syntax, i simply go into /opt/Mailscanner/etc/rules and edit spam.whitelist Its been working ok for years, except now its stopped.... That email is simply my hotmail address that i sent via the hotmail website to one of my other email addresses, so yes it should be in the envelope as the sender.... Is there another way i should be creating whitelists??? I would like to be as standard as i can be.... Thanks for your prompt reply... Rob Morin Dido InterNet Inc. Montreal, Canada Http://www.dido.ca 514-990-4444 Glenn Steen wrote: > On 31/05/07, Rob Morin wrote: >> Hello all... >> >> I just added a new email in the white list, i restarted SA and tested >> the email , however it still comes through as normal email and not as >> whitelisted, it still gets knocked out as spam?? >> >> I have other emails in the list that work fine still.... i made sure i >> used tabs rather than spaces... it simply looks like this... >> >> FromOrTo: bloddy_ceaser@hotmail.com yes > Um, this is an MS rule, not an SA rule. > Whitelisting like that (email address) is generally a bad idea, but > that aside... Is that the _envelope_ sender/recipient? Are you sure it > is your system removing it? > >> and yet it will get deleted if i send it with reconized spam stuff in >> it.... >> >> I rechecked the file for bad characters, and i see nothing, i used VI to >> be safe... >> >> linting SA comes back ok > > And if you do > MailScanner --lint > .... that gives...? > >> Any ideas? >> >> I am using MS 4.53 from tarball install, everything is in /opt as per >> default install >> >> I am confused.. >> >> Thanks.. >> > > Cheers From alex at nkpanama.com Thu May 31 21:13:38 2007 From: alex at nkpanama.com (Alex Neuman van der Hans) Date: Thu May 31 21:15:58 2007 Subject: Default Virus Actions In-Reply-To: <2579c6b20705311308o37a4ca14u97197e50049083cd@mail.gmail.com> References: <2579c6b20705311308o37a4ca14u97197e50049083cd@mail.gmail.com> Message-ID: <465F2C72.5080407@nkpanama.com> One thing I've noticed about this list is that people will not flame you as easily as other lists/chatrooms/forums. It's been years since I've seen an unwarranted flame - and even some who may have deserved getting flamed got a decent "please rephrase your question" or "try to explain what you mean by so and so" instead of getting "kicked in the groin". :-) Eugene MacDougal wrote: > Thanks for pointing that out. That option was right in my face and I > missed it. I appreciate you not flaming me like other lists may have. > > -Eugene > > -----Original Message----- > From: mailscanner-bounces@lists.mailscanner.info > > [mailto:mailscanner-bounces@lists.mailscanner.info > ] On Behalf Of > Julian Field > Sent: Thursday, May 31, 2007 3:00 PM > To: MailScanner discussion > Subject: Re: Default Virus Actions > > > > > Eugene MacDougal wrote: > > Is it possible to change the virus actions to be similar to spam? I > > would like to quarantine the virus messages that come through and not > > deliver them to the users. Is this possible with MailScanner or does > > it only remove the virus from the original messge? > Take a look at "Deliver Cleaned Messages", and the "Quarantine" options. > > > > Thanks in advance, > > -Eugene > > Jules > > -- > Julian Field MEng CITP > www.MailScanner.info > Buy the MailScanner book at www.MailScanner.info/store > > > MailScanner customisation, or any advanced system administration help? > Contact me at Jules@Jules.FM > > PGP footprint: EE81 D763 3DB0 0BFD E1DC 7222 11F6 5947 1415 B654 For > all your IT requirements visit www.transtec.co.uk > > > > > -- > This message has been scanned for viruses and > dangerous content by MailScanner, and is > believed to be clean. > For all your IT requirements visit www.transtec.co.uk > > > -- > MailScanner mailing list > mailscanner@lists.mailscanner.info > > http://lists.mailscanner.info/mailman/listinfo/mailscanner > > Before posting, read http://wiki.mailscanner.info/posting > > Support MailScanner development - buy the book off the website! > From ssilva at sgvwater.com Thu May 31 22:10:06 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 31 22:10:30 2007 Subject: New Clamav 0.90.3 In-Reply-To: <465F1AF8.7010709@nkpanama.com> References: <465F08B1.2060009@ecs.soton.ac.uk> <465F1AF8.7010709@nkpanama.com> Message-ID: Alex Neuman spake the following on 5/31/2007 11:59 AM: > You could almost say his response time *improved*! :-) > Because he hasn't had to run the "work" process. But that probably won't last too much longer. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Thu May 31 22:13:03 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 31 22:15:11 2007 Subject: How to store and delete a message In-Reply-To: <1566947004.20070531150553@SYO.Com> References: <451805095.20070531135138@SYO.Com> <1566947004.20070531150553@SYO.Com> Message-ID: Jason Gottschalk spake the following on 5/31/2007 12:05 PM: > Hello Scott, > > Can I write to a mbox from the spam rules? or do I need half of my > goal in the spam ruleset and the other half of my gola in the archive > ruleset. > > And if it is split, will the archive process before the spam? > Are you trying to archive "everything" or just non-spam? Do you have one archive, or one for each recipient? -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From ssilva at sgvwater.com Thu May 31 22:19:16 2007 From: ssilva at sgvwater.com (Scott Silva) Date: Thu May 31 22:20:19 2007 Subject: Default Virus Actions In-Reply-To: <465F2C72.5080407@nkpanama.com> References: <2579c6b20705311308o37a4ca14u97197e50049083cd@mail.gmail.com> <465F2C72.5080407@nkpanama.com> Message-ID: Alex Neuman van der Hans spake the following on 5/31/2007 1:13 PM: > One thing I've noticed about this list is that people will not flame you > as easily as other lists/chatrooms/forums. It's been years since I've > seen an unwarranted flame - and even some who may have deserved getting > flamed got a decent "please rephrase your question" or "try to explain > what you mean by so and so" instead of getting "kicked in the groin". :-) > Julian usually "puts out the flames" very quickly. After you get a couple "nice -n 19"'s from the superuser you tend to quiet down a little. -- MailScanner is like deodorant... You hope everybody uses it, and you notice quickly if they don't!!!! From itdept at fractalweb.com Thu May 31 22:30:48 2007 From: itdept at fractalweb.com (Chris Yuzik) Date: Thu May 31 22:31:10 2007 Subject: New Clamav 0.90.3 In-Reply-To: References: <465F08B1.2060009@ecs.soton.ac.uk> <465F1AF8.7010709@nkpanama.com> Message-ID: <465F3E88.4060502@fractalweb.com> Scott Silva wrote: > Alex Neuman spake the following on 5/31/2007 11:59 AM: > >> You could almost say his response time *improved*! :-) > Because he hasn't had to run the "work" process. But that probably won't last > too much longer. > Ok, that's funny. I was just reading an aricle detailing the inner-workings of load averages. So Julian, what is your load average these days? ;-) Cheers! From dave.list at pixelhammer.com Thu May 31 23:25:58 2007 From: dave.list at pixelhammer.com (DAve) Date: Thu May 31 23:27:04 2007 Subject: Default Virus Actions In-Reply-To: <465F2C72.5080407@nkpanama.com> References: <2579c6b20705311308o37a4ca14u97197e50049083cd@mail.gmail.com> <465F2C72.5080407@nkpanama.com> Message-ID: <465F4B76.4020909@pixelhammer.com> Alex Neuman van der Hans wrote: > One thing I've noticed about this list is that people will not flame you > as easily as other lists/chatrooms/forums. It's been years since I've > seen an unwarranted flame - and even some who may have deserved getting > flamed got a decent "please rephrase your question" or "try to explain > what you mean by so and so" instead of getting "kicked in the groin". :-) > Yea, I've been on THAT list ;^) DAve -- Three years now I've asked Google why they don't have a logo change for Memorial Day. Why do they choose to do logos for other non-international holidays, but nothing for Veterans? Maybe they forgot who made that choice possible.