Re: Why emails relayedfrom trusted/internal networks trigger rules?

2018-04-26 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. 10 GOTO 10 : REM (C) Bill Gates 1998, All Rights Reserved!

Re: Spamassassin and spamc do not use same rules

2018-04-25 Thread Matus UHLAR - fantomas
ow_user_rules" is enabled, which may be the error I don't advise per-user rules, I would better advise configure rules globally but enable/disable them only for some users, which can be done in user_prefs. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish N

Re: Spamassassin and spamc do not use same rules

2018-04-25 Thread Matus UHLAR - fantomas
assassin. That way, different users' settings are used. check how does your spamd run (which user, if any) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek r

Re: anyone recognize these headers? From SA or are they from another spam product?

2018-04-25 Thread Matus UHLAR - fantomas
common and considered best practice by many. It also puts handling the spam/virus erorrs on their senders, not recipients, which is a good thing imho. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na t

Re: Can't locate Mail/SpamAssassin/Plugin/SpamCop.pm: lib/Mail/SpamAssassin/Plugin/SpamCop.pm: Permission denied

2018-04-20 Thread Matus UHLAR - fantomas
0 lib" and you'll see the problem is back. I think this problem started appearing few years ago when perl started throwing error when it could not search @INC because of permissions. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive

Re: Can't locate Mail/SpamAssassin/Plugin/SpamCop.pm: lib/Mail/SpamAssassin/Plugin/SpamCop.pm: Permission denied

2018-04-19 Thread Matus UHLAR - fantomas
pamCop.pm directory was not readable by the user running spamassassin checks. if by any chance you have lib/ or lib/Mail/ etc. in current directory that is not readable by current user, this can happen. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish N

Re: Differing scores on spamassassin checks

2018-04-17 Thread Matus UHLAR - fantomas
On 15.04.18 20:04, RW wrote: >All setting bayes_path buys you here is the ability to run sa-learn >and spamassassin as root, something you should *never* do anyway. On Tue, 17 Apr 2018 13:55:13 +0200 Matus UHLAR - fantomas wrote: it's the only way to use per-user settings and

Re: Differing scores on spamassassin checks

2018-04-17 Thread Matus UHLAR - fantomas
eded. just the spamassassin and sa-learn should be done under spamd user. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I drive way too fast to worry about cholesterol.

Re: Differing scores on spamassassin checks

2018-04-15 Thread Matus UHLAR - fantomas
On 15.04.18 11:55, Computer Bob wrote: Here is a root scan:  https://pastebin.com/qdXMRzKb On Sun, 15 Apr 2018, Matus UHLAR - fantomas wrote: X-Spam-Status: Yes, score=10.2 required=4.0 tests=HTML_MESSAGE, RAZOR2_CF_RANGE_51_100,RAZOR2_CHECK,RCVD_IN_SBL_CSS,SPF_HELO_PASS

Re: Differing scores on spamassassin checks

2018-04-15 Thread Matus UHLAR - fantomas
is the difference ? * * -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Atheism is a non-prophet organization.

Re: SPF_NONE rule for spamassassin

2018-04-12 Thread Matus UHLAR - fantomas
::Plugin::SPF in /etc/spamassassin/init.pre and maybe install perl mofule for mail-spf (no idea what's its name in redhat) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: low score on very spammy email

2018-04-11 Thread Matus UHLAR - fantomas
must accept that a FP appears. otherwise, there would be no spam and no discussion here :-) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.

Re: bayes: cannot open bayes databases lock failed: File exists

2018-04-10 Thread Matus UHLAR - fantomas
you are running amavis, you need to check ~amavis/.spamassassin/ directory, not /.spamassassin. if you are running spamd unser one user, does the user homedir set to / ? otherwise, it can be a result of no mail trained, since you have bayes_auto_learn set to 0 -- Matus UHLAR - fantomas, uh

Re: bayes: cannot open bayes databases lock failed: File exists

2018-04-09 Thread Matus UHLAR - fantomas
bayes database, you can try redis - even faster than mysql. Much much much faster -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu

Re: bayes: cannot open bayes databases lock failed: File exists

2018-04-06 Thread Matus UHLAR - fantomas
emails are analyzed per hour. under such load, yes. if you use per-site bayes database, you can try redis - even faster than mysql. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: how to remove T_RP_MATCHES_RCVD

2018-04-06 Thread Matus UHLAR - fantomas
een true in the past, since I have already disabled this on some of systems we maintain in our company. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek rekl

Re: This sucks

2018-04-02 Thread Matus UHLAR - fantomas
hile using spamc+spamd does not. how do you run spamd? apparently when checking through spamd, different user preferences are used. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto ad

Re: BODY custom rule not working if text and html parts are different?

2018-03-31 Thread Matus UHLAR - fantomas
does not. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Microsoft dick is soft to do no harm

Re: FSL_BULK_SIG tweak?

2018-03-13 Thread Matus UHLAR - fantomas
ive. Afaik this is often a sign of spam, not ham. iirc such unsubscribe link was already reported as email address verifier, resulting into more spam being sent to such address. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertisi

Re: The "goo.gl" shortner is OUT OF CONTROL (+ invaluement's response)

2018-03-10 Thread Matus UHLAR - fantomas
On 3/10/2018 11:22 AM, Matus UHLAR - fantomas wrote: this is apparently not the case of one url redirector (shortener) points to another shortener. I really hope that the DecodeShortURLs only checks fopr redirection at those known redirectors (shorteners), not each http->https shortener

Re: The "goo.gl" shortner is OUT OF CONTROL (+ invaluement's response)

2018-03-10 Thread Matus UHLAR - fantomas
On 3/10/2018 3:20 AM, Matus UHLAR - fantomas wrote: do you have an example of any chained redirection not suspicious? On 10.03.18 11:04, Rob McEwen wrote: I haven't examined the code for that plugin very much (yet!) but one type of very common redirect that is very innocent... is the

Re: razor?

2018-03-10 Thread Matus UHLAR - fantomas
ves where "false-positives" is a mbox file format. On 09.03.18 09:26, David Jones wrote: RAZOR like DCC and PYZOR shouldn't be used as a sole source of determining spam. especially DCC, since it measures bulkiness, not spamminess. -- Matus UHLAR - fantomas, uh...@fantomas.sk

Re: The "goo.gl" shortner is OUT OF CONTROL (+ invaluement's response)

2018-03-10 Thread Matus UHLAR - fantomas
n one redirect is highly suspicious and more than two is probably a waste of time, just score 5.0 and be done with it. Has anyone done any analysis on multi-redirects? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this ad

Re: Spammers, IPv6 addresses, and dnsbls

2018-03-10 Thread Matus UHLAR - fantomas
On 02.03.18 09:58, Leandro wrote: Hi Danilele! Our DNSBL works with individual /128 IPv6 addresses: http://spfbl.net/en/dnsbl/ Even if the provider is offering less then /64 to customers, our DNSBL can list IPv6 of each one. 2018-03-02 10:08 GMT-03:00 Matus UHLAR - fantomas : how/who do

Re: Spammers, IPv6 addresses, and dnsbls

2018-03-02 Thread Matus UHLAR - fantomas
approach to balance spam detection while avoiding fps -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I drive way too fast to worry about cholesterol.

Re: URIBL_BLOCKED

2018-02-15 Thread Matus UHLAR - fantomas
can change with SA rules without your knowledge. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. (R)etry, (A)bort, (C)ancer

Re: URIBL_BLOCKED

2018-02-15 Thread Matus UHLAR - fantomas
signing their zones. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Christian Science Programming: "Let God Debug It!".

Re: Train SA with e-mails 100% proven spams and next time it should be marked as spam

2018-02-14 Thread Matus UHLAR - fantomas
rease probability by training anything too far from BAYES_00 for ham and BAYES_99 for ham -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. LSD will

Re: sa-learn

2018-02-12 Thread Matus UHLAR - fantomas
ery inefficient. Luckily you have been advised a better approaches. Good luck. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I'm not intere

Re: sa-learn

2018-02-11 Thread Matus UHLAR - fantomas
except from making the set of messages smaller? you are not supposed to repeatedly call sa-learn over huge maildir. calling over new mail (or, better, false-positives and false-negatives) is faster and won't eat all your memory. -- Matus UHLAR - fantomas, uh...@fantomas.sk ;

Re: Barracuda Reputation Block List (BRBL) removal from the SA ruleset

2018-02-06 Thread Matus UHLAR - fantomas
o we need to help spammers ? network checks including DNS lookups help much in spam processing, after bayes they are second best mechanism to detect spam. NOT using them is helping spammers. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive

repeating tflags difrective

2018-02-05 Thread Matus UHLAR - fantomas
are rules with high negative score that I don't want to trigger autolearn. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. A day without sunshine is like, night.

Re: Shortcircuit reports only 1 test

2018-01-29 Thread Matus UHLAR - fantomas
(trusting header added by spammer is not a good idea). If not, SA validates SPF and DKIM itself. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu

Re: Scoring Issues

2018-01-27 Thread Matus UHLAR - fantomas
r SPF_HELO_PASS. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. My mind is like a steel trap - rusty and illegal in 37 states.

Re: Scoring Issues

2018-01-27 Thread Matus UHLAR - fantomas
-spam. in fact, spammers exploit this. SPF only talks about FORGERY (often spam sign), not about spamminess. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek

Re: Penalty for no/bad SPF

2018-01-25 Thread Matus UHLAR - fantomas
ld be safe since they do have good SPF records on subdomains: whitelist_auth *@*.nytimes.com this only applies when SPF succeeds so it won't fix their broken SPF :-) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to th

Re: moving spam to junk folder

2018-01-16 Thread Matus UHLAR - fantomas
il to Junk, if it matches spam headerd (X-Spam-Flag: YES). -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I'm not interested in yo

Re: moving spam to junk folder

2018-01-13 Thread Matus UHLAR - fantomas
. you need to configure your MDA (procmail, maildrop, sieve etc) to deliver mail marked as spam to Junk folder. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: srs with spamassassin SPF check

2018-01-10 Thread Matus UHLAR - fantomas
pl, nor mx45-71.futurehost.pl have SPF records, so SPF can not fail here. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. How does cat play with mouse? cat /dev/mouse

Re: FSL_MIME_NO_TEXT and MIME_NO_TEXT

2018-01-09 Thread Matus UHLAR - fantomas
On 09.01.18 10:56, Joseph Brennan wrote: Both FSL_MIME_NO_TEXT and MIME_NO_TEXT are very similar. Both look for a multipart/mixed message with no "text/" part that has an attachment. Combined score is just under 5. That's a lot. Comments? On 09.01.18 19:43, Matus UHLAR - fantom

Re: FSL_MIME_NO_TEXT and MIME_NO_TEXT

2018-01-09 Thread Matus UHLAR - fantomas
good example where similar rules that should not have that big combined score. looking at those scores, one of those rules should be removed, or at least a meta should be created, lowering combined scores (aparently through mass-check) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fa

Re: Question about BAYES_999

2018-01-04 Thread Matus UHLAR - fantomas
pening a small percentage of the time. On 02.01.18 15:39, @lbutlr wrote: Checking my mail I see an incidence rate of this of about 0.5%, which matches the rate you posted earlier. amavis? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receiv

Re: Malformed spam email gets through.

2018-01-03 Thread Matus UHLAR - fantomas
On 1 Jan 2018, at 10:47, Matus UHLAR - fantomas uh...@fantomas.sk> wrote: On 1 Jan 2018, at 11:41 (-0500), Matus UHLAR - fantomas wrote: the gross format in RFCs 822,2822 and 5322 describes message-id consisting of local and domain part, thus is must contain "@". On 01.01.1

Re: Malformed spam email gets through.

2018-01-01 Thread Matus UHLAR - fantomas
is local rule unless someone wants to write a plugin that can detect this dynamically. I've had probelms with a similar rule when I send mail directly from one of mailservers. I've had to replace it by !ALL_TRUSTED && !NO_RELAYS just FYI -- Matus UHLAR - fantomas, uh...@fantomas.s

Re: Malformed spam email gets through.

2018-01-01 Thread Matus UHLAR - fantomas
On 1 Jan 2018, at 11:41 (-0500), Matus UHLAR - fantomas wrote: the gross format in RFCs 822,2822 and 5322 describes message-id consisting of local and domain part, thus is must contain "@". On 01.01.18 12:17, Bill Cole wrote: No, it does not. Re-read the cited sections. From RFC5322

Re: Malformed spam email gets through.

2018-01-01 Thread Matus UHLAR - fantomas
message-id consisting of local and domain part, thus is must contain "@". -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Due t

Re: DMARC and mailing lists (was Re: IADB whitelist)

2017-12-26 Thread Matus UHLAR - fantomas
Matus UHLAR - fantomas skrev den 2017-12-26 18:49: have you never been subscribed to spammers' blacklist without your permission? On 26.12.17 19:01, Benny Pedersen wrote: hopefully apache.org does know how to handle spam you did not narrow your sentence on apache mailing lists, perhap

Re: DMARC and mailing lists (was Re: IADB whitelist)

2017-12-26 Thread Matus UHLAR - fantomas
you never been subscribed to spammers' blacklist without your permission? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Microsoft dick is soft to do no harm

Re: orphan spamd childs?

2017-12-20 Thread Matus UHLAR - fantomas
On 19.12.17 21:47, Pedro David Marco wrote: It has just happened now again... :-( There are 2 spamd child processes in 'S' state... i run spamc  -R can you show us those scores? pastebin please. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I w

Re: rbl

2017-12-19 Thread Matus UHLAR - fantomas
RBL lists. I was looking for samples. you mix up multiple things: 1. DNS blacklists (and whitelistt) at postfix level 2. DNS blacklists (and whitelists) at SA level 3. URI blacklists (and probably whitelist) at SA level 4. manual whitelists at SA level. -- Matus UHLAR - fantomas, uh...@fantomas.s

Re: rbl

2017-12-16 Thread Matus UHLAR - fantomas
On 16.12.17 20:37, Gokan Atmaca wrote: I use Zimbra OCS. How do I use RBL? (Except Postfix ... I just want to use spamassassin.) On Sat, Dec 16, 2017 at 10:04 PM, Matus UHLAR - fantomas wrote: zimbra bundles both postfix and spamassassin. What makes you think you don't use RBL&#x

Re: rbl

2017-12-16 Thread Matus UHLAR - fantomas
On 16.12.17 20:37, Gokan Atmaca wrote: I use Zimbra OCS. How do I use RBL? (Except Postfix ... I just want to use spamassassin.) zimbra bundles both postfix and spamassassin. What makes you think you don't use RBL's? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.f

Re: orphan spamd childs?

2017-12-16 Thread Matus UHLAR - fantomas
Debian Linux)?? maybe a known bug?? or it is maybe just my spamd daemons that hate me for any reason... maybe they are processing mail and will exit after it's done... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to

Re: FIlter

2017-12-06 Thread Matus UHLAR - fantomas
.dnswl.org=127.0.[0..255].1*-3 list.dnswl.org=127.0.[0..255].2*-4 list.dnswl.org=127.0.[0..255].3*-5 -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek rek

Re: HTML_IMAGE_ONLY_* generating too many FP's

2017-12-02 Thread Matus UHLAR - fantomas
d that when you start tuning scores, you can get to hell very fast. unless you do your own mass-checks and tune according to them. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu c

Re: HTML_IMAGE_ONLY_* generating too many FP's

2017-12-02 Thread Matus UHLAR - fantomas
On 28.11.17 19:39, Sebastian Arcus wrote: I'm having more and more problems with the HTML_IMAGE_ONLY_* set of rules recently generating false positives. On 30/11/17 12:45, Matus UHLAR - fantomas wrote: those have lower scorew with BAYES and network rules enabled. configure BAYES and e

Re: HTML_IMAGE_ONLY_* generating too many FP's

2017-11-30 Thread Matus UHLAR - fantomas
es be lowered a bit - or is there anything else to be done - aside from educating all the internet on optimising logos in the email signatures? :-) those have lower scorew with BAYES and network rules enabled. configure BAYES and enable netowrk rules... -- Matus UHLAR - fantomas, uh...@fantom

Re: spamd Will Not Create unix:socket

2017-11-28 Thread Matus UHLAR - fantomas
because /run is on a tmpfs, and because hard links can't cross filesystem boundaries. But I would bet that you have something else sensitive in /run that can be used to gain root. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-

Re: SPF check though external relay

2017-11-13 Thread Matus UHLAR - fantomas
nd internal_networks properly, so SA knows which header to use for SPF checks. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Emacs is a c

Re: Sending spam forwarded by backup MX directly to primary server spam folder

2017-11-13 Thread Matus UHLAR - fantomas
Il 2017-11-07 10:10 Matus UHLAR - fantomas ha scritto: [..] Thus, messages received from the world will be scored locally, messages received from backup MX will be scored on backup MX. Then, your sieve filter will work as expected. On 09.11.17 16:54, Davide Marchi wrote: Well, but could I

Re: Sending spam forwarded by backup MX directly to primary server spam folder

2017-11-07 Thread Matus UHLAR - fantomas
Il 2017-11-05 16:26 Matus UHLAR - fantomas ha scritto: However, you can tell your server to: - not run SA when mail is received from backup MX (I assume you alweays run SA otherwise) - move mail to spam folder when it's scored as spam (I think you have this done already) On 06.11.17

Re: very basic SA-Learn performance question: is 90 seconds or so per token really, really slow or roughly normal?

2017-11-07 Thread Matus UHLAR - fantomas
data into redis database, but I think your problem is still elsewhere -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Save the whales. Collect

Re: Sending spam forwarded by backup MX directly to primary server spam folder

2017-11-05 Thread Matus UHLAR - fantomas
primary server may have better information about which mail is spam and which is not. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Savi

Re: Determining originating source IP

2017-11-03 Thread Matus UHLAR - fantomas
even in SA. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "One World. One Web. One Program." - Microsoft promotional advertis

Re: Sending spam forwarded by backup MX directly to primary server spam folder

2017-11-02 Thread Matus UHLAR - fantomas
system "server2.foo.org", this is caused by "report_safe" SA option, if this is what annoys you, simply set "report_safe 0" on the backup MX -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to

Re: very basic SA-Learn performance question: is 90 seconds or so per token really, really slow or roughly normal?

2017-10-31 Thread Matus UHLAR - fantomas
thing like specifying the mailbox format also help? only if you use mbox format. No, maildir. Not really relevant (I don't think) but: dovecot2-2.2.31_1 dovecot's antspam plugin could fix your problems https://wiki2.dovecot.org/Plugins/Antispam your users would maintain the SA DB the

Re: very basic SA-Learn performance question: is 90 seconds or so per token really, really slow or roughly normal?

2017-10-31 Thread Matus UHLAR - fantomas
with spamd The OP has amavisd running and therefore apparently does not use spamd. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Ch

Re: very basic SA-Learn performance question: is 90 seconds or so per token really, really slow or roughly normal?

2017-10-31 Thread Matus UHLAR - fantomas
ask ever completes (or can be killed) I'll test that for speed on a smaller collection. --no-sync only helps if you have "bayes_learn_to_journal 1" - it's 0 by default. try turning it on. Would something like specifying the mailbox format also help? only if you use

Re: Your header "To: undisclosed-recipients:;" is RFC 822 compliant

2017-10-27 Thread Matus UHLAR - fantomas
group-list] ";" [CFWS] -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. "Where do you want to go to die?" [Microsoft]

Re: Preventing duplicated matches

2017-10-21 Thread Matus UHLAR - fantomas
On 21.10.17 07:45, Pedro David Marco wrote: is there any way to avoid duplicated matches when tflag is set to "multiple"? that's the whole point of multiple. you can limit it to some number by "maxhits" option. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://ww

tflags repeated

2017-10-05 Thread Matus UHLAR - fantomas
Hello, when "tflags" is repeated (e.g. in local.cf and /var/lib/spamassassin), are all flags set or does the next appearance clear flags set formerly? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to th

Re: Writing rules to parse Kaspersky-headers

2017-09-27 Thread Matus UHLAR - fantomas
UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I'm not interested in your website anymore. If you need cookies, bake them yourself.

Re: Writing rules to parse Kaspersky-headers

2017-09-27 Thread Matus UHLAR - fantomas
ere asked to provide samples e.g. on pastebin. Therefore my question "when will the header be added"? 2. how do you integrate SA and kaspersky AV? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this addre

Re: Writing rules to parse Kaspersky-headers

2017-09-26 Thread Matus UHLAR - fantomas
urth, don't you believe kaspersky enough to give first rules small negative score? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Fucking

Re: Increasing spam level for MX backup server?

2017-09-24 Thread Matus UHLAR - fantomas
f the primary server is up? postscreen, if ou use postfix, supports this: http://www.postfix.org/POSTSCREEN_README.html#white_veto -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu

Re: Identifiying PDF phish docs

2017-08-23 Thread Matus UHLAR - fantomas
know there was a PDF OCR plugin of some sort, but I don't recall it being all that effective. Ideas greatly appreciated. I think you mean PDFassassin, but I'd prefer ExtractText both described at https://wiki.apache.org/spamassassin/UnmaintainedCustomPlugins -- Matus UHLAR - fantomas, uh

Re: message/rfc822 to mbox script for use with sa-learn workflow

2017-08-15 Thread Matus UHLAR - fantomas
mailbox format, they are quite useful, although some information may be lost - outlook kind of "sanitizes" the mail, in which case many details helping to trace spam are lost. The best is, to catch mail before it hits microsoft clients or servers. -- Matus UHLAR - fantomas, uh...@f

Re: Bayes auto-learn - not happening, tentative success....

2017-08-11 Thread Matus UHLAR - fantomas
On 10.08.17 20:15, Scott wrote: About the only difference in my old, functioning box and this new "clean" install was the location of the bayes files. Old box: /var/spool/amavisd/.spamassassin/ New box: /etc/mail/bayes On 11.08.17 16:22, Matus UHLAR - fantomas wrote: Do did you ch

Re: Bayes auto-learn - not happening, tentative success....

2017-08-11 Thread Matus UHLAR - fantomas
7;t hurt autolearn don't set the path, that way it should work OOTB. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. The only

Re: Bayes auto-learn - not happening

2017-08-10 Thread Matus UHLAR - fantomas
only need permission for amavis user, not for anyone. Is /etc/mail/bayes writeable by amavisd? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu p

Re: Bayes auto-learn - not happening

2017-08-09 Thread Matus UHLAR - fantomas
quot; - apparently permissions make the directory or files in it unwritable for amavis user. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu p

Re: blacklist_from with whitelist

2017-07-29 Thread Matus UHLAR - fantomas
#x27;s what you mean by "work", it should work. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. He who laughs last thinks slowest.

Re: Direct download link detection

2017-07-26 Thread Matus UHLAR - fantomas
I would buy a Mac today if I was not working at Microsoft. -- James Allchin, Microsoft VP of Platforms --- 10 days until the 282nd anniversary of John Peter Zenger's acquittal -- M

Re: reason why sendmail w/ SA3.4.1 scantime=15.0, delay=00:01:06 w/ SquirrelMail?

2017-07-14 Thread Matus UHLAR - fantomas
MAY cause some delay but the default pyzor timeout is 3.5 seconds -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Posli tento mail 100 svojim

Re: "bout u" campaign

2017-07-13 Thread Matus UHLAR - fantomas
ect server to their nwetwork). -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. Fucking windows! Bring Bill Gates! (Southpark the movie)

Re: URIBL_BLOCKED on 2 Fedora 25 servers with working dnsmasq, w/ NetworkManager service

2017-05-19 Thread Matus UHLAR - fantomas
queries */ [...] zone "combined.njabl.org" { type forward; forward first; forwarders {}; }; see above zone "fulldom.rfc-ignorant.org" { type forward; forward first; forwarders {}; }; rfc-ignorant.org is dead for years. -- Matus UHLAR - fantomas, uh...@fantomas.sk ; ht

Re: Strict/Relaxed DKIM alignment possible with SA?

2017-05-07 Thread Matus UHLAR - fantomas
mpiling opendmarc against libspf2 makes the opendmarc internal SPF > > > checker functional and now the SA SPF checks (triggered by amavis) are > > > firing as well. > On 07.05.17 - 11:46, Matus UHLAR - fantomas wrote: > > I would like to note that SPF can be used without

Re: Strict/Relaxed DKIM alignment possible with SA?

2017-05-07 Thread Matus UHLAR - fantomas
ecks (triggered by amavis) are > firing as well. On 07.05.17 - 11:46, Matus UHLAR - fantomas wrote: I would like to note that SPF can be used without openDMARC, and imho should work in SA itself. Did you (try to) make SPF working on valhalla.nano-srv.net? On 07.05.17 12:05, Thore Boedeck

Re: Strict/Relaxed DKIM alignment possible with SA?

2017-05-07 Thread Matus UHLAR - fantomas
f2 makes the opendmarc internal SPF checker functional and now the SA SPF checks (triggered by amavis) are firing as well. I would like to note that SPF can be used without openDMARC, and imho should work in SA itself. Did you (try to) make SPF working on valhalla.nano-srv.net? On 06.05.17

Re: Strict/Relaxed DKIM alignment possible with SA?

2017-05-06 Thread Matus UHLAR - fantomas
On 06.05.17 15:49, Thore Boedecker wrote: After looking at the headers it became clear what the issue was: It seems that Yahoo (at least yahoo.co.jp) is allowing emails from @gmail.com senders to be sent through their servers. From: Matus UHLAR - fantomas @gmail.com From: and envelope from

Re: Strict/Relaxed DKIM alignment possible with SA?

2017-05-06 Thread Matus UHLAR - fantomas
in has to belong to the 'From:' address? every domain using yahoo mail servers would have to delegate DKIM to yahoo and yahoo would need to sign under all those domains. the same applies about any domain that does DKIM signing (e.g. gmail) that is in fact change in requirements on DK

Re: Strict/Relaxed DKIM alignment possible with SA?

2017-05-06 Thread Matus UHLAR - fantomas
FREEMAIL domains? what does Sender: header give us in addition to envelope from? this mail already hit FREEMAIL_REPLYTO -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT

Re: DKIM_VALID EnvelopeFrom

2017-05-06 Thread Matus UHLAR - fantomas
On Fri, 5 May 2017, David Jones wrote: I think I would have to write a simple SA plugin to compare the envelope-from with the DKIM signature domain to see if they matched then I could use a meta rule to glue all of this together. From: Matus UHLAR - fantomas agreed but there's stil

Re: DKIM_VALID EnvelopeFrom

2017-05-05 Thread Matus UHLAR - fantomas
enticated, including headers like From:. what's the point of checking if SPF and DKIM domains match? This way authentic (but forwarded, e.g. through mailing lists) mail will get "caught" but what's the poit of it? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fanto

Re: DKIM_VALID EnvelopeFrom

2017-05-05 Thread Matus UHLAR - fantomas
On 05.05.17 11:37, Merijn van den Kroonenberg wrote: I want to test in SA if the Envelope From domain is DKIM_VALID. the envelope from can't be DKIM-VALID. DKIM validated message content, including some of its headers, not envelope from address. -- Matus UHLAR - fantomas, uh...@fantom

Re: Outgoing email without DMARC

2017-05-02 Thread Matus UHLAR - fantomas
7 08:09, Marc Perkel wrote: The rejection message specified dmarc as the reason. show us the message. Doesn't it just recommmend using DMARC as one of ways to fix your problem? -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail ad

Re: ANY_BOUNCE_MESSAGE questions

2017-05-02 Thread Matus UHLAR - fantomas
On Mon, 2017-05-01 at 17:13 +0200, Matus UHLAR - fantomas wrote: Is there something on vbounce that does notappl for you? loading it and settings proper whitelist_bounce_relays should hit all bounces that did not come as response to mail from your systems... On 01.05.17 19:11, Martin Gregorie

Re: FORGED_HOTMAIL_RCVD2 and legit hotmail

2017-05-01 Thread Matus UHLAR - fantomas
, they should clean it up otherwise their SPF record is pretty useless (if it's not another Micro$oft attempt to make SPF useless) -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu ch

Re: ANY_BOUNCE_MESSAGE questions

2017-05-01 Thread Matus UHLAR - fantomas
notappl for you? loading it and settings proper whitelist_bounce_relays should hit all bounces that did not come as response to mail from your systems... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Va

Re: ANY_BOUNCE_MESSAGE questions

2017-05-01 Thread Matus UHLAR - fantomas
yes saying "insufficient data for an opinion". score BAYES_50 0 0 2.00.8 not that I disagree with this score, but it does not have 0 score... -- Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address

<    3   4   5   6   7   8   9   10   11   12   >