Re: dns*.registrar-servers.com as a rogue registrar?

2013-05-07 Thread Jan P. Kessler
For this particular case it would be better to write a DNS plugin that would do a DNS lookup for the domain nameservers and return that in a matchable form. Going via the registrar to get the nameservers incurs far too much overhead. Two examples with postfwd: # hard version

Re: Samples?

2010-08-26 Thread Jan P. Kessler
Am 25.8.2010 22:47, schrieb Karsten Bräckelmann: Jan, any chance you could provide the paragraphs or text parts corresponding to the seeks? Just to clarify: We do *not* require the full message, even though it makes things simpler. In fact, no headers (other than Subject) are ever used in

Sought False Positives

2010-08-20 Thread Jan P. Kessler
Hi, we use spamassassin with the sought ruleset since several years at our company. After the upgrade to from 3.2.5 to 3.3.1 we notice tons of false-positives hitting on the rules JM_SOUGHT_1 and JM_SOUGHT_2. Unfortunaley I can not give examples as these messages contain confidental customer

Re: [NEW SPAM FLOOD] www.shopXX.net

2009-06-30 Thread Jan P. Kessler
Jason Haar schrieb: All this talk about trying to catch urls that contain spaces/etc got me thinking: why isn't this a standard SA feature? i.e if SA sees www(whitespace|comma|period)-combo(therest), then rewrite it as the url and process. How would you distinguish between ... go to WWW

Re: [NEW SPAM FLOOD] www.shopXX.net

2009-06-30 Thread Jan P. Kessler
Martin Gregorie schrieb: ... go to WWW EVIL ORG for new meds ... and ... digging through the WWW HE SAW this link ... Both IMO should be caught and given a positive score. I've never seen legitimate mail containing URLs written this way. Maybe I was not clear: The last one is NOT an url.

Re: [NEW SPAM FLOOD] www.shopXX.net

2009-06-30 Thread Jan P. Kessler
Michelle Konzack wrote: Is SAW a valid TOPLEVEL domain? SA could use a list of valid TLD's. Ok, let's change that (do not forget that there's more than .com) the www seems to become the primary source of information these days (-www.seems.to?) And I think we agree, that it would

Re: [NEW SPAM FLOOD] www.shopXX.net

2009-06-30 Thread Jan P. Kessler
Martin Gregorie schrieb: What makes you think I'm using URI tests or that any of these would be recognised as a URI? My tests are simple body tests with {1,n} limits on repetitions to keep things under control. So you want obfuscated urls to be recognised as urls but not treated as urls?

Re: How many people are still using perl 5.6.x?

2009-06-25 Thread Jan P. Kessler
Justin Mason schrieb: For the upcoming release, we're considering dropping support for that interpreter version. If you're still using 5.6.x, or know of a (relatively recent) distro that does, please reply to highlight this --j. Don't know if it's still relevant: Solaris 8 # uname

Re: How many people are still using perl 5.6.x?

2009-06-25 Thread Jan P. Kessler
Jan P. Kessler schrieb: Justin Mason schrieb: For the upcoming release, we're considering dropping support for that interpreter version. If you're still using 5.6.x, or know of a (relatively recent) distro that does, please reply to highlight this --j. Don't know

Re: How many people are still using perl 5.6.x?

2009-06-25 Thread Jan P. Kessler
Henrik K schrieb: sorry, just missed the relatively recent statement ;-) When the system gets old enough that it's not supported officially and you are forced to manually CPAN fresh modules (and possibly wreak havoc on the OS), there is no reason not to compile your own perl (or upgrade

Re: dnsbl checks time out

2009-02-27 Thread Jan P. Kessler
Elsa Andrés schrieb: OTOH, that server cannot be dead as I can perform any host or dig queries with it: Just a guess: Is /etc/resolv.conf readable by the uid you run sa/amavis?

Re: Novice Installation Help

2009-01-08 Thread Jan P. Kessler
dave_c00 schrieb: I have run the 'perl Makefile.PL' in the correct directory but the 'make install' isn't working. Something is going wrong! So, you think my comment is not very helpful? Maybe your desciption of the problem is not that helpful, too. If you don't provide more information

sought rules update fails

2008-12-12 Thread Jan P. Kessler
Hi, sa-update currently fails with: http: request failed: 403 Forbidden: !DOCTYPE HTML PUBLIC -//IETF//DTD HTML 2.0//EN htmlhead title403 Forbidden/title /headbody h1Forbidden/h1 pYou don't have permission to access /rules/stage/320725913.tar.gz on this server./p hr addressApache/2.2.8

FIXED: sought rules update fails

2008-12-12 Thread Jan P. Kessler
Karsten Bräckelmann schrieb: On Fri, 2008-12-12 at 15:03 +0100, Jan P. Kessler wrote: sa-update currently fails with: http: request failed: 403 Forbidden: [...] Any permission issues on yerp.org? Just tested, works for me. Did you try again? Jep, it's working now

Re: hostkarma junkemailfilter

2008-11-24 Thread Jan P. Kessler
mouss schrieb: Micah Anderson a écrit : Benny Pedersen [EMAIL PROTECTED] writes: On Tue, November 18, 2008 22:16, Henrik K wrote: postfwd and trusted_networks msa_networks is what i do use here, then minimal dns lookups is needed olso, facebook have random helo so need to be

Re: Enable Spamcop only

2008-01-25 Thread Jan P. Kessler
Mofo_Jones schrieb: Just Postfix. In postfix and I believe Sendmail. John D. Hardin wrote: On Fri, 25 Jan 2008, Mofo_Jones wrote: One more question. This site has multiple domains that it does a MX backup for and there are a few domains that I do not want SA to scan and add any