Re: Another form of obfuscation email.

2018-12-10 Thread Bill Cole
On 10 Dec 2018, at 14:13, RW wrote: On Mon, 10 Dec 2018 12:45:53 -0500 Mark London wrote: Hi - Here's another form of obfuscation spam. This time, not a porn blackmail one. Almost the whole text is obfuscated. https://pastebin.com/VURwmrrF You say obfuscated, but it looked completely

Re: Spamassassin using remote rules definition source?

2018-12-10 Thread David B Funk
On Mon, 10 Dec 2018, ozgurerdogan wrote: I simply need to write custom rules to block certain mails, domain names. Do I have to learn programming language for this? Is not it easy like create a conf file and let Sa update rules from that source remotely via http? If your primary need is to

Re: Spamassassin using remote rules definition source?

2018-12-10 Thread Kevin A. McGrail
On 12/10/2018 2:49 PM, Kris Deugau wrote: > The master/reference files are stored in a Subversion repository. > Commits to particular paths trigger the creation of the tarball, SHA* > hash files, and GPG signature.  A cron job on our DNS master server > polls the repository to see if any of the

Re: Another form of obfuscation email.

2018-12-10 Thread John Hardin
On Mon, 10 Dec 2018, Mark London wrote: Hi - Here's another form of obfuscation spam. This time, not a porn blackmail one. Almost the whole text is obfuscated. https://pastebin.com/VURwmrrF __UNICODE_OBFU_ASC hits that pretty well, but the FP avoidance for the scored version was a bit

Re: Spamassassin using remote rules definition source?

2018-12-10 Thread Kris Deugau
John Hardin wrote: On Mon, 10 Dec 2018, ozgurerdogan wrote: I have many servers using spamassassin. Time to time, I may need to add custom rules to SA to block certain mails. It is time consuming doing it on each server. Is it somehow possible to create a one source for all Spamassassin

Re: Another form of obfuscation email.

2018-12-10 Thread RW
On Mon, 10 Dec 2018 12:45:53 -0500 Mark London wrote: > Hi - Here's another form of obfuscation spam. This time, not a porn > blackmail one. Almost the whole text is obfuscated. > > https://pastebin.com/VURwmrrF > You say obfuscated, but it looked completely unreadable to me.

Re: Spamassassin using remote rules definition source?

2018-12-10 Thread Bill Cole
On 10 Dec 2018, at 13:28, ozgurerdogan wrote: Can you give me some more step by step for : "set up your own local published ruleset source and configure your instances to include that in their rule sources for the standard sa-update processing (will require managing DNS entries and generating

Re: Spamassassin using remote rules definition source?

2018-12-10 Thread ozgurerdogan
Can you give me some more step by step for : "set up your own local published ruleset source and configure your instances to include that in their rule sources for the standard sa-update processing (will require managing DNS entries and generating SHA checksums for the rules file) " This is

Re: Spamassassin using remote rules definition source?

2018-12-10 Thread John Hardin
On Mon, 10 Dec 2018, ozgurerdogan wrote: I have many servers using spamassassin. Time to time, I may need to add custom rules to SA to block certain mails. It is time consuming doing it on each server. Is it somehow possible to create a one source for all Spamassassin using server and update

Re: Subtest __E_LIKE_LETTER and __LOWER_E listed many times in message header

2018-12-10 Thread Bill Cole
On 9 Dec 2018, at 18:23, Chris Pollock wrote: > On Sun, 2018-12-09 at 13:06 -0500, Bill Cole wrote: >> On 9 Dec 2018, at 12:04, Chris Pollock wrote: >> >>> This is probably very trivial and doesn't affect anything except >>> maybe >>> the size of the headers but I have to ask. When looking at the

Another form of obfuscation email.

2018-12-10 Thread Mark London
Hi - Here's another form of obfuscation spam. This time, not a porn blackmail one. Almost the whole text is obfuscated. https://pastebin.com/VURwmrrF I had a high score assigned to the rule HTML_OBFUSCATE_90_100, which is why the message got a high spam rating. By default though, that

Re: Spamassassin using remote rules definition source?

2018-12-10 Thread Alan Hodgson
On Mon, 2018-12-10 at 04:57 -0700, ozgurerdogan wrote: > I simply need to write custom rules to block certain mails, domain names. Do > I have to learn programming language for this? Is not it easy like create a > conf file and let Sa update rules from that source remotely via http? > > cron +

SCAM Bitcoins

2018-12-10 Thread Pedro David Marco
FYI Our "friends" of the SCAM_PORNO_BTC campaign are sending scams with wrong wallets ID, hence the __BITCOIN_ID  rule does not trigger...   Be aware of this if you have METAs depending on that rule. PedroD

Re: Spamassassin using remote rules definition source?

2018-12-10 Thread Martin Gregorie
On Mon, 2018-12-10 at 04:57 -0700, ozgurerdogan wrote: > I simply need to write custom rules to block certain mails, domain > names. Do I have to learn programming language for this? Is not it > easy like create a conf file and let Sa update rules from that source > remotely via http? > Thats all

Re: Spamassassin using remote rules definition source?

2018-12-10 Thread Brent Clark
On 2018/12/10 13:57, ozgurerdogan wrote: I simply need to write custom rules to block certain mails, domain names. Do I have to learn programming language for this? Is not it easy like create a conf file and let Sa update rules from that source remotely via http? Nothing comes to mind,

Re: Spamassassin using remote rules definition source?

2018-12-10 Thread ozgurerdogan
I simply need to write custom rules to block certain mails, domain names. Do I have to learn programming language for this? Is not it easy like create a conf file and let Sa update rules from that source remotely via http? -- Sent from:

Re: Spamassassin using remote rules definition source?

2018-12-10 Thread Brent Clark
On 2018/12/10 13:18, ozgurerdogan wrote: I have many servers using spamassassin. Time to time, I may need to add custom rules to SA to block certain mails. It is time consuming doing it on each server. Is it somehow possible to create a one source for all Spamassassin using server and update

[SA 3.4.1] Are all Perl module dependencies necessary?

2018-12-10 Thread Matteo Dessalvi
Hi all. I am running SA version 3.4.1 on Debian Jessie (from the backport archives). SA run through Amavis and so far I did not have any problem, nor with the classification orthe updates through sa-update. Following the advises on the SA wiki

Spamassassin using remote rules definition source?

2018-12-10 Thread ozgurerdogan
I have many servers using spamassassin. Time to time, I may need to add custom rules to SA to block certain mails. It is time consuming doing it on each server. Is it somehow possible to create a one source for all Spamassassin using server and update rule set from that source? -- Sent from: