Re: [Declude.JunkMail] Deculde hanging

2008-11-06 Thread Darrell ([EMAIL PROTECTED])
Usually in situations like this you ran into a killer message. When Declude restarts it will copy all of the files from the work directory into the review directory. You can slowly copy those messages to track down the killer message and than when you find the message submit it to Declude

Re: [Declude.JunkMail] Deculde hanging

2008-11-06 Thread Darrell ([EMAIL PROTECTED])
: Darrell ([EMAIL PROTECTED]) [EMAIL PROTECTED] To: declude.junkmail@declude.com Sent: Thursday, November 06, 2008 9:02 AM Subject: Re: [Declude.JunkMail] Deculde hanging Usually in situations like this you ran into a killer message. When Declude restarts it will copy all of the files from

Re: [Declude.JunkMail] URIBL vs. SURBL

2008-10-17 Thread Darrell ([EMAIL PROTECTED])
I get good hits from both lists with invURIBL. uribl.com is more aggressive (IMO) than surbl. I query SURBL first and than uribl second. Even with that config (and skip weights set) I still get more hits on URIBL. F:\Logs\invURIBLgrep -i message body found in multi.uribl.com

Re: [Declude.JunkMail] New Blacklist / Whitelist

2008-10-17 Thread Darrell ([EMAIL PROTECTED])
They (Barracuda) ask that you register with them your DNS server that you will be querying from. I suspect at some point if the volume gets out of hand they may restrict the service to those who entered in their DNS servers. -- Check out

Re: [Declude.JunkMail] DNS Changes

2008-10-08 Thread Darrell ([EMAIL PROTECTED])
The diags.txt file is created as infomation whent he declude proc service is restarted. One thign you need to check is do you have a DNSOVERRIDE set in your declude.cfg file? Declude by default (as long as there is no DNSOVERRIDE) will use the IP of the DNS server in Imail Admin interface.

Re: [Declude.JunkMail] Declude Crashing

2008-08-02 Thread Darrell ([EMAIL PROTECTED])
Do you have autoreview enabled? If so when Declude crashes on restart it will copy the files (work dir) back into the proc for processing. These types of crashes are most likely assuming no changes to your system a result of a bad message. If you disable autoreview and the crashes stop you

Re: [Declude.JunkMail] Firewall rule question

2008-06-09 Thread Darrell ([EMAIL PROTECTED])
Scott, Here are my thoughts.. My question is... Is/Has anyone else tried this approach If so is impact on the amount of mail your server had to process? Yes, I have taken this approach for the absolute worst offenders. Mostly the most abusive senders. This however has very limited

Re: [Declude.JunkMail] Filter Backscatter

2008-05-03 Thread Darrell ([EMAIL PROTECTED])
Ruben, One thing you can do is create a from filter that looks for the null sender and than do a copyfile action on it if it did not match the backscatter filter. This way you will be able to see which messages did not get filtered to improve the back scatter filter for your system.

Re: [Declude.JunkMail] Undeliverable mails

2008-04-28 Thread Darrell ([EMAIL PROTECTED])
Glen, This is fairly normal. When spammers send out campaigns they pretty much use spoofed addresses. Unfortunately your address as well as others in your domain have been used thus you are receiving the back scatter. On some of the servers I maintain for clients we have seen waves of

Re: [Declude.JunkMail] No Reverse DNS pointer?

2008-04-22 Thread Darrell ([EMAIL PROTECTED])
1) If a mail server is configured without a reverse DNS pointer, is enough to prevent email from reaching AOL, Yahoo, Hotmail, etc? AOL indicates they will do this, on occasion I have seen this, but not all the time. 2) Do you block email coming from mail servers with no reverse DNS? No,

Re: [Declude.JunkMail] blocking certain character sets

2008-04-21 Thread Darrell ([EMAIL PROTECTED])
Ferrell, After you added that charset to the declude.cfg file did you restart the decludeproc service? Darrell -- Check out http://www.invariantsystems.com for utilities for Declude, Imail, mxGuard, and ORF. IMail/Declude Overflow Queue Monitoring, SURBL/URI

Re: [Declude.JunkMail] Reasons to renew

2008-04-19 Thread Darrell ([EMAIL PROTECTED])
Michael, Judging by that screen cap you are having a rough time to say the least. I am sure you have exhausted a ton of options, but have you turned off DEP for Declude? I have seen repeated crashes like that on a system which did not exclude Declude under DEP. Darrell

Re: [Declude.JunkMail] Filters not triggering

2008-04-07 Thread Darrell ([EMAIL PROTECTED])
Dave, I noticed with the relevant lines from the filter posted below some of the lines were indented more than the one line. Is it possible you have extraneous whitespaces between contains and the text you want to filter on? Dsrrell -- Check out

Re: [Declude.JunkMail] Filters not triggering

2008-04-07 Thread Darrell ([EMAIL PROTECTED])
between the contains and the data that I want to filter on. I was under the understanding that those were ignored? Dave -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Darrell ([EMAIL PROTECTED]) Sent: Monday, April 07, 2008 2:42 PM To: declude.junkmail

Re: [Declude.JunkMail] 4.4.00 Released

2008-04-04 Thread Darrell ([EMAIL PROTECTED])
Has anyone tried this option yet? DEC ADD Can use for 4 digit year on log file names in the format ddmm IS the format really ddmm - it seems like it would make more sense if the format was actually mmdd? Especially since the regular format of

Re: [Declude.JunkMail] Version 4.4.0 leaving some trash?

2008-04-04 Thread Darrell ([EMAIL PROTECTED])
I just checked and I am seeing this as well. Darrell -- Check out http://www.invariantsystems.com for utilities for Declude, Imail, mxGuard, and ORF. IMail/Declude Overflow Queue Monitoring, SURBL/URI integration, MRTG Integration, and Log Parsers. Adolfo

Re: [Declude.JunkMail] Forged-Spam Backscatter

2008-04-03 Thread Darrell ([EMAIL PROTECTED])
Jim, While others may cringe regarding this, but some of the backscatter I have had to deal with (excess of 500-1000 messages a minute at times) I have had to put filters in place to delete null senders for periods of time. Darrell Jim Comerford wrote: Over the last several weeks we have

[Declude.Virus] DLAnalyzer 5.2.2 Released

2008-03-15 Thread Darrell ([EMAIL PROTECTED])
DLAnalyzer 5.2.2 has been released. DLAnalyzer is a comprehensive reporting tool that integrates both Junkmail and Virus statistics into one report. Some of the features require the Enterprise or Standard version, but we also have a FREE LITE version available. Report Samples:

[Declude.JunkMail] DLAnalyzer 5.2.2 Released

2008-03-15 Thread Darrell ([EMAIL PROTECTED])
DLAnalyzer 5.2.2 has been released. DLAnalyzer is a comprehensive reporting tool that integrates both Junkmail and Virus statistics into one report. Some of the features require the Enterprise or Standard version, but we also have a FREE LITE version available. Report Samples:

Re: [Declude.JunkMail] evaluating foreign spam

2008-03-05 Thread Darrell ([EMAIL PROTECTED])
Do you expect to receive russian messages (other than spam) if not than you can filter by charset koi8-r. Charset filtering is not CPU intensive. Darrell -- Check out http://www.invariantsystems.com for utilities for Declude, Imail, mxGuard, and ORF.

Re: [Declude.JunkMail] multiple simultaneous problems

2008-03-01 Thread Darrell ([EMAIL PROTECTED])
. David Dodell wrote: -Original Message- From: Darrell ([EMAIL PROTECTED]) [EMAIL PROTECTED] Which RBL's are timing out? Is your DNS server having problems? Is your DNS server local to the mail server or is it located somewhere else? It is totally random ... sometimes none

Re: [Declude.JunkMail] multiple simultaneous problems

2008-02-29 Thread Darrell ([EMAIL PROTECTED])
David, Comment's inline (2) Declude is failing to make connections on RBL tests about 10 to 20% of the time. Running in debug mode will show one message running against multiple DBL tests, and then the message will show the first 5 DBL tests running, and the rest fail with no connection

Re: [Declude.JunkMail] Filter for Bounce messages

2008-02-18 Thread Darrell ([EMAIL PROTECTED])
Don, Depending on your situation you could simply filter the null sender in a from file filter. I would not suggest this as a permanent solution as NDR's are helpful in most cases. About two weeks ago I had a user get hammered with probably 500-1000 NDR's per second from a spam campaign.

Re: [Declude.JunkMail] Barracuda Quarantine bypass

2008-02-18 Thread Darrell ([EMAIL PROTECTED])
Scott, Does the Barracuda system add any headers that we could trigger a filter to hit will reduce the weight so we can prevent it from being captured? Darrell -- Check out http://www.invariantsystems.com for utilities for Declude, Imail, mxGuard, and ORF.

Re: [Declude.JunkMail] DecludePro Eating Up CPU

2008-02-10 Thread Darrell ([EMAIL PROTECTED])
David, It really depends on several factors: how you have Declude configured (tests, filters, etc), how many threads your running, volume. It's not uncommon to see for me to see decludeproc on a dual proc xeon 2.4ghz using 75% of ram, but I am running ~50 threads at a volume of 200K+

Re: [Declude.JunkMail] DecludePro Eating Up CPU

2008-02-10 Thread Darrell ([EMAIL PROTECTED])
. IMail/Declude Overflow Queue Monitoring, SURBL/URI integration, MRTG Integration, and Log Parsers. David Dodell wrote: On Feb 10, 2008, at 1:42 PM, Darrell ([EMAIL PROTECTED]) wrote: David, It really depends on several factors: how you have Declude configured (tests, filters, etc), how

Re: [Declude.JunkMail] counting mail

2008-02-08 Thread Darrell ([EMAIL PROTECTED])
Bonno, With emails that have multiple recipients its not uncommon to see last actions multiple times for the same message. This will skew your results. Your better off using a tool like DLAnalyzer to analyze your logs as it takes all of this into account. Plus it can be scheduled to run

Re: [Declude.JunkMail] Any Known issues Inv-URIBL today?

2008-02-06 Thread Darrell ([EMAIL PROTECTED])
Randy, None that I am aware of. It's processing fine on all of my servers. Also, version 1.x is very old (several years). We are now on version 3.1.1. Darrell -- Check out http://www.invariantsystems.com for utilities for Declude, Imail, mxGuard, and ORF.

Re: [Declude.JunkMail] Any Known issues Inv-URIBL today?

2008-02-06 Thread Darrell ([EMAIL PROTECTED])
In addition to what Pete suggests with Weightgate (which I also use on some servers with older hardware). You will want to set inside your invuribl.exe.config file values for max and min skipweights to skip any unnecessary processing of messages. Darrell --

Re: [Declude.JunkMail] re: [384-0F3A4F35-96D8] You do not have permission to post to the declude.junkmail@declude.com list

2008-02-05 Thread Darrell ([EMAIL PROTECTED])
At the bottom of the message the morons posted the proper way to remove oneself from the list. This E-mail came from the Declude.JunkMail mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type unsubscribe Declude.JunkMail. The archives can be found at

Re: [Declude.JunkMail] Indicate msg size in header on an authenticated whitelisted

2008-01-24 Thread Darrell ([EMAIL PROTECTED])
John, It's hard to say depending on how the message was whitelisted dictates which tests are ran. I never seen an official list on what tests get run based on the level of whitelisting but I believe user authenticated skips all tests. Can anyone confirm that? Darrell

Re: [Declude.JunkMail] Declude ??? Long Delay Processing?

2008-01-05 Thread Darrell ([EMAIL PROTECTED])
The first thing to do is check and make sure you do not have a ton of files in your proc folder. This would indicate a queue backup. The next thing if your not having a ton of files in your proc is to kick the logs into debug mode and send a test message. Look through the debug log and find

Re: [Declude.JunkMail] Re: Outbound weight

2007-12-22 Thread Darrell ([EMAIL PROTECTED])
WEIGHT10 does delete outbound since it is defined, but I never defined WEIGHT40 so that was ignored.I needed to add a line that now says WEIGHT10 DELETE WEIGHT40 DELETE for the outbound in global.cfg Yes, that is absolutely correct. After enabling that if its still not working post a

Re: [Declude.JunkMail] Outbound weight

2007-12-21 Thread Darrell ([EMAIL PROTECTED])
Are you sure your scanning outbound mail? Their is a directive that needs to be turned on for it to work. By default its off. JM ADD Spam checking for inbound/outbound scanning can be turned on/off. Located as a directive in the global.cfg file, below are the default settings.

Re: [Declude.JunkMail] Re: Outbound weight

2007-12-21 Thread Darrell ([EMAIL PROTECTED])
Your weight ranges are set fine. There is nothing wrong with the syntax of those. To be certain you only have weight ranges defined once right? Can you throw your logs into debug and send a test outbound message through. We will be able to help you better seeing this output. Darrell

Re: [Declude.JunkMail] Loop

2007-12-17 Thread Darrell ([EMAIL PROTECTED])
From looking at this the st07.edmsa.net server is running MSSMTP and sending it back to you. Are they using MSSMTP as a gateway to relay it internally to themself's? If so in the settings do they have it set to use a smarthost instead of use DNS to deliver? Darrell

Re: [Declude.JunkMail] OT: Use MS IIS SMTP server as a gateway

2007-12-12 Thread Darrell ([EMAIL PROTECTED])
Craig, I currently use MS SMTP as a gateway for several customers. Shoot me a note off list and I can help you get going. Darrell -- Check out http://www.invariantsystems.com for utilities for Declude, Imail, mxGuard, and ORF. IMail/Declude Overflow Queue

Re: [Declude.JunkMail] akamai.net Redirect/obfuscation

2007-12-11 Thread Darrell ([EMAIL PROTECTED])
Don, That's interesting. That line is actually an Akamai cache key that is being used to reference the image directly from Akamai's cache. Based on the cache key I suspect this showed up in a phish. For folks that utilize Akamai's caching services would never reference content via that

Re: [Declude.JunkMail] my DNS tests

2007-11-08 Thread Darrell ([EMAIL PROTECTED])
FWIW - I pulled CSMA-SBL ip4r sbl.csma.biz 127.0.0.2 5 0 earlier this week as it was timing out for us. Darrell -- Check out http://www.invariantsystems.com for utilities for Declude, Imail, mxGuard, and ORF. IMail/SmarterMail/Declude Queue Monitoring,

Re: [Declude.JunkMail] new virus/spam as mp3?

2007-10-18 Thread Darrell ([EMAIL PROTECTED])
MP3 spam - the new kid on the block Posted on 18 October 2007. Spammers are back with a new trick, this time round sending messages with MP3 attachments that contain the latest pump-and-dump stock scams. One sample identified this morning by GFI, was a heavily distorted 30-second MP3 file.

Re: [Declude.JunkMail] SMTP_DELIV_FAILED

2007-10-09 Thread Darrell ([EMAIL PROTECTED])
Matt wrote: I haven't followed this thread much, but it seems fairly obvious what the the problem is related to. When your server is connecting to the recipient's server, it fails to establish a connection with that server. This log line indicates the likely source of the problem:

Re: [Declude.JunkMail] noticed problem after upgrade to beta

2007-10-08 Thread Darrell ([EMAIL PROTECTED])
Herb, There were a lot of posts on this late last week on the forum. Declude is working on the fix. -- Check out http://www.invariantsystems.com for utilities for Declude, Imail, mxGuard, and ORF. IMail/Declude Overflow Queue Monitoring, SURBL/URI

Re: [Declude.JunkMail] SMTP_DELIV_FAILED

2007-10-08 Thread Darrell ([EMAIL PROTECTED])
Your A / PTR records look fine. mail.rogersbenefit.com. 7200IN A 207.47.22.58 58.22.47.207.in-addr.arpa. 86288 IN PTR mail.rogersbenefit.com Your listed in one RBL - backscatter so it would seem that it should not be related to spam. Can you post a more detailed smtp

Re: [Declude.JunkMail] OT: Setting Up DNS Service on Server 2003

2007-10-08 Thread Darrell ([EMAIL PROTECTED])
Kevin, All you need to do is install the service and your already in caching mode. Just limit the outsides ability to query it since you will need to have recursion enabled and MSDNS does not allow you to set what ip blocks can and can not query the dns service. Any problems let me know

Re: [Declude.JunkMail] OT: Setting Up DNS Service on Server 2003

2007-10-08 Thread Darrell ([EMAIL PROTECTED])
So if my server's local IP is 192.168.0.4 and I have simply installed the DNS service, I can change Imail's SMTP settings to include 192.168.0.4 as one of my DNS servers? I would use 127.0.0.1 as it speeds things up a bit opposed to using the IP address. In my Network Connection applet

Re: [Declude.JunkMail] HELP, Declude stoped functioning

2007-09-29 Thread Darrell ([EMAIL PROTECTED])
Randy, Is the decludeproc service started? Also, in the declude folder to you have a diags text file? Darrell -- Check out http://www.invariantsystems.com for utilities for Declude, Imail, mxGuard, and ORF. IMail/Declude Overflow Queue Monitoring, SURBL/URI

Re: [Declude.JunkMail] HELP, Declude stoped functioning

2007-09-29 Thread Darrell ([EMAIL PROTECTED])
: [81CDE419-BDA4-44DB-9090-89C4A7492A98] IS EXPIRED KEY but we just renewed this yesterday.. --- Randy A. Technical Support Director Global Web Solutions, Inc. 804-442-5300 globalweb.net - Original Message - From: Darrell ([EMAIL PROTECTED]) [EMAIL PROTECTED] To: declude.junkmail

Re: [Declude.JunkMail] HELP, Declude stoped functioning

2007-09-29 Thread Darrell ([EMAIL PROTECTED])
. Matt wrote: Darrell, The Web server at fluidhosting.com that dlanalyzer.com is hosted on is listed in CBL currently and has been before. http://cbl.abuseat.org/lookup.cgi?ip=204.14.91.21 Matt Darrell ([EMAIL PROTECTED]) wrote: You will need to contact Declude at this point

Re: [Declude.JunkMail] What am I doing wrong with Revdns filter?

2007-09-09 Thread Darrell ([EMAIL PROTECTED])
Queue Monitoring, SURBL/URI integration, MRTG Integration, and Log Parsers. David Dodell wrote: .On Sep 8, 2007, at 10:55 AM, Darrell ([EMAIL PROTECTED]) wrote: .It should have. Do you also have an entry in the $default$.junkmail file as well? I would bump your logs up to debug for a quick

Re: [Declude.JunkMail] What am I doing wrong with Revdns filter?

2007-09-08 Thread Darrell ([EMAIL PROTECTED])
David, It should have. Do you also have an entry in the $default$.junkmail file as well? I would bump your logs up to debug for a quick couple of seconds to verify indeed the test is being called. The other thing is if 66.135.209.210 did not resolve on your system you would not get a hit

[Declude.JunkMail] New RBL

2007-08-26 Thread Darrell ([EMAIL PROTECTED])
FYI - Seen this on another list (SA-Users). David you may want to add this to the RBL list. This may interest those playing with RBL checks in SA, we have released spamrats.com as a free RBL service now. http://www.spamrats.com RATS-NoPtr and RATS-Dyna will be the most useful, RATS-Spam is

Re: [Declude.JunkMail] F-Prot 6?

2007-08-23 Thread Darrell ([EMAIL PROTECTED])
SJ, Marc was only trying to help by pointing out that F-Prot has a different licensing scheme for mail servers than client machines. At one time F-Prot did not differentiate the two and a lot of us were using F-Prot with a much higher user count than even what the chart listed below. Than

Re: [Declude.JunkMail] Upgrade to version 4 causes processor to skyrocket

2007-08-21 Thread Darrell ([EMAIL PROTECTED])
What are your settings in your declude.cfg file. Are you still using the same setting in that file from Version 3? Has your mail volume increased? Darrell Kevin Stanford wrote: Hi all, Since upgrading to Declude Version 4 (from version 3) my processor has really taken a hit (runs about

Re: [Declude.JunkMail] copyfile ?

2007-08-17 Thread Darrell ([EMAIL PROTECTED])
Looks right to me - I use WEIGHT-TAG-RVW1 COPYFILE X:\Review\ WEIGHT-TAG-RVW2 COPYFILE X:\Review\Low Darrell -- Check out http://www.invariantsystems.com for utilities for Declude, Imail, mxGuard, and ORF. IMail/Declude Overflow Queue

Re: [Declude.JunkMail] ZEN test

2007-08-01 Thread Darrell ([EMAIL PROTECTED])
Bonno, Due to your HOP setting you are checking multiple hops. Since you use a multihop setting you should score the hops differently or run into problems like you identified. I would suggest reducing it to 1. This will score the last two hops. Than you can modify your tests like the

Re: [Declude.JunkMail] How to whitelist this

2007-07-27 Thread Darrell ([EMAIL PROTECTED])
Why not just base it on a REVDNS test for .fedex.com and assign a large negative weight? -- Check out http://www.invariantsystems.com for utilities for Declude, Imail, mxGuard, and ORF. IMail/Declude Overflow Queue Monitoring, SURBL/URI integration, MRTG

Re: [Declude.JunkMail] frustration

2007-07-18 Thread Darrell ([EMAIL PROTECTED])
Uwe, It's always a battle. However, there are a lot of good resources on this list that are willing to share and help. I am sure we can get you to the point where you can breath a bit again... Darrell -- Check out http://www.invariantsystems.com for

Re: [Declude.JunkMail] Filtering outbound as a default

2007-07-02 Thread Darrell ([EMAIL PROTECTED])
Ben, In newer versions of Declude there is a directive for the global.cfg that needs to be turned on OUTBOUNDSCANNINGSPAM ON. I believe in newer versions ON is the default? Than you would need to add your tests and actions like in the $default$.junkmail file into the global.cfg file.

Re: [Declude.JunkMail] Filtering outbound as a default

2007-07-02 Thread Darrell ([EMAIL PROTECTED])
integration, MRTG Integration, and Log Parsers. Imail Admin wrote: What about older versions? Thanks, Ben - Original Message - From: Darrell ([EMAIL PROTECTED]) [EMAIL PROTECTED] To: declude.junkmail@declude.com Sent: Monday, July 02, 2007 2:14 PM Subject: Re: [Declude.JunkMail] Filtering

[Declude.JunkMail] invURIBL 3.0.7 Released

2007-06-29 Thread Darrell ([EMAIL PROTECTED])
For those using invURIBL with Declude we have released an update today. For more information http://www.invariantsystems.com/invuribl/ Any questions let me know, Darrell -- Check out http://www.invariantsystems.com for utilities for Declude, Imail, and

Re: [Declude.JunkMail] New PDF worm?

2007-06-27 Thread Darrell ([EMAIL PROTECTED])
SJ, Andrew posted a blurb from SANS a couple of days ago. Pump and dump scams now in PDF Published: 2007-06-20, Last Updated: 2007-06-20 21:33:39 UTC by Maarten Van Horenbeeck (Version: 1) Apparently the groups behind what we know as pump and dump spam have found a new way to bypass spam

Re: [Declude.JunkMail] OT: Software for copying files with permissions

2007-06-26 Thread Darrell ([EMAIL PROTECTED])
Sharyn, I would check out robocopy in the resource kit. I use it all the time to do stuff like this. Darrell - Check out http://www.invariantsystems.com for utilities for Declude, Imail, mxGuard, and ORF. IMail/Declude Overflow Queue Monitoring,

Re: [Declude.JunkMail] Looking for an Secure Email Solution that works with Imail Premium 2006.2 and declude 4.x

2007-06-07 Thread Darrell ([EMAIL PROTECTED])
Are you looking for a solution like the PGP plug in's for Outlook or something else? Darrell --- Check out http://www.invariantsystems.com for utilities for Declude and Imail. IMail/Declude Overflow Queue Monitoring, SURBL/URI integration, MRTG

Re: [Declude.JunkMail] is the list working?

2007-06-05 Thread Darrell \([EMAIL PROTECTED])
Still here, just quiet. Sometimes that's a good thing :) Darrell Check out http://www.invariantsystems.com for utilities for Declude And Imail. IMail/Declude Overflow Queue Monitoring, SURBL/URI integration, MRTG

Re: [Declude.JunkMail] More accidental whitelisting

2007-05-29 Thread Darrell \([EMAIL PROTECTED])
I think the whole idea of whitelisting the address book should be an option that can be turned on/off from the config file. It is with the AUTOWHITELIST setting in the global.cfg. Darrell invURIBL - Intelligent URI

Re: [Declude.JunkMail] Per user config and performance

2007-05-16 Thread Darrell \([EMAIL PROTECTED])
For 5,000 users I wouldnt expect a major performance hit, but keep in mind if you had 5,000 files they all need to be loaded when a message is processed. However, I would only drop a user config file with actions set to WARN for the users who did not want to be spam filtered. This way the

[Declude.JunkMail] Anyone seeing the 419 Death Threat Scam yet?

2007-05-08 Thread Darrell \([EMAIL PROTECTED])
See - http://isc.sans.org/diary.html Wondering if anyone has actually seen any of these? 419 death threat scam Published: 2007-05-08, Last Updated: 2007-05-08 18:49:23 UTC by Swa Frantzen (Version: 1) A new scam is circulating on the Internet: There are a number of variation on the text, but it

Re: [Declude.JunkMail] X-Note: REVDNS: (timeout)

2007-04-30 Thread Darrell \([EMAIL PROTECTED])
Harry, REVDNS timeout occurs when Declude does not get an answer from the DNS serer indicating the reverse entry does not exist. Basically this means the REVDNS could exist but Declude is not sure because it never received a response back saying it did or did not exist. Darrell

[Declude.JunkMail] Vulnerability in RPC on Windows DNS Server Could Allow Remote Code Execution

2007-04-13 Thread Darrell \([EMAIL PROTECTED])
FYI - This looks pretty serious and will probably affect most of us. This alert is to notify you that Microsoft has released Security Advisory 935964 - Vulnerability in RPC on Windows DNS Server Could Allow Remote Code Execution - on 12 April 2007. Summary: Microsoft is investigating new

Re: [Declude.JunkMail] Vulnerability in RPC on Windows DNS Server Could Allow Remote Code Execution

2007-04-13 Thread Darrell \([EMAIL PROTECTED])
this could lead to some trouble as well. Darrell -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Darrell ([EMAIL PROTECTED]) Sent: Friday, April 13, 2007 10:08 AM To: [EMAIL PROTECTED] Subject: [Declude.JunkMail] Vulnerability in RPC on Windows DNS Server

Re: [Declude.JunkMail] Vulnerability in RPC on Windows DNS Server Could Allow Remote Code Execution

2007-04-13 Thread Darrell \([EMAIL PROTECTED])
Mark, You have a link for those? Darrell Check out http://www.invariantsystems.com for utilities for Declude And Imail. IMail/Declude Overflow Queue Monitoring, SURBL/URI integration, MRTG Integration, and Log Parsers.

Re: [Declude.JunkMail] Increase in CPU usage since upgrade

2007-04-10 Thread Darrell \([EMAIL PROTECTED])
What version did you upgrade from? Darrell Check out http://www.invariantsystems.com for utilities for Declude And Imail. IMail/Declude Overflow Queue Monitoring, SURBL/URI integration, MRTG Integration, and Log Parsers.

Re: [Declude.JunkMail] Increase in CPU usage since upgrade

2007-04-10 Thread Darrell \([EMAIL PROTECTED])
was: Current:32/Average:23/Maximum:49 After the upgrade to 4.3.40: Current:66/Average:49/Maximum:100 (With spikes at 100% cpu usage sometimes lasting an 3 hours.) Mike TNWEB -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Darrell ([EMAIL PROTECTED]) Sent

Re: [Declude.JunkMail] OT: Yahoo Email Problems

2007-03-29 Thread Darrell \([EMAIL PROTECTED])
A couple months ago there was a big thread on the imail list about yahoo doing 451 Message temporarily deferred - 4.16.50However nothing on unable to read configuration - that does sound like a remote option. When you try other yahoo.com servers does it go through? Maybe you got a bad server

Re: [Declude.JunkMail] Body Filter - Stupid/Simple Question

2007-03-15 Thread Darrell \([EMAIL PROTECTED])
Don, You can put a space in the filter file to do that, but it has some drawbacks. For example if the word was terminated with any character like a period etc. What I tend to do is something like this .1cialis .-1specialist i.e. reverse credit for legit hit words.

Re: [Declude.JunkMail] COMMTOUCH FP Reporting

2007-03-06 Thread Darrell \([EMAIL PROTECTED])
Jeff, I had the exact same thing happen. I sent them a list of refid's that were false positives per the false positive reporting document and never received a response back either. Has anyone received a response back? Darrell

Re: [Declude.JunkMail] COMMTOUCH FP Reporting

2007-03-06 Thread Darrell \([EMAIL PROTECTED])
, Commtouch does not respond to individuals, only to partners. It would be nice for some response, especially on FP's. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Darrell ([EMAIL PROTECTED]) Sent: Tuesday, March 06, 2007 9:37 AM To: declude.junkmail

Re: [Declude.JunkMail] Help: Domain not found

2007-02-26 Thread Darrell \([EMAIL PROTECTED])
BlankIs there really a space in the logs or is that just a formatting issue? philippe @ malivsion.com Darrell Check out http://www.invariantsystems.com for utilities for Declude And Imail. IMail/Declude Overflow Queue

Re: [Declude.JunkMail] Declude/Sniffer Issues

2007-02-19 Thread Darrell \([EMAIL PROTECTED])
What are you seeing the logs that indicates this? Declude will terminate long running external processes and log that it terminated it. Are you seeing those entries? Also, during these times when you look at task manager do you see a bunch of idle sniffer processes? Typically from my

Re: [Declude.JunkMail] Decludeproc.ex Faulting Applicaction

2007-02-19 Thread Darrell \([EMAIL PROTECTED])
I know you mentioned that you have tried a reinstall - but have you tried an uninstall and made sure after that the decludeproc and declude.exe files are gone from the Imail directory? Once you know they are gone try to reinstall again. Darrell

Re: [Declude.JunkMail] Declude/Sniffer Issues

2007-02-19 Thread Darrell \([EMAIL PROTECTED])
: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Darrell ([EMAIL PROTECTED]) Sent: Monday, February 19, 2007 9:32 AM To: declude.junkmail@declude.com Subject: Re: [Declude.JunkMail] Declude/Sniffer Issues What are you seeing the logs that indicates this? Declude

Re: [Declude.JunkMail] Declude/Sniffer Issues

2007-02-19 Thread Darrell \([EMAIL PROTECTED])
] On Behalf Of Darrell ([EMAIL PROTECTED]) Sent: Monday, February 19, 2007 2:53 PM To: declude.junkmail@declude.com Subject: Re: [Declude.JunkMail] Declude/Sniffer Issues What is your mail volume and how many threads do you have declude configured for? Darrell

Re: [Declude.JunkMail] Declude/Sniffer Issues

2007-02-19 Thread Darrell \([EMAIL PROTECTED])
: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Darrell ([EMAIL PROTECTED]) Sent: Monday, February 19, 2007 2:53 PM To: declude.junkmail@declude.com Subject: Re: [Declude.JunkMail] Declude/Sniffer Issues What is your mail volume and how many threads do you have declude

Re: [Declude.JunkMail] Weird email problem

2007-01-25 Thread Darrell \([EMAIL PROTECTED])
MessageBased on the headers and the logs this was a retransmission. Something happened in the initial send that caused it to be aborted. They did not attempt the resend until today. That's a very long retransmission interval. As Kevin said earlier these kinds of things happen from time to

Re: [Declude.JunkMail] [IANA Reserved] ?

2007-01-04 Thread Darrell \([EMAIL PROTECTED])
I would be very careful with this. IANA just released (I believe in October) 96/8, 97/8, 98/8, 99/8. With the all_list.dat not being updated frequently I would tred very lightly in this area. Part of 96/8 has been handed out. Darrell

Re: [Declude.JunkMail] change location of spam email folders

2006-12-30 Thread Darrell \([EMAIL PROTECTED])
You sure can - see example below. WEIGHT30 HOLD F:\SPAM-HOLD\%DATE% Darrell Check out http://www.invariantsystems.com for utilities for Declude And Imail. IMail/Declude Overflow Queue Monitoring, SURBL/URI integration,

Re: [Declude.JunkMail] Resend email caught by Declude/Sniffer

2006-12-20 Thread Darrell \([EMAIL PROTECTED])
If you would like them to be reprocessed by Declude you can do the following below. Declude (service version) - Drop the files into the proc directory off the spool. If you are running the non service version drop the q* into the overflow directory and the d* into the spool directory. If you

Re: [Declude.JunkMail] Imail 2006.1 and declude

2006-12-19 Thread Darrell \([EMAIL PROTECTED])
threads 150 This is very high - even on a dual proc xeon (2.6) box - HT enabled - I am easily able to run with 40 threads processing 150K messages a day. What is your message volume? Darrell Check out

Re: [Declude.JunkMail] New Version 4.3.2.3

2006-12-17 Thread Darrell \([EMAIL PROTECTED])
4.3.2.3 If it installed correctly it will. It may be putting it in a different directory, in which case it is probably using the wrong configs as well. Herb Darrell ([EMAIL PROTECTED]) wrote: I am noticing that when restarting the Declude Proc service it does not generate a diags.txt file

Re: [Declude.JunkMail] New Version 4.3.2.3

2006-12-17 Thread Darrell \([EMAIL PROTECTED])
?? What are you using? Darrell ([EMAIL PROTECTED]) wrote: I am noticing that when restarting the Declude Proc service it does not generate a diags.txt file anymore. Is this normal behavior to be expected with this version. Darrell Chris Asaro Technical Support Engineer Declude Your Email

Re: [Declude.JunkMail] New Version 4.3.2.3

2006-12-17 Thread Darrell \([EMAIL PROTECTED])
] New Version 4.3.2.3 Actually Darrell I hadn't checked this on a server running Imail?? What are you using? Darrell ([EMAIL PROTECTED]) wrote: I am noticing that when restarting the Declude Proc service it does not generate a diags.txt file anymore. Is this normal behavior to be expected

Re: [Declude.JunkMail] Interesting ORF stats

2006-12-15 Thread Darrell \([EMAIL PROTECTED])
Goes to prove spammers are still trying the lowest priority MX record to get around spam filters. That is very true. I think the mindset is that folks don't have access to features like IPBYPASS and trust mail coming from their backup mail server by default. Darrell

Re: [Declude.JunkMail] Why are these being whitelisted?

2006-12-14 Thread Darrell \([EMAIL PROTECTED])
Why are these being whitelisted?If you change your log level to high it will log the exact reason the message was whitelisted. Also, remember if one user on the email (even if they were BCC'ed) is whitelisted the whole message will be whitelisted. Darrell

Re: [Declude.JunkMail] Why are these being whitelisted?

2006-12-14 Thread Darrell \([EMAIL PROTECTED])
MessageOn that one I am not sure - I would bump your logs to HIGH and than we will be able to tell for sure. Darrell Check out http://www.invariantsystems.com for utilities for Declude And Imail. IMail/Declude Overflow

[Declude.JunkMail] MimeOLE

2006-12-02 Thread Darrell \([EMAIL PROTECTED])
What can anyone tell me about this X-Header X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2962 Does outlook produce this or is this added by a MS tool? Darrell Check out http://www.invariantsystems.com for utilities

Re: [Declude.JunkMail] Way to delete spam over a certain weight?

2006-12-01 Thread Darrell \([EMAIL PROTECTED])
Sure - setup another weightrange test with your weight and set that action to delete. Darrell Check out http://www.invariantsystems.com for utilities for Declude And Imail. IMail/Declude Overflow Queue Monitoring,

[Declude.JunkMail] Re: [sniffer] Configuring Sniffer in declude....

2006-11-29 Thread Darrell \([EMAIL PROTECTED])
Chuck, Declude will only call Sniffer one time as long as the path and executable are identical which they are. Darrell Check out http://www.invariantsystems.com for utilities for Declude And Imail. IMail/Declude

Re: [Declude.JunkMail] Declude v2.06 and Imail 2006.1

2006-11-28 Thread Darrell \([EMAIL PROTECTED])
MessageAs Matt said - Imail 8.22+ requires Declude 3+. So if you end up trying to use 2.x under 2006 you may or may not have issues. Darrell Check out http://www.invariantsystems.com for utilities for Declude And Imail.

Re: [Declude.JunkMail] Blacklists Recommendations.

2006-11-27 Thread Darrell \([EMAIL PROTECTED])
Chuck, I would look to add MxRate and FiveTen. Darrell Check out http://www.invariantsystems.com for utilities for Declude And Imail. IMail/Declude Overflow Queue Monitoring, SURBL/URI integration, MRTG Integration, and

Re: [Declude.JunkMail] Spamhaus

2006-11-16 Thread Darrell \([EMAIL PROTECTED])
Bill, Thanks for posting that - one interesting thing I found was this. Use of the Spamhaus DNSBLs by commercial users, including corporate networks, ISPs and ESPs, requires a subscription to Spamhaus's Data Feed service. Looked at the cost for some of the scenario's and it does not seem

  1   2   3   4   5   6   >