Re: SA user users whitelist @ SMTP time

2007-09-28 Thread Paul Griffith
On Fri, 28 Sep 2007 09:49:33 -0400, Bowie Bailey [EMAIL PROTECTED] wrote: Paul Griffith wrote: Greetings SA users, I have a question that many of you have had to deal with. In our setup we use Exim to call SA. Here is the issue, we reject anything over a score 5.0. If a user that is in my

RE: SA user users whitelist @ SMTP time

2007-09-28 Thread Bowie Bailey
Paul Griffith wrote: Greetings SA users, I have a question that many of you have had to deal with. In our setup we use Exim to call SA. Here is the issue, we reject anything over a score 5.0. If a user that is in my whitelist sends a spammy e-mail with a score over 5.0, the mail is

SA user users whitelist @ SMTP time

2007-09-28 Thread Paul Griffith
Greetings SA users, I have a question that many of you have had to deal with. In our setup we use Exim to call SA. Here is the issue, we reject anything over a score 5.0. If a user that is in my whitelist sends a spammy e-mail with a score over 5.0, the mail is rejected. i.e This is

Re: R: New domains (was: URIWhois plugin)

2007-09-28 Thread Kenneth Porter
--On Thursday, September 27, 2007 7:05 PM +0200 Giampaolo Tomassoni [EMAIL PROTECTED] wrote: The only problem is that a spammer could query it days before it will bulk send, thereby impairing the effectiveness of such approach. I think we need some official data like the domain's creation

Spamhaus Rules and Datafeed

2007-09-28 Thread Duane Hill
We now subscribe to the Spamhaus datafeed service. Being the zones are now running locally under the name zen.dnsbl, I have to rewrite some of the rules in SA. Do I just have to rewrite the relevant parts? I.e.: Instead of: header __RCVD_IN_ZENeval:check_rbl('zen',

Re: R: New domains

2007-09-28 Thread Jonas Eckerman
Giampaolo Tomassoni wrote: The only problem is that a spammer could query it days before it will bulk send, thereby impairing the effectiveness of such approach. So we check (with DNS) wether a domain MX record exists before adding it to the database. Something like this: 1: It receives a

Re: Spamhaus Rules and Datafeed

2007-09-28 Thread Duane Hill
On Fri, 28 Sep 2007 at 11:01 -0400, [EMAIL PROTECTED] confabulated: Duane Hill wrote: On Fri, 28 Sep 2007 at 10:37 -0400, [EMAIL PROTECTED] confabulated: On Sep 28, 2007, at 10:14 AM, Duane Hill wrote: We now subscribe to the Spamhaus datafeed service. Being the zones are now running

RE: SA user users whitelist @ SMTP time

2007-09-28 Thread Bowie Bailey
Paul Griffith wrote: On Fri, 28 Sep 2007 09:49:33 -0400, Bowie Bailey [EMAIL PROTECTED] wrote: Paul Griffith wrote: Greetings SA users, I have a question that many of you have had to deal with. In our setup we use Exim to call SA. Here is the issue, we reject anything over a

RE: New PayPal phish?

2007-09-28 Thread Skip
I saw one of these nearly a month ago, but that was it. That it comes addressed to a personal name is a bit disturbing. - Skip

Re: Perl error after upgrade to 3.2.3

2007-09-28 Thread Rank1st
It is definately Sys:Syslog causing the problem. If you look in the actual spamd file, it gives some indication of this. I found that if I specified my log file options in the spamassassin options files that the problem is resolved. Add something like -s /var/log/spam.d to the existing options

Re: Bayes innodb problems

2007-09-28 Thread Micah Anderson
* Alex Woick [EMAIL PROTECTED] [070927 02:14]: Micah Anderson schrieb am 27.09.2007 02:20: processing has ground down to really slow. I'm seeing some incredibly long queries now in my slow-query log, such as: Try an optimize table tabname for each of the sa tables. You just filled the

Re: Spamhaus Rules and Datafeed

2007-09-28 Thread Daryl C. W. O'Shea
Duane Hill wrote: I have made the changes and it is working. I just didn't want the queries going off server in the event either rbldnsd or bind had issues. I have more than one entry in /etc/resolv.conf for this reason. Unless I'm mistaken and the feature made the 3.2.3 release, 3.2.4 (as

RE: New PayPal phish?

2007-09-28 Thread Robert - elists
At 08:10 AM 9/28/2007, Kenneth Porter wrote: Is there a new PayPal phish going about? This almost looks legitimate, and I imagine it would have a lot of appeal to the survey-lovers. (I had no communication with PayPal this week, so I know this is bogus.) some time ago when setup on

Re: looking into spamassassin mail proxy solution

2007-09-28 Thread mouss
tuxbeagle wrote: Thanks, Knowing what to search for helps. The first document I started reading has an installation where spam is filtered to a specific user 'spammy'. I hope that there is a way to just tag the spam in the header and let the user filter locally. visit the postfix and

Re: Bayes innodb problems

2007-09-28 Thread Alex Woick
processing has ground down to really slow. I'm seeing some incredibly long queries now in my slow-query log, such as: Try an optimize table tabname for each of the sa tables. You just filled the database from scratch, so perhaps the counters/statistics do not reflect the actual value

reaching incoming connections queued max, what happens?

2007-09-28 Thread Micah Anderson
I was interested to find out what would happen if spamd was totally overloaded, so I set my --max-children=1 and --max-conn-per-child=1 and then started hitting spamd with spamc and -t timeout values to see what happens. Essentially, each connection (simultaneously generated) took 1 second

Re: Spamhaus Rules and Datafeed

2007-09-28 Thread Vivek Khera
On Sep 28, 2007, at 10:14 AM, Duane Hill wrote: We now subscribe to the Spamhaus datafeed service. Being the zones are now running locally under the name zen.dnsbl, I have to rewrite some of the rules in SA. Do I just have to rewrite the relevant parts? I.e.: Why would you need to do

Re: Bayes innodb problems

2007-09-28 Thread micah
* Michael Parker [EMAIL PROTECTED] [070926 21:14]: micah wrote: On Wed, 26 Sep 2007 17:54:05 -0700, John D. Hardin wrote: On Wed, 26 Sep 2007, Micah Anderson wrote: SELECT count(*) FROM bayes_token WHERE id = '4' AND ('1190846660' -

Re: New PayPal phish?

2007-09-28 Thread Jari Fredriksson
Is there a new PayPal phish going about? This almost looks legitimate, and I imagine it would have a lot of appeal to the survey-lovers. (I had no communication with PayPal this week, so I know this is bogus.) I received those too, and before that, an email from their customer support

RE: New PayPal phish?

2007-09-28 Thread Simon Standley
disgusting as it is, this is almost certainly genuine. ... and to them we trust them with out money ~:( Mup. -Original Message- From: Kenneth Porter [mailto:[EMAIL PROTECTED] Sent: 28 September 2007 16:11 To: users@spamassassin.apache.org Subject: New PayPal phish? Is there a new

Re: New PayPal phish?

2007-09-28 Thread Evan Platt
It IS legitimate. I received one 07/14 referencing a e-mail on 07/12, and yes, on 07/12, Paypal did e-mail me (I had asked about a broken security key). At 08:10 AM 9/28/2007, Kenneth Porter wrote: Is there a new PayPal phish going about? This almost looks legitimate, and I imagine it would

Re: Spamhaus Rules and Datafeed

2007-09-28 Thread Duane Hill
On Fri, 28 Sep 2007 at 10:37 -0400, [EMAIL PROTECTED] confabulated: On Sep 28, 2007, at 10:14 AM, Duane Hill wrote: We now subscribe to the Spamhaus datafeed service. Being the zones are now running locally under the name zen.dnsbl, I have to rewrite some of the rules in SA. Do I just have

Re: New PayPal phish?

2007-09-28 Thread John D. Hardin
On Fri, 28 Sep 2007, Kenneth Porter wrote: Is there a new PayPal phish going about? This almost looks legitimate, and I imagine it would have a lot of appeal to the survey-lovers. (I had no communication with PayPal this week, so I know this is bogus.) I reported it to paypal as such. If

Re: looking into spamassassin mail proxy solution

2007-09-28 Thread Bazooka Joe
open source ipcop firewall has a pluging called copfilter that has a transparent mail proxy that scans all pop and smtp email using sa and clamav On 9/25/07, tuxbeagle [EMAIL PROTECTED] wrote: I am trying to find a mail proxy/spamassassin solution for 2 situations. Situation 1 is Mail

Re: Spamhaus Rules and Datafeed

2007-09-28 Thread Daryl C. W. O'Shea
Duane Hill wrote: On Fri, 28 Sep 2007 at 10:37 -0400, [EMAIL PROTECTED] confabulated: On Sep 28, 2007, at 10:14 AM, Duane Hill wrote: We now subscribe to the Spamhaus datafeed service. Being the zones are now running locally under the name zen.dnsbl, I have to rewrite some of the rules in

Re: R: New domains (was: URIWhois plugin)

2007-09-28 Thread Jeff Chan
Quoting Kenneth Porter [EMAIL PROTECTED]: --On Thursday, September 27, 2007 7:05 PM +0200 Giampaolo Tomassoni [EMAIL PROTECTED] wrote: The only problem is that a spammer could query it days before it will bulk send, thereby impairing the effectiveness of such approach. I think we need

New PayPal phish?

2007-09-28 Thread Kenneth Porter
Is there a new PayPal phish going about? This almost looks legitimate, and I imagine it would have a lot of appeal to the survey-lovers. (I had no communication with PayPal this week, so I know this is bogus.)---BeginMessage--- Dear Kenneth Porter, On 09/26/2007, I sent you an email regarding

Re: Bayes innodb problems

2007-09-28 Thread Jari Fredriksson
Micah Anderson schrieb am 27.09.2007 02:20: processing has ground down to really slow. I'm seeing some incredibly long queries now in my slow-query log, such as: Try an optimize table tabname for each of the sa tables. You just filled the database from scratch, so perhaps the

Re: Bayes innodb problems

2007-09-28 Thread Duane Hill
On Fri, 28 Sep 2007 at 21:57 +0300, [EMAIL PROTECTED] confabulated: Micah Anderson schrieb am 27.09.2007 02:20: processing has ground down to really slow. I'm seeing some incredibly long queries now in my slow-query log, such as: Try an optimize table tabname for each of the sa tables. You

Re: reaching incoming connections queued max, what happens?

2007-09-28 Thread micah
On Fri, 28 Sep 2007 13:01:23 -0400, Micah Anderson wrote: This leads me to wonder what would happen if I hit my SOMAXCONN with incoming messages, would they not be queued up? The SOMAXCONN on my linux box appears to be 128. So to test, I did the following on my spamd server, and then

RE: Botnet 0.8 Plugin is available (FINALLY!!!)

2007-09-28 Thread Jason Bertoch
On Friday, September 28, 2007 4:06 PM hanz wrote: looking at the debug code, I notice that botnet,pm version 0.8 is only checking the last server IP and not all IPs in the path. A botnet sends mail directly from the infected source, rather than relay it via the ISP's mail server. Any

RE: Botnet 0.8 Plugin is available (FINALLY!!!)

2007-09-28 Thread hanz
Thanks for confirming how botnet works. This is exactly the problem! Botnet.pm is only checking the LAST IP and not the FIRST in the example email. The first IP in the list is a definite botnet source but botnet.pm does not detect this as a botnet email. hanz Jason Bertoch [Electronet]

Re: Botnet 0.8 Plugin is available (FINALLY!!!)

2007-09-28 Thread hanz
Botnet 0.8 is up and available. It took me a while (things have been REALLY busy at work for the last 6 months), but it's there. http://people.ucsc.edu/~jrudd/spamassassin/Botnet-0.8.tar ooking at the debug code, I notice that botnet,pm version 0.8 is only checking the last server IP and

RE: Botnet 0.8 Plugin is available (FINALLY!!!)

2007-09-28 Thread James E. Pratt
-Original Message- From: hanz [mailto:[EMAIL PROTECTED] Sent: Friday, September 28, 2007 4:31 PM To: users@spamassassin.apache.org Subject: RE: Botnet 0.8 Plugin is available (FINALLY!!!) Thanks for confirming how botnet works. This is exactly the problem! Botnet.pm is only

Re: Botnet 0.8 Plugin is available (FINALLY!!!)

2007-09-28 Thread René Berber
Hanz wrote: [L]ooking at the debug code, I notice that botnet,pm version 0.8 is only checking the last server IP and not all IPs in the path. Which is correct, if you checked the originating address in the list then all messages sent from home (through your ISP or work) would be marked as

Odd Memory problem: SA NOT using available memory

2007-09-28 Thread JOW
I'm out of my element on this, so please forgive me if I ask something silly. We have two SpamAssassin (v3.002003) servers on Red Hat, each with 4gb RAM. ServerA ROCKS while ServerB SUCKS. So I've been comparing the two systems hoping to find some configuration differences between them. When

Re: Odd Memory problem: SA NOT using available memory

2007-09-28 Thread Matus UHLAR - fantomas
On 28.09.07 14:06, JOW wrote: I'm out of my element on this, so please forgive me if I ask something silly. We have two SpamAssassin (v3.002003) servers on Red Hat, each with 4gb RAM. ServerA ROCKS while ServerB SUCKS. ServerA (the good one) is using nearly all of the 4gb of RAM available

Re: Odd Memory problem: SA NOT using available memory

2007-09-28 Thread John D. Hardin
On Fri, 28 Sep 2007, JOW wrote: ServerA (the good one) is using nearly all of the 4gb of RAM available to it. But ServerB is only using a fraction of available RAM and the # of context switches is tons higher, too. I hope this isn't a silly question, but how significant is this, and where

Re: Odd Memory problem: SA NOT using available memory

2007-09-28 Thread JOW
Thanks for the quick reply. So I shouldn't read anything into the disparity of memory usage between the two boxes? I'm at a loss as to why the one box is consistently in distress, while the other is consistently doing great. I should have mentioned we're using spamd (-m 50) and I've compared

Re: Botnet 0.8 Plugin is available (FINALLY!!!)

2007-09-28 Thread John Rudd
hanz wrote: I believe if botnet.pm is checking all the path the mail went thru like how dnsbl is used, botnet will get more accurate. No, it would throw a lot more false-positives. Every end user (corporate, home, etc.) on a dynamic IP address would suddenly get their email flagged by

Re: Botnet 0.8 Plugin is available (FINALLY!!!)

2007-09-28 Thread Jerry Durand
At 02:31 PM 9/28/2007, John Rudd wrote: Consider this senario: a) user on dynamic IP sends email to their ISP's mail server b) ISP's mail server submits message to your mail server In your suggested processing, this would generate a false positive: the message would be marked as a

Re: Odd Memory problem: SA NOT using available memory

2007-09-28 Thread JOW
From a uname -v, they both appear to be #1 SMP Fri Oct 13 17:56:20 EDT 2006. Here's a uname -a on each: ServerB (B as in bad): Linux expurgate2 2.4.21-47.0.1.ELsmp #1 SMP Fri Oct 13 17:56:20 EDT 2006 i686 i686 i386 GNU/Linux ServerA (A as in awesome): Linux expurgate1 2.4.21-47.0.1.ELsmp #1 SMP

Re: Botnet 0.8 Plugin is available (FINALLY!!!)

2007-09-28 Thread Jari Fredriksson
Thanks for confirming how botnet works. This is exactly the problem! Botnet.pm is only checking the LAST IP and not the FIRST in the example email. The first IP in the list is a definite botnet source but botnet.pm does not detect this as a botnet email. hanz As far as I have

Re: Bayes innodb problems

2007-09-28 Thread Jari Fredriksson
On Fri, 28 Sep 2007 at 21:57 +0300, [EMAIL PROTECTED] confabulated: Optimize table does not work with InnoDB. Are you sure? An excerpt from the MySQL 5.0 documentation found here: May be old information what I told. I tried and no errors from optimize table with InnoDB table.

Re: Bayes innodb problems

2007-09-28 Thread Alex Woick
processing has ground down to really slow. I'm seeing some incredibly long queries now in my slow-query log, such as: Try an optimize table tabname for each of the sa tables. You just filled the database from scratch, so perhaps the counters/statistics do not reflect the actual value