Re: Suggested Change For FS_TEEN_BAD

2009-06-17 Thread Kelson
Wouldn't it be more efficient to write all the single-letter matches like (?:s|z)? as [sz]? or does it end up not making a difference when the regex is actually processed? -- Kelson Vibber SpeedGate Communications www.speed.net

Re: BAYES_99 score lint

2009-06-23 Thread Kelson
), in which case BAYES_99 will be scored at 0. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: JMF whitelist and RAZOR conflict

2009-09-11 Thread Kelson
does check URLs as well. It's one of the signature types. Type 8, I think. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: unsubscribe

2009-09-30 Thread Kelson
the list and not a question or comment. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: OT: Spamtraps

2007-09-18 Thread Kelson
, you won't hear back from them. If not, and they start sending you spam, they have no business contacting an address that you used to UNsubscribe.) Wait. The bottom line: be patient. It may take several weeks for them to bite, but once they do, they won't let go. -- Kelson Vibber SpeedGate

Re: Mail Classification

2007-09-21 Thread Kelson
further classifications. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Milter vs. Procmail

2007-09-27 Thread Kelson
that need to be split up. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Rule for TLS verify=OK?

2007-10-29 Thread Kelson
-pass/ -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Pretty good, Paypal are making their own phish these days!

2007-11-06 Thread Kelson
false positives through whitelisting. It was nice to see a sender that had learned to not make that mistake. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Pretty good, Paypal are making their own phish these days!

2007-11-07 Thread Kelson
. Please do not enter any personal or financial information into this website. So apparently email1.paypal.com in some manner is NOT part of paypal.com! I wonder how they managed that. *blink* *blink* Great. Now *that's* encouraging. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: What to do with known spam connections

2007-11-09 Thread Kelson
to a mix of real and bogus addresses. It could be worth blocking them from hitting any real addresses after they've hit a couple of spamtraps. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: What to do with known spam connections

2007-11-12 Thread Kelson
mouss wrote: Kelson wrote: Rob Sterenborg wrote: SM wrote: The spam content shouldn't even be getting through as the recipient address is invalid. Unless you don't know who your recipients are, which may be the case when operating a mailrelay. (I'm not saying that such situation is optimal

Re: Adjusting SA scores in 50_scores.cf...

2007-12-13 Thread Kelson
efficient than the other. They're looking at different data. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Score all emails and delete some of them

2007-12-13 Thread Kelson
with them. MIMEDefang, also. And you can set up procmail rules to delete or redirect mail based on the headers that SpamAssassin adds. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: DDOS, Dictionary Attack... not sure what it is...

2008-01-02 Thread Kelson
that get hit repeatedly and temporarily activating them, or even turning on a catch-all for 20 seconds or so, to capture some of the messages and see whether you're dealing with a botnet or backscatter. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: HABEAS_ACCREDITED_COI

2008-02-26 Thread Kelson
to an IP-based whitelist because the unauthenticated header proved unreliable. They changed their business model YEARS ago. -- Kelson Vibber SpeedGate Communications www.speed.net

Blogspot (was Re: giberish)

2008-03-03 Thread Kelson
in their email signatures. We do still score blogspot URIs --- but we only add 1 point for it. Scoring at 5 would block legit mail. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: How to report 120,000 spams a day

2008-03-10 Thread Kelson
MX so that it can still query that information if/when the primary is unavailable. Looking through the MIMEDefang mailing list archives is left as an exercise for the reader. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: tmp file handling

2008-03-27 Thread Kelson
. http://mimedefang.org/node.php?id=64 -- Kelson Vibber SpeedGate Communications www.speed.net

Re: office rule

2008-04-02 Thread Kelson
header __SUBOFFICE Subject =~/\boffice\b/i -- Kelson Vibber SpeedGate Communications www.speed.net

Re: dns tests and scoring info for modification

2008-04-04 Thread Kelson
you put the zeroed-out scores in your local config dir (i.e. /etc/mail/spamassassin or the like) so that they won't be overwritten the next time you upgrade and/or run sa-update. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Returned mail spam

2008-04-10 Thread Kelson
anything about spam from an authorized source? The problem *being discussed* is spam with a forged sender address, causing bounce notices to go to an innocent third party. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: DNS Blocklists with Spamassassin (scoring only)

2008-04-10 Thread Kelson
listed IP addresses (which is already in the default rule, RCVD_IN_DSBL). -- Kelson Vibber SpeedGate Communications www.speed.net

Re: FW: Why is this spam passing my SA (counterfeit goods)

2008-04-11 Thread Kelson
Rick Macdougall wrote: I'm an ISP and we use 5 to mark and 10 to reject at smtp time (not bounce, smtp reject 551). Same here. Dropping below 5 would cause way too many false positives. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Returned mail spam

2008-04-15 Thread Kelson
a disconnect here. I assume everyone here has heard the joke about the difference between theory and practice? -- Kelson Vibber SpeedGate Communications www.speed.net

Re: joe jobbed or hacked?

2008-05-05 Thread Kelson
this helps. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: List of Banks often spoofed in Phishing scams

2008-06-03 Thread Kelson
. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Replies to this list

2008-06-09 Thread Kelson
/chech.html Let's remember that these essays are matters of individual opinion, not statements of indisputable truth handed down from on high. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Opera's revolutionary e-mail client?

2008-06-24 Thread Kelson
it regularly for web browsing. I just set up email on my copy of Opera 9.5 (the latest release), and hit Compose to see what would happen. The text you're seeing is the default signature. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: freemail plugin

2008-06-26 Thread Kelson
company, we need to add it to the list because it isn't a free email service? I don't think that's going to save much effort. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Pyzor issue since upgrade to 3.1.3

2006-06-06 Thread Kelson
server has been down for a few days. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Found on a stock spam:

2006-06-19 Thread Kelson
on the server. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Can SA be used to implement greylisting?

2006-06-20 Thread Kelson
, but you have no control over how long it'll really take for them to try again. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: sudden deluge of university spams

2006-06-22 Thread Kelson
be (assuming you haven't done these already): Run sa-update Turn on Razor2 and Bayes Grab the sare_specific ruleset Run sa-learn on the messages. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: textocr and deleting messages

2006-06-23 Thread Kelson
frequently, and I know there are programs that will work with Postfix and other mail servers that will do the same kind of thing. We've used MIMEDefang www.mimedefang.org quite successfully for several years, and I'd definitely recommend it. -- Kelson Vibber SpeedGate Communications

Re: Confused about sa-update, directory locations

2006-06-23 Thread Kelson
Logan Shaw wrote: For what it's worth, I haven't added my own rules (yet), but I believe those are done in a separate place, so the fact that one set is substituted for another shouldn't cause problems. Yes, local rules go in their own directory, usually /etc/mail/spamassassin -- Kelson

Re: Blocking all inline GIF or JPG Images

2006-06-27 Thread Kelson
John D. Hardin wrote: On Tue, 27 Jun 2006, Kelson wrote: Until something comes along that (a) handles all the formatting that people want to be able to do, including adding silly backgrounds, changing the font or color for no reason, Why in the world do we need to support/encourage

Re: Spammers and images...

2006-06-29 Thread Kelson
This line from the article: Image spam can also tax e-mail systems because each message is about 7.5 times larger than regular spam, Sprosts said. ...reminds me of an old(ish) saying I once read: A picture had better be worth a thousand words -- it takes up a lot more disk space! -- Kelson

RBL classes (was Re: make bayes autolearn ignore specific scores)

2006-07-11 Thread Kelson
of your trusted networks area. check_uridnsbl* tests look the domain names in URLs that appear in the body of the message -- in other words, they look at links. P.S. in the future, please start a new thread instead of replying to an old one with a completely different topic. -- Kelson Vibber

Re: Problems on rethad 9.0

2006-07-13 Thread Kelson
to be supported for several years, unlike Red Hat 9, which lost official support two years ago and will likely lose the unofficial support from Fedora Legacy within the next 6 months to a year. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Spamassassin for web input forms ?

2006-07-13 Thread Kelson
Loren Wilton wrote: If this web form isn't high volume, you could format the form input as a mail message and pipe it to spamassassin, then check the result. Also, if the web form is written in Perl, you could access the SpamAssassin Perl modules directly. -- Kelson Vibber SpeedGate

Re: more stoopid spammer tricks

2006-07-25 Thread Kelson
of $country. The body is just the 2-line signature applied by the free email provider. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Non-english mail and Bayes

2006-07-26 Thread Kelson
a las dos y media. is Spanish, it only cares whether it's seen the words Necesito, ir, casa, etc. more often in ham or in spam. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: OT humor

2006-07-27 Thread Kelson
appropriately and thoroughly. In fact the scammer's end was quite cathartic. So this story would fall under the category of Science fiction that you wish would be fact, right? -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Problems after upgrade to 3.1.4

2006-07-27 Thread Kelson
on it will (a) throw this warning and (b) assume a value of false for that condition. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Rules for short spams?

2006-07-28 Thread Kelson
Evan Platt wrote: I'm getting hammered with short spams. Basically one line, a URI, then about 2 more lines. ... Any rules that would help these? Enable network tests. URIBL rules were basically invented for this type of spam, and they tend to work quite well. -- Kelson Vibber SpeedGate

Re: Ah, an honest spammer!

2006-07-31 Thread Kelson
Yeah. A link to a blank hostname. *That's* gonna work. More quotes at http://tinyurl.com/prv8z if anyone's interested. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: What changes would you make to stop spam? - United Nations Paper

2006-08-02 Thread Kelson
in perspective, there are plenty of people who would say the exact same thing, except substituting US for UN and George W. Bush for Kofi Annan. Even the comparison to Palpatine. Now, back on the subject of actually fighting spam... -- Kelson Vibber SpeedGate Communications www.speed.net

Re: What changes would you make to stop spam? - United Nations Paper

2006-08-02 Thread Kelson
it to a keystroke logger and capture the password that way. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: spf fails for smtp auth clients

2006-08-02 Thread Kelson
for both incoming and outgoing mail, it's a bit trickier. You have to set up your system to either not run SpamAssassin on submitted mail, or run SA with a different config. -- Kelson Vibber SpeedGate Communications www.speed.net

More honesty in spam

2006-08-03 Thread Kelson
I received a stock spam this morning. The randomly generated sender name was, and I kid you not... Bagle variant Somehow, that wouldn't surprise me at all! -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Looking for advice on rule creation regular expressions

2006-08-03 Thread Kelson
there somewhere... -- Kelson Vibber SpeedGate Communications www.speed.net

Re: whitelist poisoned? spam getting through

2006-08-04 Thread Kelson
Mathias Homann wrote: Kelson Vibber schrieb: Simple answer: don't whitelist your own address. Some spammers will do this deliberately, hoping it will get them past filters. I understood as much, but how exactly do i do that, in terms of mysql-stored spamassassin user preferences? if i use

Re: [ot] Re: HTML-tests good or bad?

2006-08-10 Thread Kelson
Daryl C. W. O'Shea wrote: Actually spelled correctly but I picked the wrong synonym. So it was a case of synonymitis. (Yeah, I admit I am prone to neologisms.) {^_-} Nope. righting isn't a synonym for writing. :p Homophonitis, perhaps? -- Kelson Vibber SpeedGate Communications

Re: Hashcash plugin to stamp outgoing mails (for postfix only)

2006-08-16 Thread Kelson
through zombies, the spammer isn't using their own CPU time, they're using some random person's home CPU. They can send the same amount of spam in the same amount of time *and* add the hashcash signatures just by using a bigger botnet. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Hashcash plugin to stamp outgoing mails (for postfix only)

2006-08-16 Thread Kelson
decoder wrote: This would slow spammers down by a factor of 10-100 or more per compromised machine (depending on whether the messages sent are sent individually or to many users at once). So they get a bigger botnet. There's no shortage of compromised machines out there. -- Kelson Vibber

Re: USER_IN_WHITELIST problem

2006-08-23 Thread Kelson
at spamassassin.apache.org -- Kelson Vibber SpeedGate Communications www.speed.net

Re: What does ALL_NATURAL BODY mean?

2006-08-29 Thread Kelson
jdow wrote: Somebody who write the rule had a sense of humor, I suspect. ... 2.6 ALL_NATURAL BODY: Spam is 100% natural?! I wonder if it dates back to the time of the original PURE_PROFIT rule, which was described as something like, Profit is dirty, not pure -- Kelson Vibber SpeedGate

Re: Strange SPF problem/wrong result

2006-09-01 Thread Kelson
the outside or other untrusted mail. * Dialup/Dynamic IP RBLs misfiring for properly relayed mail. * Dialup/Dynamic IP RBLs not catching direct-delivered mail. * whitelist_from_rcvd fails to match. * SPF tests misfiring (failing when they should pass and vice versa) -- Kelson Vibber SpeedGate

Re: Please sanity check these ideas for rules.

2006-09-05 Thread Kelson
structure but no content in either part. Scored an easy 6.1, and not without justification, as no legit mailer would deliberately send this sort of message. (Accidentally, on the other hand...) I've been meaning to report the error to them. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: RPM -vs- CPAN install

2006-09-06 Thread Kelson
from one installation method to another, you should completely uninstall the older version first. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Customizing RBL and SURBL lists

2006-09-08 Thread Kelson
is: score NAME_OF_RULE 0 -- Kelson Vibber SpeedGate Communications www.speed.net

OT: Webmail (was Re: LOG: Re: Marking Mail in the future as SPAM?)

2006-09-08 Thread Kelson
a native mail client (because generally speaking, it doesn't), but that it does email more *conveniently*. Zero install, minimal configuration, virtually infinite portability, and you can let someone else worry about your backups. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Animated graphics display a subliminal message to manipulate stock market

2006-09-11 Thread Kelson
! -- Kelson Vibber SpeedGate Communications www.speed.net

Re: postcard exploit email

2006-09-11 Thread Kelson
conditions, and exposing the mail server to potential malware, there are plenty of URLs which perform actions that the user might want to have some say in, such as: - Unsubscribe links - Web bugs - Survey results - Moderation decisions (click URL A to accept, URL B to reject) and so on. -- Kelson

Re: postcard exploit email

2006-09-11 Thread Kelson
. The link could be to a redirect script, or to a download script that provides a content-disposition header: http://server/path/to/evil/but/innocuous/looking/file -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Fishing

2006-09-13 Thread Kelson
, such that the server will execute the EXE and output HTML, not offer the EXE for download. .com will, of course, be a challenge. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: sa-learn and Caught spams

2006-09-28 Thread Kelson
duplicates. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Migrate dependencies problem

2006-09-29 Thread Kelson
to consider moving to something a bit more...well, supported than Red Hat 9. Even Fedora Legacy is dropping it at the end of the year. Centos 3 www.centos.org is a good bet, since it's based on RHEL 3, which is based on RH9, and will continue to get security updates through 2010.) -- Kelson Vibber

Re: Razor removal

2006-10-02 Thread Kelson
) 1.7 MSGID_DOLLARS Message-Id has pattern used in spam 1.9 RATWARE_MS_HASHBulk email fingerprint (msgid ms hash) found -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Parsing Email

2006-10-11 Thread Kelson
-in function, action_replace_with_url, which does exactly what you want. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Increase in Spam

2006-10-12 Thread Kelson
/spamassassin/FuzzyOcrPlugin Drawback: it needs lots of CPU and extra time per message (more precisely, per message with attached images). YMMV. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: What's with UCEPROTECT List?

2006-10-17 Thread Kelson
attack. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: This image is turning frequent..

2006-10-17 Thread Kelson
38,500 pixels? -- Kelson Vibber SpeedGate Communications www.speed.net

Re: What's with UCEPROTECT List?

2006-10-17 Thread Kelson
anyway, *after* verifying it. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: sa-update versus rulesdujour questions

2006-10-18 Thread Kelson
made to local.cf, none of them had anything to do with RDJ. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: sa-update versus rulesdujour questions

2006-10-18 Thread Kelson
, or /etc/sysconfig/rulesdujour depending on what fits best with your system layout. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Psst!

2006-10-19 Thread Kelson
Giampaolo Tomassoni wrote: Any suggestion to spread a spamtrap e-mail address? Subscribe it to some mailing lists. Make a few posts, preferably using the address in your signature. Unsubscribe it. Then wait for spammers to crawl the list archives. -- Kelson Vibber SpeedGate

Re: ebay THIEF! or spamming IDIOT?

2006-10-19 Thread Kelson
your money (at least, not directly) -- they're phishers trying to get your eBay login and password. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Pyzor problem

2006-10-23 Thread Kelson
to gracefully handle these conditions, and no one seems to have picked it up to patch it. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Off Topic - SPF - What a Disaster

2010-02-23 Thread Kelson
on how you use it. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Off Topic - SPF - What a Disaster

2010-02-24 Thread Kelson
. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: FROM_STARTS_WITH_NUMS matches on text-to-email

2010-04-12 Thread Kelson
thoroughly. They just made sure that the city, state and zip code matched. Strangely, they had a lot of users living in Beverly Hills, 90210. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: How not to implement SPF (nationwide.co.uk)

2010-06-30 Thread Kelson
generally, I don't think it's our place to decide what users can and can't do without among email that they've actually requested. False positives are one thing. *Deliberately* blocking something on the grounds that it's not necessary? That's something else. -- Kelson Vibber SpeedGate

Re: I'm thinking about suing Microsoft

2006-10-25 Thread Kelson
your programs or manually search through 20 levels of RPM hell just to install one program. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: I'm thinking about suing Microsoft

2006-10-25 Thread Kelson
Mike Woods wrote: The ultimate windows security accessory, A pair of scissors to cut the power cable :D A truly shocking idea! -- Kelson Vibber SpeedGate Communications www.speed.net

Re: It works great, but looking for advise...

2006-10-25 Thread Kelson
Jon D. Slater wrote: What rule set do you suggest for the spoof Paypal and eBay spam (and assorted fake links to assorted banks and credit unions). 70_sare_spoof will catch some of them. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Feature Request: envelope scanning

2006-10-26 Thread Kelson
. Last I remember reading, he said he was looking into another way to do it. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: bayes_auto_learn_threshold_nonspam

2006-10-31 Thread Kelson
, scores sets are: 0 - no bayes, no network 1 - no bayes, network 2 - bayes, no network 3 - bayes, network This does mean that the score used for autolearn isn't quite the same as just taking the real score and subtracting/adding the bayes score. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Do something useful with bad addresses?

2006-11-07 Thread Kelson
of spam that simulates real mail more effectively, or that manages to get auto-learned in the initial SA process (if you have auto-learn enabled). -- Kelson Vibber SpeedGate Communications www.speed.net

Re: No hit on this..

2006-11-07 Thread Kelson
Razor, DCC, and Bayes have been catching these handily here, with occasional header tests. They've all hit in the 5.5-10 range. I think this is the next stage of the So-and-so wrote: spams, which would explain where my Bayes DB got the data. -- Kelson Vibber SpeedGate Communications

Re: SA and Catch-All

2006-11-09 Thread Kelson
list is more likely to be able to answer your question. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Well, that didn't take very bloody long

2006-11-10 Thread Kelson
, and those haven't been run through SA in the first place. I've concluded the subject line is a trap. They make it so consistent that it just begs to be targeted, then they change it to another consistent rule just to yank our chains and keep us busy. -- Kelson Vibber SpeedGate Communications

Re: Help with dumb mistake

2006-11-13 Thread Kelson
. Also, keep in mind that sa-update puts new rules in /var/lib/spamassassin rather than /usr/share/spamassassin. For now, I'd suggest uninstalling the spamassassin RPM and any dependent RPMs, wiping /usr/share/spamassassin, and reinstalling the RPM using yum. -- Kelson Vibber SpeedGate

Re: question re. whitelist_from_rcvd

2006-11-13 Thread Kelson
is the email address itself. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Microsoft blacklisted?

2006-11-14 Thread Kelson
using action_bounce as the command to reject a message, and the log info matches that. AFAIK it hasn't been renamed for the same reason that SpamAssassin's auto-whitelist hasn't been renamed. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Where to submit SARE rule patches?

2006-11-14 Thread Kelson
Matthias Haegele wrote: iirc: local.cf would be a good place since it overwrites other rules (which might get updated and your changes overwritten) ... I think he meant where to submit it as a suggested change to the actual ruleset... -- Kelson Vibber SpeedGate Communications www.speed.net

Re: White listing yahoo groups

2006-11-14 Thread Kelson
. -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Them spammers are getting smarter..

2006-11-21 Thread Kelson
at the phrase, Make it huge with nanotechnology. Part of it is the huge/nano contrast, but make it huge sounds more typical of another category of spam entirely...) -- Kelson Vibber SpeedGate Communications www.speed.net

Re: Forged From, Other servers bouncing back

2006-11-21 Thread Kelson
to a certain recipient and from . -- Kelson Vibber SpeedGate Communications www.speed.net

  1   2   3   4   >