Re: Spam getting scored but not tagged -- redux

2008-06-16 Thread Chris St. Pierre
using pyzor -> no suckage. I'm not sure it's directly caused by pyzor, either, but I think it's pretty clearly related in some way. I'd be interested to hear how a problem like this could be related to _any_ MTA; Postfix doesn't know or care what pyzor does. Chris

Re: Spam getting scored but not tagged -- redux

2008-06-13 Thread Chris St. Pierre
Pyzor, and would like to be able to run it. Thoughts? Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University On Fri, 13 Jun 2008, Chris St. Pierre wrote: On Fri, 13 Jun 2008, Matus UHLAR - fantomas wrote: How do you use spamassassin, from procmail/maildrop? milter? I ca

Re: Spam getting scored but not tagged -- redux

2008-06-13 Thread Chris St. Pierre
} Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: Spam getting scored but not tagged -- redux

2008-06-13 Thread Chris St. Pierre
For what it's worth, this appears to be happening on _every_ message that comes through. In other words, no spam at all is getting tagged, and we're running on RBLs, etc., alone. So I'd appreciate any and all suggestions. :) Thanks. Chris St. Pierre Unix Systems Adminis

Spam getting scored but not tagged -- redux

2008-06-12 Thread Chris St. Pierre
299]: spamd: setuid to spamd succeeded Jun 12 08:04:08 vostok spamd[1299]: spamd: processing message <[EMAIL PROTECTED]> for spamd:402 Any other ideas? Thanks! Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: What are some of the most frequently used strings?...

2008-05-28 Thread Chris St. Pierre
do naive word matching (and why you shouldn't, either). Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: Spoofed Email But Different User Name

2008-05-07 Thread Chris St. Pierre
sults from that. Thanks for any help. Bad idea. My name can be easily and legitimately displayed in dozens of different ways, without even considering typos: Chris St. Pierre Chris St Pierre Chris St-Pierre Chris Saint Pierre Chris Saint-Pierre Christopher St. Pierre ... Christopher A. St. P

Re: Bayes DB growing without bound; expiry not working

2008-04-21 Thread Chris St. Pierre
on as each user individually? Manual expiration was recommended to me a long time ago as a way to increase database performance, but it seems like it may not be worth it if I have to run N forced expirations, for potentially large values of N. Thanks for your help. Chris St. Pierre Un

Bayes DB growing without bound; expiry not working

2008-04-21 Thread Chris St. Pierre
completely dumping the database?) Thanks! Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

RE: Spamcontrol Question !!

2007-11-05 Thread Chris St. Pierre
for help. You might try, I dunno, a SpamControl list. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: Purpose for SpamAssassin using MySQL

2007-09-26 Thread Chris St. Pierre
than one MX. Using a MySQL backend for Bayes and AWL lets me share that data between our MXes. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: Some thoughts on Baysian Setup...

2007-08-27 Thread Chris St. Pierre
y needs a 1-2Mb file per user. I think users would be just as adept at poisoning such a split database as they would be at poisoning a unified, site-wide database. In any reasonably diverse user base, what my fellow user thinks is spam should not affect what I get in my mailbox. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: why not doing a test that checks "name"- pairs

2007-08-17 Thread Chris St. Pierre
sting to have a test that checks the "user name-email address" pairs according to some settings? That's an interesting idea, but it a) is probably going to be quite resource-intensive; b) requires LDAP, NIS, etc., so that SpamAssassin can have a clue about your accounts; c) req

Spam getting scored but not tagged

2007-08-16 Thread Chris St. Pierre
eader spam Flag _YESNOCAPS_ add_header all Level _STARS(*)_ add_header all Status _YESNO_, bayes=_BAYES_ score=_SCORE_ required=_REQD_ tests=_TESTSSCORES(,)_ autolearn=_AUTOLERRN_ version=_VERSION_ rewrite_header Subject [SPAM:_STARS(*)_] What's going on here that prevents the tagging from happening?

Re: Scanning outgoing e-mails

2007-06-05 Thread Chris St. Pierre
t anything: score ALL_TRUSTED 0 Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University LOPSA Sysadmin Days: Professional Training for Professional SysAdmins August 6-7, Cherry Hill, NJ http://lopsa.org/SysadminDays

Re: Using sa-learn on an anti-spam gateway

2007-05-31 Thread Chris St. Pierre
lly no reason to be concerned about the difference in the amount of spam and ham getting reported. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University LOPSA Sysadmin Days: Professional Training for Professional SysAdmins August 6-7, Cherry Hill, NJ http://lopsa.org/SysadminDays

Re: Auto Reporting of Spam to Freemail Vendors

2007-04-30 Thread Chris St. Pierre
ubmissions -- that's what gave them such low rates of FPs. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

Re: IP -> Responsible Person

2007-04-25 Thread Chris St. Pierre
mmers do best? I'll give you a minute to think about it. ... If you said, "Send a lot of email really quickly," you were right! Why on earth would you willingly make the ability to DOS a site dependent on volume, the one thing that spammers are the best at? Chris St. Pierre

Re: spam graphs

2007-04-04 Thread Chris St. Pierre
hard numbers in your presentation on why you need N more servers and X more sysadmins. Good luck! Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

Re: Newbie, Has Questions

2007-03-30 Thread Chris St. Pierre
I can't tell from a quick browse through the Scalix wiki what delivery agent it uses, but I'd look into that and see if you can use procmail or Sieve with it. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

Re: Stop the CCing please. (was "Who is APEWS.ORG" & "Sender Address Verification is NOT abouse and very effective")

2007-03-30 Thread Chris St. Pierre
SPAM-L or some other forum where it's relevant. I can't help but note that you have only yourself to blame: From: Jonas Eckerman <[EMAIL PROTECTED]> Reply-To: [EMAIL PROTECTED] Fix your Reply-To header and you won't get any more list messages in your private email. Chris S

Re: Who is APEWS.ORG

2007-03-29 Thread Chris St. Pierre
fake message and checking for recipient errors. Still, a lot of people don't reject mail for bum users, choosing instead to accept the mail and bounce it -- again, for precisely this reason. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: sa-update too quiet

2007-03-29 Thread Chris St. Pierre
On Fri, 30 Mar 2007, Henrik Krohns wrote: On Thu, Mar 29, 2007 at 03:50:52PM -0500, Chris St. Pierre wrote: On Thu, 29 Mar 2007, Craig M wrote: Could future versions of sa-update please be a little more vocal? Like maybe "no new updates found | loaded xxx new updates | error xxx&q

Re: sa-update too quiet

2007-03-29 Thread Chris St. Pierre
everywhere. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

Re: Foreign Languages

2007-03-27 Thread Chris St. Pierre
ge, then you'll need to translate the rules, as it were. SA does not have a language abstraction layer. Spam detection is based heavily on content. Content is mired in language. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: spamhaus / whitelist

2007-03-27 Thread Chris St. Pierre
xcuse to use whitelist_from. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: R: New method of spamming

2007-03-26 Thread Chris St. Pierre
he URIBL_* family of rules aren't among your top 5 most effective, something is seriously wrong with your SA installation. FWIW, the OP's message scored 31.3 on my system, as it hit Razor2 and two URIBL rules (the scores for which I crank up). Chris St. Pierre Unix Systems Administrato

Re: Need help with a rule

2007-03-22 Thread Chris St. Pierre
Sure. header __LOCAL_SENDER From =~ /@example\.com/i meta FORGED_LOCAL_SENDER __LOCAL_SENDER && !TRUSTED_NETWORKS score FORGED_LOCAL_SENDER 1 This depends on a proper setting of TRUSTED_NETWORKS. (Note: untested code, YMMV, etc.) Chris St. Pierre Unix Systems Administrator

Re: Reporting spam by forwarded/attached message

2007-03-21 Thread Chris St. Pierre
bounce/redirect the message (which doesn't munge sender data) or forward as an attachment (ditto, but harder to extract). Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

Re: why I get it?

2007-03-19 Thread Chris St. Pierre
should use the _TESTSSCORES(,)_ macro in your add_header line to figure that out. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

RE: Make Bayes more efficient?

2007-03-17 Thread Chris St. Pierre
am you missed: http://sas.nebrwesleyan.edu/forum/index.php?action=vthread&forum=6&topic=3 Heh. That's the page of one of our student organizations, so I happily have nothing to do with it Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

RE: Make Bayes more efficient?

2007-03-17 Thread Chris St. Pierre
yes DB? Feed it from the primary? (you don't want a secondary MX to have a different bayes from the primary since it will have a VERY jaded view of the world. Spammers go for the secondary first) We don't have a secondary MX. Our MySQL database is shared between two MX nodes of equal pr

Re: Make Bayes more efficient?

2007-03-17 Thread Chris St. Pierre
directive -- I believe innodb_flush_method=O_DSYNC -- can cause data loss if your machine crashes, but I don't really care because this is just Bayes data. HTH. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

Re: Can't Locate Tie/Handle.pm

2007-03-16 Thread Chris St. Pierre
can find a Handle.pm file, then you're probably looking at a borked @INC path. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

Re: Bit OT - SA not running on same time as rest of system

2007-03-16 Thread Chris St. Pierre
your machines -- that ensures that all of your processes (including SA) get restarted and get the new tz data. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

Re: AW: how to archive/save mails that are scanned by spamd ???

2007-03-15 Thread Chris St. Pierre
ad of just dumping the stripped, decoded text to stdout, though, he'd want to write the whole message (which would probably have to be reassembled from its constituent parts) to wherever he wanted it. No idea what the I/O requirements of such a plugin would be, but I'd bet it ain'

Re: Make Bayes more efficient?

2007-03-09 Thread Chris St. Pierre
#x27;ll have to wait and see how much things have improved. If they haven't improved much, I'll be back on Monday. :) Thanks again! Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

Re: R: Make Bayes more efficient?

2007-03-09 Thread Chris St. Pierre
he flux by adopting some greylisting technique. Actually, I meant that, of the 40K messages I receive, about 30K are discarded by greylisting, RBLs, HELO restrictions, etc. I can't imagine trying to scan all the mail I get. :) Chris St. Pierre Unix Systems Administrator Nebraska Wesl

Make Bayes more efficient?

2007-03-08 Thread Chris St. Pierre
0K messages per day, <10K of which ever make it to SpamAssassin. Ideas? Thanks! Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University ------------ Never send mail to [EMAIL PROTECTED] Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: HAM and SPAM mailboxes

2007-03-05 Thread Chris St. Pierre
} If you're not using Maildir, you'll have to figure out what to do from there. I know Mail::Box supports MH, Mbox, and who knows what else, but haven't used those myself. http://search.cpan.org/~markov/Mail-Box-2.069/lib/Mail/Box-Overview.pod should ge

Re: Qustions about sa-learn

2007-03-03 Thread Chris St. Pierre
nt to do per-user learning, you'll have to grab the ReSent-From: header out of each message, but that's pretty trivial. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

Re: Qustions about sa-learn

2007-03-03 Thread Chris St. Pierre
your question right above it? Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

Re: SA learning from arrived SPAMs

2007-03-02 Thread Chris St. Pierre
t_ do. Alternatively, you can forward them on as attachments and then strip the attachments and learn those, but I think this makes it much more complicated than necessary. If so, how ? man sa-learn Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan Unive

Re: HAM and SPAM mailboxes

2007-03-02 Thread Chris St. Pierre
which is a lot less trivial. In that case, Perl's Mail::Box::Manager is your friend. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

Re: Bounce spam into spamtrap

2007-02-21 Thread Chris St. Pierre
On Wed, 21 Feb 2007, Dean Clapper wrote: Do the emails that I put in the spamtrap have to be in original form? Or, can I "Bounce" them from my mail client to [EMAIL PROTECTED] Bouncing preserves the original form of the message. What you don't want to do is forward the mess

Re: Google Summer of Code 2007 ...

2007-02-17 Thread Chris St. Pierre
measure of the success of a spam filtering plan is user satisfaction. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University -- Never send mail to [EMAIL PROTECTED]

Re: Google Summer of Code 2007 ...

2007-02-16 Thread Chris St. Pierre
ice plugin to have. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

Re: sa-stats and Spamtagging

2007-02-13 Thread Chris St. Pierre
agged with BAYES_99 but are not marked as spam. If Bayes is right about them, turn up your scoring; if not, continue training. This is where a user feedback look -- such as spam/ham reporting links in your webmail client, or the equivalent training for desktop client users -- can be really useful.

Re: about traing bayes method.

2007-02-01 Thread Chris St. Pierre
ike you're delivering to Mbox-style mail boxes, so you'll want to do: $ sa-learn --mbox --ham /var/spool/mail/ham Hope that helps! Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

Re: Should I use greylisting

2007-01-26 Thread Chris St. Pierre
spamhaus, etc.). You could also take care of this by greylisting on the /24 netblock instead of the /32 address. Most greylisters support this these days, and it eliminates retry problems with large mx pools. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: Should I use greylisting

2007-01-25 Thread Chris St. Pierre
only Sendmail greylister I know of that uses MySQL Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

Re: [SPAM:**] Bad spelling spams

2007-01-22 Thread Chris St. Pierre
It looks like 7.0 is enough to get them tagged as spam. If you want to get them higher (e.g., so that Amavis or something will discard them), crank up the scores on RAZOR2_CHECK and URIBL_*. I've found both to be very reliable with exceedingly few FPs. Chris St. Pierre Unix Sy

Re: [SPAM:***] blacklisting

2007-01-18 Thread Chris St. Pierre
scan them, etc., and you'll save yourself some cycles and some headaches. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University Never send mail to [EMAIL PROTECTED]

Re: Percentage of email that is spam after filtering?

2006-11-28 Thread Chris St. Pierre
of delivered mail: Total messages delivered: 17842 (32.8% of all messages) Delivered ham: 5869 (32.9% of delivered, 10.8% of total) Delivered spam: 2975 (16.7% of delivered, 5.5% of total) On-campus mail: 8998 (50.4% of delivered, 16.5% of total) RBL is still the king for us. Chris St. Pierre Un

RE: Greylisting

2006-11-22 Thread Chris St. Pierre
% of the mail we filter (and about 25% of our total mail) is rejected by greylisting. Each of our MTAs processes about 400K messages per week. We greylist after all other MTA restrictions, so that boils down to over 100K messages that SA would have to scan if we weren't using greylisting. Ch

RE: How do i catch this

2006-11-01 Thread Chris St. Pierre
ame (misconfigured) spamming software to send out his legitimate mailing lists. If someone can't properly identify themselves to your server, tell 'em to pound sand. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: Newbie - Need Help in writing rules

2006-10-26 Thread Chris St. Pierre
Check out the SARE rulesets, ImageInfo, FuzzyOcr, ... Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University On Thu, 26 Oct 2006, san wrote: > >Hi, How to write a rules to avoid below type of mails or is there a rule >already which marks this as spam. Everday i g

Re: Spamassassin double scan through backup MX

2006-10-26 Thread Chris St. Pierre
dn't have to worry about setting up what you describe, which I'm pretty sure is impossible anyway. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: Change scoring?

2006-10-25 Thread Chris St. Pierre
ither of these places: http://daryl.dostech.ca/sa-update/sare/sare-sa-update-howto.txt http://www.exit0.us/index.php?pagename=RulesDuJour Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: Change scoring?

2006-10-24 Thread Chris St. Pierre
spam sneaks through our system tends to be scored in the 3-4.9 range -- i.e., just below our threshold of 5. I see _very_ few reported false negatives with a score below 2 or 3. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: It works great, but looking for advise...

2006-10-23 Thread Chris St. Pierre
ve MTA configuration (blacklists, forcing somewhat RFC-compliant behavior, etc.), I see very little phishing mail. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

DNS lookup plugin?

2006-10-18 Thread Chris St. Pierre
eed to rev up my Perl? Thanks! Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: SA Webmail Portal

2006-10-17 Thread Chris St. Pierre
mp;c2coff=1&client=opera&rls=en&q=spam+backscatter&btnG=Search If so, you'll need to look at your MTA. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: SA Webmail Portal

2006-10-17 Thread Chris St. Pierre
hing else. You can use it to munge the message, but anything else is up to other software -- in this case, probably your IMAP server. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: double letter porn

2006-10-10 Thread Chris St. Pierre
F distance -- did not show an appreciable improvement in the accuracy of the algorithm, although the processing time improved. It's too bad this won't work, although if someone else wants to take a crack at it, I'd be happy to share my code, word lists, etc. Chris St. Pierre Unix Sy

Re: Mail server performance problems. Possible SA slow down?

2006-10-09 Thread Chris St. Pierre
accepted. Still, you can see that we're rejecting over 9 messages per minute due to bad HELOs, bogus recipients, etc., and only marking 3 messages per minute as spam. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

Re: Mail server performance problems. Possible SA slow down?

2006-10-09 Thread Chris St. Pierre
27;re filtering SpamAssassin stuff to a different log, that could cause the problems. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University

RE: double letter porn

2006-10-05 Thread Chris St. Pierre
ple message would score a 48 and the guilty sample would score a 118, yet a larger gap (magnitude-wise). Another option would be to use a combination of Levenshtein distance and an algorithm like metaphone for representing the pronunciation of a word. So levenshtein(metaphone("orgy", &q

Re: double letter porn

2006-10-05 Thread Chris St. Pierre
re getting spam advertising "analr bictches" or the like. Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University On Wed, 4 Oct 2006, Eric A. Hall wrote: > >On 10/4/2006 5:57 PM, Richard Doyle wrote: >> I've been getting lots of porn site spam containing wo

Re: PureMessage-like spam gauge?

2006-08-03 Thread Chris St. Pierre
+ return $arg x $length; + }, + TESTS => sub { my $arg = (shift || ','); return (join($arg, sort(@{$self->{test_names_hit}})) || "none"); Chris St. Pierre Unix Systems Administrator Ne

PureMessage-like spam gauge?

2006-08-03 Thread Chris St. Pierre
e unable to duplicate the behavior I'm accustomed to, but I'd like to give my users as much consistency as possible. Thanks! Chris St. Pierre Unix Systems Administrator Nebraska Wesleyan University