Re: [AMaViS-user] Insecure dependency in exec while running with -T switch

2006-11-07 Thread Mark Martinec
MK, after updating to amavisd-new version 2.4.3 i see the following in amavis.log: ... /usr/sbin/amavisd[28277]: (27642) (!!)run_command: child process [28277]: Insecure dependency in exec while running with -T switch at /usr/sbin/amavisd line 2385. ... /usr/sbin/amavisd[27642]: (27642)

Re: [AMaViS-user] Milter errors

2006-11-07 Thread Mark Martinec
Rocco, I've a sendmail-milter configuration for amavisd-new. During this days I get errors like this in my milter log: Nov 7 10:41:54 av4 amavis-milter[26836]: kA79fr2Z025517: (mlfi_envfrom) creating file /var/amavis/tmp/amavis-milter-kA79fr2Z025517/email.txt failed: Too many open files

Re: [AMaViS-user] write(O) returned -1, expected 17: Broken pipe

2006-11-07 Thread Mark Martinec
Rocco, In my sendmail-milter amavisd-new system I get the following messages in maillog: Nov 7 10:00:29 av4 sendmail[6752]: kA790TXs006752: Milter (milter-amavis): write(O) returned -1, expected 17: Broken pipe I cant figure out what it can be the problem. For the archive: looking at a

Re: [AMaViS-user] Anyone else gets these?

2006-11-07 Thread Mark Martinec
CRivera, This is a higly annoying mail that started to flow through late yesterday, it doesn't get tagged at all, and I have the lower score set to 1.4 I posted about this to the list last week under the subject Stock tips Emails I am at a loss here on what to do, I have sare_stocks

Re: [AMaViS-user] Postgresql encoding?

2006-11-07 Thread Mark Martinec
TROUBLE in check_mail: quar+notif FAILED: temporarily unable to quarantine: 451 4.5.0 Storing to sql db as mail_id 2i86bAAnI5jq failed: writing mail text to SQL failed: Error closing, flush: sql inserting text failed, sql exec: err=7, 22021, DBD::Pg::st execute failed: ERROR: invalid

Re: [AMaViS-user] ot: SA FuzzzyOCR rejection Q

2006-11-07 Thread Mark Martinec
Voytek, Nov 3 14:19:17 koala amavis[26922]: (26922-03-3) SPAM, [EMAIL PROTECTED] - [EMAIL PROTECTED], Yes, score=6.941 tag=0.5 tag2=6.31 kill=6.31 tests=[BAYES_00=-2.599, EXTRA_MPART_TYPE=1.091, FUZZY_OCR=6.000, HTML_MESSAGE=0.001, HTML_TITLE_EMPTY=0.214, RCVD_IN_WHOIS_INVALID=2.234],

Re: [AMaViS-user] forward_method and MX records

2006-11-08 Thread Mark Martinec
Julian, I want AMaViS to use my MX records for redundant mail routing but it seems that only the A record is beeing used. How can I make AMaViS using the MX records? Mapping host name (e.g. in $forward_method) to IP address is entirely in hands of Perl modules Net::SMTP and IO::Socket::INET,

Re: [AMaViS-user] possible hack attempt via user amavis

2006-11-08 Thread Mark Martinec
Mark Richards, This afternoon (4pm EST) I was doing some maintenance work on our server and suddenly my ssh telnet session dropped. Attempts at reconnecting yielded a certificate missing error. FTP, HTTP, and our email services (dovecot with amavisd/clamd/spamassassin and postfix with

Re: [AMaViS-user] Bad file descriptor errors with AMaVIS under Zimbra

2006-11-09 Thread Mark Martinec
Bradley, ...parts_decode_ext FAILED: Error reading from file(1) utility: Bad file descriptor at (eval 51) line 151 This is probably unrelated to Net::Server. Must be something weird with a pipe to a subprocess running file(1) utility. Are you running amavisd chrooted? Does file(1) utility work

Re: [AMaViS-user] Postgresql encoding?

2006-11-09 Thread Mark Martinec
Justin, Thanks for the idea on how to fix the problem, unfortunately it doesn't seem to totally fix it, I have a feeling that it's not just the mail_text field that is being affected but other fields like subject etc, it seems to only happen with poorly built email and viruses Fields From:,

Re: [AMaViS-user] Double maildelivery

2006-11-09 Thread Mark Martinec
Maurice, I've have a problem with double mail delivery when using recipient_bcc_maps and transport_maps. When the BCC recipient contains an adres which is routed by the transport_map postfix will deliver the mail twice, when de BCC recepient address domain is not listed in the transport_map

Re: [AMaViS-user] amavis ignores spamassassin config file

2006-11-13 Thread Mark Martinec
Vincent, I've modified the /etc/mail/spamassassin/local.cf to include new rules (SARE from rulesemporium) and new scores for the Bayes test. Although these rules are used by the spamd daemon launched from procmail rules, they are not used by amavis.

Re: [AMaViS-user] amavisd-new-2.4.4 RELEASE CANDID ATE 1 is available

2006-11-13 Thread Mark Martinec
On Monday November 13 2006 22:17, Daniel J McDonald wrote: And in another message, Mark Martinex wrote: Here is a setting just for you (not really just for you:), available with 2.4.4-rc1 (just announced): # BADH tests: other mime 8bit control empty long syntax missing multiple #

Re: [AMaViS-user] Bad file descriptor errors with AMaVIS under

2006-11-14 Thread Mark Martinec
Bradley, I downgraded both file and libmagic1 and had the same problem. However, thanks to your subsequent email, I did get a lot better data from amavisd. http://www.tux.org/~storm/files/amavisd.log Thanks, that is more helpful. It sounds like a known PerlIO bug:

Re: [AMaViS-user] Bad file descriptor errors with AMaVIS under

2006-11-14 Thread Mark Martinec
Here is the information: Nov 14 15:10:27 merrimac amavis[28922]: (28922-01) result line from file(1): p001: ASCII English text\n Nov 14 15:10:27 merrimac amavis[28922]: (28922-01) result line from file(1): p002: ASCII English text, with very long lines \n Nov 14 15:13:34 merrimac

Re: [AMaViS-user] parts_decode_ext FAILED: Unix utility file(1) not available

2006-11-15 Thread Mark Martinec
pollox, After an upgrade to amavisd-new version 2.4.2-3 on a debian etch I encounter the following error in mail.log: Nov 15 09:37:37 etch-sa-new amavis[3476]: (03476-02) (!!) TROUBLE in check_mail: parts_decode_ext FAILED: Unix utility file(1) not available, but is needed at (eval 43) line

Re: [AMaViS-user] adding a subscript signature

2006-11-15 Thread Mark Martinec
gmax, I want to add a postscript signature (something like: This email was checked by Amavisd-new) to every email we process. Is there a standard hook/feature for this ? No there isn't. It is not straightforward to do so, amavisd is geared towards ensuring the mail body stays unchanged even

Re: [AMaViS-user] parts_decode_ext FAILED: Unix utility file(1) not available

2006-11-15 Thread Mark Martinec
Where does the file utility reside? Is it in one of directories listed in your $path variable in amavisd.conf? A usual setting is: $path = '/usr/local/sbin:/usr/local/bin:/usr/sbin:/sbin:/usr/bin:/bin'; P.S. if you prefer to keep $path empty, you may explicitly specify (amavisd.conf) where

Re: [AMaViS-user] Forward mail directly to an MDA

2006-11-15 Thread Mark Martinec
Jona, I'm planning to set up a personal spam filtering gateway. It should collect mail from several remote POP servers, scan them through amavis and make them available through an IMAP server. I managed to figure out how to configure every piece of software involved, there is only one step

Re: [AMaViS-user] Bad file descriptor errors with AMaVIS under

2006-11-15 Thread Mark Martinec
Bradley, Yes. I have posted what I think is a single message's path through the logs. It does result in a bad file descriptor error. It is up at http://www.tux.org/~storm/files/amavisd.log.1 Thanks, the output from file(1) looks normal, yet your PerlIO or libc returns incorrect status on

[AMaViS-user] amavisd-new-2.4.4 RC2 is available

2006-11-15 Thread Mark Martinec
amavisd-new-2.4.4-rc2 is available at: http://www.ijs.si/software/amavisd/amavisd-new-2.4.4-rc2.tar.gz Compared with 2.4.4-rc1 it fixes SQL quarantining with PostgreSQL by suggesting the use of data type 'bytes' for field quarantine.mail_text, and specifying attribute { pg_type =

Re: [AMaViS-user] Postgresql encoding?

2006-11-15 Thread Mark Martinec
Justin, I agree with you with regards to using LATIN1 for the connection, I only used it to see if I could get it to insert into the quarantine... The software I am used is DBD:Pg 1.49 PostgreSQL 8.14 Amavis 2.4.3 I don't think it's the 255 chars being chopped, Would you be so kind and

Re: [AMaViS-user] Bad file descriptor errors with AMaVIS under

2006-11-15 Thread Mark Martinec
Bradley, I guess I'll be rebuilding that server with sarge over the weekend... Before you do that, please run the little test program and tell us what happens. Mark - Take Surveys. Earn Cash. Influence the Future of IT

Re: [AMaViS-user] To Warn Or not To Warn?

2006-11-15 Thread Mark Martinec
Andres, Well, I have this on my 50-user file config $warn_offsite = 1; Is this a good practice ? Or should I shut this down to lower the load on the MTA? (the load of sending warn emails to outside) The extra load is minimal, but the annoyance to recipients is non-negligible. On

Re: [AMaViS-user] To Warn Or not To Warn?

2006-11-16 Thread Mark Martinec
Lucio Chiappetti wrote: I've never really understood the fuss about banned files and bad header, at the end we decided to let them pass (we get about 2 bad header per day over 2000 spamham, and no banned files) silently. The primary reason for banned files checks is to be able to catch new

Re: [AMaViS-user] Postgresql encoding?

2006-11-16 Thread Mark Martinec
Jus, If I upgrade the Amavis will it go straight on or will I need to reconfigure everything? just that it's currently running on a live system I read through the release log and it looks like it would be a idea to upgrade any way... It is a drop-in replacement for your 2.4.3, no changes in

Re: [AMaViS-user] Postgresql encoding?

2006-11-16 Thread Mark Martinec
Jus, I'll be more specific: If you don't ALTER the quarantine.mail_text to bytea then PostgreSQL will complain when amavisd 2.4.4 tries to store a message to a SQL quarantine. You would be getting an error like: TROUBLE in check_mail: quar+notif FAILED: temporarily unable to quarantine:

Re: [AMaViS-user] Forward mail directly to an MDA

2006-11-16 Thread Mark Martinec
How limited is the RAM? 64MB PC100 SDRAM currently. I'll try that out. If the box runs out of RAM I'll simply buy some more. Those old DIMMs are not very expensive anymore. If the machine architecture will allow it, you really need to. Performance goes through the floor when you start

Re: [AMaViS-user] Bad file descriptor errors with AMaVIS under

2006-11-16 Thread Mark Martinec
Bradley, So I ran it on a couple of other boxes, monitor has identical hardware, defiant, my Athlon-XP workstation and riogrande, my HP Pentium-M laptop: Thanks, interesting. So it works fine on monitor, but not on merrimac or defiant. All three boxes are running Debian/sid. I'm looking

Re: [AMaViS-user] auto-whitelist

2006-11-17 Thread Mark Martinec
Andrea, I have auto-whitelist default in /var/amavis/.spamassassin/ I list this auto-whitelist db with my check_whitelist and I have: 316.2 (316.2/17) -- [EMAIL PROTECTED]|ip=none Now I want to delete the line ... spamassassin [EMAIL PROTECTED] I think that the line is been

Re: [AMaViS-user] More info on problems with Amavis on Debian/etch

2006-11-17 Thread Mark Martinec
Keith, I did an strace and get a loop that looks like the following: select(0, NULL, NULL, NULL, {10, 0})= 0 (Timeout) time(NULL) = 1163696544 select(0, NULL, NULL, NULL, {10, 0})= 0 (Timeout) time(NULL) = 1163696554

Re: [AMaViS-user] Problems with Debian/etch

2006-11-17 Thread Mark Martinec
Keith, Anyway, I installed sendmail and amavisd-new from packages, along with amavisd-new-milter. Copied over the sendmail.mc from the old setup, went through the amavisd config ... no dice. It's timing out on the child process without chewing any CPU. At this point I still have AV and spam

Re: [AMaViS-user] policy bank for bypass scan for internal mails

2006-11-17 Thread Mark Martinec
Davide, i'm trying to setup a policy banks in order to bypass spam scanning of outgoing mails for a remote postfix server. xxx.xxx.xxx.45 = amavis server xxx.xxx.xxx.62 = postfix server smtpd_recipient_restrictions = permit_sasl_authenticated, permit_mynetworks,

Re: [AMaViS-user] SPAM and SPAMMY

2006-11-17 Thread Mark Martinec
Davide, what's the difference between spam and spammy? if score kill level = SPAM else if score tag3 level = SPAMMY, minor ccat 1 else if score tag2 level = SPAMMY else if score tag level = CLEAN, minor ccat 1 else = CLEAN Mark

Re: [AMaViS-user] SPAM and SPAMMY

2006-11-17 Thread Mark Martinec
actually, '' should be '=' if score = kill level = SPAM else if score = tag3 level = SPAMMY, minor ccat 1 else if score = tag2 level = SPAMMY else if score = tag level = CLEAN, minor ccat 1 else= CLEAN Mark

Re: [AMaViS-user] Solved? Re: Bad file descriptor errors with AMaVIS under

2006-11-17 Thread Mark Martinec
Bradley, I believe I have found the problem, thanks to Mark's direction. I wrote a quick script to dump most of the information to a file (except the perlrun stuff) on all four of the servers and diffed them. All the three servers which failed also had %ENV: PERLIO=stdio while monitor did

Re: [AMaViS-user] Solved? Re: Bad file descriptor errors with AMaVIS under

2006-11-17 Thread Mark Martinec
I guess I should submit a Perl bug report, unless you volunteer to do it. It seems to be closely related to the bug I mentioned earlier: http://rt.perl.org/rt3/Ticket/Display.html?id=39060 P.S. I updated the existing bug report with new information. Mark

Re: [AMaViS-user] Removing SQL Logging

2006-11-17 Thread Mark Martinec
DH, Our mail server has been suffering performance problems due to excessive use of the local MySQL server in the various configurations. Looking over the Amavisd-new configuration, I see that SQL Logging is enabled via: @storage_sql_dsn = @lookup_sql_dsn; The lookups are necessary, but

Re: [AMaViS-user] subject lines

2006-11-21 Thread Mark Martinec
Curtis, I've go amavisd-new running with spamassassin and dbmail. I've been getting inundated with spam lately. subject lines are not being modified as I've defined in the config file. $sa_spam_subject_tag = '***SPAM***'; $sa_spam_modifies_subj = 1; I'm seeing spam blocked, but everything

Re: [AMaViS-user] Can't locate object method max_parts

2006-11-23 Thread Mark Martinec
Leon, 451 4.5.0 Error in processing, id=15039-05, mime_decode-1 FAILED: Can't locate object method max_parts via package MIME::Parser at /usr/sbin/amavisd line 5933. Your version of MIME::Parser (i.e. MIME-Tools) is too old, use 5.420. Mark

Re: [AMaViS-user] p0f with dual sendmail?

2006-11-23 Thread Mark Martinec
Tapani, Is it possible to use p0f with dual-sendmail setup? Release notes only talk about sendmail/milter and postfix, and mention postfix needs xforward extension - does sendmail have/need something similar? xforward is Postfix-specific extension, sendmail can not pass such information over

Re: [AMaViS-user] Only one address exclude

2006-11-23 Thread Mark Martinec
Jim, I want to exclude ONLY one address from all checks, spam checks, virus check and banned files checks. Is this right? @spam_lovers_maps = ( [qw( [EMAIL PROTECTED] )] ); @virus_lovers_maps = ( [qw( [EMAIL PROTECTED] )] ); @banned_files_lovers_maps = ( [qw( [EMAIL PROTECTED] )] ); or

Re: [AMaViS-user] trouble with rules_du_jour

2006-11-23 Thread Mark Martinec
Peter, I am running amavisd 2.44 chrooted on OpenBSD 4.0. I am running rules_du_jour.sh and even though I specify my SA_DIR (inside /etc/rulesdujour/config) as /var/amavisd/etc/mail/spamassassin I keep getting errors because I have score modifications for non-existent rules inside

Re: [AMaViS-user] Per-domain *_quarantine_method

2006-11-23 Thread Mark Martinec
Paolo, I think the following quarantining method is not supported right-away, but it requires policy banks: @domain1 = quarantine to SQL DB_ONE @domain2 = quarantine to SQL DB_TWO As Gary correctly determined, it is not possible to use more than one SQL database. However, it should be

Re: [AMaViS-user] .asc file part flagged as a match for a banned file type.

2006-11-23 Thread Mark Martinec
Bob, Nov 20 13:22:21 mailgateway.forsythshirt.com /usr/sbin/amavisd[6586]: (06586-09) lookup (check_bann:[EMAIL PROTECTED]) = true, [multipart/mixed,multipart/alternative,text/plain,.asc,.asc,fill i ng orders towards the end of next week.] matches, result=1,

Re: [AMaViS-user] Mail header

2006-11-24 Thread Mark Martinec
David, I have two questions regarding amavisd: I would like to use the character + instead of * in the header line X-Spam-Level. I changed it in /usr/sbin/amavisd-new and it works but I would prefer to set it in a config file and not in the programm itself. Whenever there comes an update,

Re: [AMaViS-user] p0f with dual sendmail?

2006-11-24 Thread Mark Martinec
Tapani, Yes, moving from dual sendmail to milter would be an obvious solution, but my past experiences with milter under heavy load discourage me from going that route. It's been some time since I looked at it though, perhaps the issues have been solved since. I wouldn't recommend it

Re: [AMaViS-user] Only one address exclude

2006-11-24 Thread Mark Martinec
Jim, thanks. And how is it with mysql? Same thing. Example. ID 1 non-paying All options to Y (YES)? spam_lover, virus_lover, and so on bypass_*, and so on Right. Or just bypass* 'Y', and *_lovers at 'N', which could let unpaying customers benefit from alreay known check results made on

Re: [AMaViS-user] p0f with dual sendmail?

2006-11-24 Thread Mark Martinec
Vincent, Any volunteers to prepare a SA plugin for p0f lookup? Should be quite straightforward. Suppose I have script like this: ... sub p0f_lookup { # get the first trusted header . What to do next? I am still not clear how the fingering printing information get

Re: [AMaViS-user] P0f strangeness with Freebsd and amavisd-new-2.4.3_1, 1

2006-11-24 Thread Mark Martinec
On Friday November 24 2006 22:24, Michael Scheidell wrote: Figured it out: ... It looks like starting p0f analyzer using the ports supplied rc.subr script on Freebsd does something strange. - /usr/local/bin/p0f ${amavis_p0f_daemon_flags} \ + /usr/local/bin/p0f

Re: [AMaViS-user] Multiple simultaneous quarantines?

2006-11-24 Thread Mark Martinec
Tom, We've got a current setup that is doing quarantine via SMTP. We'd like to try out SQL quarantine as well, but need to keep the current method up and running while we try it and perhaps later transition to the new setup. Is it possible to have two different simultaneous quarantine

Re: [AMaViS-user] debug question

2006-11-27 Thread Mark Martinec
module = 'Net::Ident', desc = 'If you plan to use the --auth-ident option to spamd This one is not needed by amavisd-new (and is of dubious value with spamd). Mark - Take Surveys. Earn Cash. Influence the Future of IT

Re: [AMaViS-user] spam_lovers syntax

2006-11-28 Thread Mark Martinec
Leon, I want to add several mailinglists to spam_lovers_maps directives, so mails sent to these lists go directly to the list without spam checks: Couls I just do it like this (i.e. every address on a new line)? @spam_lovers_maps = @bypass_spam_checks_maps = ( [ qw( [EMAIL PROTECTED]

Re: [AMaViS-user] (!)WARN: Using cpio instead of pax can be a security risk;

2006-11-29 Thread Mark Martinec
why can using cpio be a security risk? (i'm using cpio (GNU cpio) 2.7) cpio can be tricked to decode multiple archive components into the same file, overwriting previous contents, which could help in camouflaging a virus. pax has options which can reduce the problem to large extent (including

Re: [AMaViS-user] Amavis 421 4.3.2 Service shutting down and LDAP

2006-11-29 Thread Mark Martinec
Jim, When we enable LDAP in the amavisd conf file, we get this error message. But if we don't enable ldap, everything works fine. (host 127.0.0.1[127.0.0.1] said: 421 4.3.2 Service shutting down, closing channel (in reply to RCPT TO command)) So what does 'amavisd debug' say? Mark

Re: [AMaViS-user] (!)WARN: Using cpio instead of pax can be a security risk;

2006-11-29 Thread Mark Martinec
tar is very much nonstandard and limited in formats ... ...nonstandard across platforms that is, each Unix variant has quite a different tar, while pax is pretty much the same everywhere. Mark - Take Surveys. Earn Cash.

Re: [AMaViS-user] amavis

2006-12-01 Thread Mark Martinec
Macci, I'm running FC5 with postfix, amavisd-new and spamassassin and ClamAv. The spam is being tag as spam, but its not forwarded to my junk mail box and it does not looks like it is being scaned by ClamAv. Here is my maillog. Dec 1 13:04:09 genesisprojects spamd[17004]: spamd: connection

Re: [AMaViS-user] Q: DMZ Using 'forward_method' - Which port to use on internal postfix server?

2006-12-01 Thread Mark Martinec
Peter, I thought I should send it to 192.168.0.99:10025 (the feedback from AMaViS to the Postfix queue) in order for it not to be double checked. The connections are refused: (no firewall) Dec 1 14:31:01 pollux.scarceskills.com /usr/local/sbin/amavisd[22381]: (22381-03) (!)FWD via SMTP:

Re: [AMaViS-user] Determining which rules a clean message violated

2006-12-01 Thread Mark Martinec
Michael, ... To facilitate training I quarantine clean messages for 7 days along with all the others. The problem I have, is in finding out which SpamAssassin rules a clean message actually triggered. These show up in the headers of the delivered message, but not in the quarantined message

Re: [AMaViS-user] [OT] Virus heads up

2006-12-01 Thread Mark Martinec
We got our first specimen on Nov 30 19:40 UTC, and at first these only hit 'Blocked UNCHECKED'. The first recognized by Sophos as W32/Bagle-Zip came in on Dec 1 03:10 UTC, but still not all of them are recognized. P.S. all of these UNCHECKED (not yet recognized as infected) scored 21..25 hits

Re: [AMaViS-user] [OT] Virus heads up

2006-12-01 Thread Mark Martinec
P.S. all of these UNCHECKED (not yet recognized as infected) scored 21..25 hits by SA, so luckily it's not a big deal when spam checking is turned on. Pictures in a virus are bogging down virus propagation, nice! P.P.S: some of the more pronounced SA tests hit by W32/Bagle-Zip: BAYES_60 = 1

Re: [AMaViS-user] Q: DMZ Using 'forward_method' - Which port to use on internal postfix server?

2006-12-01 Thread Mark Martinec
Peter, You have restricted smtpd service to bind on a loopback interface, which is why it won't listen on other interfaces. Remove the restriction: 10025 inet n -n - - smtpd -o mynetworks=127.0.0.0/8,192.168.0.0/24 Do you mean in master.cf, on the receiving server - remove the 10025 line

Re: [AMaViS-user] FW: Your message to AMaViS-user awaits moderator approval

2006-12-01 Thread Mark Martinec
Melissa, I keep getting this when I try to post to the list. Do you know why? Your mail to 'AMaViS-user' with the subject @bypass_spam_checks_acl not working? Is being held until the list moderator can review it for approval. The list has no active moderators, so I can only guess. The

Re: [AMaViS-user] SA whitelist usage

2006-12-01 Thread Mark Martinec
Andres, RCVD_IN_DSBL=2.6, RCVD_IN_SORBS_DUL=2.046, The user is sending email OUTSIDE my network, because he works at other location. And uses SASL Auth. He uses an automatic IP given by his ISP ( Could it be that IP being blacklisted because of the public condition?) Mail is being checked

Re: [AMaViS-user] ANNOUNCE: amavisd-new-2.4.4 has been released

2006-12-02 Thread Mark Martinec
Jo, So, I'm confused. The release notes say: - AM.PDP/milter setup: new configuration setting $prepend_header_fields_hdridx, also a member of policy banks, with a default value of 0. But amavisd.conf-default has this line: # $prepend_header_fields_hdridx = 1; Am I misunderstanding the

Re: [AMaViS-user] Clamav amavisd-new and optional depackers

2006-12-03 Thread Mark Martinec
Michael, For 'all' of the depackers, if we are using Clamav and clamav can do ALL the unpacking for us, would it be a memory saving device to undef ALL of the unpackers in @decoders? Yes, there is some memory saving there (about 3 MB of virtual memory), but is pretty small portion of total

Re: [AMaViS-user] Score= -

2006-12-04 Thread Mark Martinec
X-Spam-Score: - X-Spam-Status: No, score=x tagged_above=-999 required=5 tests=[] When spamassassin is not called, score=x is reported. When score is undefined, score='-' is reported. Yes. Actually both the '-' and 'x' mean the same thing, i.e. score is not known (normally because SA was

Re: [AMaViS-user] Score= -

2006-12-04 Thread Mark Martinec
Peter, I've also wondered about the '-' score. Now my question is why SA would not be called? - message larger than $sa_mail_body_size_limit, or - all recipients have bypass_spam_checks, or - sender is hard- white or blacklisted. Mark

Re: [AMaViS-user] hung child processes

2006-12-04 Thread Mark Martinec
Bill, Problem 1: after an 'amavisd reload' or 'amavisd stop' command, not all child processes die. The main server thread exits and some children may exit, but often one or more children hang around. Example: ... 31249 ?R877:28 amavisd (ch4-31249-04) Note that 31249 is still

Re: [AMaViS-user] SA whitelist usage

2006-12-04 Thread Mark Martinec
# Internal clear_internal_networks internal_networks 127/8 IP_of_first_mail_relay IP_of_second_mail_relay # Trusted clear_trusted_networks trusted_networks 127/8 IP_of_first_mail_relay IP_of_second_mail_relay If you properly list your internal network (127/8 is in your internal

Re: [AMaViS-user] hung child processes

2006-12-04 Thread Mark Martinec
Leon, Sometimes, I got similar problems after restarting amavis, postfix stops communicate with amavis (and I see that mailq rapidly grows). I needed to restart postfix to make it work normally again: ... But thanks for the tip Mark, I'll try 'postfix flush'. 'postfix flush' should suffice

Re: [AMaViS-user] Messages getting caught in Postfix's Queue

2006-12-04 Thread Mark Martinec
Mike, (host 127.0.0.1[127.0.0.1] said: 421 4.3.2 Service shutting down, closing channel (in reply to end of DATA command)) amavisd-new is closing its end of the session. This only happens when it encounters a serious problem. Look into its log to see what the problem was. This appears to be

Re: [AMaViS-user] sendmail, XFORWARD and policy_banks

2006-12-05 Thread Mark Martinec
Claude, Is there a solution to use the policy-banks with the dual config sendmail, although there is no XFORWARD ? Policy banks based on incoming TCP port number are still possible, but not a policy bank MYNETS, for which the information about client IP address is lacking. It should be

Re: [AMaViS-user] LDAP lookups for mydomains

2006-12-07 Thread Mark Martinec
Dave, Is possible to put $mydomains in an LDAP lookup ? Not sure what you mean by that. What you place in LDAP is up to you, amavisd does not place anything in LDAP. If the question is how to match on some domains besides those that are in your LDAP, you may use static lookup tables for

Re: [AMaViS-user] sendmail, XFORWARD and policy_banks

2006-12-07 Thread Mark Martinec
Claude, I think, a very simple solution would be do include a special X-Header in the message coming from the receiving sendmail instance, in which one the IP address of the client would be included. sendmail can easily be configured in order to do this. Because this receiving sendmail

Re: [AMaViS-user] FP on p0f

2006-12-07 Thread Mark Martinec
Michael, I understand the suggested high value for windows XP, (since a workstation isn't a mail server) But the original suggested pattern matches, match this one as windows XP (and score it high!) when it could just as well be a windows 2000 sp3 server: X-Amavis-OS-Fingerprint: Windows

Re: [AMaViS-user] User settable option for RBLs?

2006-12-08 Thread Mark Martinec
Jorgen, Is it possible to control if Amavisd should use RBLs based on a user's profile? Currently I can set local_tests_only to disable RBL, but if I can enable/disable it based on LDAP attribute that would be sufficient. That is conceptually not possible: message can have multiple

[AMaViS-user] ASA-2006-1: Convert::UUlib 1.04 exploitable buffer overflow

2006-12-08 Thread Mark Martinec
AMAVIS SECURITY ADVISORY ASA-2006-1: Convert::UUlib 1.04 exploitable buffer overflow IMPACT Gain shell access to a remote system running a content filter which uses Convert::UUlib 1.04 or earlier. HOW TO CHECK The following command will write version of the module to stdout: perl

Re: [AMaViS-user] Amavis doesn't start anymore

2006-12-11 Thread Mark Martinec
PhiL, I installed some days ago amavisd-new-2.3.3 (20050822) without any problems and tested it against virus successfuly. Yesterday I discovered that it was stopped and can't be started anymore. Dec 8 21:57:07 mysystem.homelinux.net /usr/sbin/amavisd-new[5879]: \ Creating db in

Re: [AMaViS-user] Too many false negatives

2006-12-11 Thread Mark Martinec
rocsca, I'm receing a lot of messages with gif attachment. The most efficient tools against such are currently FuzzyOcr plugin, ImageCheck plugin, and some of Theo Van Dinter's rules that comes with sa-update (TVD_*). I've instructed SA using such email, but still amavisd-new don't block

Re: [AMaViS-user] Amavis SQL Blaclist mail bounce

2006-12-11 Thread Mark Martinec
Gert, I have amavisd-new install by yum on my FC5 box. I used the http://www.ijs.si/software/amavisd/README.sql.txt file to configure mysql and amavis. I changed my amavisd.conf file to include: $sql_select_policy = 'SELECT *,users.id FROM users,policy'. ' WHERE

Re: [AMaViS-user] Amavis SQL Blaclist mail bounce

2006-12-11 Thread Mark Martinec
How do I configure my policy table to bounce the mail. $final_spam_destiny = D_BOUNCE; and not have recipients declared spam lovers. P.S. forgot to mention $sa_dsn_cutoff_level. If you have this defined, any spam with score above $sa_dsn_cutoff_level will suppress sending the non-delivery

Re: [AMaViS-user] amavisd with spamc/spamd for load balancing

2006-12-11 Thread Mark Martinec
Trey, I am not opposed to multiple amavisd-new servers, but I'm not sure how that would be implemented with our setup. The messages are all delivered to one server, so how do you propose that we distribute the email among multiple servers? We cannot just do it on a per-domain basis,

Re: [AMaViS-user] Exclude authenticated Users Dual Sendmail

2006-12-11 Thread Mark Martinec
Peter, I have a bit of a problem here. Many of my mailusers are using a provider, whose dynamic addresses seem to be blocked by sorbs and other such places. I have them connect to my mailserver with sasl authentication, so I was wondering if there is a way to bypass spamfiltering for

Re: [AMaViS-user] Amavis doesn't start anymore

2006-12-11 Thread Mark Martinec
PhiL, I didn't modify anything in who is owner:group. I removed the directory et created a new one with exactly the same access right and user:group then restarted cyrus. Now it works fine. I'm glad. I don't know what happend. Would it be possible that changing my server hostname or

Re: [AMaViS-user] Amavisd-new does not start after yum install on FC3

2006-12-11 Thread Mark Martinec
Greg, Problem in the Amavis::Unpackers code: Archive::Zip version 1.14 required--this is only version 1.01 at (eval 50) line 21. Thanks for the response Mike, however, I currently have 1.16 installed. I have 1.12, 1.14, and 1.16 downloaded as rpms. I have tried all 3 versions and I keep

Re: [AMaViS-user] plain text mail banned as .EXE ???

2006-12-11 Thread Mark Martinec
Jakob, Update : Even to send the mail including the snippet to the amavis list I had to put myself on the banned_filenames_maps list How does amavis recognize banned .exe types (not names, there was no attachment...) ? Could that be a file(1) problem ? I forgot what the original thread

Re: [AMaViS-user] ***virus*** plain text mail banned as .EXE ???

2006-12-11 Thread Mark Martinec
Thanks everybody for a quick analysis! Sure I can and will do that; but I think there is more to the point. Rejecting a mail because of two letters is a hard thing to do. There might be a lot of linguistic combinations around that lead to two-letter patterns matching those of file(1). After

Re: [AMaViS-user] Bayes autolearn not working?

2006-12-12 Thread Mark Martinec
Jef, At log level2, I see some autolearn entries. I started with an empty logfile and used fetchmail to retrieve a pop3 mailbox with 278 messages (almost all spam). They are all correctly marked a spam. In the log, I see only 133 autolearn headers: - autolearn=no: 103 - autolearn=spam:

Re: [AMaViS-user] Too many false negatives

2006-12-12 Thread Mark Martinec
rocsca, The most efficient tools against such are currently FuzzyOcr plugin, ImageCheck plugin, and some of Theo Van Dinter's rules that comes with sa-update (TVD_*). Could you instruct me on the installation of (one or all) the plugin(s) above? Where I can download them? I cant find it

Re: [AMaViS-user] Amavisd-new 2.4.4 and log files

2006-12-12 Thread Mark Martinec
rocsca, I'm new to amavisd-new-2.4.4. I can't get log from amavis using syslog and I cant figure out why: $syslog_facility = 'local7'; $syslog_priority = 'info'; In previous versions I set: $SYSLOG_LEVEL = 'local7.info'; Same thing. With 2.4.4 either the new or the old style can be

Re: [AMaViS-user] Exclude authenticated Users with Sendmail/milter

2006-12-12 Thread Mark Martinec
Jurek, Passing just a policy name over the protocol is less work and no additional configuration parameters for me, and more for Petr. And vice versa. Mark I'm very interested in this solution. I've been testing new beta version of amavisd-milter by Petr Rehor

Re: [AMaViS-user] ask_daemon_internal timeout on retry

2006-12-12 Thread Mark Martinec
Nick, Sorry for a late reply. We're using the very excellent amavisd-new 2.4.2 (Debian's latest version) with sophie as AV scanner. Occasionally sophie gets into a state where it is accepting connections on the Unix socket but never replies to scan requests. Amavis times out OK on its

Re: [AMaViS-user] Bad File Descriptor problem

2006-12-12 Thread Mark Martinec
Z, Last night after a long overdue update to my Debian Sarge system, my Amavis install went on the fritz (amavisd-new-20030616-p10). I found I have the same problem that Bradley Alexander did on 11/17/06 with PERLIO begin set to stdio somewhere in the environment... My question is where can

Re: [AMaViS-user] WARN: MIME::Parser error:

2006-12-13 Thread Mark Martinec
Peter, I got amavisd-new 2.4.4 on a ubuntu dapper server running. Following error appears several times in my log files: amavis[32083]: (32083-01-12) WARN: MIME::Parser error: unexpected end of preamble amavis[32101]: (32101-01-12) WARN: MIME::Parser error: part did not end with expected

Re: [AMaViS-user] Bayes autolearn not working?

2006-12-13 Thread Mark Martinec
Jef, SA debugging can be turned on selectively, e.g: # amavisd -d bayes,learn debug-sa I have the default settings from ubuntu for spamassassin. bayes_auto_learn_threshold_nonspam0.1 bayes_auto_learn_threshold_spam 12.0 bayes_auto_learn 1 Ok. So what did

Re: [AMaViS-user] Can amavis cc a message before it's filtered?

2006-12-13 Thread Mark Martinec
Joshua, I'm running under Sendmail using amavis-new-2.4.1 (20060508). I'd like to have a copy of all messages that are filtered sent to another e-mail address *before* they are filtered. I'm trying to train another spam filter, and I don't want the current spam filter's headers to become

Re: [AMaViS-user] Bad File Descriptor problem

2006-12-13 Thread Mark Martinec
Zachariah, perl -le 'print join(, ,PerlIO::get_layers(\*STDIN))' unix, perlio PERLIO='' perl -le 'print join(,,PerlIO::get_layers(\*STDIN))' unix, perlio PERLIO='stdio' perl -le 'print join(,,PerlIO::get_layers(\*STDIN))' stdio PERLIO='perlio' perl -le 'print

Re: [AMaViS-user] Bayes autolearn not working?

2006-12-14 Thread Mark Martinec
Jef, On a total of 232 messages, 25 get learned (4 ham, 21 spam) and 129 are not learned. I have no idea what happened to the other 78 messages. http://wiki.apache.org/spamassassin/AutolearningNotWorking Mark - Take

Re: [AMaViS-user] Bayes autolearn not working?

2006-12-14 Thread Mark Martinec
http://wiki.apache.org/spamassassin/AutolearningNotWorking I should add: 'autolearn=...' is not shown when SA is not called, which can be because results from previous instance of the same message was cached, or other reasons for not calling SA (white/blacklisted, bypass_spam_checks, message

<    5   6   7   8   9   10   11   12   13   14   >