Re: sa-update does not pick up newest German spam wave

2008-12-04 Thread Jonas Eckerman
Richard Hartmann wrote: While I agree in general, the text is very static and antivirus eats CPU, SA does not (so much). What AV application do you use? Is it daemonized or does it have to load it's database for every call? Here SA uses lots more CPU than clamd and fprotd does. /Jonas --

sa-update does not pick up newest German spam wave

2008-12-02 Thread Richard Hartmann
Hi all, this mail: Subject: Die E-Mail Adresse [EMAIL PROTECTED] wird gesperrt Body: Sehr geehrte Damen und Herren, Ihre Email [EMAIL PROTECTED] wird wegen Missbrauch innerhalb der naechsten 24 Stunden gesperrt. Es sind \d{2} Beschwerden wegen Spamversand bei uns eingegangen. Details und

Re: sa-update does not pick up newest German spam wave

2008-12-02 Thread Yet Another Ninja
On 12/2/2008 12:22 PM, Richard Hartmann wrote: Hi all, this mail: Subject: Die E-Mail Adresse [EMAIL PROTECTED] wird gesperrt Body: Sehr geehrte Damen und Herren, Ihre Email [EMAIL PROTECTED] wird wegen Missbrauch innerhalb der naechsten 24 Stunden gesperrt. Es sind \d{2} Beschwerden wegen

Re: sa-update does not pick up newest German spam wave

2008-12-02 Thread Richard Hartmann
2008/12/2 Yet Another Ninja [EMAIL PROTECTED]: these should be caught by your AV - submit samples to your vendor if its still not being detected. While I agree in general, the text is very static and antivirus eats CPU, SA does not (so much). Richard

Re: sa-update does not pick up newest German spam wave

2008-12-02 Thread Richard Hartmann
On Tue, Dec 2, 2008 at 13:03, Kai Schaetzl [EMAIL PROTECTED] wrote: http://wiki.apache.org/spamassassin/WritingRules Works like a charm, thank you very much! Added to my local wiki :) Is there a keyword to drop mail instead of changing its score, as well? Googling for that proved to be futile

Re: sa-update does not pick up newest German spam wave

2008-12-02 Thread Matus UHLAR - fantomas
2008/12/2 Yet Another Ninja [EMAIL PROTECTED]: these should be caught by your AV - submit samples to your vendor if its still not being detected. On 02.12.08 13:04, Richard Hartmann wrote: While I agree in general, the text is very static and antivirus eats CPU, SA does not (so much).

Re: sa-update does not pick up newest German spam wave

2008-12-02 Thread Kai Schaetzl
Richard Hartmann wrote on Tue, 2 Dec 2008 13:04:31 +0100: While I agree in general, the text is very static and antivirus eats CPU, SA does not (so much). In general, that's absolutely not true. If you have a correctly configured MTA most of this spam will not even make it on your system.

Re: sa-update does not pick up newest German spam wave

2008-12-02 Thread Kai Schaetzl
Richard Hartmann wrote on Tue, 2 Dec 2008 13:26:23 +0100: Is there a keyword to drop mail instead of changing its score, as well? SA does not drop anything, it only detects spamminess. Kai -- Kai Schätzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com

Re: sa-update does not pick up newest German spam wave

2008-12-02 Thread Kai Schaetzl
Richard Hartmann wrote on Tue, 2 Dec 2008 12:22:00 +0100: If not, what doc should I read to create my own? http://wiki.apache.org/spamassassin/WritingRules Kai -- Kai Schätzl, Berlin, Germany Get your web at Conactive Internet Services: http://www.conactive.com

Re: sa-update does not pick up newest German spam wave

2008-12-02 Thread Robert Schetterer
Richard Hartmann schrieb: Hi all, this mail: Subject: Die E-Mail Adresse [EMAIL PROTECTED] wird gesperrt Body: Sehr geehrte Damen und Herren, Ihre Email [EMAIL PROTECTED] wird wegen Missbrauch innerhalb der naechsten 24 Stunden gesperrt. Es sind \d{2} Beschwerden wegen Spamversand

Re: sa-update does not pick up newest German spam wave

2008-12-02 Thread Karsten Bräckelmann
Ihre Email [EMAIL PROTECTED] wird wegen Missbrauch innerhalb der naechsten 24 Stunden gesperrt. Es sind \d{2} Beschwerden wegen Spamversand bei uns eingegangen. Details und moegliche Schritte zur Entsperrung finden Sie im Anhang. Attachment: randomly named zip file which contains an exe

Re: sa-update does not pick up newest German spam wave

2008-12-02 Thread Richard Hartmann
On Tue, Dec 2, 2008 at 18:20, Karsten Bräckelmann [EMAIL PROTECTED] wrote: This is not spam but malware. Got a virus scanner? Yes. But when your scanners do not detect it yet, alternatives are needed. sa-update generally is *not* meant for signature style updates once an hour like that.

Re: sa-update does not pick up newest German spam wave

2008-12-02 Thread Karsten Bräckelmann
This is not spam but malware. Got a virus scanner? Yes. But when your scanners do not detect it yet, alternatives are needed. Does your virus scanner support custom signatures? :) sa-update generally is *not* meant for signature style updates once an hour like that. Noted. I just