Hi,
Another topic on stock spam? Lots of them are coming through. What do you
guys do to limit the number of false negatives?
Michiel
Jim,
We have upgraded to 9.51. The plugin works the
same.
Met vriendelijke groet,
ing. Michiel Prins
Small Office Solutions
tt. Vasumweg 24a
1033 SC Amsterdam
the Netherlands
tel. 020-4082627
fax
Crew,
If I might suggest something that has nothing to do with sniffer directly...
I succesfully reduced the number of spams delivered to our server with 25%
by automatically blacklisting the IP adresses which deliver spam. If the
weight of an e-mail goes over the hold weight, I add the IP
Crew,
I'm a bit concerned about the amount of spam that Sniffer's not
getting. It used to be a near 99% catch rate, but now it looks like it's
down to70%...? I opened my own mailbox
this morning and saw 5 false negatives, while 11 others were caught by
Sniffer. Haven't checked with my
Isn't it time to call for an
exorcist?
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Goran
JovanovicSent: donderdag 2 februari 2006 5:31To:
sniffer@SortMonster.comSubject: [sniffer] Stock SPAM now
HTML
Well the plain text stock spam has just taken a turn to
more
G'day,
I'm just wandering... what CAN be done about this? If I send an embedded
picture to someone, how's sniffer gonna see the difference between my
holiday picture and the stock spam?
I reckon it's gonna be tough to block these?
Cheers,
Mike
-Original Message-
From: [EMAIL PROTECTED]
Can I also use this
product on my snailmail? :p
From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Jonathan Hickman
Sent: vrijdag 30 december 2005
16:58
To: sniffer@SortMonster.com
Subject: Re: Re[2]: [sniffer] Last
chance to renew at the old price!
I believe
Pete,
I have an additional question. What do you do with spam in foreign
languages, like dutch? Do you create rules for those as well? Lots of dutch
messages are not blocked by sniffer.
Regards,
Michiel
-Original Message-
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf
Same here, MD 8.11 and Sniffer (running from Content Filter) and NOT seeing
the reported behaviour.
Michiel
-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
On Behalf Of Jorge Asch
Sent: zondag 21 augustus 2005 22:28
To: sniffer@SortMonster.com
Subject: Re: [sniffer]
That one was not blocked by my rulebase...?
Regards,
Michiel
-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
On Behalf Of Daniel Bayerdorffer
Sent: vrijdag 13 mei 2005 16:32
To: sniffer@SortMonster.com
Subject: [sniffer] Message Sniffer says Sniffer List is Spam
Yes, you read it correctly... Mdaemon is capable of blocking spam by sending
'User Unknown' replies during SMTP, which might actively do something
against spammers who clean up their lists when these reponses are received.
Dunno if they're bright enough to do that tho...
Michiel
Title: Re: Re[2]: [sniffer] Sniffer Updates
I made this one, which is probably also somewhere on the
sniffer site. Change directories and keys for your use:
d:
cd\Batch Files\Sniffer
wget http://sniffer:[EMAIL PROTECTED]/Sniffer/Updates/key.snf -O key.snf.gz --timestamping
Title: Message
There's a Sniffer plugin for MDaemon v8.0 (MD 8.0 is still
in beta)
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of Joe
WolfSent: woensdag 22 december 2004 15:42To:
[EMAIL PROTECTED]Subject: [sniffer] Sniffer
updates...
I'm currently using Sniffer via Imail
Rob,
If you followed the walkthrough on the site, you should
have result code headersin your e-mail messages. Could you check if that's
the case?
Regards,
Michiel
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED] On Behalf Of ~ ROB @ ZELLEM
~Sent: woensdag 8 december 2004 20:54To:
What we did was write a wrapper around sniffer, and fire that wrapper from
the Content Filter. that wrapper measures how long each sniffer instance
takes. In the previous version, it took way longer when using the persistent
version than when not using the persistent version. You would expect it
But did you run the persistent version also?
-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
On Behalf Of Jorge Asch
Sent: woensdag 20 oktober 2004 22:03
To: [EMAIL PROTECTED]
Subject: Re: [sniffer] Version 2-3.0i8 published.
If you fire up Task Manager on a
Does this version have speed improvements over the previous official
release, when NOT using the persistent option (with Mdaemon)?
-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
On Behalf Of Pete McNeil
Sent: zondag 17 oktober 2004 21:39
To: [EMAIL PROTECTED]
Nope, all is working as expected here.
Regards,
Michiel Prins
Reject.nl
-Original Message-
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
On Behalf Of [EMAIL PROTECTED]
Sent: donderdag 16 september 2004 16:13
To: [EMAIL PROTECTED]
Subject: [sniffer] rules file?
Has anyone else out
Pete, even your message had a chaset header:
Content-Type: text/plain; charset=us-ascii
I think you'll generate more FP's if you do something like that than FN's
you might have now. Aren't there spamassassin config files that detect this
spam?
Met vriendelijke groet,
ing. Michiel Prins
SOS
Can't you use the content filter of your mail server to detect if the
charset is used?
Met vriendelijke groet,
ing. Michiel Prins
SOS Small Office Solutions / REJECT
Wannepad 27
1066 HW Amsterdam
tel. 020-4082627
fax. 020-4082628
[EMAIL PROTECTED]
-Original Message-
From: [EMAIL
Regards,
ing. Michiel Prins
SOS Small Office Solutions / REJECT
Wannepad 27
1066 HW Amsterdam
tel. 020-4082627
fax. 020-4082628
[EMAIL PROTECTED]
Spamvrije zakelijke e-mail? reject.nl!
Consultancy
is list so
other ppl can check how long it really takes to execute sniffer (measured from
'the outside').
Regards,
ing. Michiel Prins
SOSSmallOffice
Solutions/REJECT
Wannepad 27
1066
HWAmsterdam
tel. 020-4082627
fax. 020-4082628
[EMAIL PROTECTED]
Spamvrijezake
levels are in
the regions that you mentioned.
Thanks for thinking along!
Groet, (regards)
--
ing. Michiel Prins bsc
[EMAIL PROTECTED]
SOSSmallOffice
Solutions /Reject /
Wannepad 27 -
1066 HW - Amsterdam
t.+31(0)20-4082627 -
f.+31-(0)20-4082628
Pete,
My Sniffer log file logs times which are two hours early. I supspect that
it's because Amsterdam is in GMT+2. Why does sniffer not log local time?
Groet, (regards)
--
ing. Michiel Prins bsc [EMAIL PROTECTED]
SOS Small Office Solutions / Reject
Preliminary tests show there's no I/O problem but I'll do some
additional benchmarking here and get back to you on
this.
Groet, (regards)
--
ing. Michiel Prins bsc
[EMAIL PROTECTED]
SOSSmallOffice
Solutions /Reject /
Wannepad 27 -
1066 HW
.msg18815Clean000361133h0t861s420040407080638md5581533.msg125125Clean0002756845h0t861s420040407080650md5581534.msg18778Clean0001615533
I'm really
puzzled about the cause for the extra delays.
Groet, (regards)
--
ing. Michiel Prins bsc
[EMAIL PROTECTED]
SOSSmallOffice
Solutions /Reject
Paul,
Did you have the persistent sniffer.exe running when this log was generated?
Groet, (regards)
--
ing. Michiel Prins bsc [EMAIL PROTECTED]
SOS Small Office Solutions / Reject /
Wannepad 27 - 1066 HW -Amsterdam
t.+31(0)20-4082627
)
--
ing. Michiel Prins bsc
[EMAIL PROTECTED]
SOSSmallOffice
Solutions /Reject /
Wannepad 27 -
1066 HW - Amsterdam
t.+31(0)20-4082627 -
f.+31-(0)20-4082628
--
Consultancy-
Installation- Maintenance
Network Security
-Internet - E-mail
I use WGET, which is available for free on the internet. This is my script:
c:
cd \MDaemon\Sniffer
wget
http://sniffer:[EMAIL PROTECTED]/Sniffer/Updates/12345678.snf -O
serial.tst
if exist 12345678.tst goto Test
goto Done
:Test
snf2check.exe
29 matches
Mail list logo