Re: Better phish detection

2012-03-15 Thread sporkman
Ned Slider wrote: > > On 12/03/12 17:02, David B Funk wrote: >> On Mon, 12 Mar 2012, Paul Russell wrote: >> >>> On 3/10/2012 16:43, Ned Slider wrote: This one is easy enough - if the latter is the only valid url that should ever appear in an email, create a meta rule that looks f

Re: Understanding AXB_X_AOL_SEZ_S

2012-03-15 Thread Benny Pedersen
Den 2012-03-15 21:32, Alex skrev: That's basically a poison pill rule... ask aol why thay add it ?

Re: Understanding AXB_X_AOL_SEZ_S

2012-03-15 Thread Benny Pedersen
Den 2012-03-15 20:52, Alex skrev: I've noticed that a number of hams have been tagged with AXB_X_AOL_SEZ_S, creating false positives. Is this looking for a simple pattern in the body that would cause so many fp's for me? AOL SAYS ITS SPAM whitelist_auth dbeltz2...@aol.com in local.cf or user

Re: does bayes_auto_learn expire bayes

2012-03-15 Thread RW
On Thu, 15 Mar 2012 17:38:03 -0500 (CDT) David B Funk wrote: > On Thu, 15 Mar 2012, Chris Hunt wrote: > > > On 3/15/2012 2:53 PM, RW wrote: > >> On Thu, 15 Mar 2012 14:27:53 -0700 > >> Chris Hunt wrote: > >> > >>> I'm trying to eliminate opportunistic bayes expirations and run > >>> them via cron

Re: does bayes_auto_learn expire bayes

2012-03-15 Thread Chris Hunt
On 3/15/2012 3:38 PM, David B Funk wrote: > On Thu, 15 Mar 2012, Chris Hunt wrote: > >> On 3/15/2012 2:53 PM, RW wrote: >>> On Thu, 15 Mar 2012 14:27:53 -0700 >>> Chris Hunt wrote: >>> I'm trying to eliminate opportunistic bayes expirations and run them via cron. >>> bayes_auto_expire 0

Re: Understanding AXB_X_AOL_SEZ_S

2012-03-15 Thread Alex
Hi, >> I've noticed that a number of hams have been tagged with >> AXB_X_AOL_SEZ_S, creating false positives. Is this looking for a >> simple pattern in the body that would cause so many fp's for me? >> >> Here's an example: >> >> http://pastebin.com/raw.php?i=5USWwdQT >> >> What is it in this tha

Re: does bayes_auto_learn expire bayes

2012-03-15 Thread David B Funk
On Thu, 15 Mar 2012, Chris Hunt wrote: On 3/15/2012 2:53 PM, RW wrote: On Thu, 15 Mar 2012 14:27:53 -0700 Chris Hunt wrote: I'm trying to eliminate opportunistic bayes expirations and run them via cron. bayes_auto_expire 0 RW, Thanks for the rapid reply... I have RT*M AFAIK. Sorry, I shou

RE: Help with blocking Chinese Spam

2012-03-15 Thread Jenny Lee
Well, it is not easy to quote properly from hotmail. Excuse my mess up and top posting. Bottom line is... I got rid of this chinese crap. Thank you all for the help SA users. Jenny - > Subject: Re: Help with blocking Chinese Spam > > On Tue, 13 Mar 2012 12:40:16 + > Jenny L

Re: does bayes_auto_learn expire bayes

2012-03-15 Thread Chris Hunt
On 3/15/2012 2:53 PM, RW wrote: > On Thu, 15 Mar 2012 14:27:53 -0700 > Chris Hunt wrote: > >> I'm trying to eliminate opportunistic bayes expirations and run them >> via cron. > bayes_auto_expire 0 RW, Thanks for the rapid reply... I have RT*M AFAIK. Sorry, I should have posted the relevant bits

Re: does bayes_auto_learn expire bayes

2012-03-15 Thread RW
On Thu, 15 Mar 2012 14:27:53 -0700 Chris Hunt wrote: > I'm trying to eliminate opportunistic bayes expirations and run them > via cron. bayes_auto_expire 0

does bayes_auto_learn expire bayes

2012-03-15 Thread Chris Hunt
I'm trying to eliminate opportunistic bayes expirations and run them via cron. I do have bayes_auto_learn enabled, however, and I'm curious if anyone knows if that does or does not use opportunistic expirations. If it just runs sa-learn, with no additional switches, then I'd assume it is doing op

Re: Understanding AXB_X_AOL_SEZ_S

2012-03-15 Thread Axb
On 03/15/2012 08:52 PM, Alex wrote: Hi, I've noticed that a number of hams have been tagged with AXB_X_AOL_SEZ_S, creating false positives. Is this looking for a simple pattern in the body that would cause so many fp's for me? Here's an example: http://pastebin.com/raw.php?i=5USWwdQT What is

Re: Understanding AXB_X_AOL_SEZ_S

2012-03-15 Thread Alex
Hi, >> I've noticed that a number of hams have been tagged with >> AXB_X_AOL_SEZ_S, creating false positives. Is this looking for a >> simple pattern in the body that would cause so many fp's for me? >> > cluestick: > find where your updated rules live. > (locate MIRRORED.BY) > > grep AXB_X_AOL_SE

Re: Understanding AXB_X_AOL_SEZ_S

2012-03-15 Thread Michael Scheidell
On 3/15/12 3:52 PM, Alex wrote: Hi, I've noticed that a number of hams have been tagged with AXB_X_AOL_SEZ_S, creating false positives. Is this looking for a simple pattern in the body that would cause so many fp's for me? cluestick: find where your updated rules live. (locate MIRRORED.BY) gr

Understanding AXB_X_AOL_SEZ_S

2012-03-15 Thread Alex
Hi, I've noticed that a number of hams have been tagged with AXB_X_AOL_SEZ_S, creating false positives. Is this looking for a simple pattern in the body that would cause so many fp's for me? Here's an example: http://pastebin.com/raw.php?i=5USWwdQT What is it in this that is hitting? Here's a l

Re: Updated: 90_axb_fraud.cf

2012-03-15 Thread Axb
On 03/15/2012 04:08 PM, Benny Pedersen wrote: Den 2012-03-15 15:33, Axb skrev: what description do you want for a bunch of rules and 3 metas? i like to commit my own sought rules generation, or atleast learn howto as there is no sa-update channel for this and I will never make one you are w

Re: WAS Re: Updated: 90_axb_fraud.cf / read: 90_axb_phish.cf

2012-03-15 Thread Benny Pedersen
Den 2012-03-15 15:38, Axb skrev: pristine phish samples. If you can help, pls contact me offlist. if github is problematic :-)

Re: Updated: 90_axb_fraud.cf

2012-03-15 Thread Benny Pedersen
Den 2012-03-15 15:33, Axb skrev: what description do you want for a bunch of rules and 3 metas? i like to commit my own sought rules generation, or atleast learn howto as there is no sa-update channel for this and I will never make one you are welcome to run it for the community ;-) why n

WAS Re: Updated: 90_axb_fraud.cf / read: 90_axb_phish.cf

2012-03-15 Thread Axb
On 03/15/2012 03:31 PM, Michael Scheidell wrote: On 3/15/12 7:34 AM, Axb wrote: I've run a small update of 90_axb_fraud.cf https://sourceforge.net/projects/sare/ As nobody except John Hardin has shown up to contribute data, this is the last update I'll release as it requires massive fresh data

Re: Updated: 90_axb_fraud.cf

2012-03-15 Thread Michael Scheidell
On 3/15/12 10:28 AM, Benny Pedersen wrote: sa-update how ? click download. copy it to your spamassassin (local) rules dir bsd: /usr/local/etc/mail/spamassassin others (might be) /etc/mail/spamassassin. its where your local.cf lives if you use sa-compile, compile now. if you use spamd, restart

Re: Updated: 90_axb_fraud.cf

2012-03-15 Thread Axb
On 03/15/2012 03:28 PM, Benny Pedersen wrote: Den 2012-03-15 12:34, Axb skrev: I've run a small update of 90_axb_fraud.cf thanks, where is rule generating described ? what description do you want for a bunch of rules and 3 metas? https://sourceforge.net/projects/sare/ sa-update how ?

Re: Updated: 90_axb_fraud.cf

2012-03-15 Thread Michael Scheidell
On 3/15/12 7:34 AM, Axb wrote: I've run a small update of 90_axb_fraud.cf https://sourceforge.net/projects/sare/ As nobody except John Hardin has shown up to contribute data, this is the last update I'll release as it requires massive fresh data to make the work worthwhile. I didn't know a

Re: Updated: 90_axb_fraud.cf

2012-03-15 Thread Benny Pedersen
Den 2012-03-15 12:34, Axb skrev: I've run a small update of 90_axb_fraud.cf thanks, where is rule generating described ? https://sourceforge.net/projects/sare/ sa-update how ? As nobody except John Hardin has shown up to contribute data, this is the last update I'll release as it requires

Updated: 90_axb_fraud.cf

2012-03-15 Thread Axb
I've run a small update of 90_axb_fraud.cf https://sourceforge.net/projects/sare/ As nobody except John Hardin has shown up to contribute data, this is the last update I'll release as it requires massive fresh data to make the work worthwhile. enjoy... -- Do not use SARE rules - use sa-upda