Re: email address forgery

2010-11-11 Thread Jeremy Van Rooyen
To give more detail on my issue is as follows: *example log: * 1PGasp-0007C4-Tl SA: Debug: SAEximRunCond expand returned: '1 ' 1PGasp-0007C4-Tl SA: Debug: check succeeded, running spamc 1PGasp-0007C4-Tl SA: Action: scanned but message isn't spam: score=-1.0 required=7.0 (scanned in 1/1 secs | Mes

Re: email address forgery

2010-11-11 Thread Noel Butler
On Thu, 2010-11-11 at 19:38 -0600, René Berber wrote: > On 11/11/2010 4:13 PM, Noel Butler wrote: > > > *and* as an SPF record type, the TXT method is deprecated, but for > > time being it's good to use it since there are a lot, and I mean a LOT > > of outdated DNS servers around that do not s

Re: email address forgery

2010-11-11 Thread Noel Butler
On Thu, 2010-11-11 at 20:07 -0500, Rob McEwen wrote: > On 11/11/2010 7:41 PM, Noel Butler wrote: > > Really? I don't use SPF in SA, only MTA, if that's the case, it is a > > shame that SA also is behind the times. It was years ago SPF type was > > ratified. Justin: Any plans to change that? > >

Re: email address forgery

2010-11-11 Thread Benny Pedersen
On tor 11 nov 2010 23:31:11 CET, Michael Scheidell wrote On 11/11/10 5:13 PM, Noel Butler wrote: *and* as an SPF record type, the TXT method is deprecated, but then again, SA doesn't support SPF record type, only TXT type.. uninstall Mail::SPF::Query install Mail::SPF problem solved have

Re: email address forgery

2010-11-11 Thread Benny Pedersen
On tor 11 nov 2010 23:13:51 CET, Noel Butler wrote *and* as an SPF record type, the TXT method is deprecated, but for time being it's good to use it since there are a lot, and I mean a LOT of outdated DNS servers around that do not support it even today, yes, the fault of the DNS server admin

Re: email address forgery

2010-11-11 Thread Karsten Bräckelmann
On Thu, 2010-11-11 at 21:19 -0500, Jason Bertoch wrote: > On 11/11/2010 8:09 PM, Karsten Bräckelmann wrote: > > /me points at bugzilla > > > > Guys, mind checking there? If there's not even a bug filed about it, the > > answer most likely would be "no plans yet". As an exercise to the > > reader,

Re: email address forgery

2010-11-11 Thread David F. Skoll
On Thu, 11 Nov 2010 21:35:11 -0500 Jason Bertoch wrote: > After many complaints from the DNS community over SPF "hijacking" the > TXT record, a new SPF record type was eventually accepted. The proper fix would have been to make SPF lookups for "example.com" request the TXT record for "_spf.exam

Re: email address forgery

2010-11-11 Thread Jason Bertoch
On 11/11/2010 8:38 PM, René Berber wrote: On 11/11/2010 4:13 PM, Noel Butler wrote: *and* as an SPF record type, the TXT method is deprecated, but for time being it's good to use it since there are a lot, and I mean a LOT of outdated DNS servers around that do not support it even today, yes,

Re: email address forgery

2010-11-11 Thread Jason Bertoch
On 11/11/2010 8:09 PM, Karsten Bräckelmann wrote: On Thu, 2010-11-11 at 19:57 -0500, Jason Bertoch wrote: On 11/11/2010 7:41 PM, Noel Butler wrote: but then again, SA doesn't support SPF record type, only TXT type.. Really? I don't use SPF in SA, only MTA, if that's the case, it is a shame th

Re: email address forgery

2010-11-11 Thread René Berber
On 11/11/2010 4:13 PM, Noel Butler wrote: > *and* as an SPF record type, the TXT method is deprecated, but for > time being it's good to use it since there are a lot, and I mean a LOT > of outdated DNS servers around that do not support it even today, yes, > the fault of the DNS server admin fo

Re: email address forgery

2010-11-11 Thread Karsten Bräckelmann
On Thu, 2010-11-11 at 19:57 -0500, Jason Bertoch wrote: > On 11/11/2010 7:41 PM, Noel Butler wrote: > > > but then again, SA doesn't support SPF record type, only TXT type.. > > > > Really? I don't use SPF in SA, only MTA, if that's the case, it is > > a shame that SA also is behind the times.

Re: email address forgery

2010-11-11 Thread Rob McEwen
On 11/11/2010 7:41 PM, Noel Butler wrote: > Really? I don't use SPF in SA, only MTA, if that's the case, it is a > shame that SA also is behind the times. It was years ago SPF type was > ratified. Justin: Any plans to change that? I guess I'm one of those mail admins who is behind the times. But

Re: email address forgery

2010-11-11 Thread Jason Bertoch
On 11/11/2010 7:41 PM, Noel Butler wrote: On Thu, 2010-11-11 at 17:31 -0500, Michael Scheidell wrote: On 11/11/10 5:13 PM, Noel Butler wrote: > *and* as an SPF record type, the TXT method is deprecated, but then again, SA doesn't support SPF record type, only TXT type.. Really? I don't use

Re: email address forgery

2010-11-11 Thread Noel Butler
On Thu, 2010-11-11 at 17:31 -0500, Michael Scheidell wrote: > On 11/11/10 5:13 PM, Noel Butler wrote: > > *and* as an SPF record type, the TXT method is deprecated, > but then again, SA doesn't support SPF record type, only TXT type.. > > Really? I don't use SPF in SA, only MTA, if that's th

How (not) to Generate Forged Addresses

2010-11-11 Thread Karsten Bräckelmann
Guys, anyone else seeing these? What I am mostly interested in is, whether this pattern is specific to this long-standing German spam run, or if there are actually payload variants in other languages, too. header BCDE From:addr =~ /^(?:[bcde][a-z]){16,}\@/ Going from memory, they are botnet g

Re: email address forgery

2010-11-11 Thread Michael Scheidell
On 11/11/10 5:13 PM, Noel Butler wrote: *and* as an SPF record type, the TXT method is deprecated, but then again, SA doesn't support SPF record type, only TXT type.. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Cert

Re: email address forgery

2010-11-11 Thread Noel Butler
On Thu, 2010-11-11 at 10:07 -0500, Rob McEwen wrote: > On 11/11/2010 9:11 AM, Jeremy Van Rooyen wrote: > > Can anybody explain to me how to do this and how would I be able to > > test it? > > Jeremy, > > I really like to use the following wizard to generate my SPF strings: > > http://www.opensp

Re: SA and SELinux

2010-11-11 Thread Philip Prindeville
On 11/10/10 11:39 AM, John Williams wrote: No on my server I have a hard requirement to run SELinux. I cannot turn that off. I find that when i enable SA with SELinux turned on, my CPU rate sky rockets eventually forcing my system to stop responding. I've seen this thread several times through

Re: email address forgery

2010-11-11 Thread Karsten Bräckelmann
On Thu, 2010-11-11 at 16:11 +0200, Jeremy Van Rooyen wrote: > Thanks to this list who help me(Newby) with my Spamassasin > configuration the last time, but here I am again. > > I've been having email spoofing issues for sometime now and have > complaints about it allot. Please elaborate. What exa

Re: email address forgery

2010-11-11 Thread Rob McEwen
On 11/11/2010 9:11 AM, Jeremy Van Rooyen wrote: > Can anybody explain to me how to do this and how would I be able to > test it? Jeremy, I really like to use the following wizard to generate my SPF strings: http://www.openspf.org/ Scroll down to the section that says "Deploying SPF", enter the

email address forgery

2010-11-11 Thread Jeremy Van Rooyen
Hi All, Thanks to this list who help me(Newby) with my Spamassasin configuration the last time, but here I am again. I've been having email spoofing issues for sometime now and have complaints about it allot. I need to implement SPF checks If I'm correct on thinking so, to handle email spoofing