[sniffer] FW: Summary, Form #21539

2006-08-23 Thread Andy Schmidt
Pete, I have the same concern. I have been submitting the below spam (possible Words virus) almost daily for more than week - yet, it still is not discovered. Am I submitting correctly? Best Regards Andy Schmidt Phone: +1 201 934-3414 x20 (Business) Fax:+1 201 934-9206 -Original Mes

[sniffer] Re: FW: Summary, Form #21539

2006-08-23 Thread Pete McNeil
Hello Andy, Wednesday, August 23, 2006, 8:57:48 AM, you wrote: > Pete, > I have the same concern. I have been submitting the below spam (possible > Words virus) almost daily for more than week - yet, it still is not > discovered. > Am I submitting correctly? This particular spam campaign is a

[sniffer] Paypal failing SNIFFER-GENERAL

2006-08-23 Thread Darin Cox
FYI... I just reported one of these, so watch out. Darin.    

[sniffer] Re: Paypal failing SNIFFER-GENERAL

2006-08-23 Thread Pete McNeil
Hello Darin, I may be behind... but I don't see an FP report on this. Do you have the rule id? _M Wednesday, August 23, 2006, 1:36:08 PM, you wrote: > > > FYI... I just reported one of these, so watch out. > > Darin. > >   > >   > -- Pete McNeil Chief Scientist, Arm Research

[sniffer] Re: Paypal failing SNIFFER-GENERAL

2006-08-23 Thread Darin Cox
Hi Pete, I'm not sure which column is which, but here are the log lines for the message (minus the authorization code) 20060823163449 D83a20d3001502962.SMD 0 32 Match 1100444 60 1502 1551 98 20060823163449 D83a20d3001502962.SMD 0 32 Final 1100444 60 0 3798 98 The FP was submitt

[sniffer] Re: Paypal failing SNIFFER-GENERAL

2006-08-23 Thread Colbeck, Andrew
Column 7 is the one that contains the rule that was hit. In this case, it was 1100444. Column 8 is the one that contains the group. In this case, it was 60 "Ungrouped Black Rules" (Sniffer General). Andrew 8) > -Original Message- > From: Message Sniffer Community > [mailto:[EMAIL P

[sniffer] Re: Paypal failing SNIFFER-GENERAL

2006-08-23 Thread Pete McNeil
Hello Darin, I have processed an FP with that rule (1100444) - the rule was for an obscure ebay link and has been removed. Best, _M Wednesday, August 23, 2006, 3:23:55 PM, you wrote: > Hi Pete, > I'm not sure which column is which, but here are the log lines for the > message (minus the autho

[sniffer] Blank emails

2006-08-23 Thread David Moore
I am seeing a lot of Spam emails with blank body’s is this because our internet connection is too slow or because the spammers are failing to complete there transaction     Received: from CIBER2.ctijdq6u.org [201.135.34.108] by romtech.com.au with ESMTP   (SMTPD-8.22) id A02D0268; Thu,

[sniffer] Another example of an empty email but looking at the source.

2006-08-23 Thread David Moore
Received: from PC05.4ueleoz.org [202.215.167.25] by romtech.com.au with ESMTP   (SMTPD-8.22) id A7AC0224; Thu, 24 Aug 2006 08:33:16 +1000 Message-Id: <[EMAIL PROTECTED]> X-mxGuard-Info: Processed by romtech.com.au using mxGuard v2.4 X-mxGuard-SpoolID: d7ab017912af X-mxGuard-Sender:

[sniffer] Re: Another example of an empty email but looking at the source.

2006-08-23 Thread Support
Hi David: There has been a rise in spam again and we just added some new rules to our system. Lets give it a few days to see if they stop. Have a great day. Phil David Moore wrote: *Received: from PC05.4ueleoz.org [202.215.167.25] by romtech.com.au with ESMTP* * (SMTPD-8.22) id A7AC0224

[sniffer] Re: Blank emails

2006-08-23 Thread Pete McNeil
Hello David, Spammers are sending a lot of broken spam lately, including those with blank bodies and missing headers etc. We have been able to build abstracts for some of these... other attempts have been retracted due to FPs or simply were ineffective. Difficult to filter what is not there. Stil

[sniffer] Re: Another example of an empty email but looking at the source.

2006-08-23 Thread Pete McNeil
Hello David, Sometimes we have rules for empty email --- but there are many different kinds of "empty" ;-) Often enough, some "empty" messages are legitimate. _M Wednesday, August 23, 2006, 6:39:23 PM, you wrote: > > > > Received: from PC05.4ueleoz.org [202.215.167.25] by romtech.com