Re: unsubscribe

2009-07-11 Thread Dave Funk
HERE to post a message. | It has had mail-list support for over 10 years. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_admin

Re: Adding remote-ip/ESMTPID/X-Envelope to logging output?

2009-12-27 Thread Dave Funk
sendmail spamd) and you can log what ever you desire. By the time you get to procmail the message is already in the 'delivery' phase and some of your desired info is no longer available. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege

Re: [Fwd: Re: No SPF_FAIL flag, why?]

2008-02-27 Thread Dave Funk
represents a valid domain via DNS). In that case the message should have been blocked at the MTA and never even made it to SA. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256

Re: relays.ordb.org returning positive for everything?

2008-03-26 Thread Dave Funk
using the dead RBL and needed the clue-by-4 along side the head to wake him up. This is not the first time an expiring RBL resorted to that technique and probably will not be the last (sad to say). -- Dave Funk University of Iowa dbfunk

Re: whitelist_from_rcvd not working

2008-04-09 Thread Dave Funk
that for whitelist_from_rcvd. You have two choices, either get 213.183.100.11 to DNS map to gw.dtdm.tomsk.ru or use some other whitelist method such as whitelist_from_spf (which will work as there are matching SPF records published for dtdm.tomsk.ru) -- Dave Funk University

Re: Upgrading

2008-04-12 Thread Dave Funk
/init.d/# spamassassin restart But I get: Unable to open restart: No such file or directory [snip..] so /etc/init.d/spamassassin restart or so cd /etc/init.d/ ./spamassassin restart Linux basics. ;) -- Dave Funk University of Iowa dbfunk

Re: can we make AWL ignore mail from self to self?

2008-05-22 Thread Dave Funk
' passwords, etc? We require our PC users to authenticate when sending and I had assumed that would stop viruses/trojans. Am I being naive? -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549

Re: Scanning aliases for spam

2006-10-15 Thread Dave Funk
the general answer is to look at your incoming MTA and see how you can fit SA into that (different MTAs have different sets of options available to them). This is similar to the question of how to SA filter mail for an Exchange server (no procmail there ;). Dave -- Dave Funk

Re: How to stop weird From: crap?

2010-07-11 Thread Dave Funk
according to your mail environment. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City, IA 52242-1527

Re: Writing an MTA

2010-07-25 Thread Dave Funk
and borrow good ideas. ;) FWIW, I'm prejudiced as I've only ever worked with sendmail postfix. Other people can chime in about other MTAs. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549

Re: IPv6 problem with sa-update

2010-08-08 Thread Dave Funk
no IPv6 address). For some reason when you set that options inet6 your system is not willing to fall back to IPv4 mode (or a bug is preventing it). That's what you need to look into (until such time as spamassassin.apache.org gets v6 connected ;). -- Dave Funk

Re: scantime=249.2; scantime=175.0; scantime=190.9; scantime=68.9

2010-09-04 Thread Dave Funk
service (EG DCC), database access, etc. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City, IA 52242-1527

Re: user_prefs questions/problem

2010-09-18 Thread Dave Funk
then there's an issue with your per-user prefs, if not then there's an issue with the white-listing itself. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center

Re: header issues

2011-01-02 Thread Dave Funk
are written to std-out of SA) do not have any direct effect on the message as passed thru sendmail. That is entirely the function of the milter. You need to look at the documentation (or source code) of the milter to see what header mods you can make/change. -- Dave Funk

Re: header issues

2011-01-02 Thread Dave Funk
On Sun, 2 Jan 2011, Jack L. Stone wrote: At 04:23 PM 1.2.2011 -0600, Dave Funk wrote: On Sun, 2 Jan 2011, Jack L. Stone wrote: Sorry to have to return to the trough so soon, but still dealing with issues since recent upgrade of SA. Downgraded but no help there either, so went back to latest

Re: header issues

2011-01-02 Thread Dave Funk
of the arguments (2nd or 3rd) being the name of the header in question. Either comment out that line of code or look for some option mechanism to control it. Given that SnertSoft sells that code and has a year's support included in the price, why not just ask them? -- Dave Funk

Re: how to disable network tests?

2011-03-12 Thread Dave Funk
disabling all network tests which would imply that he had some reason to suspect the latter. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin

Re: Bad Helo Host impersonating

2011-03-23 Thread Dave Funk
name pointer 202.44.190.49.static.nexnet.net.au. afnsecurity.com != 202.44.190.61.static.nexnet.net.au Thus the claim that you are an imposterer any chance you can get your ISP to fix that DNS reverse map and those SPF records? -- Dave Funk University of Iowa

Re: Bayes Apache James server

2011-07-30 Thread Dave Funk
are good but have too high a FP rate for me to feel comfortable running them as a SMTP reject process. I'm quite happy to run them as a part of SA where Bayes, white-lists, score adjustments, etc can ameliorate damage from FPs. -- Dave Funk University of Iowa dbfunk

Re: [sanesecurity] FP feedback from large sites

2011-09-10 Thread Dave Funk
of both worlds. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City, IA 52242-1527 #include

Re: How to get rid of spam with From spoofed to my own domain

2011-09-11 Thread Dave Funk
and combined that with SPF_FAIL in a meta that really whacks the score. IE, in general it's not safe to use SPF_FAIL as a one-shot-kill but when restricted to our domain I can trust it. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege

Re: Rule matching in a wrapped header

2011-10-04 Thread Dave Funk
things such as authentication bits). In particular if you add custom headers to your sendmail config, you must customize your milter to match. This probably means getting the source code for the milter and doing it yourself. -- Dave Funk University of Iowa

Re: How to write rule for From: line

2011-10-23 Thread Dave Funk
bounding on it). This tactic does need to be used with caution to avoid FPs. The greater the usage of non-fixed pattern matches, the larger the group of matched strings and thus the greater the possibility of FPs. -- Dave Funk University of Iowa dbfunk

Re: Has the effect of '__' changed recently?

2011-11-27 Thread Dave Funk
edit substition). Doesn't require any addtional lines in your config files, score added is infinitesimal but does show up in score report. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549

Re: installation problem

2012-01-01 Thread Dave Funk
your spamassassin never finds them. You need to make sure that spamassassin sa-update agree upon the dirs to use for rules. You can either install matching kits or use command line switches to tell everybody where things are stored. -- Dave Funk University

Re: SPF tests and authenticated SMTP

2012-01-05 Thread Dave Funk
0.0 HELO_MISC_IP Looking for more Dynamic IP Relays -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_admin

Re: [OT] RBLs

2012-01-11 Thread Dave Funk
. ;( -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City, IA 52242-1527 #include std_disclaimer.h Better

Re: Lots of comment in mail, how to score

2012-02-06 Thread Dave Funk
. If there was some easy way to extract those numbers, calculate the ratio, and make it available to the rules processor, then a score could be generated at very little cost. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege

Re: SPF and DKIM tests by default?

2012-02-12 Thread Dave Funk
: loading' lines for SPF DKIM, then there's your problem. Either they're not installed on your system in a way that SA can find them, wrong verions, or not invoked by 'loadplugin' statements. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.edu

what should spamc --headers do?

2012-02-20 Thread Dave Funk
should I use, I just want the report any additional headers that SA added to the message, I don't want the body back. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256

Re: Better phish detection

2012-03-10 Thread Dave Funk
it too. [3] Damn people who insist that HTML should be acceptable everwhere. I tried creating rules that blacklist email containing javascript but there's legit sites (purchase confirmations, reservation notices, etc) that insist on doing that crap. -- Dave Funk

Re: use_bayes=0 completly disables report function

2012-04-21 Thread Dave Funk
with auto-learning and occasional hand training. Maybe not optimal but still worth doing and doesn't need much attention. Over the past 9 years I've had to discard my Bayes database and start from fresh (due to going totally off the rails) -once-. -- Dave Funk University

Re: setting up auto submit (forward to sa-learn)

2012-04-22 Thread Dave Funk
explain why you wern't finding what you expected. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City, IA

Re: Could not retrieve sendmail macro _!. Please add it to confMILTER_MACROS_CONNECT for better spamassassin results

2012-06-03 Thread Dave Funk
to make a compilation of parameters for each kind of statement. Onec you've made these edits, re-make your sendmail.cf file and restart sendmail to use the new .cf -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319

Re: False Positive on Domain Name

2012-06-08 Thread Dave Funk
networks in SA). -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City, IA 52242-1527 #include

Re: Tagging Spam

2012-07-01 Thread Dave Funk
? There may be some up-stream system that is doing SA processing on your mail. If so, you either need to get them to not do that, not run your own SA be willing to accept their scoring, or find some other way to get unfiltered mail service. -- Dave Funk University

Re: setup spamassassin without amavisd

2012-07-08 Thread Dave Funk
around. Each child uses up memory but multiple children help thruput during bursts of incoming messages. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center

Re: Spamhaus and others check at MTA level: how disable in Spamassassin?

2012-08-04 Thread Dave Funk
-boy servers aren't directly handing your server messages. (this depends upon having trusted_networks configured correctly). -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549

Re: Academic interested in interviewing you for research paper.

2012-08-17 Thread Dave Funk
of contributions is a major psychological component of why people go to this kind of effort. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin

Re: Header exposes account name

2012-09-02 Thread Dave Funk
2.6.32-20120131.55.1.zzz.x86_64 (machbu...@build6.hoster.com) (gcc version 4.4.6 20110731 (Red Hat 4.4.6-3) (GCC) ) #1 SMP Tue Jan 31 15:43:27 EST 2012 -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751

Re: Exclude from RCVD_IN_DNSWL_MED

2012-09-10 Thread Dave Funk
and if he trusts his MX/relays correctly then this shouldn't be happening. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_admin

Re: Scoring Yahoo mail from certain continents/countries ?

2012-12-09 Thread Dave Funk
a couple different threads on this list about exactly that issue (ranging from just increase the max-size for everything, to make special connector that truncates bloated spams). Until you get SA to actually process these messages, there's no point to discussing added bells-and-whisles. -- Dave

Re: Spamassassin not parsing email messages

2012-12-28 Thread Dave Funk
where singleemail.spam contains a single spam email. Regards, -Sean. -- View this message in context: http://spamassassin.1065346.n5.nabble.com/Spamassassin-not-parsing-email-messages-tp102770p102782.html Sent from the SpamAssassin - Users mailing list archive at Nabble.com. -- Dave Funk

Re: Hot News

2013-03-15 Thread Dave Funk
. It's a compromised Yahoo! account.  One of the #1 spamming issues right now for us. Regards, KAM Not only a compromised Yahoo! account but also a compromised website so listing the URLs in some kind of RBL will be probelmatic for FPs. -- Dave Funk University

Re: spamass-milter rejecting messages because no score found in large emails

2013-03-23 Thread Dave Funk
version of miltrassassin which speaks the 'SPAMC' network protocol directly to spamd, no use of the spamc client program at all. There are some milters that don't even use spamd, they directly instantiate the spamassassin engine within themselves. -- Dave Funk

Re: re-learning ? was - bayes - large message

2013-04-21 Thread Dave Funk
to local (on your SA server) 'mbox' format folders and then learn from them. Dave -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster

Re: rule problem basing on X-Spam-ASN - not a rule problem

2013-04-25 Thread Dave Funk
T__MY_CLAMAV_SANE) meta MY_CLAMAV_MSRBL(L_CLAMAV T__MY_CLAMAV_MSRBL) [snip..] -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin

Re: .pw / Palau URL domains in spam

2013-05-04 Thread Dave Funk
successtopdeals.pw superbtopdeals.pw supertopdeals.pw usdirects1.pw vision-virtualhosting12.pw vision-virtualhosting14.pw visionsvirtualwebhost2.pw zbidnow.pw avanheertyu.pw getsuperiordeal.pw sleeplessdaysnow.pw gwampuer.pw treelendnews.pw getmatchednows.pw -- Dave Funk

Re: .pw / Palau URL domains in spam

2013-05-05 Thread Dave Funk
Donesh, Thanks for your prompt response. Do you just want the domain names or do you also want copies of the spam? Dave On Sun, 5 May 2013, doneshlaher wrote: Hello Dave Funk, Thank you for providing us with the list of domain names. We are acting on them and will be taken down within 24/48

Re: MariaDB instead of MySQL

2013-05-17 Thread Dave Funk
was about 6-7 times as fast on random reads as Berkeley DB. If CDB is read-only, how do you store the a-time values on lookups so you know which tokens aren't being used to facilitate expiry? -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.edu

Re: False negatives/positives on debian

2013-06-21 Thread Dave Funk
a local caching DNS server? Are you using some explicit DNS forwarder? Does your ISP do anything special with DNS queries? ... -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549

Re: False negatives/positives on debian

2013-06-22 Thread Dave Funk
configuration. (allow all queries on lo0 and selected queries on eth*). -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_admin

Re: Errors when processing mail.

2013-07-14 Thread Dave Funk
by that directory name (/nonexistent/) it's something that you need to explicitly create and change your configuration to point to. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549

Re: Catching fake LinkedIn invites

2013-08-28 Thread Dave Funk
. There is a low-power version of whitelist_auth called def_whitelist_auth which only boosts by +15 (I use it for a lot of stuff). However there isn't a def_blacklist_from so you have to use the full strength versions of both white/black list (+100/-100) to make them balance out each other. -- Dave

Re: Rules not working

2013-09-08 Thread Dave Funk
File system permissions issues? Are the new rules files readable by the exim user? -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster

Re: How do I find a parent rule for a test?

2013-09-16 Thread Dave Funk
-- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City, IA 52242-1527 #include std_disclaimer.h Better

Re: Explanation of message of RDNS_NONE??

2013-10-22 Thread Dave Funk
...@ngdc.net and ask them to fix that. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City, IA 52242-1527

Re: dependency hell (completely off-topic...)

2013-11-15 Thread Dave Funk
. That would earn him a visit by the MiB who snoop all incoming outgoing emails (would perplex the c**p outta them, they'd assue he was up to something ;). -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX

Re: autolearn=failed

2007-09-05 Thread Dave Funk
and then retest? Strong suggestion, do -not- put your bayes stuff into a directory that contains other SA components. Best to have a directory in your /var partition just for the bayes stuff. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.edu

Re: Solution for Disaster spam?

2008-07-27 Thread Dave Funk
too. Bottom line, network tests seem to be the best defense. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa

Re: Spamassassin RBL

2008-12-20 Thread Dave Funk
to spamassassin in test mode: spamassassin -t testmessage.txt Look at the output. Now open the testmessage in your favorite text editor, change the final '.1' in that URL to '.2' and retest. You should see a bunch of URI rule hits and the total score should jump by 20 points or more. -- Dave

Re: DNS MX Question [OT]

2009-02-14 Thread Dave Funk
10 blackhole.example.com. Yes, it -is- that simple. ;) Not recommended for normal use but if you understand the risks involved, it does work that way. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751

Re: DNS MX Question [OT]

2009-02-15 Thread Dave Funk
On Sat, 14 Feb 2009, Marc Perkel wrote: Dave Funk wrote: On Sat, 14 Feb 2009, Marc Perkel wrote: Marc Perkel wrote: Hi, I have a quick bind question. I want to set the MX records on a domain to something normal but I want to set the MX for all subdomains to something else

Re: DNS MX Question [OT]

2009-02-15 Thread Dave Funk
On Sat, 14 Feb 2009, Marc Perkel wrote: Lindsay Haisley wrote: On Sat, 2009-02-14 at 22:06 -0800, Marc Perkel wrote: Dave Funk wrote: Yes, it -is- that simple. ;) Not recommended for normal use but if you understand the risks involved, it does work that way. Thanks Dave, but I

Re: emailBL

2009-04-27 Thread Dave Funk
. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City, IA 52242-1527 #include std_disclaimer.h Better is not better

Re: Bombed by PNG spam and spamassassin say its HAM argh

2009-04-30 Thread Dave Funk
into their Outlook hit 'send'. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City, IA 52242-1527 #include

Re: sa with spamass-milter UNPARSEABLE_RELAY problem - fixed

2009-04-30 Thread Dave Funk
that are not offered. So when in doubt give it more than it needs. EG for your instance, set that confMILTER_MACROS_ENVRCPT to be: define(`confMILTER_MACROS_ENVRCPT',`r, v, Z, b, _, {greylist}')dnl -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.edu

Re: tons of forged bills in german

2014-01-18 Thread Dave Funk
a whitelist_auth entry for them then either black list them or create rules to hit on any sign of the comnpany's messages. The whitelist_auth will override any rules so real messages will get thru and the blacklist/targeted rules will hit the imposterers. -- Dave Funk

Re: Remove spam results from mail header

2014-03-16 Thread Dave Funk
% [score: 0.4901]   0.8 RDNS_NONE  Delivered to internal network by a host with no rDNS X-SA-Exim-Connect-IP: x.x.x.x X-SA-Exim-Mail-From: xxx X-SA-Exim-Scanned: No (on ); SAEximRunCond expanded to false -- Re@lBanda -- Dave Funk

Re: meta test HEXHASH_WORD has undefined dependency '__KAM_BODY_LENGTH_LT_512'

2014-04-06 Thread Dave Funk
that rule will be effectively disabled but the whole SA engine should still run. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_admin

Re: Missing header when skipping mail

2014-04-18 Thread Dave Funk
the MTA nor spamd. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City, IA 52242-1527 #include

Re: some questions on sa-compile

2014-05-03 Thread Dave Funk
with care. So if you see that warning about uncompileable rules, take a second look at those specific rules. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center

Re: FYI - ahbl.org and BIND DNS errors

2014-06-10 Thread Dave Funk
you expect? That's truth in advertising. It's 'invalid', as a matter of fact all of those addresses aren't usable, they're either RFC-1918 or multicast/local-scope. So none of those are valid for remote queries. Do NOT use rhsbl.ahbl.org. period. end of song. -- Dave Funk

Re: SA rule to detect prior SA pass?

2014-06-28 Thread Dave Funk
clues to create meta rules. However cannot test out this hypothesis with out the ability to detect those headers. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans

Re: Bayes, Manual and Auto Learning Strategies

2014-07-02 Thread Dave Funk
, and manual VS auto learning is just one factor. It's been this way for the past 10+ years AFAIK (well, maybe 10 years ago it didn't have as many options for back-end database storage, mostly limited to Berkeley-DB type methods). I hope this helps you. -- Dave Funk

Re: Bayes, Manual and Auto Learning Strategies

2014-07-02 Thread Dave Funk
twice in 10 years. Dave -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City, IA 52242-1527 #include

Re: Somewhat OT - how do I whitelist a host which is in a DNSBL in sendmail?

2014-07-24 Thread Dave Funk
your client IP address in your 'access' file but what happens when that address changes? (I assume your ISP gives you a DHCP address). -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549

Re: spam with hashes and

2014-08-15 Thread Dave Funk
There were a couple of possible solutions discussed, including new features added to the latest version (trunk) of spamassassin. I took one of them (new functions in MIMEEval) back-ported it to my SA kit and it has been hitting pretty regularly on that kind of spam. -- Dave Funk

Re: punctuation in subjects

2014-09-01 Thread Dave Funk
their tactics. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City, IA 52242-1527 #include std_disclaimer.h Better

Re: .link TLD spammer haven?

2014-10-13 Thread Dave Funk
a similar comment about .link URLs inside the message. Last week I created a uri rule to fire on any .link hosted URL and so far havn't seen a single FP. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX

Re: yahoo rcvd bug?

2014-10-20 Thread Dave Funk
and how to fix it. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City, IA 52242-1527 #include

Re: URIBL_RHS_DOB #fail

2014-11-09 Thread Dave Funk
day this morning. I saw a number of FP hits on DOB for stuff that hadn't changed in years (EG amtrak.com ). It looks better now. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549

Re: Honeypot email addresses

2014-11-22 Thread Dave Funk
!-- honey...@example.com -- HTML comment. Is that too obvious? Should we put it into a CSS invisible div as well? Any other ideas? -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549

Re: Honeypot email addresses

2014-12-04 Thread Dave Funk
that mistake and a totally perfect spam filtering system that never has a FN there are other people/systems in the world which may be on that shotgun spam recpient list which may be less than perfect. -- Dave Funk University of Iowa dbfunk

Re: Gmail password reset FPs

2014-12-17 Thread Dave Funk
that I've done here to help improve deliverability. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City

Re: Recent spate of Malicious VB attachments II

2015-02-19 Thread Dave Funk
*(;|$)/x REJECT Attachment Blocked (Executables And RAR-Files Not Allowed) $1 (.rar because ClamAV can't scan the content on Fedora) Is that a politically inspired limitation? If you build ClamAV from source it can scan RAR. -- Dave Funk University of Iowa

Re: Recent spate of Malicious VB attachments II

2015-02-19 Thread Dave Funk
inside them. Are you saying that doesn't work or are you saying that the malware is mutating fast enough that the ClamAV signatures aren't keeping up with it? If the latter case, is there -any- AV kit that is? Are the Sanesecurity add-in ClamAV signatures helpful? -- Dave Funk

Re: regex: chars to escape bsides @

2015-01-03 Thread Dave Funk
-To =~ /^(\h\.reindl\@thelounge\.net\)$/i score CUST_MANY_SPAM_TO -4.0 describe CUST_MANY_SPAM_TO Custom Scoring Umm, SA is written in Perl, not PHP. So you should look at Perl regex documentation, not PHP docs. -- Dave Funk University of Iowa dbfunk

Re: Handling very large messages (was Re: Which milter do you prefer?)

2015-03-15 Thread Dave Funk
mess with the body. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City, IA 52242-1527 #include

Re: whitelist_from_rcvd not working, WAIDW

2015-02-28 Thread Dave Funk
are working as expected. Note that a DNS fubar (even temporary) will break whitelist_from_rcvd. Also if the sender changes MSP, it will break thus is a maintanance head-ache. I see that message has a valid DKIM signature, why not use whitelist_auth. Same goodness with less head-aches. -- Dave Funk

Re: no BAYES checking

2015-02-25 Thread Dave Funk
possibility is that sa-learn is looking at a different bayes database. Try running that sa-learn --dump magic with the -D option to see what bayes database it's looking at. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering

Re: Rejecting without backscatter (was Re: Spamassassin not catching spam (Follow-up))

2015-03-26 Thread Dave Funk
that sets the compatibility matrix at the beginning of a session and 452's any recipient that isn't compatible. Note that Gmail is already doing something like this (the multiple destinations not supported in one transaction status). -- Dave Funk University of Iowa

Re: local.cf, user_prefs etc

2015-05-21 Thread Dave Funk
internal settings. Invoke spamassassin with the --lint -D flags and it will tell you which config files it's using. The 'local' variants of the config files that it says it's reading are the ones you want to modify. For the last method you'll have to consult the relevant documentation. -- Dave Funk

Re: Bayes Filtering

2015-08-02 Thread Dave Funk
the clarity, but the info is there. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City, IA 52242-1527

Re: Classifying mail as unsolicited

2015-07-07 Thread Dave Funk
to, forwarding opens up a while can-of-worms but forwarding to gmail is the most problematic. -- Dave Funk University of Iowa dbfunk (at) engineering.uiowa.eduCollege of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin

Re: URIBL_BLOCKED while using local BIND

2015-09-15 Thread Dave Funk
okup. did you EMPTY cache after each query? -- Dave Funk University of Iowa College of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_adminIowa City, IA 52242-1527 #include Be

Re: Help with RegEx Rule

2015-09-19 Thread Dave Funk
inal note; now that we've discussed this spam sign, it will probably become useless as spammers follow this list and mutate their crap accordingly to dodge our rules. ;( -- Dave Funk University of Iowa College of Engineering 319/335-5751 FAX: 319/384-0549 1

Re: Help with RegEx Rule

2015-09-19 Thread Dave Funk
? The '*' repeat operator is "zero or more" instances. So that pattern degenerates to // which will match everything. Guaranteed FP generator. -- Dave Funk University of Iowa College of Engineering 319/335-5751 FAX: 319/384-0549 12

Re: SA bayes file db permission issue

2016-06-11 Thread Dave Funk
001 So it works. It's a single data byte but since the display field is a two byte object, where within that two byte object does that single byte show up? -- Dave Funk University of Iowa College of Engineering 319/335-5751 FAX: 319/384-0549 1256

Re: Spamassassin not capturing obvious Spam

2016-05-30 Thread Dave Funk
                 Has X-Priority header Notice that none of the  other body tags are triggered. Thanks, Shivram -- Dave Funk University of Iowa College of Engineering 319/335-5751 FAX: 319/384-0549 1256 Seamans Center Sys_admin/Postmaster/cell_admin

  1   2   >