Re: [Clamav-users] Help with clamav-milter white list

2009-10-28 Thread Steve Basford
 I am getting some legitimate mail tagged as SPAM. Below is the header
 from one such e-mail.

 X-Virus-Status: Infected (Sanesecurity.Phishing.Pay.6348.UNOFFICIAL)
 Subject: freebsd-stable Digest, Vol 328, Issue 3

Hi,

Just a quick note to add that this wasn't a False Positive as such, a
phishing email was posted to the freebsd-stable list and as this is a
digest email, it got blocked too.

Still a good idea to whitelist it though.

Cheers,

Steve
Sanesecurity

___
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


[Clamav-users] Help with clamav-milter white list

2009-10-27 Thread Jerry
I am getting some legitimate mail tagged as SPAM. Below is the header
from one such e-mail.

Return-Path: owner-freebsd-sta...@freebsd.org
Delivered-To: ges...@yahoo_.com
Received: from scorpio.seibercom.net (localhost [127.0.0.1])
by scorpio.seibercom.net (Postfix) with ESMTP id EC70F228A5
for ges...@yahoo_.com; Tue, 27 Oct 2009 08:04:33 -0400 (EDT)
X-Virus-Status: Infected (Sanesecurity.Phishing.Pay.6348.UNOFFICIAL)
X-Virus-Scanned: clamav-milter 0.95.2 at scorpio.seibercom.net
X-Apparently-To: ges...@yahoo.com via 98.136.165.127; Tue, 27 Oct 2009 05:02:36 
-0700
X-YMailISG: 
ZBdeIw0WLDsFSGrTxcmHOtzn4IfksXNL3v.qhV5ugvuPnzRn2QkfFmE4xV41U.lL0aNH5jroOi8MvL77RvEKDbPkqlsecmiOI0uSF4G8MmNx5YDDmSSlOvYVnTCN02KR6dwWRoMf4Ur8qkc42QlWsQko678yretOrDfnbbuULf5FyDQoIw.KmCQ24TX22MJZ7vJLsoQXRCF2fT_lBAL6drHRzi60.zBV3lJJgy6dTOPacIsaLxtZtFmUKrRRcY59BgIozl6ugBm8iTQYI4dEvcU_kkBh5FX8NGwuBltUcooSqMb0FxYP15BZQ42HDNzPDd8BuLKgx13Oxhskse_yQQsxVRIPhSDziPgGym4k5ZoUbdIBTwvt8iTJrWCD6.WjlpQqfoG3oX_thKLqsU6JwNkI5r4rOfCMLqqSKTotBdGo69clic9hnOvWExgIJMXwetLTz320bm84JNHPs982ME9mNN5hVrGQDxwzTLuS00GcFnGUnUVWhD3u_fziHZ1p
X-Originating-IP: [69.147.83.53]
Authentication-Results: mta330.mail.mud.yahoo.com  from=freebsd.org; 
domainkeys=neutral (no sig)
Received: from pop-ssl.plus.mail.a06.yahoodns.net [206.190.53.40]
by scorpio.seibercom.net with POP3 (fetchmail-6.3.11)
for ges...@yahoo_.com (single-drop); Tue, 27 Oct 2009 08:04:33 -0400 
(EDT)
Received: from 69.147.83.53  (EHLO mx2.freebsd.org) (69.147.83.53)
  by mta330.mail.mud.yahoo.com with SMTP; Tue, 27 Oct 2009 05:02:35 -0700
Received: from hub.freebsd.org (hub.freebsd.org [IPv6:2001:4f8:fff6::36])
by mx2.freebsd.org (Postfix) with ESMTP id A991D176442;
Tue, 27 Oct 2009 12:00:23 + (UTC)
Received: from hub.freebsd.org (localhost [127.0.0.1])
by hub.freebsd.org (Postfix) with ESMTP id 14C6E10657D6;
Tue, 27 Oct 2009 12:00:21 + (UTC)
(envelope-from owner-freebsd-sta...@freebsd.org)
Content-Type: multipart/mixed; boundary0013662984==
MIME-Version: 1.0
From: freebsd-stable-requ...@freebsd.org
Subject: freebsd-stable Digest, Vol 328, Issue 3
To: freebsd-sta...@freebsd.org
Reply-To: freebsd-sta...@freebsd.org
X-BeenThere: freebsd-sta...@freebsd.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Production branch of FreeBSD source code freebsd-stable.freebsd.org
List-Unsubscribe: http://lists.freebsd.org/mailman/listinfo/freebsd-stable, 
mailto:freebsd-stable-requ...@freebsd.org?subject=unsubscribe
List-Archive: http://lists.freebsd.org/pipermail/freebsd-stable
List-Post: mailto:freebsd-sta...@freebsd.org
List-Help: mailto:freebsd-stable-requ...@freebsd.org?subject=help
List-Subscribe: http://lists.freebsd.org/mailman/listinfo/freebsd-stable,
mailto:freebsd-stable-requ...@freebsd.org?subject=subscribe
Sender: owner-freebsd-sta...@freebsd.org
Errors-To: owner-freebsd-sta...@freebsd.org
Message-Id: 20091027120021.14c6e1065...@hub.freebsd.org
Date: Tue, 27 Oct 2009 12:00:21 + (UTC)

Now, if I understand it correctly, just putting the following:
From:freebsd-stable-requ...@freebsd.org sans quotation marks in a text
file and setting: Whitelist /etc/whitelisted_addresses, assuming that
the file actually exists, would notwork. Maybe that would be to easy.

Now, would this work: from:hub.freebsd.org? I am having a hard time
figuring out exactly what needs to be in that file to white-list
mail. :-(

-- 
Jerry
ges...@yahoo.com

|===
|===
|===
|===
|

You can't hug a child with nuclear arms.

___
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml


Re: [Clamav-users] Help with clamav-milter white list

2009-10-27 Thread aCaB
Jerry wrote:
 I am getting some legitimate mail tagged as SPAM. Below is the header
 from one such e-mail.
 
 Return-Path: owner-freebsd-sta...@freebsd.org
[...]
 From: freebsd-stable-requ...@freebsd.org
[...]
 Now, if I understand it correctly, just putting the following:
 From:freebsd-stable-requ...@freebsd.org sans quotation marks in a text

Jerry,
You should use something like From:owner-freebsd-sta...@freebsd.org


 Now, would this work: from:hub.freebsd.org? I am having a hard time
 figuring out exactly what needs to be in that file to white-list
 mail. :-(

No. Whitelisting based on the Received header is not supported as it
doesn't make much sense.

-aCaB
___
Help us build a comprehensive ClamAV guide: visit http://wiki.clamav.net
http://www.clamav.net/support/ml