I have to
enable only the plugin with loadPlugin.
... and it's enabled by default, so you should be all set. :)
Then I have to use the command 'urirhssub' of the plugin
URIDNSBL to
specify that I want to use SURBLs:
... the rules exist by default, so you should be all set. :)
I am still getting some Storm Worm messages that are not being caught,
even with Sane Security / ClamAV. I thought I'd write a rule to score
any URL that has a dot exe, scr or pif extension. However, my rule is
not working. Can someone help advise what is wrong? I want it to
pickup any
I am still getting some Storm Worm messages that are not being caught,
even with Sane Security / ClamAV. I thought I'd write a rule to score
any URL that has a dot exe, scr or pif extension. However, my rule is
not working. Can someone help advise what is wrong? I want it to
pickup any
* Michael Scheidell [EMAIL PROTECTED] [080223 13:46]:
I feel like a lot of pretty obvious spams are getting through my system
with appallingly low scores. I'm starting to wonder if something may be
wrong with my setup. Looking at what spam tests did fire, I'm frequently
surprised that more
Untested, but try
uri EXECUTABLE_WEBSITE/\.(?:exe|scr|pif)$/i
Loren
- Original Message -
From: Dave Koontz [EMAIL PROTECTED]
To: users@spamassassin.apache.org
Sent: Saturday, February 23, 2008 6:52 AM
Subject: Please help with rule
I am still getting some Storm Worm
On Sat, February 23, 2008 15:52, Dave Koontz wrote:
I am still getting some Storm Worm messages that are not being caught,
even with Sane Security / ClamAV. I thought I'd write a rule to score
any URL that has a dot exe, scr or pif extension. However, my rule is
not working. Can someone
Kathryn Allan wrote:
How do you set a rule to expire?
I think you could use this construct:
if (conditional perl expression)
rules ...
endif
And do a check on the date in the expression.
/Per Jessen, Zürich
Michael Scheidell [EMAIL PROTECTED] writes:
http://www.spamhaus.org/organization/dnsblusage.html
says:
1. Your use of the Spamhaus DNSBLs is non-commercial*, /and/
2. Your email traffic is less than 80,000 SMTP connections per day, /and/
3. Your DNSBL query volume is less than
Kathryn Allan wrote:
Bob Proulx wrote:
I just did the brute force thing and looked for an entire phrase from
that message. It really isn't worthy and this will change very
quickly such that any rule I post now won't be interesting to have in
a ruleset in a couple of days. It needs to
Hi,
I have setup the mysql userprefs and it is working with one exception,
From: addresses listed as being whitelisted in mysql are not triggering
the SA whitelist scores. Other values like required_hits are being
properly returned, so SA is able to connect and query mysql. I do not
have
Regarding this spam: http://pastebin.ca/916902 , it seems we've been
listwashing pretty thoroughly, I have no copies of it yet.
If you have a spamtrap address that gets 100% spam (no ham), is receiving
copies of this spam, isn't too high-volume, and would be willing to
forward copies to our
Apologies if this hasn't been done in the right way, but I have gone to
the website and couldn't find out how to do it - how do you change the
email address that these get sent to please ? I will be changing email
addresses and want to ensure I don't miss any posts.
Any help appreciated.
Chris.
Hi list.
I'm new to the list and let me tell you that i haven't got deep knowledges
about SA, so i need your help
with this issue and most of all, pacience :).
I'm using postfix with SpamAssassin version 3.0.6, running on Perl version
5.8.5.
I noticed a time ago that the message queue of postfix
Chris wrote:
Apologies if this hasn't been done in the right way, but I have gone
to the website and couldn't find out how to do it - how do you change
the
email address that these get sent to please ? I will be changing
email addresses and want to ensure I don't miss any posts.
You
-Original Message-
From: Per Jessen [mailto:[EMAIL PROTECTED]
Sent: Monday, February 25, 2008 2:13 PM
To: users@spamassassin.apache.org
Subject: Re: Changing email address for these
Chris wrote:
Apologies if this hasn't been done in the right way, but I have gone
to the website and
Quoting Rocco Scappatura [EMAIL PROTECTED]:
I have to
enable only the plugin with loadPlugin.
... and it's enabled by default, so you should be all set. :)
Then I have to use the command 'urirhssub' of the plugin
URIDNSBL to
specify that I want to use SURBLs:
... the rules exist by
--On Saturday, February 23, 2008 23:08 -0500 Dave Koontz [EMAIL PROTECTED]
wrote:
I am still getting some Storm Worm messages that are not being caught,
even with Sane Security / ClamAV. I thought I'd write a rule to score
any URL that has a dot exe, scr or pif extension. However, my rule
Unsubscribe
http://www.spamhaus.org/organization/dnsblusage.html
says:
1. Your use of the Spamhaus DNSBLs is non-commercial*, /and/
2. Your email traffic is less than 80,000 SMTP connections per day,
/and/
3. Your DNSBL query volume is less than 320,000 queries per day.
Michael
Based on googles standard 'we don't have any clients who would email
from google' ignore bot, then what? if google doesn't have any direct
clients, then does this indicate they are running an open relay? (email
purports to come from Argentina (and
201.231.43.135 does.)
, RDNS for first
Aaron Wolfe wrote:
I have 24 hours of data to play with.. at first results seemed
promising. I found over 300,000 hosts that had connected only to my
highest MX and did not issue a quit. But.. of that group:
96.0% are listed on spamhaus (zen, i did not breakdown onto the
individual lists)
Rob McEwen wrote:
Aaron Wolfe wrote:
I have 24 hours of data to play with.. at first results seemed
promising. I found over 300,000 hosts that had connected only to my
highest MX and did not issue a quit. But.. of that group:
96.0% are listed on spamhaus (zen, i did not breakdown onto the
Sorry for the Off Topic thread but I'm at a loss.
Is anyone else having issues sending mail to Yahoo?
They are returning 421 Message temporarily deferred to every message my servers
try to send. My server then retries like it should but yahoo never accepts the
message, even after day of
Tony Bunce wrote:
Sorry for the Off Topic thread but I’m at a loss.
Is anyone else having issues sending mail to Yahoo?
They are returning 421 Message temporarily deferred to every message my
servers try to send. My server then retries like it should but yahoo
never accepts the
On Mon, February 25, 2008 16:18, Chris wrote:
Unsubscribe
list-unsubscribe: mailto:[EMAIL PROTECTED]
in squirrelmail i just press a bottom :-)
Tony Bunce wrote:
Sorry for the Off Topic thread but I’m at a loss
Is anyone else having issues sending mail to Yahoo?
They are returning 421 Message temporarily deferred to every message
my servers try to send. My server then retries like it should but
yahoo never accepts the message, even
Rick Macdougall schrieb:
Tony Bunce wrote:
Sorry for the Off Topic thread but I’m at a loss.
Is anyone else having issues sending mail to Yahoo?
They are returning 421 Message temporarily deferred to every message
my servers try to send. My server then retries like it should but
Ditto, please share any resolve should you get one. This has been an
ongoing problem for us for well over a year now.
Ramprasad wrote:
Tony Bunce wrote:
Sorry for the Off Topic thread but I’m at a loss
Is anyone else having issues sending mail to Yahoo?
They are returning 421 Message
At 08:54 25-02-2008, Tony Bunce wrote:
Is anyone else having issues sending mail to Yahoo?
No.
They are returning 421 Message temporarily deferred to every message
my servers try to send. My server then retries like it should but
yahoo never accepts the message, even after day of
Thanks all for the info, the uri check is much better.
Joseph you were absolutely correct about it catching too wide. I modified
it to pattern check the end only and it now works a treat!
uri DANGEROUS_URL/\.(exe|scr|pif|cmd|bat|vbs|wsh)$/i
describe DANGEROUS_URLURL
SM wrote:
At 08:54 25-02-2008, Tony Bunce wrote:
Is anyone else having issues sending mail to Yahoo?
No.
They are returning 421 Message temporarily deferred to every message
my servers try to send. My server then retries like it should but
yahoo never accepts the message, even after day
They do have a feedback loop now:
http://help.yahoo.com/l/us/yahoo/mail/postmaster/cfl-form.html?from_url=http://help.yahoo.com/l/us/yahoo/mail/postmaster/
But it takes several days to receive a reply from that form, which is just a
standard reply that tells you to fill out a form and mail it in
Tony Bunce wrote:
Is anyone else having issues sending mail to Yahoo?
They are returning 421 Message temporarily deferred to every message my
servers try to send. My server then retries like it should but yahoo
never accepts the message, even after day of retrying.
Where I work, we had
-Original Message-
From: Dave Koontz [mailto:[EMAIL PROTECTED]
Sent: Sunday, 24 February 2008 5:09 p.m.
To: users@spamassassin.apache.org
Subject: Please help with rule
I am still getting some Storm Worm messages that are not being caught,
even with Sane Security / ClamAV. I
--- original message ---
From: Tony Bunce [mailto:[EMAIL PROTECTED]
Sent: Tuesday, 26 February 2008 5:54 a.m.
To: users@spamassassin.apache.org
Subject: [OT] Yahoo Deferred
Sorry for the Off Topic thread but I'm at a loss.
Is anyone else having issues
On 24/02/2008 10:06 AM, giga328 wrote:
Client in example is Outlook Express at 89.110.202.24 also in trusted
networks.
Relevant configuration lines are:
trusted_networks 212.62.32.0/19
trusted_networks 89.110.192.0/18
Not that this is the cause of your problem, but I'm wondering why
Michael Hutchinson wrote:
--- original message ---
From: Tony Bunce [mailto:[EMAIL PROTECTED]
Sent: Tuesday, 26 February 2008 5:54 a.m.
To: users@spamassassin.apache.org
Subject: [OT] Yahoo Deferred
Sorry for the Off Topic thread but I'm at a loss.
Quoting Rocco Scappatura [EMAIL PROTECTED]:
I have to
enable only the plugin with loadPlugin.
... and it's enabled by default, so you should be all set. :)
Then I have to use the command 'urirhssub' of the plugin
URIDNSBL to
specify that I want to use SURBLs:
... the rules exist
I have tried different approaches, and let us not forget I have
filled
out 3 whitelist forms, and received no response from Yahoo. Their
service
is breaking RFC's by not delivering mail. They are ignorant towards
other
companies trying to use their service.
But they do deliver the mail.
Hi,
I'm get alot of these February 77% OFF or variations (ie January 73%
OFF and my guess March 75% OFF next month) thereof in the subject
line for spam. The body always changes so I can't really key on this.
I would like to make rule that subject line filter this type of spam.
Thank you in
Is anyone else having issues sending mail to Yahoo?
Yes. I have heard using Domainkeys or DKIM helps greatly? Is that
true? We have not implemented it yet but do use SPF records which are
much easier to implement with Exim or any MTA and do mostly the same
thing if you ask me.
Matt
I'm get alot of these February 77% OFF or variations (ie January 73% OFF
and my guess March 75% OFF next month) thereof in the subject line for
spam. The body always changes so I can't really key on this. I would like
to make rule that subject line filter this type of spam.
I have never seen
fchan wrote:
I'm get alot of these February 77% OFF or variations (ie January 73%
OFF and my guess March 75% OFF next month) thereof in the subject
line for spam.
Is that from Kohls? I have been annoyed with their spam quite a bit
lately. But I wouldn't block based upon the subject because
Duane Hill wrote:
On Fri, 22 Feb 2008 17:02:11 -0800
Bob Amen [EMAIL PROTECTED] wrote:
Michael Scheidell wrote:
Works fine for me. Are you sure you weren't blocked?
In fact, I found several sites (different networks, not mine) where
it doesn't work.
(I don't query more
79.137.219.171
79.137.223.42
79.137.225.194
79.137.231.242
79.137.233.223
79.137.235.210
79.137.235.252
79.137.237.210
Slightly off subject,
This list of class Cs appears to be a HUGE block 79.137.170ish.0/24 -
79.137.240.0ish a russian spam gang. They appear to right now be using
On Monday 25 February 2008 9:34 am, Michael Scheidell wrote:
Based on googles standard 'we don't have any clients who would email
from google' ignore bot, then what? if google doesn't have any direct
clients, then does this indicate they are running an open relay? (email
purports to come from
I have heard using Domainkeys or DKIM helps greatly? Is that
true?
So far DomainKeys has not helped from what I can tell.
Yahoo is deferring the message as soon as my server connects, so it never even
gets a chance to see the DomainKeys header.
-Tony B
Do you get through to Yahoo Groups?
Does the reverse address work correctly?
For grins I'd look at how Earthlink.net handles their smtp sending and
addressing. There might be a useful hint there. They do get through. So
does DSLExtreme.com.
{^_^}
- Original Message -
From: Tony Bunce
We have been experiencing this problem for about a year now. It normally
lasts for about a month and then clears with no explanation and no
corrective action taken on our part. I thought that maybe yahoo were
experiencing load issues and targeted certain TLDs (in our case .co.za) to
alleviate
Federico Raúl López Sarmiento wrote:
Hi list.
I'm new to the list and let me tell you that i haven't got deep
knowledges about SA, so i need your help
with this issue and most of all, pacience :).
I'm using postfix with SpamAssassin version 3.0.6, running on Perl
version 5.8.5.
I noticed a
Unsubscribe
Hi,
I had the same problem before and needed to contact yahoo.com
postmaster and they resolved it within one day. Here is the yahoo.com
postmaster URL:
http://help.yahoo.com/l/us/yahoo/mail/postmaster/
Click on Contact Customer Care and select Delivery Issues.
I hope this helps.
Frank
Sorry
Hi,
I don't mind taking RAM since I have 3GB. I can raise the amount of
child processes and I wanted to find out how much RAM does each child
takes so I can decide how many max children to raise it without
killing my system. Also I would like to check where to raise the
max-child and I was
53 matches
Mail list logo