Re: Can anyone help me? surbl.org FP problems?

2008-02-01 Thread David Zinder
I ran several emails through SA with -D and search for RBL I find things like: [2891] dbg: async: starting: URI-DNSBL, DNSBL:multi.surbl.org.:worldchanging.com (timeout 15.0s, min 3.0s) [2891] dbg: dns: URIBL_PH_SURBL lookup start [2891] dbg: async: starting: URI-DNSBL,

Re: Can anyone help me? surbl.org FP problems?

2008-02-01 Thread mouss
David Zinder wrote: I ran several emails through SA with -D and search for RBL I find things like: [2891] dbg: async: starting: URI-DNSBL, DNSBL:multi.surbl.org.:worldchanging.com (timeout 15.0s, min 3.0s) [2891] dbg: dns: URIBL_PH_SURBL lookup start [2891] dbg: async: starting: URI-DNSBL,

Re: Re: Can anyone help me? surbl.org FP problems?

2008-01-31 Thread Dallas Engelken
John Hardin wrote: On Tue, 2008-01-29 at 15:25 -0800, John Hardin wrote: On Tue, 2008-01-29 at 17:51 -0500, Matt Kettler wrote: Perhaps Verizon is screwing up their DNS? Ahh, yes they are: http://www.freedom-to-tinker.com/?p=1227 Hrm. As a troubleshooting hack for this

Re: Re: Can anyone help me? surbl.org FP problems?

2008-01-31 Thread John Hardin
On Thu, 31 Jan 2008, Dallas Engelken wrote: Or better yet, just fix the URIBLDNS plugin code to expect responses matching ^127\. Anything else is a dns monetizer. Do any of the DNSBLs or URIBLs that return bitmapped results bitmap into the first octet? If not, then this sounds like the

Re: Can anyone help me? surbl.org FP problems?

2008-01-31 Thread David Zinder
What should dig return? I too have Verizon fios. If /etc/resolve.conf contains their DNS servers I get similar dig results as you. If I change it to DNS servers I trust I get: $ dig techweb.com.multi.surbl.org ; DiG 9.2.4 techweb.com.multi.surbl.org ;; global options: printcmd ;; Got

DNS hijacking (was: Can anyone help me? surbl.org FP problems?)

2008-01-31 Thread SM
At 11:40 31-01-2008, John Hardin wrote: Do any of the DNSBLs or URIBLs that return bitmapped results bitmap into the first octet? If not, then this sounds like the best solution, even though it doesn't give the administrator any feedback that DNS hijacking is taking place... This hijacking

Re: Can anyone help me? surbl.org FP problems?

2008-01-31 Thread David B Funk
On Thu, 31 Jan 2008, David Zinder wrote: What should dig return? I too have Verizon fios. If /etc/resolve.conf contains their DNS servers I get similar dig results as you. If I change it to DNS servers I trust I get: $ dig techweb.com.multi.surbl.org ; DiG 9.2.4

Re: Can anyone help me? surbl.org FP problems?

2008-01-31 Thread Daryl C. W. O'Shea
David Zinder wrote: Is this a correct response from dig? If so, changing the DNS servers in /etc/resolve.conf does not fix my problem. The techweb.com email is still reported on the blocklists. Did you restart SA after editing resolv.conf? I have also tried dig from two other email servers

Re: Can anyone help me? surbl.org FP problems?

2008-01-31 Thread Matt Kettler
David Zinder wrote: What should dig return? I too have Verizon fios. If /etc/resolve.conf contains their DNS servers I get similar dig results as you. If I change it to DNS servers I trust I get: $ dig techweb.com.multi.surbl.org ; DiG 9.2.4 techweb.com.multi.surbl.org ;; global options:

Re: Can anyone help me? surbl.org FP problems?

2008-01-30 Thread Matt Kettler
mouss wrote: Matt Kettler wrote: John Hardin wrote: On Tue, 2008-01-29 at 17:51 -0500, Matt Kettler wrote: Perhaps Verizon is screwing up their DNS? Ahh, yes they are: http://www.freedom-to-tinker.com/?p=1227 Hrm. As a troubleshooting hack for this increasingly-common feature,

Re: Can anyone help me? surbl.org FP problems?

2008-01-29 Thread Karsten Bräckelmann
On Tue, 2008-01-29 at 11:34 -0500, David Zinder wrote: If I understand the request for more info... It seems to get caught by all the lists. Here is an example from an email this morning. I'm not sure how to munge, but I think this is what you requested. Content analysis details: (5.2

Re: Can anyone help me? surbl.org FP problems?

2008-01-29 Thread Matt Kettler
Note: I fixed your subject line to try to draw the attention of the right people. Generic subject lines tend to get overlooked by folks with specific interests, since many just skim the subject lines. David Zinder wrote: I think my problem is related to surbl.org, but I can't figure out how

Re: Can anyone help me? surbl.org FP problems?

2008-01-29 Thread David Zinder
Thank you for the response and suggestions. Yes - lists.surbl.org - I was using the link Contacts-mailing lists from www.surbl.org If I understand the request for more info... It seems to get caught by all the lists. Here is an example from an email this morning. I'm not sure how to munge,

Re: Can anyone help me? surbl.org FP problems?

2008-01-29 Thread Theo Van Dinter
On Tue, Jan 29, 2008 at 06:07:08PM +0100, Karsten Bräckelmann wrote: This looks fishy. Your problem doesn't seem to be specific to SURBL. All URIBL tests are hitting. http://wiki.apache.org/spamassassin/OpenDnsAndUribls ? -- Randomly Selected Tagline: You will have good luck and overcome

Re: Can anyone help me? surbl.org FP problems?

2008-01-29 Thread Matt Kettler
David Zinder wrote: Thank you for the response and suggestions. Yes - lists.surbl.org - I was using the link Contacts-mailing lists from www.surbl.org If I understand the request for more info... It seems to get caught by all the lists. Here is an example from an email this morning. I'm not

Re: Can anyone help me? surbl.org FP problems?

2008-01-29 Thread John Hardin
On Tue, 2008-01-29 at 17:51 -0500, Matt Kettler wrote: Perhaps Verizon is screwing up their DNS? Ahh, yes they are: http://www.freedom-to-tinker.com/?p=1227 Hrm. As a troubleshooting hack for this increasingly-common feature, perhaps a URIBL/DNSBL rule could be defined that checks a

Re: Can anyone help me? surbl.org FP problems?

2008-01-29 Thread Matt Kettler
John Hardin wrote: On Tue, 2008-01-29 at 17:51 -0500, Matt Kettler wrote: Perhaps Verizon is screwing up their DNS? Ahh, yes they are: http://www.freedom-to-tinker.com/?p=1227 Hrm. As a troubleshooting hack for this increasingly-common feature, perhaps a URIBL/DNSBL rule could be

Re: Can anyone help me? surbl.org FP problems?

2008-01-29 Thread mouss
Matt Kettler wrote: John Hardin wrote: On Tue, 2008-01-29 at 17:51 -0500, Matt Kettler wrote: Perhaps Verizon is screwing up their DNS? Ahh, yes they are: http://www.freedom-to-tinker.com/?p=1227 Hrm. As a troubleshooting hack for this increasingly-common feature, perhaps a