Re: extract eml forwarded attached mail and sa-learn

2017-03-15 Thread John Hardin
on it... Be careful when you say "redirect". It may not look like a forwarded RFC-822 attachment in that case, it might instead be "resent" by the (MUA or MTA of the) user who originally received it and just look like a regular message that went via a few e

Re: spamc report different for the same message (same user)

2017-03-10 Thread John Hardin
rks on most often correctly. Any ideas? Can you upload the message to someplace like pastebin so that we can look at it? Otherwise we're just guessing. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.

Re: top and other spammy TLDs

2017-02-20 Thread John Hardin
nchor the end with (?:/|$) - if it's a bare domain the TLD will be at the end of the URI. If it's got a path part the domain will be followed by a slash. Thanks for bringing that up, fixed here too. Dunno about __KAM_TINYDOMAIN -- John Hardin KA7OHZhttp://www.impsec.org/~jhard

Re: Great spam filtering, until now

2017-02-20 Thread John Hardin
HEADER, MIME_CHARSET_FARAWAY hits seem problematic here). -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B87

Re: New type of monstrosity / RFC Pedantry

2017-02-09 Thread John Hardin
r is being warmed up. Please, everyone, just stop now, before it's too late. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76

Re: RFC compliance pedantry (was Re: New type of monstrosity)

2017-02-07 Thread John Hardin
people, what do you propose should be put into the To: header? -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76

Re: Custom rule problem

2017-01-31 Thread John Hardin
/31/17, 11:36 AM, "John Hardin" <jhar...@impsec.org> wrote: On Tue, 31 Jan 2017, Zinski, Steve wrote: > I’m trying to write a custom rule to block a certain type of spam. When I view the message source, the very last lines of the spam look like this: >

Re: Custom rule problem

2017-01-31 Thread John Hardin
uri __ALL_URI /.*/ tflags __ALL_URI multiple Then all the detected URIs appear in the rule hits debug output. Post the full email on Pastebin or similar, we can't meaningfully comment on what you provided beyond "uri *should* work for that". -- John Hardin KA7OHZ

Re: Suddenly blocking email from SASL authenticated dynamic IP users

2017-01-26 Thread John Hardin
authenticated senders? Can you provide the full headers from such a message? It's possible that the authentication information is (for some reason) being incorporated in a manner that SA does not recognize. Also post your trusted_networks and internal_networks settings. -- John Hardin KA7OHZ

Re: No rule updates since 1/1/17

2017-01-21 Thread John Hardin
On Sat, 21 Jan 2017, Kevin Golding wrote: On Sat, 21 Jan 2017 19:08:39 -, Jari Fredriksson <ja...@iki.fi> wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 John Hardin kirjoitti 20.1.2017 22:38: > Collecting spam after RBL filtering is much less helpful to masscheck. >

Re: No rule updates since 1/1/17

2017-01-21 Thread John Hardin
lack box, but pretty close. You do, however, have to get all the bits working initially. I like the idea of a VM image. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4

Re: No rule updates since 1/1/17

2017-01-20 Thread John Hardin
and rule scoring is thus baised against non-English languages to a degree. (however there are some honeypots in Europe feeding masscheck so that may actually be less of a problem than I believe it is...) -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar

Re: Keyword Whitelist?

2017-01-11 Thread John Hardin
technical RE tuning suggestions... :) score LOCAL_WHITELIST_PRODUCTS -10 describe LOCAL_WHITELIST_PRODUCTS Message names one of my products Reload spamassassin if you modified local.cf. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic

Re: Low spam score: -1.9

2017-01-10 Thread John Hardin
nabled. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B87

Re: how to enable autolearn?

2017-01-10 Thread John Hardin
know enough mails yet it will state it in the log file. Have you trained your Bayes filter accordingly or just enabled it and expect it to start autolearning out of the box? The sample hit BAYES_99 so he has done basic training. -- John Hardin KA7OHZhttp

Re: how to enable autolearn?

2017-01-09 Thread John Hardin
. Particularly, the BAYES rules don't contribute to the autolearning decision in order to avoid positive feedback loops. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411

Re: R: learn ham

2017-01-05 Thread John Hardin
decision that is self-reinforcing. Nicola Piazzi CED - Sistemi COMET s.p.a. Via Michelino, 105 - 40127 Bologna - Italia Tel.  +39 051.6079.293 Cell. +39 328.21.73.470 Web: www.gruppocomet.it -Messaggio originale- Da: John Hardin [mailto:jhar...@impsec.org] Inviato: giovedì 5 gennaio

Re: learn ham

2017-01-05 Thread John Hardin
safely be automated, though I'd agree once per minute is a bit excessive. The classification of messages into the folders that are trained from is what needs manual supervision. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174

Re: Huge... sums of money

2016-12-19 Thread John Hardin
On Mon, 19 Dec 2016, Shao Miller wrote: Regarding the following: 0.0 LOTS_OF_MONEY Huge... sums of money Is this a Monty Python reference about huge tracts of land? Of course. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org

Re: recent increase in spam getting through

2016-12-17 Thread John Hardin
der's DNS sever, and the local MTA/SA DNS server not forward queries to an upstream DNS server. Caching results is not related to that. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E

Re: recent increase in spam getting through

2016-12-15 Thread John Hardin
as ham. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79

Re: Weird Spamassassin startup behaviour on Ubuntu 16.10

2016-12-05 Thread John Hardin
/spamassassin start - Michael On 6/12/16 11:15, John Hardin wrote: On Tue, 6 Dec 2016, Michael Heuberger wrote: > Anyone? If you shut down SA and run the /etc/init.d/spamassassin script to restart it, how long does that take to complete? Is there something like a rules recompile bu

Re: Spam with attachments and UNPARSEABLE_RELAY

2016-12-05 Thread John Hardin
On Mon, 5 Dec 2016, geoff.sa_users_161...@alphaworks.co.uk wrote: On 05/12/2016 22:38, John Hardin wrote: On Mon, 5 Dec 2016, geoff.sa_users_161...@alphaworks.co.uk wrote: > OK, blindly following your suggestion yielded the following; does it > tell you anything? > > Dec 5

Re: Spam with attachments and UNPARSEABLE_RELAY

2016-12-05 Thread John Hardin
ain it with at least 200 ham and 200 spam messages before it can start analyzing messages. Are you training at all? Are you training the right Bayes database? -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.

Re: Weird Spamassassin startup behaviour on Ubuntu 16.10

2016-12-05 Thread John Hardin
g how it starts up. Any clues welcome -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C

Re: "Complex regular subexpression recursion limit exceeded" error from sa-learn

2016-11-24 Thread John Hardin
pache.org/SpamAssassin/show_bug.cgi?id=7374) disable html postings on maillist still left to do ? :=) and output to this ticket of "spamassassin --lint -D 2>&1 >/tmp.txt" so all installed plugins versions are known, in case its already fixed "I can repro on trunk" sugg

Re: "Complex regular subexpression recursion limit exceeded" error from sa-learn

2016-11-23 Thread John Hardin
. Please open a bug and attach that spample as a repro test case. I'm not too familiar with that bit of the code so I don't have a fast fix. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key

Re: "Complex regular subexpression recursion limit exceeded" error from sa-learn

2016-11-23 Thread John Hardin
to identify specific individual e-mails that generate this diagnostic, but I've looked at them and can't see anything obviously strange. Any thoughts? The RE at that line looks pretty firmly anchored... Can you gzip up a sample that fails for you and send it to me? -- John Hardin KA7OHZ

Re: .info TLD gives 2.1?

2016-11-21 Thread John Hardin
5. CGI script parameters. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79 ---

Re: BODY_EMPTY score

2016-11-18 Thread John Hardin
On Thu, 17 Nov 2016, Alex wrote: We have a lot of users who use email to share photos. Empty body, 2M JPG attachment, nothing in the subject. Is the subject header missing entirely, or present but empty? -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar

Re: BODY_EMPTY score

2016-11-18 Thread John Hardin
also a great way for a spammer to then sending image spam. Indeed, though I haven't seen that type of spam for a long time and IIRC they tended to carry obfuscatory text as well as the image payload. It's performing well in masscheck, so there is that type of spam out there currently. -- John

Re: __MSGID_NOFQDN2 and URI_ONLY_MSGID_MALF

2016-11-14 Thread John Hardin
but don't put much in it, which seems more sensible. Agreed. I hope iceportal/surgemail is open to doing the same. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411

Re: __MSGID_NOFQDN2 and URI_ONLY_MSGID_MALF

2016-11-12 Thread John Hardin
authentication? -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79

Re: __MSGID_NOFQDN2 and URI_ONLY_MSGID_MALF

2016-11-12 Thread John Hardin
Given the S/O I can't understand why it's being scored that high (ignoring the score limit!), or even being published. I've disabled it as masscheck still doesn't seem to be handling this rule correctly. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@imps

Re: __MSGID_NOFQDN2 and URI_ONLY_MSGID_MALF

2016-11-12 Thread John Hardin
. That should fix you when it goes out. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79

Re: __MSGID_NOFQDN2 and URI_ONLY_MSGID_MALF

2016-11-12 Thread John Hardin
On Sat, 12 Nov 2016, Alex wrote: Hi, On Sat, Nov 12, 2016 at 12:07 PM, John Hardin <jhar...@impsec.org> wrote: On Sat, 12 Nov 2016, Alex wrote: Hi, We have one user whose mail server consistently hits URI_ONLY_MSGID_MALF for what appears to be a misconfigured Exchange server: Mess

Re: __MSGID_NOFQDN2 and URI_ONLY_MSGID_MALF

2016-11-12 Thread John Hardin
could communicate this to the sender, and I will try, but everyone knows how that goes. If it's warranted, I'll make a local adjustment, but just wanted to make sure this was scored properly. What is the total score his messages are getting? 2.7 points isn't a poison pill score. -- John Hardin

Re: Doubt about compiled rules precedence

2016-11-10 Thread John Hardin
the last good results? -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79

Re: Doubt about compiled rules precedence

2016-11-10 Thread John Hardin
imes (only sometimes) if i modify the rule, spamassassin keeps using the compiled version... does it make sense? I'm assuming that you *are* recompiling the rules and restarting spamd/Amavis after you make changes to the rules? -- John Hardin KA7OHZhttp://www.impsec.or

Re: training the filter

2016-11-07 Thread John Hardin
orrect it, and if necessary wipe and retrain the Bayes database from scratch. Don't discard messages after you're trained from them. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F

Re: Anyone else just blocking the ".top" TLD?

2016-11-03 Thread John Hardin
members' email addresses? They caused the problem in the first place, after all, with their promiscuous creation of new TLDs. (I kid (sorta)) -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key

RE: local.cf example

2016-11-01 Thread John Hardin
that. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79 --- "B

Re: Useful and simple script to reduce high spam load at mta level, what do you think

2016-10-27 Thread John Hardin
2) Put in crontab a line like this to run every 15 minutes : # 0/15 * * * * /batch/postban.sh -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B87

Re: Custom rule based on AWL score

2016-10-24 Thread John Hardin
)?)$/ metaTAGMATCH_TXREP_IP_HIGHSCORE __TXREP_IP_MEAN > 5.0 describeTAGMATCH_TXREP_IP_HIGHSCORE TXRep mean score quite large score TAGMATCH_TXREP_IP_HIGHSCORE 0.1 (...this sort of thing might be really useful as a general purpose rule type in base SA too...) -- John Hardin KA7OHZ

Re: PYZOR_CHECK always have zero score, why?

2016-10-23 Thread John Hardin
lag exists to allow SA to know what tests to disable when it is told to run only local tests. And which score set to use. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4

Re: Custom rule based on AWL score

2016-10-21 Thread John Hardin
On Fri, 21 Oct 2016, Paul Stead wrote: On 21/10/16 18:40, Paul Stead wrote: On 21/10/16 16:22, John Hardin wrote: > I was going to say: you can't write a rule based on the *current* AWL > adjustment because that's calculated after all the rules have hit. But > SA *could* potenti

Re: Custom rule based on AWL score

2016-10-21 Thread John Hardin
content scanning and save time & cycles. +1 -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873

Re: Custom rule based on AWL score

2016-10-21 Thread John Hardin
ical average that AWL uses... I suggest you file a New Feature bug to expose a mechanism to use the current AWL average (not the per-message adjustment) in a rule. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@imp

Re: Custom rule based on AWL score

2016-10-20 Thread John Hardin
On Thu, 20 Oct 2016, Bowie Bailey wrote: On 10/20/2016 12:55 PM, David B Funk wrote: On Thu, 20 Oct 2016, John Hardin wrote: > On Thu, 20 Oct 2016, Ian Zimmerman wrote: > > > On 2016-10-20 08:34, simplerezo wrote: > > > > > My understanding is that AWL is h

Re: Custom rule based on AWL score

2016-10-20 Thread John Hardin
e affected if you do it right. ITYM -100 points. :) Small but important detail... :) -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76

Re: PYZOR_CHECK always have zero score, why?

2016-10-19 Thread John Hardin
) to pastebin? -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79

Re: PYZOR_CHECK always have zero score, why?

2016-10-18 Thread John Hardin
throughout the full system... and no more files contain that string. Bizarre. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79

Re: Assistance needed

2016-10-18 Thread John Hardin
l GetResponse fixes their systems. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79 -

RE: Assistance needed

2016-10-18 Thread John Hardin
n what the current base rules are providing A recommendation for GetResponse: include the names of the rule hits in that report. It won't have meaning to most nontechnical users, but if it reaches the point you have reached it will really help the analysis. -- John Hardin KA7OHZ

RE: Assistance needed

2016-10-17 Thread John Hardin
is looking for mangled "cialis" without considering word boundaries. Were there any other problems reported? While that rule may hit, its score is currently 0.001 so it would not cause your email to be classified as spam. -- John Hardin KA7OHZhttp://www.impsec

Re: Assistance needed

2016-10-17 Thread John Hardin
ody you're trying to send, and if there are more details about the spam analysis than just that one line, please post that as well. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 --

Re: multiple maxhits to detect multiple attachments

2016-10-13 Thread John Hardin
multiple attachments? A "full" rule would probably support "multiple". Most of the base rule types do (not, of course, meta). -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.

Re: multiple maxhits to detect multiple attachments

2016-10-11 Thread John Hardin
ot; in MIMEHeader.pm If it is not designed to work with it, would there be any workarounds to detect multiple attachments? perhaps: rawbody __MIME_ATTACH_MULT /^Content-Disposition: / tflags__MIME_ATTACH_MULT multiple maxhits=3 but that has obvious drawbacks. -- John Hardin KA7OHZ

Re: FROM_WORDY rule is a false-positive

2016-10-07 Thread John Hardin
ere are other spammy characteristics to the message as well. What's the complete list of rules that hit? -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411

Re: Persistent phishing attacks with word/pdf macros

2016-10-03 Thread John Hardin
On Mon, 3 Oct 2016, Axb wrote: On 10/03/2016 09:03 PM, John Hardin wrote: On Mon, 3 Oct 2016, Axb wrote: > On 10/03/2016 07:46 PM, Alex wrote: > > Hi, > > > > These are a real concern. If you receive any kind of real mail > > volume, > > you're

Re: Persistent phishing attacks with word/pdf macros

2016-10-03 Thread John Hardin
infected attachments Agreed, but *phishing* PDFs are appropriate to detect, as are 419 scam PDFs (which I am starting to see). -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C

Re: Persistent phishing attacks with word/pdf macros

2016-10-03 Thread John Hardin
be scanned as if they were body text. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79

Re: R: R: regular expression needed

2016-09-28 Thread John Hardin
information in a database of some sort since doing a search of a large text file for every incoming email would probably be too slow. That sounds like two-word Bayes to me... :) -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk

Re: spamassassin -D --lint

2016-09-28 Thread John Hardin
ent them out to make the warning go away. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76

Re: FROM_WORDY and score

2016-09-25 Thread John Hardin
On Sun, 25 Sep 2016, Alex wrote: On Sun, Sep 25, 2016 at 6:18 PM, John Hardin <jhar...@impsec.org> wrote: BAYES_50? Are you training ham? :) Yes :-) Does this hit bayes00 for you? No, but if you were training things that looked like order confirmations I'd expect that to have

Re: FROM_WORDY and score

2016-09-25 Thread John Hardin
tebin.com/3qw6jLZp BAYES_50? Are you training ham? :) -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 1

Re: FROM_WORDY and score

2016-09-25 Thread John Hardin
; <customer.supp...@e.heritageparts.com> dbg: rules: ran header rule __FROM_WORDY ==> got hit: "Customer.Support@" It is causing those hams to be incorrectly classified as spam? -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.org

Re: FROM_WORDY and score

2016-09-25 Thread John Hardin
the masscheck performance, score limit and possible exclusions. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79

Re: Spam by IP-address? Spamassassin with geoiplookup?

2016-09-23 Thread John Hardin
On Fri, 23 Sep 2016, Greg Troxel wrote: "Bill Cole" <sausers-20150...@billmail.scconsult.com> writes: On 22 Sep 2016, at 23:24, John Hardin wrote: As far as I understand it, dnsmasq cannot be used for local recursion; it's purely a lightweight local DNS cache layer. Yo

Re: DNS Terminology

2016-09-23 Thread John Hardin
ay do both. Why is the use of iteration the defining feature of a recursive server and not the support for recursion. Think "actual behavior", not "capability". -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174

Re: DNS Terminology

2016-09-23 Thread John Hardin
On Fri, 23 Sep 2016, RW wrote: On Thu, 22 Sep 2016 20:24:21 -0700 (PDT) John Hardin wrote: Lists shouldn't have said "caching", that confuses the issue. Caching and recursion are two different, unrelated pieces. Focus on the "recursion" and "no forwarding"

Re: Spam by IP-address? Spamassassin with geoiplookup?

2016-09-23 Thread John Hardin
On Fri, 23 Sep 2016, li...@rhsoft.net wrote: Am 23.09.2016 um 05:24 schrieb John Hardin: On Thu, 22 Sep 2016, Thomas Barth wrote: > Am 21.09.2016 um 16:13 schrieb li...@rhsoft.net: > > > > URIBL_BLOCKED shows you are using still a dns-forwarder and so won't > > g

Re: Spam by IP-address? Spamassassin with geoiplookup?

2016-09-22 Thread John Hardin
age and tell it to not forward. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79

Re: spample of "data" URL in well-crafted Phish

2016-09-16 Thread John Hardin
On Thu, 15 Sep 2016, John Hardin wrote: On Wed, 15 Sep 2016, Chip M. wrote: Sadly, I have more FP data for you. :( Here's one specific example (just a single very long line from one corpse): background-image: url("data:image/svg+xml;charset=utf8,%3Csvg width='104px' height=

Re: spample of "data" URL in well-crafted Phish

2016-09-15 Thread John Hardin
etect either of those. At the least, detecting javascript (much less hostile javascript) within a data:image/svg+xml block probably would be really inefficient. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a

Re: Tuning recommendations?

2016-09-12 Thread John Hardin
years back. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79

Re: Tuning recommendations?

2016-09-12 Thread John Hardin
On Mon, 12 Sep 2016, Ian Zimmerman wrote: On 2016-09-12 11:06, John Hardin wrote: Consider greylisting. This will depend on the OP business needs, Right, which is why I said "consider". -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@

Re: Tuning recommendations?

2016-09-12 Thread John Hardin
On Mon, 12 Sep 2016, thomas cameron wrote: On 09/12/2016 01:06 PM, John Hardin wrote: On Mon, 12 Sep 2016, thomas cameron wrote: Make sure you have a local recursing (**NOT** forwarding) DNS server that your MTA and SA are configured to use. Reason: if you're forwarding your MTA DNS requests

Re: Tuning recommendations?

2016-09-12 Thread John Hardin
Harald on this list regarding weighted DNSBL scoring that you may find useful. You'll have to search the archives to find those. There are some other MTA-level checks you can perform, like greet pause and HELO validation (e.g. reject if the HELO has no dots). Consider greylisting. -- John Hardin

Re: drive-by malware customized to the From.RealName of actual Friends

2016-09-08 Thread John Hardin
On Thu, 8 Sep 2016, Chip M. wrote: Last week, I sent John Hardin some spamples, and he very kindly wrote & masschecked rules over the long weekend (Geek!). :) He found a significant FP risk. It's possible meta'ing with some of the conditions mentioned above would reduce the

Re: spample of "data" URL in well-crafted Phish

2016-09-08 Thread John Hardin
On Thu, 8 Sep 2016, Chip M. wrote: On Sat, 3 Sep 2016, John Hardin wrote: I've tweaked the FP avoidance a bit, maybe that will be enough to get the S/O up high enough to publish it. John, do you have any detailed info about the Ham hits? It's possible to look up what rules hit those

Re: Stuff slipping through STYLE_GIBBERISH filter!

2016-09-07 Thread John Hardin
to be more lightweight than an actual EBNF syntax verifier :) , there are limits to what can be done... -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76

Re: What are the T_ rules ?

2016-09-05 Thread John Hardin
erform well enough to publish depending on them. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507

Re: How to use sa rules?

2016-09-05 Thread John Hardin
On Mon, 5 Sep 2016, RW wrote: On Sun, 4 Sep 2016 17:52:48 -0700 (PDT) John Hardin wrote: On Sun, 4 Sep 2016, RW wrote: if you skip running sa-compile, the shared library is unaltered. ...thus the rules update has no effect? If you've ever tested updates to local body rules without

Re: How to use sa rules?

2016-09-04 Thread John Hardin
On Sun, 4 Sep 2016, RW wrote: if you skip running sa-compile, the shared library is unaltered. ...thus the rules update has no effect? -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key

Re: spample of "data" URL in well-crafted Phish

2016-09-03 Thread John Hardin
2012 (I read SANS too...): https://svn.apache.org/viewvc?view=revision=1378630 but it isn't performing well enough to be published: http://ruleqa.spamassassin.org/20160902-r1758905-n/T_URI_DATA/detail I've tweaked the FP avoidance a bit, maybe that will be enough to get the S/O up high enough to pu

Re: How to use sa rules?

2016-09-02 Thread John Hardin
or amavis or whatever is using the rules. Question for others: if you're using compiled rules does the compiler need to be run explicitly, or is that automatic? -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar

Re: spample of "data" URL in well-crafted Phish

2016-08-31 Thread John Hardin
/data: data:text/html;base64 I'll see about getting those into the sandbox. *** Do any of you HTML gurus have additional suggestions? :) ... a poison-pill rule for < script > tags in email HTML? (only slightly toungue-in-cheek) -- John Hardin KA7OHZ

Re: sa-update errors

2016-08-31 Thread John Hardin
On Wed, 31 Aug 2016, li...@rhsoft.net wrote: Am 30.08.2016 um 22:03 schrieb John Hardin: On Tue, 30 Aug 2016, Joseph Brennan wrote: > We've had errors the past 2 nights for all of the uridnsbl_skip_domain > rules. It's just us? It's been fixed, waiting for a new update to be gen

Re: sa-update errors

2016-08-30 Thread John Hardin
On Tue, 30 Aug 2016, Joseph Brennan wrote: We've had errors the past 2 nights for all of the uridnsbl_skip_domain rules. It's just us? It's been fixed, waiting for a new update to be generated by masscheck. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar

Re: SoughtRules

2016-08-29 Thread John Hardin
it's been at least a couple of years since they were regenerated. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79

Re: Possible ignore CRLF?

2016-08-26 Thread John Hardin
On Fri, 26 Aug 2016, John Hardin wrote: body __ALL_BODY /./ Oops. body __ALL_BODY /.+/ {blush} -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C

Re: Possible ignore CRLF?

2016-08-26 Thread John Hardin
ight want to add this rule: body __ALL_BODY /./ That would make it clear whether or not SA was breaking the paragraph at that point. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732

Re: Matching infinite sets

2016-08-22 Thread John Hardin
ither manual or other SA rules. The restriction to probabilities 0 or 1 may mitigate the robot-off-the-rails syndrome to a degree. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D

Re: Matching infinite sets

2016-08-22 Thread John Hardin
of "token". ...and it looks like we're venturing into the "SA Bayes multiple-word token support" realm (as a surrogate). -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8

Re: New Install - Tons of Spam Getting Through

2016-08-18 Thread John Hardin
On Thu, 18 Aug 2016, Jerry Malcolm wrote: On 8/18/2016 12:16 PM, John Hardin wrote: There are also potential DNS issues that may contribute. In addition to describing your environment, perhaps you could post the X-Spam-Status header from a couple of the low-scoring spams. John

Re: New Install - Tons of Spam Getting Through

2016-08-18 Thread John Hardin
an example uncaught spam message. SA scored it a 4.7. http://pastebin.com/T1CfVgP4 That's just the rendered body. We need to see all the message headers too. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impse

Re: New Install - Tons of Spam Getting Through

2016-08-18 Thread John Hardin
it to recognize your particular email traffic. There are also potential DNS issues that may contribute. In addition to describing your environment, perhaps you could post the X-Spam-Status header from a couple of the low-scoring spams. -- John Hardin KA7OHZhttp://www.impsec.org

Re: Unsubscribe

2016-08-18 Thread John Hardin
is an intelligence test. You just failed. -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C AF76 D822 E6E6 B873 2E79

Re: Spoofed Domain

2016-08-09 Thread John Hardin
how I do it (among other things) with sendmail and milter-regex: http://www.impsec.org/~jhardin/antispam/milter-regex.conf -- John Hardin KA7OHZhttp://www.impsec.org/~jhardin/ jhar...@impsec.orgFALaholic #11174 pgpk -a jhar...@impsec.org key: 0xB8732E79 -- 2D8C

<    4   5   6   7   8   9   10   11   12   13   >