Re: [Mimedefang] rejecting on helo,drive-by-relay,forged_sender,

2004-01-16 Thread Joseph Brennan
m half the 'net! Joseph Brennan Columbia University in the City of New York Academic Technologies Group [EMAIL PROTECTED] ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL

Re: [Mimedefang] "Deep recursion on subroutine" in MIME::Parser - how to trace?

2004-01-16 Thread Joseph Brennan
n't seen a case in a long time so it's not going to make my to-do list. I'd like to tell you how we diagnosed it but I can't remember-- sorry. Probably just eyeballing syslog. Joseph Brennan Columbia University in the City of New York Academic Technologies Group

RE: [Mimedefang] Many many MX records

2004-01-16 Thread Joseph Brennan
intenance, and have to pray that it never goes down or off the network for any other reason? I don't see why this is good. Joseph Brennan Columbia University in the City of New York Academic Technologies Group [EMAIL PROTECTED] ___

Re: [Mimedefang] rejecting on helo,drive-by-relay,forged_sender,

2004-01-16 Thread Joseph Brennan
s is good. But it is widespread. Joseph Brennan Columbia University in the City of New York Academic Technologies Group [EMAIL PROTECTED] ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL

Re: [Mimedefang] Reject without PTR record

2004-01-16 Thread Joseph Brennan
more likely to be spam than mail from hosts with PTR. Joseph Brennan Columbia University in the City of New York Academic Technologies Group [EMAIL PROTECTED] ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMED

Re: [Mimedefang] rejecting on helo,drive-by-relay,forged_sender,

2004-01-16 Thread Joseph Brennan
at another port, but try and explain to users how to set a port using the email clients now on the market. SFP depends partly on email client design. I find configuring clients now much harder and more obscure than it needs to be. True, if big systems require SFP, things start to happen. Jose

Re: [Mimedefang] Reject without PTR record

2004-01-16 Thread Joseph Brennan
But I have another question (similar to first one): Does it make sense to reject email if domain part of sender's address doesn't have A or MX records? Sendmail temp fails that now. Joseph Brennan Columbia University in the City of New York Academic Technolo

Re: [Mimedefang] New .zip virus?

2004-01-26 Thread Joseph Brennan
arg-Midoom $fname $type"); return action_bounce("Bad attachment"); } This getting about 120 per minute here. Make the md_graphdefang_log data and action_bounce text be the way you like it. Joseph Brennan Columbia University, Academic Technologies Group

Re: [Mimedefang] $helo versus $ip

2004-02-03 Thread Joseph Brennan
und after a day, or a week. On my site, I could tell it was a bad idea within an hour or two :-) Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedef

Re: [Mimedefang] bugtraq discussion on email filtering

2004-02-03 Thread Joseph Brennan
has a faked sender. -- except the one that tells you to remove jdbmgr.exe and forward the warning to your friends. That actually is sent by the person whose address is in the From: header line. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University

Re: [Mimedefang] winmail.dat / ms-tnef extracting

2004-02-10 Thread Joseph Brennan
is usually not a file attachment. It is interesting that Outlook and Exchange still default to LAN behavior and have to be reset to do Internet Mail, as if sending mail to and from non-Exchange users was an exceptional situation. The developers' bosses don't seem to get out much

RE: [Mimedefang] New way of obfuscating text

2004-02-10 Thread Joseph Brennan
#x27;m afraid that might create some false positives... 1em would be pointless for obfuscation purposes, as it would be equivalent to no font-size setting at all. (In CSS, an em is the current line height.) 1pt might be useful to look for, though. I've seen spam with this: That's

Re: [Mimedefang] Idea.. spell checking?

2004-02-11 Thread Joseph Brennan
i.e if there are 100 words in the body, and 75% are misspelled, add it to the score... Misspelled in any language? Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit

[Mimedefang] new obfuscation

2004-02-17 Thread Joseph Brennan
Thread on news.admin.net-abuse.email, "Hashbusting using valid URLs and HTML tags" Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.org and http://ww

Re: [Mimedefang] new obfuscation

2004-02-17 Thread Joseph Brennan
is with nothing to click on between the two, and logging its finds. So far it's got only things that already scored pretty well as spam. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York _

[Mimedefang] Incredible spam obfuscation

2004-02-19 Thread Joseph Brennan
The most obfuscated spam I have ever seen follows. The "unencoded" message is at the end. This was disabled by Mimedefang. We change ' Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York This is a mul

Re: [Mimedefang] Incredible spam obfuscation

2004-02-19 Thread Joseph Brennan
e_header("X-Warning", "$badtag by Columbia filter"); action_rebuild(); } } # ... } Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York _

Re: [Mimedefang] Incredible spam obfuscation

2004-02-20 Thread Joseph Brennan
Would it be helpful to tweak the regex just a bit? if ( /<(iframe|script|object)\b/i ) { I like it. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit h

Re: [Mimedefang] Incredible spam obfuscation

2004-02-23 Thread Joseph Brennan
--On Friday, February 20, 2004 4:48 PM -0500 "Jon R. Kibler" <[EMAIL PROTECTED]> wrote: "Cormack, Ken" wrote: if ($badtag) { if ($io = $entity->open("w")) { $io->print($bla); $io->close; } if ($badtag) { $badtag .= "

RE: [Mimedefang] OT - Cant figure out why this is being rejected

2004-02-23 Thread Joseph Brennan
--On Monday, February 23, 2004 11:03 AM -0500 "Cormack, Ken" <[EMAIL PROTECTED]> wrote: They're already in there. That's why I cant figure this out. They're in access.db too: Both as ... 198.83.130.15 OK and... [198.83.130.15] OK If you want to allow relay,

Re: [Mimedefang] How can I stop these annoying emails?

2004-02-25 Thread Joseph Brennan
eb score CU_IMAGELINK_WEB 1.0 # Links to image from web, and that is the entire message meta CU_IMAGELINK_ONLY CU_IMAGELINK_WEB && HTML_IMAGE_ONLY_02 describe CU_IMAGELINK_ONLY Click on an image on the web, and that's all score CU_IMAGELINK_ONLY 4.0 Joseph Brennan Academ

RE: [Mimedefang] How can I stop these annoying emails?

2004-02-25 Thread Joseph Brennan
icrosoft Office Outlook" in headers of mail sent with auth smtp, so I am sure it is real. I don't know what specific Outlook product it is. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York

Re: [Mimedefang] How to best populate a spamtrap?

2004-02-26 Thread Joseph Brennan
don't read that. In fact you could say "do not send any mail to this address" next to it, for the few humans who read page source. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the C

Re: [Mimedefang] survey: dropping password protected file

2004-03-03 Thread Joseph Brennan
zingly few complaints, from a 50,000-user community. We don't know yet what the long-term plan will be. That stops bagle. To stop most variants of netsky, refuse mail with pif files. We did that many months ago. No complaints at all. Do it. By refuse, I mean action_bounce(). Joseph B

RE: [Mimedefang] survey: dropping password protected file

2004-03-03 Thread Joseph Brennan
--On Wednesday, March 3, 2004 1:11 PM -0600 Michael Sims <[EMAIL PROTECTED]> wrote: Joseph Brennan wrote: We are currently refusing all mail with zip files. Amazingly few complaints, from a 50,000-user community. We don't know yet what the long-term plan will be. That stops ba

Re: [Mimedefang] survey: dropping password protected file

2004-03-04 Thread Joseph Brennan
s exactly what we did. Thus, my unhappiness with not accepting them now. Besides, what will be next? hqx? sit? tar? I don't use Windows; I wonder whether the other archive and compression formats are as easy to open, or whether Microsoft will make them so if zip is deprecated. Joseph Brennan

Re: [Mimedefang] survey: dropping password protected file

2004-03-04 Thread Joseph Brennan
es, forget it. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PR

RE: [Mimedefang] survey: dropping password protected file

2004-03-04 Thread Joseph Brennan
to what you get doing ftp as text. Anyway the binary does not execute even after being renamed. I can't figure out how this exploit would work. Which virus was it? I'd like to see more on this. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia

Re: [Mimedefang] Milter failure processing Read and Delivery Receipts

2004-03-04 Thread Joseph Brennan
I can't think of any reason an MUA should use a null envelope Receipts. It *is* annoying though when they doublebounce to postmaster. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New

Re: [Mimedefang] survey: dropping password protected file

2004-03-05 Thread Joseph Brennan
45, and run setup.exe". Same here. One of my senior colleagues here, Frank da Cruz, told me he opposed MIME at IETF when it was proposed. He told them it was bad to use mail for file transfer. The big wheel is coming around, isn't it? Joseph Brennan Academic Technologies Group, Academic Info

Re: [Mimedefang] javascript in html attachments

2004-03-05 Thread Joseph Brennan
at then did something else. This stuff does not belong in email. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.org and http://www.canit.ca MI

Re: [Mimedefang] add to sa score for clients that only give hostname in helo.

2004-03-08 Thread Joseph Brennan
add our things $hits += $SA_score_additions; $names .= $SA_test_additions; And then take whatever actions you take. OK... the added $names are not in alphabetical order with the others. They could be sorted if I cared. Joseph Brennan Academic Technologies Group, Academic Info

Re: [Mimedefang] OT: Blocking because of MX to 127.0.0.1

2004-03-09 Thread Joseph Brennan
ve received spam from domains that mx to 127.0.0.1 and if I see much more of it, I'd like to do just what that ISP is doing, to get the clutter out of our mail queues. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia Universi

Re: [Mimedefang] OT: Blocking because of MX to 127.0.0.1

2004-03-09 Thread Joseph Brennan
allow from localhost. Some Mimedefang procedures send mail, if you happen to use those, and forwarding with .procmailrc sends a new message from localhost. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New

Re: [Mimedefang] Re: users seeing strange text attachments??

2004-03-16 Thread Joseph Brennan
ating these messages? It doesn't put its name in the headers. It appears to be the problem. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefa

Re: [Mimedefang] Re: users seeing strange text attachments??

2004-03-16 Thread Joseph Brennan
According to RFC 1341: "The use of the multipart Content-Type with only a single body part may be useful in certain contexts, and is explicitly permitted." Well... you learn something new every day! Thanks Joseph Brennan Academic Technologies Group, Academic Information Sys

Re: [Mimedefang] Bagle-Q and Bagle-R

2004-03-18 Thread Joseph Brennan
BJECT and SCRIPT html tags. I posted code to do this recently. You have to open html parts and rewrite them when they have the tags. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York

Re: [Mimedefang] scanning message body

2004-03-19 Thread Joseph Brennan
am input. I didn't peak at Anomy HTML Cleaner yet to see how they do it :-) And if you really want to do a lot of HTML cleaning, well, they do it all-- more than we want to do. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in

Re: [Mimedefang] Notify recipient?

2004-03-25 Thread Joseph Brennan
;s the double-bounce situation. There is no one to send to. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing l

[Mimedefang] MaxMIMEParts

2004-03-30 Thread Joseph Brennan
ively have any idea whether 40 is too low? Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang maili

Re: [Mimedefang] MD and all of its users appear to be in violation of a US Patent

2004-04-02 Thread Joseph Brennan
patent an idea rather than a device, so it might be weak. But imagine the dollars to be spent on lawyers to establish that. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___

Re: [Mimedefang] limiting nested mime multiparts

2004-04-05 Thread Joseph Brennan
100, mail starts tempfailing. We are setting $MaxMIMEParts = 100; at this time, as an indirect way of limiting recursion. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___

RE: [Mimedefang] MaxRecipientsPerMessage

2004-04-14 Thread Joseph Brennan
> > What is a good value to use for MaxRecipientsPerMessage > > (MAX_RCPTS_PER_MESSAGE) for sendmail? 100 We set it to 50 about a year ago to make some other host on campus happy. Put it this way- I have not thought about it since. Joseph Brennan Academic Technologies Gro

Re: [Mimedefang] Update to MIMEDefang Filter KAM

2004-04-16 Thread Joseph Brennan
md_graphdefang_log('modify',"$badtag Iframe/Object/Script tag(s) deactivated by MIMEDefang using Columbia filter"); But please replace "Columbia filter" with whatever your site is! That's there to clarify for us that our mail system did it. Joseph

Re: [Mimedefang] Update to MIMEDefang Filter KAM

2004-04-19 Thread Joseph Brennan
in here. I probably won't get to this today. It is true that this test has run for almost a year here without a problem that has been noticed. b) Steffen, it sounds like you have a simpler way in mind to do the changes and know whether to do the open("w"). What is it? PS to Kevin- W

Re: [Mimedefang] Update to MIMEDefang Filter KAM

2004-04-19 Thread Joseph Brennan
you use internal virus scanners, would it interfere with their signature matching of the email? Is this a feature that could be folded back into the default mimedefang? Joseph Brennan said: md_graphdefang_log('modify',"$badtag Iframe/Object/Script tag(s) deactivated by M

Re: [Mimedefang] Feature request: Tar pitting.

2004-04-20 Thread Joseph Brennan
ybody feel that it is worthwhile enough to write it? Only do it if you can distinguish cases of your users forwarding mail in from their other addresses on other systems. Oh wait, there's no way to do that, is there. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Colum

Re: [Mimedefang] Spammer zombie group behaviour

2004-04-22 Thread Joseph Brennan
political issues with Columbia University, many Chinese sites won't resolve for our IP space, and thus sometimes the spammer's sites are unreachable from here. It doesn't really make me feel any better but it is a small laff. Joseph Brennan Academic Technologies Group, Academic Informa

Re: [Mimedefang] limit message size

2004-04-23 Thread Joseph Brennan
too: define(`confMAX_MESSAGE_SIZE',1000) Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list

RE: [Mimedefang] FW: final fillter setup

2004-05-11 Thread Joseph Brennan
l the owner of the infected PC, but there is no way to determine who it is. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.org and http://w

Re: [Mimedefang] Rebuild Message before running SpamAssassin

2004-05-10 Thread Joseph Brennan
ampaign_id=601"> cid:525l5v2694t7534y94158y600ls09p44"; align=baseline \ border=0> ... more, not quoted This looks like a nice Spamassassin evasion technique. Just wait. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbi

Re: [Mimedefang] Accuracy of infected IP in mdlog

2004-05-14 Thread Joseph Brennan
600 This was in spam, but the kind that is sent through a hacked Windows box. The lower two Received's are fake. And I've seen this before. There's one that pretends the origin is outblaze.com. Have you seen that one? Joseph Brennan Academic Technologies Group, Academic Information S

Re: [Mimedefang] Accuracy of infected IP in mdlog

2004-05-17 Thread Joseph Brennan
fully identify all the spam). Give it a 550 and move on. We cannot waste human or computer time figuring out who to notify. We don't have the resources to consider it. If we did, I don't think it would make any difference. Joseph Brennan Academic Technologies Group, Academic Informatio

Re: [Mimedefang] Accuracy of infected IP in mdlog

2004-05-17 Thread Joseph Brennan
ave proven your machine is clean. A large university in New York does the same thing! Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.org and http

Re: [Mimedefang] Need help with filter_relay

2004-05-19 Thread Joseph Brennan
rom ISP lines to use your smtp server (if you do smtp auth for example). Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.org and http://www.ca

Re: [Mimedefang] Want to modify "read-receipt" img tags in mail

2004-05-20 Thread Joseph Brennan
ade filtering. Possibly, convert img src tags so they have to be clicked on instead of opening inline. It could raise some "what was that in your mail" questions that deserve to be asked. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia U

Re: [Mimedefang] Want to modify "read-receipt" img tags in mail

2004-05-20 Thread Joseph Brennan
rts using HTML::Parser for the html and perl for the text/plain. Any comments on this course of action? or replace with IMAGE and leave the plain text alone. Almost the same thing. I'd like to see this written out with HTML::Parser when you do it. Joseph Brennan Academic Technologies Group,

Re: [Mimedefang] Want to modify "read-receipt" img tags in mail

2004-05-21 Thread Joseph Brennan
arget to click on. Or, put $1$2 there to show what the URL is, but my guess is that would look more ugly. If I get this set up on our test server I think I would see how different things look. HTML::Parser Oh, I was hoping you didn't agree with my reaction! I always like seeing examp

Re: [Mimedefang] MessageID anti-impersonation function for sub filter()

2004-05-26 Thread Joseph Brennan
nd relies on the smtp server to generate it. This includes both PC mail clients and also some PC products that generate mail from databases. A host that acts as smtp server needs to recognize any such permitted use-- perhaps by IP address or by detecting use of smtp auth. Joseph Brennan Academic

RE: [Mimedefang] MessageID anti-impersonation function for sub fi lter()

2004-05-26 Thread Joseph Brennan
MAIL PROTECTED] and it appears to be one of our users sending mail from an ISP. Some clients construct the Message-ID using the default domain name. This is an important example but I have to admit it is the only one I can find in this syslog file, so it appears to be unusual. Joseph Brennan Academ

Re: [Mimedefang] Filter on encoding type

2004-05-28 Thread Joseph Brennan
some harebrained ideas in under an hour by doing that! This does sound like it has possibilities. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.or

Re: [Mimedefang] Filter on encoding type

2004-05-28 Thread Joseph Brennan
.0 (produced by aberrateaccelerate 8.1) MIME-Version: 1.0 (produced by allianceribonucleic 2.2) It's the same spam product that inserts patternbusters with 1-pixel characters, e.g. Hel= lo de+a85r home o)wn!er, Painfully, that's "Hello, dear howeowner"! Joseph Brennan Ac

Re: [Mimedefang] German Hate Spam

2004-06-11 Thread Joseph Brennan
andards. Real qmail Message-IDs have only numbers and dots before the ".qmail@" string. In fact the first eight chars are the date MMDD. Sober puts letters in there. Noticed because we got hit yesterday. Joseph Brennan Academic Technologies Group, Academic Information

[Mimedefang] relay_is_blacklisted timeout

2004-06-17 Thread Joseph Brennan
ble. What happens? Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTE

Re: [Mimedefang] Re: MIMEDefang Digest, Vol 9, Issue 35

2004-06-21 Thread Joseph Brennan
ue. It almost makes putting a code in the Subject look good, doesn't it? Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.org and http://www.ca

Re: [Mimedefang] Internet Virus hits IIS

2004-06-28 Thread Joseph Brennan
t mail containing it? Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED

Re: [Mimedefang] Internet Virus hits IIS

2004-06-29 Thread Joseph Brennan
To effectively block, you'd need to block all links with graphic extensions. Cool!!! Well, I don't think the user community here is ready... yet. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City o

Re: [Mimedefang] Where is best to use $SendmailMacros{"auth_authen"} ?

2004-07-01 Thread Joseph Brennan
e convoluted exceptions we agreed to deal with. But we do subject this mail to some testing, so we don't do an action_accept(). Instead we use $good to skip things with a "unless ($good) { ... }" around those stanzas. And one special case I don't fully trust gets "$goo

Re: [Mimedefang] New spam technique

2004-07-06 Thread Joseph Brennan
useless when we reject the actual spam. Let 'em spin their wheels. Of course I'll change my mind when we identify a solution. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City o

Re: [Mimedefang] Verifying mailbox...

2004-07-07 Thread Joseph Brennan
laying. I think you're seeing an example of the problem right there-- rejecting mail from your own relay host. I don't think it is of any value now except maybe to add a little to a spam scoring system like Spamassassin. Joseph Brennan Academic Technologies Group, Academic Information Systems

RE: [Mimedefang] Bogus HELO filtering

2004-07-07 Thread Joseph Brennan
t least, reject mail that claims to be from your own hostname and IP. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.org and http://www.cani

Re: [Mimedefang] Mail forged from yahoo.com

2004-07-12 Thread Joseph Brennan
that error message is in your Mimedefang filter you can rewrite it to act differently. Mimedefang does what it is told. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___

Re: [Mimedefang] Multiple servers scanning mail

2004-07-14 Thread Joseph Brennan
th a condition on it, like if $RelayAddr is not server1 then action_delete_header. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.org and http://www.c

Re: [Mimedefang] Mail and spam problem

2004-07-22 Thread Joseph Brennan
y standard in virus mail. (The other two Received headers look pretty strange to me with all those nonexistent hostnames-- but maybe they are normal. I cannot explain those.) So what about Mimedefang? Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University i

Re: [Mimedefang] Relaying denied

2004-07-22 Thread Joseph Brennan
July 22 10:30:00 njmailserv vagated [23403]: Relaying denied for rcpt [EMAIL PROTECTED] You are gorave.net not gorav.net, right? Are you sending to the wrong list? This one is about Mimedefang. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University

Re: [Mimedefang] Disabling spam checks on outgoing email

2004-07-27 Thread Joseph Brennan
;re waiting for one that puts its junk in an Outlook Express outgoing queue to be sent with smtp auth later.) You can put any conditions you want around the call to Spamassassin. We skip it: if (defined($SendmailMacros{"auth_type"})) if ($RelayAddr eq "127.0.0.1") and also i

Re: [Mimedefang] [Fwd: Internal mails are blocked-PROBLEM]

2004-07-27 Thread Joseph Brennan
s from us it gotta be good"); } return("CONTINUE",""); } See what it says $mailip is. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York __

Re: [Mimedefang] Forwarded Email Blocking

2004-08-04 Thread Joseph Brennan
it is the address as given in the RCPT command. It is not yet rewritten by sendmail rules or aliases or .forward file. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.m

Re: [Mimedefang] Deadline for SPF records

2004-08-04 Thread Joseph Brennan
That's pretty vague. If it is anything, it sounds like the addition or subtraction of points on a scale like Spamassassin. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York _

Re: [Mimedefang] Deadline for SPF records

2004-08-05 Thread Joseph Brennan
We published SPF a month ago for columbia.edu and found a handful of systems in Europe rejecting mail with it! We changed it to ~all in an attempt to tell those guys it's not required yet. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University i

RE: [Mimedefang] Deadline for SPF records

2004-08-05 Thread Joseph Brennan
--On Thursday, August 5, 2004 11:37 AM -0700 [EMAIL PROTECTED] wrote: Joseph Brennan wrote: We published SPF a month ago for columbia.edu and found a handful of systems in Europe rejecting mail with it! We changed it to ~all in an attempt to tell those guys it's not required yet. So... so

Re: [Mimedefang] Deadline for SPF records

2004-08-05 Thread Joseph Brennan
record? ___ Yes those are different. An SPF record for acme.com would affect only senders @acme.com and not senders @subdomain.acme.com. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New

RE: [Mimedefang] Deadline for SPF records

2004-08-09 Thread Joseph Brennan
OK with you for support.com to send mail as your domain, then you include support.com's IPs in your SPF record and it works. They don't need to be IPs you own and their hostnames do not matter. The sender domain is matched to that domain's SPF record. Joseph Brennan Academic Techno

RE: [Mimedefang] Deadline for SPF records

2004-08-09 Thread Joseph Brennan
gain referrals would make it really cheap to run mailing lists!! The above looks pretty good. So RESPONSIBLE could be an alias or a user's .forward file then, anything that causes authorized re-sending. Bounces would go straight to the FROM, I assume? So, all we do is change all the mail serve

Re: [Mimedefang] javascript in html attachments

2004-08-09 Thread Joseph Brennan
$io->close; } md_graphdefang_log('modify',"$badtag tag deactivated by Columbia fi\ lter"); action_change_header("X-Warning", "$badtag tag modified by Columbia filter"); a

Re: [Mimedefang] Deadline for SPF records *long w/morbid horoscope*

2004-08-10 Thread Joseph Brennan
igured differently it could cause more problems that just letting remote hosts re-try to the regular mail server. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visi

RE: [Mimedefang] Deadline for SPF records

2004-08-11 Thread Joseph Brennan
ages must be sent through their server but we want the 'From:' to be his desktop address. I think the wireless service is supposed to rewrite the envelope sender to its own domain and leave the From: alone. Users should not be expected to configure this. Joseph Brennan Academic Technol

Re: [Mimedefang] Dealing with massive spam burst

2004-09-08 Thread Joseph Brennan
th a message stating what the new address is-- for human senders. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefan

RE: [Mimedefang] JPEG exploit checking in mimedefang-filter

2004-10-12 Thread Joseph Brennan
th the OSX Mail program fail this test, quite a lot, maybe all the time. I'm going to be looking into it. If anyone else is ahead of me on a solution please say so. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in

[Mimedefang] Executable not caught

2004-09-29 Thread Joseph Brennan
uot;); } ...so that we reject all messages with scr files. So, is it my filter or is it Mimedefang generally? I'd appreciate it if someone else would try sending that message through your Mimedefang filter. Beware: that part is a virus, in mail pretending to be from me. Joseph

RE: [Mimedefang] Blocking spam senders using IPTables?

2004-11-03 Thread Joseph Brennan
of messages, never mind the 5xx responses. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAI

RE: [Mimedefang] Frustration...

2004-11-05 Thread Joseph Brennan
they go over 8. Half are travel companies that send mail with free offers and click here and html bugs. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit

Re: [Mimedefang] Need to turn off CC in Defang Notifications

2004-12-01 Thread Joseph Brennan
mail server just by receiving mail. This should be recognized, but probably as in our case it does not get them anything they can't do anyway. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the

Re: [Mimedefang] Lycos Screensaver that attacks Spammers

2004-12-01 Thread Joseph Brennan
Immediately I think of two things: Spam sent to DOS somebody else's web server, a/k/a Joe Jobs. Spam with links to unrelated web servers in an attempt to look legitimate. Some of our medical center web pages have appeared in drug spam. Spamcop then tells us we're spammers. Ugh. Jose

Re: [Mimedefang] Problem with virus bounces

2004-12-20 Thread Joseph Brennan
no clients are broken enough to try to interpret mime inside a part labelled text/plain. If you control what is on the staff desktops you only need to test that software. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York __

Re: [Mimedefang] How can I get just the domain from $sender

2005-02-22 Thread Joseph Brennan
ot as good, since anyone might send mail with your domain in the sender address, including spammers and viruses. Something like this: if ($RelayAddr =~ /66\.8\.25\./) { # add that attachment } Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia Univers

Re: [Mimedefang] Weird issue with Outlook + "Rich Text" + attachments

2005-03-16 Thread Joseph Brennan
d always be *off* for Internet mail. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing

Re: [Mimedefang] Fw: [Asrg] user-level blacklisting patented

2005-03-17 Thread Joseph Brennan
oftware" ... that's an average 250/day per user, which is about ten times what we have per user. Joseph Brennan Academic Technologies Group, Academic Information Systems (AcIS) Columbia University in the City of New York ___ Visit http://www.mimed

Re: [Mimedefang] for mcafee lovers

2005-03-22 Thread Joseph Brennan
mail viruses in the two years or so since we implemented this. Mimedefang made this possible. Our only possible interest is in being able to accept zip files by unpacking and scanning the contents. We might install Clam to do so. I would like to use Mimedefang to insert a warning text on zip fi

Re: [Mimedefang] for mcafee lovers

2005-03-23 Thread Joseph Brennan
--On Tuesday, March 22, 2005 14:29 -0500 "Kevin A. McGrail" <[EMAIL PROTECTED]> wrote: Since defang is a single user, you just need 1 license but 5 is the minimum to purchase. I never tried this one with vendors! They accept this? Joseph Brennan Academic Technologies

  1   2   3   4   >