[sniffer] FW: Summary, Form #21539

2006-08-23 Thread Andy Schmidt
Pete, I have the same concern. I have been submitting the below spam (possible Words virus) almost daily for more than week - yet, it still is not discovered. Am I submitting correctly? Best Regards Andy Schmidt Phone: +1 201 934-3414 x20 (Business) Fax:+1 201 934-9206 -Original

[sniffer] Re: FW: Summary, Form #21539

2006-08-23 Thread Pete McNeil
Hello Andy, Wednesday, August 23, 2006, 8:57:48 AM, you wrote: Pete, I have the same concern. I have been submitting the below spam (possible Words virus) almost daily for more than week - yet, it still is not discovered. Am I submitting correctly? This particular spam campaign is a bit

[sniffer] Paypal failing SNIFFER-GENERAL

2006-08-23 Thread Darin Cox
FYI... I just reported one of these, so watch out. Darin.

[sniffer] Re: Paypal failing SNIFFER-GENERAL

2006-08-23 Thread Pete McNeil
Hello Darin, I may be behind... but I don't see an FP report on this. Do you have the rule id? _M Wednesday, August 23, 2006, 1:36:08 PM, you wrote: FYI... I just reported one of these, so watch out. Darin.     -- Pete McNeil Chief Scientist, Arm Research Labs,

[sniffer] Re: Paypal failing SNIFFER-GENERAL

2006-08-23 Thread Darin Cox
Hi Pete, I'm not sure which column is which, but here are the log lines for the message (minus the authorization code) 20060823163449 D83a20d3001502962.SMD 0 32 Match 1100444 60 1502 1551 98 20060823163449 D83a20d3001502962.SMD 0 32 Final 1100444 60 0 3798 98 The FP was

[sniffer] Re: Paypal failing SNIFFER-GENERAL

2006-08-23 Thread Colbeck, Andrew
Column 7 is the one that contains the rule that was hit. In this case, it was 1100444. Column 8 is the one that contains the group. In this case, it was 60 Ungrouped Black Rules (Sniffer General). Andrew 8) -Original Message- From: Message Sniffer Community [mailto:[EMAIL

[sniffer] Re: Paypal failing SNIFFER-GENERAL

2006-08-23 Thread Pete McNeil
Hello Darin, I have processed an FP with that rule (1100444) - the rule was for an obscure ebay link and has been removed. Best, _M Wednesday, August 23, 2006, 3:23:55 PM, you wrote: Hi Pete, I'm not sure which column is which, but here are the log lines for the message (minus the

[sniffer] Blank emails

2006-08-23 Thread David Moore
I am seeing a lot of Spam emails with blank bodys is this because our internet connection is too slow or because the spammers are failing to complete there transaction Received: from CIBER2.ctijdq6u.org [201.135.34.108] by romtech.com.au with ESMTP (SMTPD-8.22) id A02D0268; Thu, 24

[sniffer] Another example of an empty email but looking at the source.

2006-08-23 Thread David Moore
Received: from PC05.4ueleoz.org [202.215.167.25] by romtech.com.au with ESMTP (SMTPD-8.22) id A7AC0224; Thu, 24 Aug 2006 08:33:16 +1000 Message-Id: [EMAIL PROTECTED] X-mxGuard-Info: Processed by romtech.com.au using mxGuard v2.4 X-mxGuard-SpoolID: d7ab017912af X-mxGuard-Sender:

[sniffer] Re: Another example of an empty email but looking at the source.

2006-08-23 Thread Support
Hi David: There has been a rise in spam again and we just added some new rules to our system. Lets give it a few days to see if they stop. Have a great day. Phil David Moore wrote: *Received: from PC05.4ueleoz.org [202.215.167.25] by romtech.com.au with ESMTP* * (SMTPD-8.22) id

[sniffer] Re: Another example of an empty email but looking at the source.

2006-08-23 Thread Pete McNeil
Hello David, Sometimes we have rules for empty email --- but there are many different kinds of empty ;-) Often enough, some empty messages are legitimate. _M Wednesday, August 23, 2006, 6:39:23 PM, you wrote: Received: from PC05.4ueleoz.org [202.215.167.25] by romtech.com.au