[sniffer] Bug Report: SNFServer for *nix

2011-09-22 Thread Pete McNeil
Hello Sniffer folks, We have discovered that some testing code escaped into the latest tarball: snf-server-3.0.12.tar.gz This testing code intentionally causes SNFServer to crash (seg fault) under special conditions. This was done so that we could examine the resulting core dump. You may

[sniffer] Re: Bad Matrix errors

2011-08-22 Thread Pete McNeil
044 x7010 # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More information see http://www.armresearch.com To unsubscribe, E-mail t

[sniffer] Re: Bad Matrix errors

2011-08-22 Thread Peer-to-Peer (Support)
Yes, the errors have now stopped with the new update. The issue ran across all servers so I must have corrupted the last update at some point. Thanks for the speedy response! --Paul -Original Message- From: Message Sniffer Community [mailto:sniffer@sortmonster.com]On Behalf Of Pete

[sniffer] Nice job, sortmonsters!

2011-08-08 Thread Colbeck, Andrew
affiliate marketing. Sent with lots of word salad). Andrew 8) # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware

[sniffer] Change in default settings

2011-05-09 Thread Pete McNeil
Hello Message Sniffer Folks, We're recommending a change in the default settings for message sniffer in order to improve our response times for new campaigns. The change is small and enhances our virtual spamtrap technology so that we see new spams sooner and with greater sampling coverage

[sniffer] Re: Change in default settings

2011-05-09 Thread Pete McNeil
because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More information see http://www.armresearch.com To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode

[sniffer] Re: Change in default settings

2011-05-09 Thread Colbeck, Andrew
it one way or the other. Andrew. -Original Message- From: Message Sniffer Community [mailto:sniffer@sortmonster.com] On Behalf Of Pete McNeil Sent: Monday, May 09, 2011 11:56 AM To: Message Sniffer Community Subject: [sniffer] Change in default settings Hello Message Sniffer Folks, We're

[sniffer] Re: Change in default settings

2011-05-09 Thread Pete McNeil
-1044 x7010 # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More information see http

[sniffer] Re: Change in default settings

2011-05-09 Thread Colbeck, Andrew
Great. I'll remove the erroneous comment I made in my configuration files. FWIW, I've set both peek-one-in='3' and grab-one-in='3' as the new recommended default. Andrew. -Original Message- From: Message Sniffer Community [mailto:sniffer@sortmonster.com] On Behalf Of Pete McNeil Sent

[sniffer] IMail mail1.exe removed

2011-04-13 Thread Pete McNeil
Hi Sniffer Folks, Many of you who use Imail also use the imail1.exe command line utility to send yourself updates and reports from your system. Be advised (if you don't already know) that this program has been removed from IMail and there does not appear to be a replacement at this time

[sniffer] So, another botnet bites the dust.

2011-03-18 Thread Colbeck, Andrew
Pete, now that Microsoft has taken down the Rustock botnet, what's your telemetry say about spam volumes? Any significant change? http://blogs.technet.com/b/microsoft_blog/archive/2011/03/18/taking-down -botnets-microsoft-and-the-rustock-botnet.aspx

[sniffer] Re: So, another botnet bites the dust.

2011-03-18 Thread Pete McNeil
On 3/18/2011 4:17 PM, Colbeck, Andrew wrote: Pete, now that Microsoft has taken down the Rustock botnet, what's your telemetry say about spam volumes? Any significant change? I don't see a dent.

[sniffer] IPv6

2011-03-11 Thread Peer-to-Peer (Support)
hours. IPv4 only has 4.3 billion IP addresses. Pete: Grab a cup of coffee. The botNet's are coming... --Paul # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list

[sniffer] Re: IPv6

2011-03-11 Thread Bonno Bloksma
  b.blok...@tio.nl  / www.tio.nl  -Oorspronkelijk bericht- Van: Message Sniffer Community [mailto:sniffer@sortmonster.com] Namens Peer-to-Peer (Support) Verzonden: vrijdag 11 maart 2011 14:25 Aan: Message Sniffer Community Onderwerp: [sniffer] IPv6 Hi everyone, I've been thinking about

[sniffer] Re: IPv6

2011-03-11 Thread Pete McNeil
Scientist ARM Research Labs, LLC www.armresearch.com 866-770-1044 x7010 # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti

[sniffer] CommuniGate Pro Plugin for MS Windows Updated

2011-01-17 Thread Pete McNeil
Hi Sniffer Folks, Just a quick note to let you know we've updated the MS Windows version of our Anti Spam / Anti Malware plugin for CommunigGate Pro. http://www.armresearch.com/products/SNF4CGP.jsp http://www.armresearch.com/message-sniffer/download/CGPSNF-Win32-Intel.zip We have rewritten

[sniffer] RulePanic on 3741490

2011-01-07 Thread Darin Cox
Hi guys, We're seeing a lot of FPs on 3741490 this morning. I've added a RulePanic for it in our systems. Roughly 150 FPs from 6:55am until a few minutes ago... Darin.

[sniffer] Re: RulePanic on 3741490

2011-01-07 Thread Pete McNeil
is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More information see http://www.armresearch.com To unsubscribe, E-mail to: sniffer-...@sortmonster.com

[sniffer] Re: RulePanic on 3741490

2011-01-07 Thread Darin Cox
- From: Pete McNeil To: Message Sniffer Community Sent: Friday, January 07, 2011 11:27 AM Subject: [sniffer] Re: RulePanic on 3741490 On 1/7/2011 10:19 AM, Darin Cox wrote: Hi guys, We're seeing a lot of FPs on 3741490 this morning. I've added a RulePanic for it in our systems

[sniffer] Re: RulePanic on 3741490

2011-01-07 Thread Pete McNeil
Scientist ARM Research Labs, LLC www.armresearch.com 866-770-1044 x7010 # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam

[sniffer] Re: RulePanic on 3741490

2011-01-07 Thread Darin Cox
rule for active/inactive state. I assume some sort of push mechanism to all subscribers, to notify their systems that a rule is no longer valid, is what you're planning here. Best. Darin. - Original Message - From: Pete McNeil To: Message Sniffer Community Sent: Friday, January 07

[sniffer] Re: RulePanic on 3741490

2011-01-07 Thread Pete McNeil
- Pete McNeil Chief Scientist ARM Research Labs, LLC www.armresearch.com 866-770-1044 x7010 # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniff

[sniffer] Bad Rule Event

2010-12-16 Thread Pete McNeil
Hello Sniffer Folks, We have had a bad rule event. The bad rules were created near 0830E, and removed by 1030E. The bad rules were discovered by our IP/Rule conflict instrument indicating that most were automatically rejected by Auto-Panic features. The rules were part of a rule family designed

[sniffer] Re: Bad Rule Event

2010-12-16 Thread Bonno Bloksma
Hi Pete, Hello Sniffer Folks, We have had a bad rule event. The bad rules were created near 0830E, and removed by 1030E. [...] Regarding this event A while ago we talked about sniffer installations exchanging rule-panic info via the GUBdb sync info as that is happening every (few

[sniffer] Re: Bad Rule Event

2010-12-16 Thread Pete McNeil
On 12/16/2010 11:07 AM, Bonno Bloksma wrote: Hi Pete, Hello Sniffer Folks, We have had a bad rule event. The bad rules were created near 0830E, and removed by 1030E

[sniffer] Hello again

2010-11-09 Thread Pete McNeil
Hello Sniffer Folks, This is just a quick note to touch base. It's been a while since we've had an update, and the list is so quiet! * Over the past few days we've finished a major re-tuning of our rulebase compiler system. The improved rulebase compiler bots are just a bit smarter

[sniffer] Testing SM direct intergration

2010-09-22 Thread Keith Dovale
Hi Guys, I would be interested in testing this ..

[sniffer] Re: Testing SM direct intergration

2010-09-22 Thread Pete McNeil
-- Chief Scientist ARM Research Labs, LLC www.armresearch.com # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware

[sniffer] Re: Rule Panic on 3364665

2010-08-17 Thread Colbeck, Andrew
I have seen one hit, and it looks like a false positive to me. Sent as a sample to the false@ address. Thanks for the heads-up, Darin. Andrew. From: Message Sniffer Community [mailto:snif...@sortmonster.com] On Behalf Of Darin Cox Sent: Tuesday, August 17

[sniffer] Re: Rule Panic on 3364665

2010-08-17 Thread Pete McNeil
spam. _M -- Chief Scientist ARM Research Labs, LLC www.armresearch.com # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message

[sniffer] Re: Rule Panic on 3364665

2010-08-17 Thread Darin Cox
To: Message Sniffer Community Sent: Tuesday, August 17, 2010 3:31 PM Subject: [sniffer] Re: Rule Panic on 3364665 I have seen one hit, and it looks like a false positive to me. Sent as a sample to the false@ address. Thanks for the heads-up, Darin. Andrew

[sniffer] Re: Rule Panic on 3364665

2010-08-17 Thread Darin Cox
Thanks, Pete. Darin. - Original Message - From: Pete McNeil To: Message Sniffer Community Sent: Tuesday, August 17, 2010 3:37 PM Subject: [sniffer] Re: Rule Panic on 3364665 On 8/17/2010 3:10 PM, Darin Cox wrote: Hi, We've had a lot of FPs on this rule, and wanted to alert

[sniffer] Re: Direct SmarterMail integration -- Some Testers ?

2010-06-10 Thread ecs
are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More information see http://www.armresearch.com To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode, E-mail

[sniffer] Re: Direct SmarterMail integration -- Some Testers ?

2010-06-10 Thread David Moore
of MessageSniffer into smartermail # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More

[sniffer] Direct SmarterMail integration -- Some Testers ?

2010-06-09 Thread Pete McNeil
Hello Sniffer Folks, We are working on testing and improving direct integration options with Smarter Mail. The current option is very simple. We've posted a QA about it here: http://www.armresearch.com/support/qa/integration/smarterMail.jsp If you are interested in testing

[sniffer] Re: Direct SmarterMail integration -- Some Testers ?

2010-06-09 Thread Pete McNeil
On 6/9/2010 2:44 PM, Pete McNeil wrote: Hello Sniffer Folks, We are working on testing and improving direct integration options with Smarter Mail. Shamelessly responding to my own post, I thought I would point out: You do not need to re-install Message Sniffer to test this option. If you

[sniffer] Re: Direct SmarterMail integration -- Some Testers ?

2010-06-09 Thread E. H. (Eric) Fletcher
Sniffer Community [mailto:snif...@sortmonster.com] On Behalf Of Pete McNeil Sent: Wednesday, June 09, 2010 12:02 PM To: Message Sniffer Community Subject: [sniffer] Re: Direct SmarterMail integration -- Some Testers ? On 6/9/2010 2:44 PM, Pete McNeil wrote: Hello Sniffer Folks, We are working

[sniffer] Re: Direct SmarterMail integration -- Some Testers ?

2010-06-09 Thread ecs
Pete, This is great news! It would also be a better option if you are able to work with smarterTools directly and see about getting sniffer integrated as a built in call when enabled. SmarterTools added an option for declude integration a few years back and we have been waiting for a true

[sniffer] Re: Direct SmarterMail integration -- Some Testers ?

2010-06-09 Thread Pete McNeil
, LLC www.armresearch.com # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More

[sniffer] Re: Direct SmarterMail integration -- Some Testers ?

2010-06-09 Thread Pete McNeil
are able to work with smarterTools directly and see about getting sniffer integrated as a built in call when enabled. We would love to do that. Please ask them about it so that they know their customers are interested in this !! We are ready to work with them to develop a tight integration

[sniffer] Re: Direct SmarterMail integration -- Some Testers ?

2010-06-09 Thread Mxuptime.com
Folks, Having integrated Sniffer into MxScan for SmarterMail, I would like to shared some of my thoughts : 1. From what I can see at the moment neither Commtouch nor Declude has direct hooks into the SMTP sessions. Any integration at SMTP session level would definitely require some changes from

[sniffer] Re: GBUdb.com Web Site is Up - truncate.gbudb.net text records updated

2010-05-30 Thread Pete McNeil
On 5/29/2010 10:45 PM, Andy Schmidt wrote: Hi, An annual donation is not a problem - of course, we are already paying for Sniffer and supplying feedback that is incorporated into GBUdb - so to us it's just another way to access information for which we are already licensed (using an RBL instead

[sniffer] Re: GBUdb.com Web Site is Up - truncate.gbudb.net text records updated

2010-05-29 Thread Andy Schmidt
Hi, In case anyone wants to use it in ORF, attached the updated definition file. (Pete, I didn't post it on their newsgroup because I didn't know if you wanted the word out). Best Regards, Andy -Original Message- From: Message Sniffer Community [mailto:snif...@sortmonster.com

[sniffer] Re: GBUdb.com Web Site is Up - truncate.gbudb.net text records updated

2010-05-29 Thread Pete McNeil
sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More information see http://www.armresearch.com To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode, E-mail to sniffer-dig...@sortmonster.com

[sniffer] Re: GBUdb.com Web Site is Up - truncate.gbudb.net text records updated

2010-05-29 Thread Andy Schmidt
Hi, An annual donation is not a problem - of course, we are already paying for Sniffer and supplying feedback that is incorporated into GBUdb - so to us it's just another way to access information for which we are already licensed (using an RBL instead of the Sniffer API) - just a bit earlier

[sniffer] GBUdb.com Web Site is Up - truncate.gbudb.net text records updated

2010-05-23 Thread Pete McNeil
Hi Sniffer Folks, The GBUdb.com web site is up http://www.gbudb.com We have also updated the generator for the truncate.gbudb.net list so that the TXT records include a link to the list descriptor at http://www.gbudb.com/truncate/ and the IP address in [square brackets]. Please tell us what

[sniffer] Volume spike Mon 9AM EST

2010-05-10 Thread Peer-to-Peer (Support)
. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More information see http://www.armresearch.com

[sniffer] Re: Volume spike Mon 9AM EST

2010-05-10 Thread Darin Cox
I'm seeing it, too. Darin. - Original Message - From: Peer-to-Peer (Support) suppor...@peertopeer.net To: Message Sniffer Community sniffer@sortmonster.com Sent: Monday, May 10, 2010 9:21 AM Subject: [sniffer] Volume spike Mon 9AM EST Just checking to see if anyone else is seeing

[sniffer] Re: Volume spike Mon 9AM EST

2010-05-10 Thread NetEase Operations Manager
I am getting a lot of complaints from my customers concerning the huge spikes too. DustyC -Original Message- From: Message Sniffer Community [mailto:snif...@sortmonster.com] On Behalf Of Darin Cox Sent: Monday, May 10, 2010 9:51 AM To: Message Sniffer Community Subject: [sniffer] Re

[sniffer] Re: Volume spike Mon 9AM EST

2010-05-10 Thread Pete McNeil
Labs, LLC www.armresearch.com # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More

[sniffer] Re: Volume spike Mon 9AM EST

2010-05-10 Thread Colbeck, Andrew
I'm not seeing any spike in inbound connections or accepted message counts. Actually, it's lower than Friday's volume and about the same as Thursday. Andrew. -Original Message- From: Message Sniffer Community [mailto:snif...@sortmonster.com] On Behalf Of Peer-to-Peer (Support) Sent

[sniffer] Re: Opening truncate.gbudb.net

2010-05-10 Thread Colbeck, Andrew
. That probably means that I'm finding users with zombie infected computers, but I'm letting that mail in, so checking which IP addresses were hit is a small problem if I want to contact those people. Andrew. -Original Message- From: Message Sniffer Community [mailto:snif...@sortmonster.com

[sniffer] Re: Opening truncate.gbudb.net

2010-05-10 Thread Greg Coffey
-- From: Colbeck, Andrew acolb...@bentall.com Reply-To: Message Sniffer Community sniffer@sortmonster.com Date: Mon, 10 May 2010 09:03:27 -0700 I looked at the effectiveness of this test and I like what I'm seeing. The volume isn't high, but it is making a difference in the edge cases

[sniffer] Re: Volume spike Mon 9AM EST

2010-05-10 Thread NetEase Operations Manager
That is the case here as well. I should have clarified that in my earlier post. Sniffer is doing its job. Unfortunately I am running through two levels of spam filtering systems and a ton is getting through still. DustyC -Original Message- From: Message Sniffer Community [mailto:snif

[sniffer] Re: Volume spike Mon 9AM EST

2010-05-10 Thread Darin Cox
Hi Pete, No. Not leakage. Sniffer et al are doing their job well. Just a large spike in incoming spam volume. It settled down for us by about 11am. Darin. - Original Message - From: Pete McNeil madscient...@armresearch.com To: Message Sniffer Community sniffer@sortmonster.com

[sniffer] Re: Volume spike Mon 9AM EST

2010-05-10 Thread Pete McNeil
On 5/10/2010 12:23 PM, Darin Cox wrote: Hi Pete, No. Not leakage. Sniffer et al are doing their job well. Just a large spike in incoming spam volume. It settled down for us by about 11am. I checked on telemetry and found a mixed bag -- some systems were up quite a bit-- others were

[sniffer] Re: Volume spike Mon 9AM EST

2010-05-10 Thread Michael Cummins
Sniffer is doing its job well, but I am nearly overwhelmed by the load - to the point where I might have to turn sniffer off to reduce my processing footprint. I've already commented out INVURIBL. My customers don't like lag at all. That being said, I wonder how I can better protect myself

[sniffer] Re: Volume spike Mon 9AM EST

2010-05-10 Thread Pete McNeil
On 5/10/2010 2:15 PM, Michael Cummins wrote: Sniffer is doing its job well, but I am nearly overwhelmed by the load - to the point where I might have to turn sniffer off to reduce my processing footprint. I've already commented out INVURIBL. My customers don't like lag at all. That being said

[sniffer] Re: Volume spike Mon 9AM EST

2010-05-10 Thread Michael Cummins
Is there a way we could get a SNIFFER feature like that implemented as an internal DECLUDE test? Barring that, perhaps get it to write a text file of current IPs to block? -- Michael Cummins -Original Message- From: Message Sniffer Community [mailto:snif...@sortmonster.com] On Behalf

[sniffer] Re: Volume spike Mon 9AM EST

2010-05-10 Thread Pete McNeil
On 5/10/2010 2:37 PM, Michael Cummins wrote: Is there a way we could get a SNIFFER feature like that implemented as an internal DECLUDE test? SNFIPREP and SNFIP tests give you some direct access to GBUdb -- of course at that point you've already accepted the message for scanning even

[sniffer] Re: Volume spike Mon 9AM EST

2010-05-10 Thread Michael Cummins
Cummins # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More information see http

[sniffer] Re: Volume spike Mon 9AM EST

2010-05-10 Thread Pete McNeil
so. _M -- Chief Scientist ARM Research Labs, LLC www.armresearch.com # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti

[sniffer] Now OT: Re: [sniffer] Re: Opening truncate.gbudb.net

2010-05-10 Thread Sanford Whiteman
. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More information see http://www.armresearch.com To unsubscribe, E-mail to: sniffer

[sniffer] Re: Opening truncate.gbudb.net

2010-05-10 Thread Colbeck, Andrew
0.2, p 0.9 for [205.188.84.131] I'll send the whole header to support@ in case you are interested in this particular IP. Andrew. -Original Message- From: Message Sniffer Community [mailto:snif...@sortmonster.com] On Behalf Of Colbeck, Andrew Sent: Monday, May 10, 2010 9:03 AM

[sniffer] Re: Opening truncate.gbudb.net

2010-05-10 Thread Pete McNeil
, LLC www.armresearch.com # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More

[sniffer] Re: Declude: Sniffer IP vs. Sniffer IP Reputation vs. Sniffer Truncate

2010-05-03 Thread Pete McNeil
On 4/30/2010 5:54 PM, Andy Schmidt wrote: Hi Pete, I'm look over Declude's recommended Sniffer configuration and trying to understand how much (if any) overlap there is between these options they implemented and recommend: This was cross-posted from the Declude.JunkMail list and I

[sniffer] Changing result code for truncate.gbudb.net to 127.0.0.2

2010-04-30 Thread Pete McNeil
Hello Sniffer Folks, RFC 5782 states: IPv4-based DNSxLs MUST NOT contain an entry for 127.0.0.1. and also states: The A record contents conventionally have the value 127.0.0.2 So we will be changing the result code for truncate.gbudb.net to 127.0.0.2 effective immediately. Thanks! _M

[sniffer] Declude: Sniffer IP vs. Sniffer IP Reputation vs. Sniffer Truncate

2010-04-30 Thread Andy Schmidt
Hi Pete, I'm look over Declude's recommended Sniffer configuration and trying to understand how much (if any) overlap there is between these options they implemented and recommend: IPREPUTATIONSNFIPREPx 0 10 -5 SNFIPCAUTIONSNFIP x

[sniffer] Opening truncate.gbudb.net

2010-04-29 Thread Pete McNeil
Hi Sniffer Folks, We have been testing a blacklist based on real-time GBUdb data (generated from Message Sniffer). We have decided to experiment with opening up the blacklist for a wider audience and so as of now you can use truncate.gbudb.net as an ip4r test. You should get a result

[sniffer] Re: Opening truncate.gbudb.net

2010-04-29 Thread John Dobbin
I've added it as a warn_if_reject on a backup mx that only seems to process junk... -Original Message- From: Message Sniffer Community [mailto:snif...@sortmonster.com] On Behalf Of Pete McNeil Sent: Thursday, April 29, 2010 4:08 PM To: Message Sniffer Community Subject: [sniffer] Opening

[sniffer] Re: RulePanic on 3059196

2010-04-06 Thread Darin Cox
list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More information see http://www.armresearch.com To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode, E-mail to sniffer-dig

[sniffer] Re: RulePanic on 3059196

2010-04-06 Thread Colbeck, Andrew
For what it is worth, there are zero hits on my two servers for this Rule. I looked back through the last 7 days. Andrew. -Original Message- From: Message Sniffer Community [mailto:snif...@sortmonster.com] On Behalf Of Darin Cox Sent: Tuesday, April 06, 2010 9:48 AM To: Message

[sniffer] Re: RulePanic on 3059196

2010-04-06 Thread Pete McNeil
to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More information see http://www.armresearch.com To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode, E-mail to sniffer-dig

[sniffer] SNF4SA Upgrade

2010-03-30 Thread Pete McNeil
Hello Sniffer Folks, We have posted two new files to our products page containing an upgrade to our Message Sniffer for Spam Assassin plugin: Message Sniffer Client/Server for *Nix (Linux, BSD, OSX, etc...) http://www.armresearch.com/message-sniffer/download/snf-server-3.0.11.tar.gz Message

[sniffer] Re: Rulebase updates increased by 25%!!!

2010-03-22 Thread Kevin Rogers
I haven't had an update since 8:45am PST. Usually I'll have 3 or 4 updates in this period. Anything going on? Thanks Kevin On 2/5/2010 11:44 AM, Pete McNeil wrote: Hi Sniffer Folks, After more back-end improvements and some careful analysis we have increased our rulebase update rate

[sniffer] Re: Rulebase updates increased by 25%!!!

2010-03-22 Thread Peer-to-Peer (Support)
something solid to work with if it continues. Thanks for your fast assistance. Regards, --Paul -Original Message- From: Message Sniffer Community [mailto:snif...@sortmonster.com]on Behalf Of Pete McNeil Sent: Monday, March 22, 2010 6:29 PM To: Message Sniffer Community Subject: [sniffer] Re

[sniffer] Re: 3 million rules and counting.

2010-03-17 Thread Richard Stupek
Congratulations. Keep up the good work!

[sniffer] Outgoing spam filtering

2010-02-21 Thread Kaj Søndergaard Laursen
. We do not have any spam-filtering on-premise at the moment. Only inbound smtp is filtered by our colleagues in another part of the organization (we are part of a university). So I'm just asking on this list because I know that there is a lot of experts on this list (and I used sniffer when I ran

[sniffer] Re: Outgoing spam filtering

2010-02-21 Thread MxUptime.com
lead to a higher rate of false positives. Cheers -Matt From: Message Sniffer Community [mailto:snif...@sortmonster.com] On Behalf Of Kaj Søndergaard Laursen Sent: Sunday, February 21, 2010 7:10 PM To: Message Sniffer Community Subject: [sniffer] Outgoing spam filtering Hi I have now

[sniffer] Rulebase updates increased by 25%!!!

2010-02-05 Thread Pete McNeil
Hi Sniffer Folks, After more back-end improvements and some careful analysis we have increased our rulebase update rate by another 25%. This will mean: -- Less time for new spam to get through between updates -- More accurate IP reputation information against new bots -- Faster removal

[sniffer] Re: New proactive false positive prevention initiatives

2010-02-04 Thread Steve Guluk
Hey Pete, Is there a hook to use Sniffer in SmarterMail 6? I just had to move to SmarterMail rather than pay over $3k to upgrade iMail to run on a 64bit windows box. I'm using eWall at this point for Message Sniffer but may retire that with iMail. On Feb 4, 2010, at 1:57 PM, Pete McNeil wrote

[sniffer] Re: New proactive false positive preventioninitiatives

2010-02-04 Thread E. H. (Eric) Fletcher
Steve: MxGuard is availabe for SmarterMail now. Eric --Original Message-- From: Pete McNeil Sender: Message Sniffer Community To: Message Sniffer Community ReplyTo: Message Sniffer Community Subject: [sniffer] Re: New proactive false positive preventioninitiatives Sent: Feb 4, 2010 14:25

[sniffer] RulePanic on 2908567

2010-02-03 Thread Darin Cox
We're noticing a lot of FPs on this rule, and have added a RulePanic entry. Pete, is there a problem with it? Darin.

[sniffer] Re: RulePanic on 2908567

2010-02-03 Thread Darin Cox
in place. Darin. - Original Message - From: Darin Cox To: Message Sniffer Community Sent: Wednesday, February 03, 2010 9:02 AM Subject: [sniffer] RulePanic on 2908567 We're noticing a lot of FPs on this rule, and have added a RulePanic entry. Pete, is there a problem with it? Darin.

[sniffer] Re: RulePanic on 2908567

2010-02-03 Thread Pete McNeil
you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More information see http://www.armresearch.com To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode, E

[sniffer] Re: RulePanic on 2908567

2010-02-03 Thread Pete McNeil
, but with the rule panic in place. Our auto-panic monitoring system also shows that many systems panicked the rule on their own. _M # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list

[sniffer] Re: RulePanic on 2908567

2010-02-03 Thread Darin Cox
We're still seeing hits. I assume the rule removal hasn't propagated to our rulebase yet? BTW, we were seeing hits on the rule across a broad range of emails that related to passport.com. Darin. - Original Message - From: Pete McNeil madscient...@armresearch.com To: Message Sniffer

[sniffer] Re: RulePanic on 2908567

2010-02-03 Thread Pete McNeil
are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More information see http://www.armresearch.com To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode, E-mail

[sniffer] Testing a black-list,.. want to help?

2010-01-22 Thread Pete McNeil
Hello sniffer folks, I'm testing a dns based blocking list for a future product release. The list works in the usual way and is derived from GBUdb IP reputation data. The list I want to test contains IPs that are statistically in the Truncate range from the perspective of the larger cloud

[sniffer] Re: Testing a black-list,.. want to help?

2010-01-22 Thread Darin Cox
Hi Pete, We would be interested in testing the DNSBL. Darin. - Original Message - From: Pete McNeil madscient...@armresearch.com To: Message Sniffer Community sniffer@sortmonster.com Sent: Friday, January 22, 2010 12:48 PM Subject: [sniffer] Testing a black-list,.. want to help

[sniffer] Re: Testing a black-list,.. want to help?

2010-01-22 Thread Pete McNeil
# This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More information see http://www.armresearch.com To unsubscribe, E-mail to: sniffer

[sniffer] Re: Testing a black-list,.. want to help?

2010-01-22 Thread Pete McNeil
of your resolver so that we can update the ACLs. Thanks! _M # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware

[sniffer] FW: [sniffer] Re: Message Sniffer DLL now used in Declude

2010-01-17 Thread Daniel Ivey
Andy, Did you ever get the new Declude implemented on your mail server, so that Sniffer isn't an external test any longer? If so, was it hard to implement? Pete, With the new Declude with Message Sniffer built into it, would I still need to purchase a Sniffer license each year

[sniffer] Updates down?

2010-01-17 Thread Peer-to-Peer (Support)
are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam, Anti-Malware, and related email topics. For More information see http://www.armresearch.com To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode, E-mail

[sniffer] Re: FW: [sniffer] Re: Message Sniffer DLL now used in Declude

2010-01-17 Thread Pete McNeil
Daniel Ivey wrote: Pete, With the new Declude with Message Sniffer built into it, would I still need to purchase a Sniffer license each year? Yes. However if you're using the built-in SNF you will get that from Declude. They may change their pricing at some point to include

[sniffer] Re: Updates down?

2010-01-17 Thread Pete McNeil
. It was unavailable for several hours but it is running fine now. Best, _M # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. This list is for discussing Message Sniffer, Anti-spam

[sniffer] Re: Message Sniffer DLL now used in Declude

2010-01-05 Thread Pete McNeil
Andy Schmidt wrote: Hi Pete, I saw their announcement. Dave says they are using THEIR rule base (not the one specific to the Sniffer customer). Yes. They have an OEM license now which allows them to embed Message Sniffer in their products with their own rulebase. This is simpler for OEMs

[sniffer] Message Sniffer DLL now used in Declude

2010-01-04 Thread Pete McNeil
Hello Sniffer Folks, The Declude folks have announced version 4.10.42. With this version Declude now integrates Message Sniffer via our DLL. Benefits: * Improved performance -- Not an external test, so no program must be launched -- Uses the message already in RAM thus saving disk IO

[sniffer] Re: Message Sniffer DLL now used in Declude

2010-01-04 Thread Andy Schmidt
Hi Pete, I saw their announcement. Dave says they are using THEIR rule base (not the one specific to the Sniffer customer). Any hints what I have to do (on the Sniffer side) to move over to their service? Which part of my current stand-alone installation do I have to undo (e.g., the Sniffer

[sniffer] Happy New Year!

2009-12-31 Thread Pete McNeil
Hello Sniffer Folks, On behalf of all at ARM Research Labs, I would like to personally wish you and yours a happy and prosperous new year! Most folks hear about Message Sniffer from our customers, and we really appreciate that. This January we have a special reason to encourage you to share

<    1   2   3   4   5   6   7   8   9   10   >