Re: [AMaViS-user] Forged 'X-Virus-Scanned' header bypasses Amavis-new scanning

2008-02-24 Thread Christopher J Shaker
Mark Martinec wrote: Chris, Also, your hints about debugging info from amavisd-new got me reading about the auto whitelist. Used the following config commands: /etc/mail/spamassassin/local.cf: use_auto_whitelist 0 /usr/local/sbin/amavisd.conf: $sa_auto_whitelist = 0;

Re: [AMaViS-user] Forged 'X-Virus-Scanned' header bypasses Amavis-new scanning

2008-02-22 Thread Christopher J Shaker
can run spamassassin on every email. I prefer that behavior. Thank you again, Chris Shaker Christopher J Shaker wrote: I tried to disable the auto whitelist, using /etc/mail/spamassassin/local.cf: ... use_auto_whitelist 0 ^ bayes_auto_learn1

Re: [AMaViS-user] Forged 'X-Virus-Scanned' header bypasses Amavis-new scanning

2008-02-19 Thread Christopher J Shaker
=29, status=sent (250 Ok: queued as 6E8F1404B6) Feb 19 01:37:34 linux amavis[32325]: (32325-09) load: 8 %, total idle 1605.757 s, busy 139.642 s Feb 19 01:37:34 linux postfix/qmgr[32311]: 516D1404B4: removed Thank you, Chris Shaker MrC wrote: Christopher J Shaker wrote: Feb 18 15:07:33

Re: [AMaViS-user] Forged 'X-Virus-Scanned' header bypasses Amavis-new scanning

2008-02-18 Thread Christopher J Shaker
Here is the /var/log/mail entry from the email that leaked past Amavis-new: Feb 18 15:07:11 linux postfix/smtpd[19386]: connect from unknown[121.27.33.247] Feb 18 15:07:12 linux postfix/smtpd[19386]: 3BFD9404B1: client=unknown[121.27.33.247] Feb 18 15:07:13 linux postfix/cleanup[19387]:

Re: [AMaViS-user] Forged 'X-Virus-Scanned' header bypasses Amavis-new scanning

2008-02-18 Thread Christopher J Shaker
[Sending again as ASCII] Here is the /var/log/mail entry from the email that leaked past Amavis-new: Feb 18 15:07:11 linux postfix/smtpd[19386]: connect from unknown[121.27.33.247] Feb 18 15:07:12 linux postfix/smtpd[19386]: 3BFD9404B1: client=unknown[121.27.33.247] Feb 18 15:07:13 linux

Re: [AMaViS-user] Forged 'X-Virus-Scanned' header bypasses Amavis-new scanning

2008-02-17 Thread Christopher J Shaker
by Amavis. When I run spamassassin on it, it gets a very high score. Other spam gets filtered just fine. Somehow, this one spammer avoids it. Thank you again, Chris Shaker [EMAIL PROTECTED] Clifton Royston wrote: On Sat, Feb 16, 2008 at 11:31:05AM -0800, Christopher J Shaker wrote: You may

Re: [AMaViS-user] Forged 'X-Virus-Scanned' header bypasses Amavis-new scanning

2008-02-17 Thread Christopher J Shaker
Clifton: I am pretty sure amavisd-new does *not* work this way. It has an implicit list of checks to run on each incoming mail, starting with virus scanning, and works its way through them. If it's working this way for you, it may be the result of something funky in your Postfix

[AMaViS-user] Forged 'X-Virus-Scanned' header bypasses Amavis-new scanning

2008-02-16 Thread Christopher J Shaker
You may all know about this, but it was new to me. Found a persistent spammer was sending email to my domain without any score information from amavis-new. After trying several possibilities, I finally realized that he was sending the email with a hand crafted 'X-Virus-Scanned' header that was