Re: WARNING: Microsoft has earned removal from SA default welcomelist

2024-04-12 Thread Jared Hall via users
On 4/12/2024 1:20 PM, Bill Cole wrote: In my opinion, this is an indication that the default welcomelist entries in the official SpamAssassin rules for '*@*.microsoft.com' are inappropriate. Note that there is an entry for '*@accountprotection.microsoft.com' which is still justified as far

Re: OT: Microsoft Breech

2024-03-18 Thread Jared Hall via users
rved an increase in the blocking of IPs belonging to Microsoft Corporation by the SpamCop blacklist since November 2023, with a notable spike in activity during February and March 2024. Yes, you are correct.  I see there is a spat between Microsoft and SpamHaus also.  Poor, poor Microsoft. T

OT: Microsoft Breech

2024-03-18 Thread Jared Hall via users
I've several customers whose accounts were used to send spam as a result of Microsoft's infrastructure breech. Curiously, NOBODY has received any breach notifications from Microsoft, despite personal information being compromised. What has anyone else experienced? Thanks, -- Jared Hall

Re: SHTML file extension handling?

2024-03-12 Thread Jared Hall via users
On 3/12/2024 4:04 PM, Benny Pedersen wrote: Jared Hall via users skrev den 2024-03-12 20:37: Is there a use case for emailing .shtml files, or can these just be simply discarded? i have seen .html attachment only reason i think its tryed was to skip url testing in spamassassin might be same

SHTML file extension handling?

2024-03-12 Thread Jared Hall via users
Is there a use case for emailing .shtml files, or can these just be simply discarded? Thanks, -- Jared Hall

mimeheader multiple?

2024-02-01 Thread Jared Hall via users
Content-Transfer-Encoding: base64 I can hit on the Content-Disposition header regex fine, but tflags/multiple doesn't seem to work here.  I'm not sure if this is a problem (1) with the Mimeheader plugin, (2) working as designed, (3) or a fault in my system. Any suggestions? Thanks, -- Jared Hall

Re: Question about forwarding email (not specifically SA, pointers greatly appreciated)

2024-01-02 Thread Jared Hall via users
, SPF/DKIM/DMARC Auth-neutral will become the new "bad". I apologize this isn't strictly SA related, I am just hoping someone can give me advice or provide I link to follow on how to make this work. package: opendkim + access to your managed domain's DNS records. $0.02, -- Jared Hall

Re: Filtering emails from word-oliv...@somewhere.com

2023-10-06 Thread Jared Hall
u can read more information about this function here: https://metacpan.org/pod/Mail::SpamAssassin::Conf#CAPTURING-TAGS-USING-REGEX-NAMED-CAPTURE-GROUPS -- Jared Hall

Re: Correct way to allowlist an IP from DNSBL checks when it's not the final Received?

2023-09-30 Thread Jared Hall
ditions.  This actual comment in SA 3.4.2's DNSEval.pm module says it all: "# Very hacky stuff and direct rbl_evals usage for now, TODO rewrite everything" An upgrade is in order. -- Jared Hall

Re: Correct way to allowlist an IP from DNSBL checks when it's not the final Received?

2023-09-28 Thread Jared Hall
On 9/28/2023 8:39 AM, Andy Smith wrote: Hello, On Thu, Sep 28, 2023 at 06:48:54AM -0400, Jared Hall wrote: Do you mind if I redirect the below back onto the spamassassin list and respond to it there? Well I was going to do that, but fair enough! On Thu, Sep 28, 2023 at 12:02:47AM -0400

Re: Correct way to allowlist an IP from DNSBL checks when it's not the final Received?

2023-09-28 Thread Jared Hall
, Sep 28, 2023 at 12:02:47AM -0400, Jared Hall wrote: On 9/27/2023 5:42 PM, Andy Smith wrote: > Hi Jared, > > > Just under that paragraph I mentioned that the supplier hosts public > mailing lists where their employees end others use addresses that I > can't predict, so I think t

Re: spam_pid not found

2023-08-16 Thread Jared Hall
d --create-prefs --max-children 5 --helper-home-dir --syslog-socket=native CPAN will put stuff in the /usr/local/bin folder.  Compare /usr/sbin/spamd -V to /usr/local/bin/spamd -V Also, check the values in /etc/init.d/spamassassin -- Jared Hall

Re: kam channel excess spamscore gives false possitive on valid mail from microsoft store

2023-08-09 Thread Jared Hall
. KAM_BODY_URIBL_PCCC=9, KAM_FROM_URIBL_PCCC=9 Still, anything blocking MS Store is pretty egregious, especially since it's both Address and Body URL.  A score of 9 for each? -- Jared Hall

Re: kam channel excess spamscore gives false possitive on valid mail from microsoft store

2023-08-09 Thread Jared Hall
. KAM_BODY_URIBL_PCCC=9, KAM_FROM_URIBL_PCCC=9 Still, anything blocking MS Store is pretty egregious, especially since it's both Address and Body URL.  A score of 9 for each? -- Jared Hall

SA and UTF-8 Filename Attachments

2023-08-03 Thread Jared Hall
\xAEPayroll_stubs\.Htm)([";']?|$)/ The more native (raw) formatted rule works even without specifying "Content-Disposition:raw": mimeheader __JR_EXPLOIT_ATT_UTF        Content-Disposition =~ /(%C2%AEPayroll_stubs\.Htm)([";']?|$)/ How does SA handle UTF-8 filenames? -- Jared Hall

Re: Really hard-to-filter spam

2023-07-28 Thread Jared Hall
and Unicode::UTF8 modules (something like "instmodsh" option "l"). Just another great mystery; like Bigfoot, Pyramids, UFOs, Crop Circles, Plains of Nazca, and Microsoft Fax Server. -- Jared Hall

Re: Newb on sa-learn - didn't get what I expected as a response...

2023-07-07 Thread Jared Hall
message and EVERY time it said it examined a message it also said it "learned" 1 token. I believe the default format is Maildir.  You  mention a single file w/ multiple emails which suggests you might be running MBox format? If so, try the --mbox command line switch. -- Jared Hall

Re: Position of X-Spam headers

2023-07-04 Thread Jared Hall
at the top, but usually this is the responsibility of the Milter.  What Milter/content_filter are you using? -- Jared Hall

Re: ALL_TRUSTED is Always in Headers

2023-06-25 Thread Jared Hall
ixed since then.  I would upgrade SA to 3.4.6. -- Jared Hall

Re: DMARC Aggregate reports - false positives

2023-06-22 Thread Jared Hall
    (ENA_SUBJ_LONG_WORD && DKIM_VALID)     score   DMARC_OFFSET    -2.2 Yes, for sure, ALL Microsoft DMARC messages hit ENA_SUBJ_LONG_WORD. dokomo.ne.jp also hits (32 chars).  In the near-miss category, mail.ru comes in OK at 29 characters. -- Jared Hall

Re: DKIM absence

2023-05-03 Thread Jared Hall
as you wish.  But IMHO, it is probably not a good idea to go looking for trouble that doesn't exist. -- Jared Hall

Re: BAYES_00 BODY. Negative score?

2023-02-17 Thread Jared Hall
ive wildly different BAYES scores. Try rattling off another Gmail message, but this time switch the two Email addresses on the "To:" line around. Maybe a case where only the first Email address is looked at by SA? Thanks, Jared Hall

Re: BAYES_00 BODY. Negative score?

2023-02-16 Thread Jared Hall
erl/5.26.1/Mail /lib/Mail Or, if you have to be more specific (say, /lib/Mail exists already), something like: ln -s /usr/lib/perl5/vendor_perl/5.26.1/Mail/SpamAssassin /lib/Mail/SpamAssassin etc... --Jared Hall

Re: How is this phishing attack called?

2023-02-15 Thread Jared Hall
-- Jared Hall

Re: Looking for advice about limiting DNS queries

2023-01-08 Thread Jared Hall
On 1/8/2023 12:57 AM, Brian Conry wrote: ... Third, to expand on something I alluded to briefly, the emails in question are generated by a security appliance on our customer's network, in accordance with their security policy and posture. The warnings we're getting when our mail server

Re: Problems matching the last word in multi-OR Regex

2022-12-15 Thread Jared Hall
On 12/15/2022 7:03 AM, Pedro David Marco via users wrote: HI, Situation: i have 2 twin servers running exactly the same OS, and SA. (3.4.4) i have an email with the word 'dog' inside. i have this rule:   body    __ANIMALS /cat|mouse|bird|dog/i Problem: Rule  __ANIMALS  its in one server, but

ToCc Header operations

2022-11-26 Thread Jared Hall
SA: 3.4.6 The Header ToCc test doesn't seem to accept :name and :addr modifiers. Is that how this function operates? Thanks, -- Jared Hall

Re: subscribe to blacklist for domains

2022-08-14 Thread Jared Hall
On 8/14/2022 2:55 PM, John Hardin wrote: On Sat, 13 Aug 2022, joe a wrote: Why waste your own system resources to help a scoundrel?  Drop them and be done. I personally perfer to TCP tarpit repeat offenders. +1 -- Jared Hall

sa-update note

2022-04-21 Thread Jared Hall
/sa-update.verein-clean.net/1900065.tar.gz.sha256, FAILED, status: exit 22 -- Jared Hall

Re: Avoid processing upsteam trusted mail with X-Spam-Flag: YES?

2022-01-05 Thread Jared Hall
t possible to match on them. Maybe rewrite the Subject on the upstream server to something unique and trigger on that.  Beware that KAM rules (eg. KAM_MARKSPAM) might detect most "standard" methods of Subject rewriting and add more points to the message. $0.02, -- Jared Hall

Re: Rawheader or Rawsubject? Or how to match UTF-8 Emoji in Header.

2021-12-14 Thread Jared Hall
format by expressing the Emoji in its 3 hexadecimal bytes: header    PP001 Subject =~ /\xE2\x9C\x85 Dein Paket/ Regards, -- Jared Hall

Re: Fw: spam from gmail.com

2021-11-10 Thread Jared Hall
11 Pin Lo Chens on staff, and 5 guests by that name. Can you be more specific?" I just sat down and ordered breakfast when the "real" Pin Lo Chen found me. First thing he says is, "Why didn't you call me?" -- Jared Hall

Re: Fw: spam from gmail.com

2021-11-09 Thread Jared Hall
ITIZE USER INPUT. Instead, their careless attitude presents a security threat to us all. -- Jared Hall

Re: Unicode considered harmful again

2021-11-05 Thread Jared Hall
ecific, Jared.  Why that one?" she queried. I chuckled, "Because then I could hook up with any other character and make a great Emoji" Happy Friday, -- Jared Hall

Re: Unicode considered harmful again

2021-11-04 Thread Jared Hall
On 11/4/2021 10:44 AM, Bill Cole wrote: On 2021-11-04 at 08:45:02 UTC-0400 (Thu, 4 Nov 2021 08:45:02 -0400) Jared Hall is rumored to have said: [...] 2) Beware of using somebody else's source code :) That's the really significant warning... Agreed.  Does one need to write a paper

Re: https://metacpan.org/pod/Mail::DKIM

2021-10-12 Thread Jared Hall
Defang, or in your case, Fuglu). -- Jared Hall <https://metacpan.org/pod/Mail::DKIM::AuthorDomainPolicy>

Re: OT: Outsourced Email Spam Filtering/Security/AV?

2021-10-02 Thread Jared Hall
: https://www.pccc.com/ 2) AppRiver is well-known.  They emerged from MIME-Defang/Roaring Penquin: https://appriver.com/ Regards, -- Jared Hall

Re: SA/MAD Interfacing

2021-10-02 Thread Jared Hall
-- Jared Hall -Original Message----- From: Jared Hall Sent: Friday, 1 October 2021 06:51 To: users@spamassassin.apache.org Subject: SA/MAD Interfacing Considering that my Linode can't deep-learn anything or become any more intelligent than it already is, it seems reasonable tha

SA/MAD Interfacing

2021-09-30 Thread Jared Hall
-learning systems communicate with Email hosts? Thanks, -- Jared Hall

Re: Spamc - connection refused

2021-09-28 Thread Jared Hall
pamd --socketmode=0660" thanks 1) Make sure spamd is running: netstat -an 2) Make sure firewall rules allow the connection. -- Jared Hall

Re: Cloudflare Is Taking a Shot at Email Security

2021-09-27 Thread Jared Hall
On 9/27/2021 4:37 PM, Lucas Rolff wrote: So is FISA702. True that.  But that is a harder sell (to my clients). -- Jared Hall

Re: Cloudflare Is Taking a Shot at Email Security

2021-09-27 Thread Jared Hall
Even Cloudflare can only go so far with signature detection.  They do have the advantage of scale.  Others, like many here, have the advantage of responsiveness. Thanks, -- Jared Hall

Re: [OT] Re: fuglu 1.0.1

2021-09-25 Thread Jared Hall
e can talk about it on the MIMEDefang ml (https://lists.mimedefang.org/mailman/listinfo/mimedefang_lists.mimedefang.org) or you can send me an email about it. Giovanni Grazie per l'aiuto.  Alex dovrebbe essere felice. :) -- Jared Hall

Re: fuglu 1.0.1

2021-09-25 Thread Jared Hall
what you want. Thanks, Alex Good Luck, -- Jared Hall

Re: Message-ID with IPv6 domain-literal

2021-09-24 Thread Jared Hall
a while() or a foreach() loop. :) -- Jared Hall

Re: FSL_BULK_SIG in 72_active.cf

2021-09-23 Thread Jared Hall
On 9/23/2021 10:07 PM, Kevin A. McGrail wrote: Jared, looks to me like an FP in Pyzor. No doubt.  The 4.608 points for a single aberration seems reasonable. -- Jared Hall

FSL_BULK_SIG in 72_active.cf

2021-09-23 Thread Jared Hall
&& !__RCD_RDNS_SMTP_MESSY DCC_CHECK = 0 RAZOR2_CHECK = 0 PYZOR_CHECK = 1 __FSL_HAS_LIST_UNSUB = 0 __UNSUB_LINK = 0 __RCVD_IN_DNSWL = 0 __JM_REACTOR_DATE = 0 __RCD_RDNS_SMTP_MESSY = 0 It does not appear that the actual rule matches the spirit of the rule. Thoughts? -- Jared Hall

Re: Disabling autolearn on given rule

2021-09-22 Thread Jared Hall
) becomes Cascading Garbage Out. Disable autolearn, wipe your Bayes store, and manually train from hand classified ham and spam. 1000% Correct, IMO.  If you must run Bayes, train it once and leave it be.  Repeat as needed. Regards, KAM -- Jared Hall * *

.sbs TLD abuse

2021-09-17 Thread Jared Hall
Be advised of spam from .sbs top-level-domains. FWIW, -- Jared Hall

Re: problems updating when using a cron job on debian 11

2021-09-03 Thread Jared Hall
on Ubuntu, /var/log/syslog and/or /var/log/kern.log on Debian. FWIW, -- Jared Hall

Re: More Norton Evil Numbers....

2021-09-03 Thread Jared Hall
Kevin, Thanks.  NBD.  Replied OL.

Re: More Norton Evil Numbers....

2021-09-02 Thread Jared Hall
Benny Pedersen wrote: is this now your newspaper to post all kind of evil numbers ?, if all rule set updates would be aswell we all loose, do your good homework, but dont make ads out it here if its just me, sorry Yes, you are right.  There's too much traffic on this list.

More Norton Evil Numbers....

2021-09-02 Thread Jared Hall
More EvilNumbers from Maria Louise, one of Norton's GMail accounts. Lucky for me my record was credited and not my actual account :) Payment for renewal of service has been credited to your record. *Order Number : JSRT-002349* *Date: Sep 02, 2021* Details:-

Yet Another Nor-Ton EvilNumber

2021-09-01 Thread Jared Hall
with a PDF attachment called: "Norton Service Invoice PDF.pdf" The PDF listed the phone number, highlighted and bolded, four times in two slightly different variants: +1855 552 2963 1855 552 2963 Blimey, -- jared Hall

Address Oddities

2021-08-31 Thread Jared Hall
LFORMED=0.1 0.1. Seriously? Could we at least get a 0.1 for the CC address also? Aargh, -- Jared Hall

Re: Lint problem with KAM.cf

2021-08-31 Thread Jared Hall
ld've been modified to check versions and load the correct DecodeShortURLs.pm module.  Say, what does happen if two plugins register the same Eval rule?  Anybody know? 2) OTOH, what's the point of sa-update doing versioning if nobody uses it? -- Jared Hall

Re: spamassassin 3.4.5 wide chars

2021-08-12 Thread Jared Hall
after that. Another Thought, -- Jared Hall

Re: spamassassin 3.4.5 wide chars

2021-08-12 Thread Jared Hall
have a lot of Unicode sprinkled throughout; the SA normalize_charset conundrum. A Thought, -- Jared Hall

Re: KAM_SOMETLD_ARE_BAD_TLD false positive

2021-08-11 Thread Jared Hall
omes a TLD :) *Maybe* a little more refinement could prevent it picking  up .hidden folders that have a BAD_TLD name. /[A-z0-9]+\.(pw|stream|trade|press|top|date|guru|casa|online|cam|shop|club|bar)(\s|$|\/)/i $0.02, -- Jared Hall

CHAOS: v1.2.2: Of Documentation

2021-07-22 Thread Jared Hall
bout.  I adapted, made changes and came out better and wiser.  My respect for these people increased 100 fold. That's how I roll. But if you're going to sit on the sidelines and complain, I have bad news for you.  There's no shortage of stuff I can shove into /dev/null. $0.02, -- Jared Hall

Re: Matching on X-Spam headers doesn't get a hit

2021-07-22 Thread Jared Hall
gory =~ /(SPAM|PHISHING)/ X-AES-Category =~ /(SPAM|PHISHING)/ These are produced by something external with an obviously KNOWN pattern.  How many of those would you expect in a message?  That'd be another problem entirely.  SA syntax is PERLish-only and has does it's own internal sanity-checks and conversions. $0.02, -- Jared Hall

Re: CHAOS: v1.2.1 Released

2021-07-21 Thread Jared Hall
Henrik K wrote: On Tue, Jul 20, 2021 at 10:44:43PM -0400, Jared Hall wrote: I went out in the garage this morning and pulled out an old Dell PowerEdge that had CentOs 6 on it. Ever heard of virtual machines, or even perlbrew? :-) I've been swamped.  Didn't really have the time to fire up

Re: CHAOS: v1.2.1 Released

2021-07-20 Thread Jared Hall
ad CentOs 6 on it.  Unfortunately it didn't recognize the drives; SCSI RAID controller probably.  So please let me know if it works OK on PERL 5.16. Sincere Thanks, -- Jared Hall

Re: SA 3.4.5 meta with RBL rules not working.

2021-07-19 Thread Jared Hall
Could be worse, like 3.4.4 on Ubuntu. Surprisingly, CPAN update worked great and put everthing in the right spots, symlinks and all! 9 out of 10 cavemen prefer Ubuntu with their Brontosaurus burgers. *Sigh* -- Jared Hall Sent from my T-Mobile 4G LTE Device Get Outlook for Android<ht

CHAOS: v1.2.1 Released

2021-07-19 Thread Jared Hall
elecom2k3/CHAOS/wiki/CHANGELOG#notes>Notes There are no configuration file changes needed in this release. Enjoy, -- Jared Hall

Re: FORGED_MUA_MOZILLA for horde-submitted mail

2021-07-16 Thread Jared Hall
using SeaMonkey for a few months now.   It never sent any User-Agent header until Monday.  Very Strange.  "Looks like I picked the wrong week to quit  sniffing glue". -- Jared Hall

Re: Another evil "order response" number

2021-07-14 Thread Jared Hall
Defender Firewall Protection +1, 888, 313, 1366 Thank you, kind Sir -- Jared Hall Sent from my 4G LTE Device Get Outlook for Android<https://aka.ms/AAb9ysg>

Re: FORGED_MUA_MOZILLA for horde-submitted mail

2021-07-13 Thread Jared Hall
a User-Agent field. It's not a Mozilla MSGID. Only question I'd have is on MSGID. $0.02, -- Jared Hall

Can't get enough of those EvilNumbers...

2021-07-12 Thread Jared Hall
:  USD 311.06 Order ID : AKSF-624F Payment Mode :Auto-Debit If you have any issues regarding this order, Connect with us: +1(867)768-0009. Thanks and Regards, +1(867)768-0009. FWIW, -- Jared Hall

Re: Email Phishing and Zloader: Redux

2021-07-12 Thread Jared Hall
t-Transfer-Encoding: quoted-printable (w/ my document anyway). I'm curious as to what HornetSecurity saw in their E-mail MIME header.  It DOES make a difference, at least regarding plugin scanning.  But a .doc file is a .doc file as far as Word is concerned. I put forth a query to them.  I'll le

Email Phishing and Zloader: Such a Disappointment

2021-07-11 Thread Jared Hall
nut in New Jersey would've stopped the whole thing.  We'll never know.  We anti-spam folks are forced to sit on the bench, waiting for another billion dollars in damages. $0.02, -- Jared Hall

Re: number in sender name

2021-07-10 Thread Jared Hall
e CHAOS.pm module has an eval: from_no_vowels that may do the job as well.  Like most of the stuff in there it has internationalization so that vowels in other language character sets are taken into account. This looks at the From Name field. $0.02, -- Jared Hall

EvilNumbers: Revisited

2021-07-10 Thread Jared Hall
\)\s889\-3387)\b/i FWIW, -- Jared Hall

Re: Looking for a sample of the Microsoft zero day print nightmare

2021-07-08 Thread Jared Hall
ng threads on a computer. The status quo is not sustainable.  Just from a national/homeland security perspective it would be a noble project; perhaps worthy of your foundation - belly of the beast and all that. $0.02, -- Jared Hall

Re: Office phish

2021-07-02 Thread Jared Hall
dary="_c23d8b80-2b40-49d4-8897-08b0026dddfb_" I called my customer to see if they opened it as it was in their Junk mailbox.  They didn't recognize the sender so no, they didn't. Interesting, indeed. -- Jared Hall

Snowshoe Eploiter

2021-06-23 Thread Jared Hall
ways named "request.zip".  Probably IcedID or Konni malware. Just FYI, -- Jared Hall

CHAOS Module: While you were out...

2021-06-21 Thread Jared Hall
From the project page at: https://github.com/telecom2k3/CHAOS here's what's transpired since my last CHAOS module SA-User's post: Version 1.2.0 Date: June 21, 2021 * New Eval, check_reference_doms() controls how many @domain.tld references can appear in a Reference header. *

More EvilNumbers :)

2021-06-21 Thread Jared Hall
:Auto Wish to upgarde/ cancel the plan, Reach out us AT +1 (850) 254-0627 Regards, +1 (850) 254-0627 -- Jared Hall

EvilNumbers?

2021-06-19 Thread Jared Hall
+1\-866\-785\-0325)\b/i As per Loren and Martin, these rules are best used in a meta rule. Loren's rule is solid.  I had one message that did not contain the word "order" in the subject and one other that had "Order Status" in the From:Name field. I also use these in conjunction with FreeMail rules.  Good Luck. My $0.02, -- Jared Hall

Re: KAM_SENDGRID and SPF_HELO_NONE

2021-05-21 Thread Jared Hall
One thing is certain, if this matter is NOT addressed by the mail admins on this list, it WILL BE addressed by the US Department of Commerce. What started out as an interesting project has become a National Security risk. -- Jared Hall

Re: Detect Emoticons in Subject: CHAOS

2021-05-20 Thread Jared Hall
will also help you with Unicode Character spoofs, via its UniBabble rulesets: ᴀмαzσи ᴘ픯픦픪ё 혼픪픞혻홤혯 혾혶혴황홤혮혦혳 홎픢혳홫혪혤픢 Amαzoɴ Priⅿë   퐀퐦퐚퐳퐨퐧 퐍퐨퐭퐢퐜퐞 ... ... CHAOS will run on PERL 5.18 and later. -- Jared Hall

Re: How do I search and capture text for use in a rule?

2021-05-09 Thread Jared Hall
R_PART:", "Dear Esteemed $USER_PART", etc.) let me know. Thanks. -- Jared Hall

Re: OT: is sorbs.net sleeping ?

2021-04-10 Thread Jared Hall
e you guys at Invaluement tracking in that area?  I saw some esp stuff on Github. -- Jared Hall

Re: Using spamassassin modules from a git repo

2021-04-09 Thread Jared Hall
I do kind of like Tom Hendrikx idea of putting cloning the folder into somewhere in /usr/local/etc and putting a modified pre file in /etc/spamassassin/. But it's true it's not perfect. Yes.  Tom's idea is correctish; perhaps a more "true" solution for some. ZERO-TRUST.  SpamAssassin is

CHAOS v1.1.1

2021-04-07 Thread Jared Hall
/telecom2k3/CHAOS May your days be long and without bifurcation. -- Jared Hall

Re: Are X-MC-xxx headers legit?

2021-03-29 Thread Jared Hall
3:59:59 Looks like your Email is the zombie offspring of Scriptkiddie meets Spamkiddie :) Hope this helps! -- Jared Hall

CHAOS: Version 1.1.0

2021-03-26 Thread Jared Hall
/Messages rule. * New Admin Fraud messages added. -- Jared Hall

Re: Trouble with XM_RANDOM rule

2021-02-24 Thread Jared Hall
. Thank you, John.  "You do that voodoo that you do so well". -- Jared Hall

Re: Trouble with XM_RANDOM rule

2021-02-24 Thread Jared Hall
company!   ;) I see that JH and the SpamAssassin crew will address your problem. In the meantime, it won't hurt to add a local rule like: header    MY_XM_RANDOM X-Mailer =~ /Qboxmail Webmail/ score        MY_XM_RANDOM                -1.154 -- Jared Hall

Re: Homoglyph spam/phishing targeting popular brands

2021-02-17 Thread Jared Hall
On 2/16/2021 2:06 PM, RW wrote: That's not a bad idea, but if anyone is interested I'd suggest copying the character matching regexes into ordinary rules. Or better still into template tags, so that they can be reused in multiple rules. Agreed, RW.  Most of the stuff in there originated from

Re: Homoglyph spam/phishing targeting popular brands

2021-02-15 Thread Jared Hall
On 2/14/2021 9:58 PM, Ricky Boone wrote: On Sun, Feb 14, 2021 at 4:45 PM John Hardin wrote: On Sun, 14 Feb 2021, Ricky Boone wrote: What are the community's thoughts on handling spam/phishing that utilize homoglyphs to obfuscate the brands they're targeting? Are there any plugins that are

CHAOS Module Released

2021-02-10 Thread Jared Hall
Hope this is useful.  Good enough for Noobs, but interesting enough for Pros; a little module with a whole lot of 'tude! Standard boilerplate introduction: Mail::SpamAssassin::Plugin::CHAOS A self-scoring cornucopia of spam-fighting utilities Created by: Jared Hall Contact: https

Re: Protection.Outlook.Com

2021-02-04 Thread Jared Hall
On 2/4/2021 9:30 AM, Kevin A. McGrail wrote: On 2/4/2021 8:59 AM, Jared Hall wrote: I ported my physical server to a Linode instance and have been trying to get Microsoft to de-list my IP address from their blacklist for four weeks now; ticket SRX1517586366ID.  Four freakin' weeks. Does

Protection.Outlook.Com

2021-02-04 Thread Jared Hall
I ported my physical server to a Linode instance and have been trying to get Microsoft to de-list my IP address from their blacklist for four weeks now; ticket SRX1517586366ID.  Four freakin' weeks. Does anybody here have a better method to get removed from their blacklist? Thanks, Jared

Re: QR-decoding

2021-02-02 Thread Jared Hall
On 2/2/2021 11:34 AM, John Hardin wrote: On Tue, 2 Feb 2021, John Hardin wrote: On Tue, 2 Feb 2021, RW wrote: On Tue, 2 Feb 2021 10:47:49 +0100 Valentijn Sessink wrote: On-list: the only thing in the last QR-code phishing mail I received that actually makes it a phishing mail is the

Re: HEADS UP: SPAMCOP MIA

2021-01-31 Thread Jared Hall
On 1/31/2021 6:58 AM, Axb wrote: Happy Sunday !!! Cisco forgot to renew spamcop.net Registry Expiry Date: 2022-01-30T05:00:00Z Better disable till it's fixed score RCVD_IN_BL_SPAMCOP_NET 0 Stay safe! OK.  Thanks.

Re: results from lint

2021-01-26 Thread Jared Hall
On 1/26/2021 5:04 PM, Joe Acquisto-j4 wrote: running version 3.42. I added a rule in local.cf and restarted spamd. (systemctl restart spamd.service) It hit. Changed the score on it and an existing rule and did a restart and they it but neither score changed. Ran lint (spamassassin -D

URIBL_BLOCKED

2012-10-24 Thread Jared Hall
Anybody else getting this this morning?

Re: Help with blocking Chinese Spam

2012-03-13 Thread Jared Hall
strings. Regards, Jared Hall

Re: Lots of Chinese Spam with attachments

2011-08-06 Thread Jared Hall
or otherwise? Regards, Jared Hall

  1   2   >