Re: Lotto/Money email address spam

2009-07-23 Thread rich...@buzzhost.co.uk
On Wed, 2009-07-22 at 19:40 +0100, Ned Slider wrote: MySQL Student wrote: Hi, I'm having trouble catching spam that contains lotto/money schemes or simply asks the user to email a particular address for a loan or otherwise. Here's an example: snip Thanks, Alex

Re: Lotto/Money email address spam

2009-07-23 Thread Karsten Bräckelmann
On Wed, 2009-07-22 at 22:34 -0400, some Alex wrote: Okay, I have configured sa-update to download the following rulesets: Do people have a script that lints the rules, copies them to /etc/mail/spamassassin/ and restarts amavisd? NO. sa-update lint checks the rules in a sandbox, and does not

Re: Lotto/Money email address spam

2009-07-23 Thread Mike Cappella
On 7/23/2009 3:34 AM, Karsten Bräckelmann wrote: Yes. SA will use the updates as provided by sa-update, when available. All you need to do is to restart your daemon, IFF there have been any updates. Just as an FYI. I have had (only) one experience where a positive download contained a

Re: Lotto/Money email address spam

2009-07-23 Thread Karsten Bräckelmann
On Thu, 2009-07-23 at 09:22 -0700, Mike Cappella wrote: Just as an FYI. I have had (only) one experience where a positive download contained a corrupted SOUGHT rule file, and an amavis restart failed. What exactly do you mean by corrupt rule file? Sounds to me like lint testing should have

Re: Lotto/Money email address spam

2009-07-23 Thread Mike Cappella
Hi Karsten, On 7/23/2009 10:00 AM, Karsten Bräckelmann wrote: On Thu, 2009-07-23 at 09:22 -0700, Mike Cappella wrote: Just as an FYI. I have had (only) one experience where a positive download contained a corrupted SOUGHT rule file, and an amavis restart failed. What exactly do you mean by

Re: Lotto/Money email address spam

2009-07-23 Thread MySQL Student
Hi, Please don't paste examples to this list. Please post them to pastebin (or a similar service) and then include the link. .. Yes, understood. FWIW, I know enough to not post an entire message with headers to the list -- I'm sure half the time it would be filtered anyway. This time it was

Re: Lotto/Money email address spam

2009-07-23 Thread MySQL Student
Hi, sa-update lint checks the rules in a sandbox, and does not update the local channel, if there are any issues. Moreover, do NOT copy these updates to your site config dir -- but keep it in the update dir where sa-update puts them [1]. SA knows how to use them instead of the install-time

Re: Lotto/Money email address spam

2009-07-22 Thread Ned Slider
MySQL Student wrote: Hi, I'm having trouble catching spam that contains lotto/money schemes or simply asks the user to email a particular address for a loan or otherwise. Here's an example: snip Thanks, Alex Alex, Please don't paste examples to this list. Please post them to

RE: Lotto/Money email address spam

2009-07-22 Thread McDonald, Dan
From: MySQL Student [mailto:mysqlstud...@gmail.com] I'm having trouble catching spam that contains lotto/money schemes or simply asks the user to email a particular address for a loan or otherwise. Here's an example: Please use pastebin. It hit BAYES_99, but that's it. Are there any rules that

Re: Lotto/Money email address spam

2009-07-22 Thread MySQL Student
Please use pastebin. Yes, will do, thanks. It hit BAYES_99, but that's it. Are there any rules that pertain to 'loan' or this type of mail that can somehow block these? FreeMail.pm and the SOUGHT_FRAUD rules. Some time ago you were speaking about the AOL tunome.com freemail domain, and that

Re: Lotto/Money email address spam

2009-07-22 Thread Jari Fredriksson
I found the SOUGHT_FRAUD rules in jm's sandbox. Are those the proper ones to use? Are the testing ones safe? Sandbox rules are not proper ones. Add sought.rules.yerp.org to your sa-update channels.txt file. My channels.txt updates.spamassassin.org sought.rules.yerp.org

Re: Lotto/Money email address spam

2009-07-22 Thread John Hardin
On Wed, 22 Jul 2009, MySQL Student wrote: I found the SOUGHT_FRAUD rules in jm's sandbox. Are those the proper ones to use? Are the testing ones safe? Subscribe your sa-update to the sought rules channel. The reulsets are regenerated too often for manual maintenance to be feasible. --

Re: Lotto/Money email address spam

2009-07-22 Thread Daniel J McDonald
On Wed, 2009-07-22 at 18:05 -0400, MySQL Student wrote: Please use pastebin. Yes, will do, thanks. It hit BAYES_99, but that's it. Are there any rules that pertain to 'loan' or this type of mail that can somehow block these? FreeMail.pm and the SOUGHT_FRAUD rules. Some time ago you

Re: Lotto/Money email address spam

2009-07-22 Thread Gene Heskett
On Wednesday 22 July 2009, Jari Fredriksson wrote: I found the SOUGHT_FRAUD rules in jm's sandbox. Are those the proper ones to use? Are the testing ones safe? Sandbox rules are not proper ones. Add sought.rules.yerp.org to your sa-update channels.txt file. My channels.txt

Re: Lotto/Money email address spam

2009-07-22 Thread Jari Fredriksson
On Wednesday 22 July 2009, Jari Fredriksson wrote: I found the SOUGHT_FRAUD rules in jm's sandbox. Are those the proper ones to use? Are the testing ones safe? Sandbox rules are not proper ones. Add sought.rules.yerp.org to your sa-update channels.txt file. My channels.txt

Re: Lotto/Money email address spam

2009-07-22 Thread Gene Heskett
On Wednesday 22 July 2009, Jari Fredriksson wrote: On Wednesday 22 July 2009, Jari Fredriksson wrote: I found the SOUGHT_FRAUD rules in jm's sandbox. Are those the proper ones to use? Are the testing ones safe? Sandbox rules are not proper ones. Add sought.rules.yerp.org to your

Re: Lotto/Money email address spam

2009-07-22 Thread MySQL Student
Hi, I found the SOUGHT_FRAUD rules in jm's sandbox. Are those the proper ones to use? Are the testing ones safe? Subscribe your sa-update to the sought rules channel. The reulsets are regenerated too often for manual maintenance to be feasible. Okay, I have configured sa-update to download

Re: Lotto/Money email address spam

2009-07-22 Thread MySQL Student
I thought FreeMail was part of SA proper, but apparently not. Who maintains that, and how do I find it? You need three files: http://sa.hege.li/FreeMail.pm http://sa.hege.li/FreeMail.cf http://sa.hege.li/freemail_domains.cf And it's also worthwhile to add the