[sniffer] Re: xci scanner command

2009-02-17 Thread Pete McNeil
. If there is something you would like to see then please let us know and we will consider adding features to support your request(s). Best, _M # This message is sent to you because you are subscribed to the mailing list sniffer

[sniffer] Re: xci scanner command

2009-02-17 Thread Richard Stupek
A question about using the XCI bad command. Assume an email passes through sniffer and does not trigger any rules, I then run it through and determine it is in fact spam. I send a bad command to let sniffer know the IP address had a bad event. Won't the good event that would occur due the spam

[sniffer] Re: ClamAID

2009-02-13 Thread Andy Schmidt
Sniffer Community [mailto:snif...@sortmonster.com] On Behalf Of Andrew Wallo Sent: Monday, February 02, 2009 1:44 PM To: Message Sniffer Community Subject: [sniffer] Re: Crosspost: ClamAV for Window (Summary of what I had posted last month on a different list) Team, Sniffer Folks, Andy

[sniffer] xci scanner command

2009-02-13 Thread Richard Stupek
Which of the 2 scan commands should we use to scan a message? Does sending the IP address help improve scanning? snfxciscannerscan file='filepath'//scanner/xci/snf OR snfxciscannerscan file='filepath' xhdr='no' log='no' ip='12.34.56.78'//scanner/xci/snf

[sniffer] Re: xci scanner command

2009-02-13 Thread Pete McNeil
# This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode, E-mail to sniffer-dig...@sortmonster.com To switch to the INDEX mode, E-mail to sniffer

[sniffer] Re: xci scanner command

2009-02-13 Thread Richard Stupek
to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode, E-mail to sniffer-dig...@sortmonster.com To switch to the INDEX mode, E-mail to sniffer-in...@sortmonster.com Send administrative queries to sniffer-requ

[sniffer] Re: xci scanner command

2009-02-13 Thread Pete McNeil
# This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode, E-mail to sniffer-dig...@sortmonster.com To switch to the INDEX mode, E-mail

[sniffer] Errorlevel issue

2009-02-08 Thread Serge
goto gziperr0 if errorlevel 1 goto gziperr1 # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode, E

[sniffer] Re: [Declude.JunkMail] Errorlevel not working

2009-02-08 Thread Sanford Whiteman
/ # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode, E-mail to sniffer-dig...@sortmonster.com To switch to the INDEX mode, E-mail to sniffer

[sniffer] Re: [Declude.JunkMail] Errorlevel not working

2009-02-08 Thread Andy Schmidt
declude.junkm...@declude.com; Message Sniffer Community sniffer@sortmonster.com Sent: Monday, February 09, 2009 12:39 AM Subject: Re: [Declude.JunkMail] Errorlevel not working I have a problem with the branching in the batch below even when the test fails and echo %errorlevel% shows 1

[sniffer] Re[2]: [Declude.JunkMail] Errorlevel not working

2009-02-08 Thread Sanford Whiteman
because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode, E-mail to sniffer-dig...@sortmonster.com To switch to the INDEX mode, E-mail to sniffer-in...@sortmonster.com Send administrative queries

[sniffer] Re: ClamAID

2009-02-05 Thread Andy Schmidt
that it supports Windows service mode. I'll definitely give that one a try. Best Regards, Andy -Original Message- From: Message Sniffer Community [mailto:snif...@sortmonster.com] On Behalf Of Mxuptime.com Sent: Wednesday, February 04, 2009 11:44 PM To: Message Sniffer Community Subject

[sniffer] Re: ClamAID

2009-02-05 Thread Andy Schmidt
the infected file name and virus name from the Reports.txt file - but that's really a problem with Declude's lack of parsing ability. Gee - I wish Sniffer had a configuration option to tie into ClamD... Best Regards, Andy -Original Message- From: Message Sniffer Community [mailto:snif

[sniffer] Re: ClamAID

2009-02-05 Thread MxUptime.com
As a correction to my previous post, both of the win32 build oss.netfarm.it and hideout.ath.cx is actually a port from clamwin.com. Thanks -Original Message- From: Message Sniffer Community [mailto:snif...@sortmonster.com] On Behalf Of Andy Schmidt Sent: Friday, February 06, 2009 1:14 AM

[sniffer] Re: ClamAID

2009-02-04 Thread Andrew Wallo
Sniffer Folks, - ASchmidt... snip ClamAV's web site states that they won't [ continue to support] and development has been stopped? http://w32.clamav.net/ /snip Oddly, I would have bet hard cash that page didn't say that just a week ago. I went there just recently in order to affirm I had

[sniffer] Re: ClamAID

2009-02-04 Thread Andy Schmidt
PM To: Message Sniffer Community Cc: andy_schm...@hm-software.com Subject: Re: ClamAID Sniffer Folks, - ASchmidt... snip ClamAV's web site states that they won't [ continue to support] and development has been stopped? http://w32.clamav.net/ /snip Oddly, I would have bet hard cash that page

[sniffer] Re: ClamAID

2009-02-04 Thread Mxuptime.com
crashed once in awhile and as such you will need to have a watchdog/recovery service monitor the daemon and restart when necessary. Cheers -Matt -Original Message- From: Message Sniffer Community [mailto:snif...@sortmonster.com] On Behalf Of Andrew Wallo Sent: Thursday, February 05, 2009

[sniffer] Re: ClamAID

2009-02-03 Thread Andy Schmidt
care of the config file. Best Regards, Andy # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode, E

[sniffer] Re: Announcing ClamAID - Clam AV installer for windows.

2009-02-03 Thread Andrew Wallo
. Thanks. Andrew Wallo - Original Message - From: Andy Schmidt andy_schm...@hm-software.com To: Message Sniffer Community sniffer@sortmonster.com Sent: Tuesday, February 03, 2009 5:42 PM Subject: [sniffer] Re: Announcing ClamAID - Clam AV installer for windows. 1. We haven't detected

[sniffer] Re: Announcing ClamAID - Clam AV installer for windows.

2009-02-03 Thread Andy Schmidt
# This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode, E-mail to sniffer-dig...@sortmonster.com To switch to the INDEX mode, E-mail to sniffer

[sniffer] Announcing ClamAID - Clam AV installer for windows.

2009-02-02 Thread Pete McNeil
Hello Sniffer Folks, We've noticed that folks often have trouble getting Clam AV (the free open source anti-virus scanner) working correctly on their mail servers, so we've created a free product to help solve that. ClamAID (Clam AV Assisted Install Device). http://www.armresearch.com/tools/arm

[sniffer] Re: Announcing ClamAID - Clam AV installer for windows.

2009-02-02 Thread Andy Schmidt
. Best Regards, Andy -Original Message- From: Message Sniffer Community [mailto:snif...@sortmonster.com] On Behalf Of Pete McNeil Sent: Monday, February 02, 2009 12:49 PM To: Message Sniffer Community Subject: [sniffer] Announcing ClamAID - Clam AV installer for windows. Hello Sniffer Folks

[sniffer] Crosspost: ClamAV for Window (Summary of what I had posted last month on a different list)

2009-02-02 Thread Andy Schmidt
code while ( objExec.Status != 1 ) WScript.Sleep(100); WScript.Echo( strClamAV + returned: + objExec.ExitCode ); WScript.Quit( objExec.ExitCode ); # This message is sent to you because you are subscribed to the mailing list sniffer

[sniffer] Re: Announcing ClamAID - Clam AV installer for windows.

2009-02-02 Thread Andrew Wallo
Team, Sniffer Folks, Beta Testers: I've handled most of the testing and the development so I'll do my best to reply: (I'll respond inline to A.Schmidt's inquiries. _Andy Wallo - The engine for official Windows build I found (http://w32.clamav.net/) was out of date (but still usable

[sniffer] Re: Announcing ClamAID - Clam AV installer for windows.

2009-02-02 Thread Pete McNeil
Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode, E-mail

[sniffer] Re: Announcing ClamAID - Clam AV installer for windows.

2009-02-02 Thread K. Mitchell
At 12:49 2/2/2009 -0500, you wrote: Hello Sniffer Folks, We've noticed that folks often have trouble getting Clam AV (the free open source anti-virus scanner) working correctly on their mail servers, so we've created a free product to help solve that. ClamAID (Clam AV Assisted Install Device

[sniffer] Re: Announcing ClamAID - Clam AV installer for windows.

2009-02-02 Thread Steve Guluk
Any plans on an eWall version? On Feb 2, 2009, at 9:49 AM, Pete McNeil wrote: Hello Sniffer Folks, We've noticed that folks often have trouble getting Clam AV (the free open source anti-virus scanner) working correctly on their mail servers, so we've created a free product to help solve

[sniffer] Re: Announcing ClamAID - Clam AV installer for windows.

2009-02-02 Thread Andy Schmidt
They offer a ClamAV tie-in: http://sssolutions.net/ew/tutor.php?topic=setup From: Message Sniffer Community [mailto:snif...@sortmonster.com] On Behalf Of Pete McNeil Sent: Monday, February 02, 2009 2:53 PM To: Message Sniffer Community Subject: [sniffer] Re: Announcing ClamAID - Clam AV

[sniffer] Re: eWall

2009-02-02 Thread Steve Guluk
On Feb 2, 2009, at 2:50 PM, Andy Schmidt wrote: Wo – how did I miss eWall all these years? I thought ASSP was the only game in Windows town, but I didn’t like the Sniffer integration and was worried about running on Perl. Sadly, the eWall web site is terrible – I don’t see any manual

[sniffer] Re: files in the Sniffer dir

2009-01-05 Thread Pete McNeil
Hello Bonno, Monday, January 5, 2009, 1:50:40 AM, you wrote: Hi, I was wondering about something and could not find info about it on the Sniffer documentation page. I have several files in my sniffer directory with a date of today. Logfiles, rulesbases etc. The next most recent files

[sniffer] files in the Sniffer dir

2009-01-04 Thread Bonno Bloksma
Hi, I was wondering about something and could not find info about it on the Sniffer documentation page. I have several files in my sniffer directory with a date of today. Logfiles, rulesbases etc. The next most recent files are my GBUdbIgnoreList.txt getrulebase.cmd, etc. which I have made

[sniffer] GBUdb

2008-12-31 Thread Richard Stupek
Does the snf XML command interface for GBUdb work? I was considering pumping in bad IPs as I find them into the GBUdb and also short-circuiting spam processing by calling the GBUdb to determine the status of an IP to reduce workload. Is this something that sounds like a workable idea?

[sniffer] Re: GBUdb

2008-12-31 Thread Pete McNeil
m Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: sniffer-...@sortmonster.com To switch to the DIGEST mode, E-mail to sniffer-dig...@sortmonster.com To switch

[sniffer] Re: favorite / best *nix distributions in the Sniffer community.

2008-12-12 Thread Sanford Whiteman
Sniffer-powered gateway or an anti-spam service provider would have a much narrower choice of hosting environments. --Sandy # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com

[sniffer] Re: favorite / best *nix distributions in the Sniffer community.

2008-12-12 Thread Dan Horne
...@taisweb.net 828.252.TAIS (8247) -Original Message- From: Message Sniffer Community [mailto:snif...@sortmonster.com] On Behalf Of Harry Palmer Sent: Friday, December 12, 2008 1:36 PM To: Message Sniffer Community Subject: [sniffer] Re: favorite / best *nix distributions in the Sniffer

[sniffer] ERROR_RULE_AUTH!

2008-12-05 Thread Hirthe, Alexander
Hello, our sniffer doesn't work anymore, so I made an Update from the 2.9 Beta to 3.0 Release. I did it from the beginning, emptied the directory (no, not planned) and copied everything new in and modified the configs. I'm getting snf2check: myIDHere.new ERROR_RULE_AUTH when I try to download

[sniffer] Re: ERROR_RULE_AUTH!

2008-12-05 Thread Pete McNeil
Hello Alexander, Friday, December 5, 2008, 8:44:50 AM, you wrote: Hello, our sniffer doesnt work anymore, so I made an Update from the 2.9 Beta to 3.0 Release. I did it from the beginning, emptied the directory (no, not planned) and copied everything new in and modified the configs

[sniffer] GBUdb

2008-12-04 Thread Richard Stupek
Is the GBUdb currently sharing information as described in the documentation? Do the GBUdb XCI commands detailed within snf_xci.xml work through the tcp interface?

[sniffer] Re: GBUdb

2008-12-04 Thread Pete McNeil
simply translates your command line parameters into XCI requests. Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com

[sniffer] Re: GBUdb

2008-12-04 Thread Richard Stupek
into XCI requests. Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL

[sniffer] Re: GBUdb

2008-12-04 Thread Pete McNeil
entist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E-mail to [EMAIL PROTECTED] To sw

[sniffer] snf_engine config file

2008-11-14 Thread John T
I am setting up a new server to migrate a client to So far, I have still be suing V 2 of sniffer server/client. If I drop in the V 3 executables, can I continue to use the same xml config files or are the configuration lines that are different?John T eServices For You

[sniffer] Re: snf_engine config file

2008-11-14 Thread Pete McNeil
Hello John, Friday, November 14, 2008, 6:51:31 PM, you wrote: I am setting up a new server to migrate a client to So far, I have still be suing V 2 of sniffer server/client. If I drop in the V 3 executables, can I continue to use the same xml config files or are the configuration

[sniffer] Re: Ping

2008-11-13 Thread Pete McNeil
. _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch

[sniffer] Re: Ping

2008-11-13 Thread MxUptime
Pong! Things are a bit slow perhaps… :-) However, we’ve started to see an increase in activity recently probably in line with the upcoming holidays. From: Message Sniffer Community [mailto:[EMAIL PROTECTED] On Behalf Of John T Sent: Thursday, November 13, 2008 7:09 PM To: Message Sniffer

[sniffer] Ping

2008-11-13 Thread John T
Testing, have not received anything from the list since 10/17/08John T eServices For You# This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED

[sniffer] Re: Ping

2008-11-13 Thread Len Conrad
to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E-mail to [EMAIL PROTECTED] To switch to the INDEX mode, E-mail to [EMAIL PROTECTED] Send administrative queries to [EMAIL PROTECTED]

[sniffer] Re: Ping

2008-11-13 Thread Pete McNeil
because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E-mail to [EMAIL PROTECTED] To switch to the INDEX mode, E-mail to [EMAIL PROTECTED] Send administrative queries to [EMAIL PROTECTED]

[sniffer] A side issue to the McColo take down

2008-11-13 Thread Pete McNeil
Hello Sniffer Folks, Another effect I've seen since the takedown is that there have been a lot more network disruptions that usual. I've seen everything from long pings and heavy packet loss through shawcable.net to routing loops in alter.net and many other events since the takedown

[sniffer] Re: ASSP Threshold

2008-10-17 Thread Pete McNeil
Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E-mail to [EMAIL PROTECTED] To switch

[sniffer] Re: ASSP Threshold

2008-10-17 Thread Andy Schmidt
Hi Pete, Then let me approach it from a different angle: Is there a way in the Sniffer config files to silence certain groups? This way, if someone doesn't want to outright block email based on certain groups, they could just exclude those groups from triggering at all. Best Regards, Andy

[sniffer] Re: ASSP Threshold

2008-10-17 Thread Len Conrad
# This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E-mail to [EMAIL PROTECTED] To switch to the INDEX mode, E-mail

[sniffer] Re: ASSP Threshold

2008-10-17 Thread Pete McNeil
Hello Andy, Friday, October 17, 2008, 1:04:14 PM, you wrote: Hi Pete, Then let me approach it from a different angle: Is there a way in the Sniffer config files to silence certain groups? Yes. But not locally. We can customize a rulebase to block rules or rule groups as needed. So far

[sniffer] Blackhats roll out new tactics in ernest -- Fresh Burst or Stampede storms hit hard!

2008-10-16 Thread Pete McNeil
Hello Sniffer Folks, I've spoken before about the blackhats using high amplitude bursts to get chunks of their spam through and that some of the time they were pre-testing their messages and then launching them on bot nets with fresh (as yet unseen) IPs. This has been an effective strategy

[sniffer] SNF Now directly supported in IMGate!

2008-10-09 Thread Pete McNeil
Hello Sniffer Folks, Message Sniffer is now directly supported in Len Conrad's IMGate. IMGate + SNF allows you to move your spam filtering out in front of your mail server improving scalability, stability, and performance. Here are some links: http://www.imgate.net/?page_id=101 http

[sniffer] Re: SNF Now directly supported in IMGate!

2008-10-09 Thread Andy Schmidt
Hi, Hopefully, you'll be able to convince Alligate and ORF next to use your new DLL API to scan the content during the SMTP connection without needing the command line environment... Best Regards, Andy -Original Message- From: Message Sniffer Community [mailto:[EMAIL PROTECTED

[sniffer] Re: SNF Now directly supported in IMGate!

2008-10-09 Thread Pete McNeil
McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E-mail

[sniffer] ASSP Threshold

2008-10-09 Thread Andy Schmidt
is higher than Malware etc.). I would say this parameter would have to be a comma-delimited list of result codes that you want to treat as Spam - or, if there is some confidence factor that Sniffer uses internally, then that could be translated into an ASSP score... Best Regards, Andy

[sniffer] Re: ASSP Threshold

2008-10-09 Thread Pete McNeil
cases there is no meaningful distinction. I would say this parameter would have to be a comma-delimited list of result codes that you want to treat as Spam - or, if there is some confidence factor that Sniffer uses internally, then that could be translated into an ASSP score... I'm not sure what

[sniffer] Re: ASSP Threshold

2008-10-09 Thread Andy Schmidt
the connection (based on a resultcode list as in ORF) and allow other resultcodes (in which I have lesser confidence) to go through and be subject to other tests. Best Regards, Andy -Original Message- From: Message Sniffer Community [mailto:[EMAIL PROTECTED] On Behalf Of Pete McNeil Sent

[sniffer] Re: Update Script - Replace WGET and GZIP with CURL

2008-10-08 Thread Andy Schmidt
compressed during transport, receives it, decompresses it before saving it - and sets timestamp from the server. All that in ONE command. Basically, you would replace these TWO lines in your current script: wget http://www.sortmonster.net/Sniffer/Updates/%LICENSE_ID%.snf -O %RULEBASE_PATH

[sniffer] Rulebase, bogus UTC Timestamps?

2008-10-08 Thread Andy Schmidt
Hi Pete, I'm running a Sniffer service on a secondary system so that I can test my rulebase update script. After I changed to curl (to maintain the server timestamps), I'm now seeing the following in the status.minute.log: rulebase utc=20081008183610 / active utc=20081008183610

[sniffer] Re: Updated getRuleBase.cmd

2008-10-08 Thread Pete McNeil
Hello Andy, Wednesday, October 8, 2008, 12:52:59 PM, you wrote: Hi, After resolving the issues with UTC vs. local time (apparently the Sniffer service doesnt actually use a version identifier inside the SNF file, but relies on the Windows file date to determine what rulebase version

[sniffer] Re: Updated getRuleBase.cmd

2008-10-08 Thread Andy Schmidt
Hi, Yes, recent Windows curl builds will convert between UTC and local time. I was just caught off-guard, that Sniffer is using an external datum which is subject for wanted or unwanted manipulation for something as crucial as determining the file version of the rule base? If (due to copying

[sniffer] How to deal with False Positives and other Documentation Issues

2008-10-07 Thread Andy Schmidt
Hi, 1. I read this page: http://www.armresearch.com/support/articles/procedures/falsePositives.jsp and it seems to be the same. However, should this chapter be expanded to contain information about what to do if some of the new technologies are responsible for the false positive?

[sniffer] Re: How to deal with False Positives and other Documentation Issues

2008-10-07 Thread Pete McNeil
-- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E

[sniffer] Re: GBUdb False Positives vs. Rule IDs

2008-10-07 Thread Andy Schmidt
the underlying rule and reported it back to me. Of course, I need to have a panic procedure in place that doesn't rely on outside assistance. Doesn't happen often, but better ask the questions now than when the brown matter hits to air circulation enhancer. Best Regards, Andy From: Message Sniffer Community

[sniffer] Re: GBUdb False Positives vs. Rule IDs

2008-10-07 Thread Pete McNeil
Hope this helps, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch t

[sniffer] Re: GBUdb False Positives vs. Rule IDs

2008-10-07 Thread Andy Schmidt
Thanks Pete - I'll save that command. I also suggest that some of your instructions might be helpful to see in the documentation in the chapters on how to deal with false positives. From: Message Sniffer Community [mailto:[EMAIL PROTECTED] On Behalf Of Pete McNeil Sent: Tuesday, October 07, 2008

[sniffer] Re: Update Script - Choice of WGET Parameter Prevents TimeStamping

2008-10-07 Thread Andy Schmidt
PS: And, for bonus points, to correctly support your sub-directory feature in your sample script, you would do that with the -P parameter, e.g.: wget http://www.sortmonster.net/Sniffer/Updates/%LICENSE_ID%.snf -N -P %RULEBASE_PATH% --header=Accept-Encoding:gzip --http-user=sniffer --http

[sniffer] Re: Update Script - Choice of WGET Parameter Prevents TimeStamping

2008-10-07 Thread Pete McNeil
Hello Andy, Wednesday, October 8, 2008, 12:50:23 AM, you wrote: PS: And, for bonus points, to correctly support your sub-directory feature in your sample script, you would do that with the P parameter, e.g.: wget http://www.sortmonster.net/Sniffer/Updates/%LICENSE_ID%.snf-N -P

[sniffer] Re: Update Script - Choice of WGET Parameter Prevents TimeStamping

2008-10-07 Thread Andy Schmidt
has more flexible parameters that will simplify your script because it will let you compare the timestamp of the unzipped, local .SNF file against the server timestamp, e.g.: curl http://www.sortmonster.net/Sniffer/Updates/(licensecode).snf -o (licensecode).snf.gz -s -S -R -z (licensecode).snf -H

[sniffer] Re: Update Script - Choice of WGET Parameter Prevents TimeStamping

2008-10-07 Thread Pete McNeil
. Best, _M -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch

[sniffer] Re: Update Script - Choice of WGET Parameter Prevents TimeStamping

2008-10-07 Thread Pete McNeil
. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E-mail to [EMAIL PROTECTED] To switch to the INDEX mode, E-mail to [EMAIL PROTECTED] Send administrative queries to [EMAIL

[sniffer] Re: Update Script - Path apparently doesn't tolerate embadded blanks

2008-10-06 Thread Pete McNeil
. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E-mail to [EMAIL PROTECTED] To switch to the INDEX mode, E-mail

[sniffer] Re: Update Script - Path apparently doesn't tolerate embadded blanks

2008-10-06 Thread Andy Schmidt
Hi Pete: http://www.armresearch.com/support/articles/software/snfServer/config/node /network/update-script.jsp http://www.armresearch.com/support/articles/software/snfServer/config/node/ network/update-script.jsp%3c%3c Yep, had read that - but that page just instructs me to use the full

[sniffer] Re: Update Script - Path apparently doesn't tolerate embadded blanks

2008-10-06 Thread Pete McNeil
. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E-mail to [EMAIL PROTECTED] To switch to the INDEX mode, E-mail to [EMAIL PROTECTED

[sniffer] Re: Update Script - Path apparently doesn't tolerate embadded blanks

2008-10-06 Thread Andrew Wallo
Message - From: Pete McNeil To: Message Sniffer Community Sent: Monday, October 06, 2008 8:26 AM Subject: [sniffer] Re: Update Script - Path apparently doesn't tolerate embadded blanks Hello Andy, Sunday, October 5, 2008, 11:25:37 PM, you wrote: Hi Pete

[sniffer] Re: Update Script - Path apparently doesn't tolerate embadded blanks

2008-10-06 Thread Pete McNeil
are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E-mail to [EMAIL PROTECTED] To switch to the INDEX mode, E-mail to [EMAIL PROTECTED] Send administrative queries to [EMAIL PROTECTED]

[sniffer] Testers wanted...

2008-10-06 Thread Pete McNeil
Hello Sniffer Folks, If you are interested in working with us to test SNF on the following platforms please let us know: SNF4Alligate -- SNF external filter on Alligate. SNF4ASSP - SNF plugin for ASSP 2.0. New SNF control script for any of: OpenBSD, FreeBSD, CentOS, RedHat, SUSE, Ubuntu

[sniffer] .xml Error

2008-10-05 Thread Greg Coffey
sent to IE. I assume these logs have some valuable info, how do I view them? # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED

[sniffer] Re: .xml Error

2008-10-05 Thread Pete McNeil
. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E-mail to [EMAIL PROTECTED] To switch to the INDEX mode, E-mail to [EMAIL PROTECTED

[sniffer] Update Script - Path apparently doesn't tolerate embadded blanks

2008-10-05 Thread Andy Schmidt
Hi Pete, Found a bug (I think): update-script on-off='on' call='D:/Program Files/SNF/getRulebase.cmd' guard-time='180'/ With THIS configuration, the script apparently gets never launched. What's particularly disturbing is, that I didn't find any place where the service reports/logs any

[sniffer] Sniffer 3.0 Installed

2008-10-04 Thread Andy Schmidt
any stale .lck files after a restart. REM if exist %WORKSPACE_PATH%\UpdateReady.lck GOTO DONE :DOWNLOAD COPY %WORKSPACE_PATH%\UpdateReady.txt %WORKSPACE_PATH%\UpdateReady.lck wget http://www.sortmonster.net/Sniffer/Updates/%LICENSE_ID%.snf -O %RULEBASE_PATH%\%LICENSE_ID%.new.gz --header

[sniffer] Re: Sniffer 3.0 Installed

2008-10-04 Thread Pete McNeil
o REM clean out any stale .lck files after a restart. REM if exist %WORKSPACE_PATH%\UpdateReady.lck GOTO DONE :DOWNLOAD COPY %WORKSPACE_PATH%\UpdateReady.txt %WORKSPACE_PATH%\UpdateReady.lck wget http://www.sortmonster.net/Sniffer/Updates/%LICENSE_ID%.snf -O %RULEBASE_PATH%\%LICENSE_ID%.new.gz

[sniffer] Re: Sniffer 3.0 Froze Mail Server

2008-10-04 Thread Andy Schmidt
Ouch - 3.0 didn't even last 12 hours. Imail was frozen up because it apparently couldn't launch any more Sniffer client instances. Event Log was full with: Event Type:Information Event Source:Application Popup Event ID: 26 Description: Application popup

[sniffer] Re: Sniffer 3.0 Installed

2008-10-04 Thread Pete McNeil
ntist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E-mail to [EMAIL

[sniffer] Re: Sniffer 3.0 Installed

2008-10-04 Thread Andy Schmidt
with different customer scenarios. Best Regards, Andy From: Message Sniffer Community [mailto:[EMAIL PROTECTED] On Behalf Of Pete McNeil Sent: Saturday, October 04, 2008 3:52 PM To: Message Sniffer Community Subject: [sniffer] Re: Sniffer 3.0 Installed My best thinking at the moment is to perhaps

[sniffer] Re: FW: [sniffer] Re: Sniffer 3.0 Froze Mail Server

2008-10-04 Thread Andy Schmidt
: Saturday, October 04, 2008 10:07 PM To: Andy Schmidt Cc: [EMAIL PROTECTED] Subject: Re: FW: [sniffer] Re: Sniffer 3.0 Froze Mail Server Hello Andy, Saturday, October 4, 2008, 9:22:39 PM, you wrote: Hi Pete, Here the log files. I can't tell you WHEN the problem was triggered. I

[sniffer] Re: FW: [sniffer] Re: Sniffer 3.0 Froze Mail Server

2008-10-04 Thread Pete McNeil
# This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E-mail to [EMAIL PROTECTED] To switch to the INDEX mode, E-mail to [EMAIL PROTECTED] Send administrative queries to [EMAIL PROTECTED]

[sniffer] Re: Sniffer Version 3 Install for FreeBSD?

2008-09-29 Thread Pete McNeil
Hello Harry, Sunday, September 28, 2008, 10:39:42 PM, you wrote: I have been using Sniffer for several years with Declude and SmarterMail on Windows. I would like to move Sniffer to my IMGate Mail Gateway (Postfix / FreeBSD). Has anyone installed Version 3 of Sniffer on FreeBSD

[sniffer] Re: Sniffer Version 3 Install for FreeBSD?

2008-09-29 Thread Harry Palmer
Hi Pete, Please do send the new FreeBSD control script and doc at your convenience. Thank you, Harry Hello Harry, Sunday, September 28, 2008, 10:39:42 PM, you wrote: I have been using Sniffer for several years with Declude and SmarterMail on Windows. I would like to move

[sniffer] Re: Sniffer Version 3 Install for FreeBSD?

2008-09-29 Thread Pete McNeil
. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe, E-mail to: [EMAIL PROTECTED] To switch to the DIGEST mode, E-mail to [EMAIL PROTECTED] To switch to the INDEX mode, E-mail to [EMAIL PROTECTED] Send administrative queries

[sniffer] Sniffer Version 3 Install for FreeBSD?

2008-09-28 Thread Harry Palmer
I have been using Sniffer for several years with Declude and SmarterMail on Windows. I would like to move Sniffer to my IMGate Mail Gateway (Postfix / FreeBSD). Has anyone installed Version 3 of Sniffer on FreeBSD? The *nix download of Sniffer v 3 doesn't contain a FreeBSD pkg and port like most

[sniffer] ASCII art spam

2008-09-25 Thread Paul Rogers
Have others also been getting pummeled recently by ASCII art spam? A lot seem to be slipping through the sniffer gate. Any good ways to tighten up the fight on them? Paul --- # This message is sent to you because you

[sniffer] Re: ASCII art spam

2008-09-25 Thread Pete McNeil
Hello Paul, Thursday, September 25, 2008, 10:06:17 PM, you wrote: Have others also been getting pummeled recently by ASCII art spam? A lot seem to be slipping through the sniffer gate. Any good ways to tighten up the fight on them? Please zip up a few messages and send them to me off line

[sniffer] Re: Alt-n Security Gateway

2008-09-11 Thread Pete McNeil
be switching to Exchange. And want to use this product with it. -- Pete McNeil Chief Scientist, Arm Research Labs, LLC. # This message is sent to you because you are subscribed to the mailing list sniffer@sortmonster.com. To unsubscribe

[sniffer] Re: What's in a name - or - objects in mirror.exe are bigger than they appear

2008-09-09 Thread 吴杰
..help 在2008-09-08 19:46:48,Dan Horne [EMAIL PROTECTED] 写道: Just want to chime in here. We use SNF on FreeBSD and more than once, when a newbie tech was troubleshooting the system, he'd remark that we seem to have the Windows version of Sniffer installed because

[sniffer] Alt-n Security Gateway

2008-09-09 Thread Daniel Bayerdorffer
Bayerdorffer, VP [EMAIL PROTECTED] Numberall Stamp Tool Co., Inc. www.numberall.com PO Box 187, Sangerville, ME 04479 USA TEL: 207-876-3541 FAX: 207-876-3566 -Original Message- From: Peer-to-Peer (Support) [EMAIL PROTECTED] To: Message Sniffer Community sniffer@sortmonster.com Date: Thu, 28 Aug

[sniffer] Re: What's in a name - or - objects in mirror.exe are bigger than they appear

2008-09-08 Thread Dan Horne
Just want to chime in here. We use SNF on FreeBSD and more than once, when a newbie tech was troubleshooting the system, he'd remark that we seem to have the Windows version of Sniffer installed because of the extension. Files with a .exe extension just LOOK like Windows progs and can cause

<    1   2   3   4   5   6   7   8   9   10   >