Re: skip virus scan for a specific sender.

2012-07-22 Thread Michael Scheidell
ant to continue with blocking PUA except for this email id (for the time being). Please let me know, how can I achieve this. zip it with a password. Sounds like 'incomtaxindiafiling' should be encrypted anyway. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SE

amavisd-new 2.7.2 vs 2.8.0:?

2012-07-03 Thread Michael Scheidell
Q what are he differences?, why two versions? (and, Mark: for FreeBSD ports, do we need two different versions in ports?) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrus

Re: Disclaimer variables passed from amavis to altermime.

2012-07-01 Thread Michael Scheidell
added mine, the mailing list adds theirs, aol adds theres, and one email out might have three. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Comp

Re: Hitman spam

2012-06-15 Thread Michael Scheidell
rs came in from yahoo and there was nothing interesting in the score. call local law enforcement, get them to order the logs of their mail servers. are you a federally protected entity? call the FBI. put the idiot behind bars so he can get new special friend. -- Michael Scheidell, CTO o: 561-999-

Re: AMaViS doesn't restart normally

2012-05-31 Thread Michael Scheidell
of *.pid files. p@rick -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security Product * Certified SN

Re: Skip virusscan for some Sender

2012-05-19 Thread Michael Scheidell
they probably won't be smart enough to rename that exe inside the password protected zip file. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company

Re: Strange Spamassassin scores

2012-05-19 Thread Michael Scheidell
. Simon with the spammy domain names tagged as ham? whitelist the sender, use a different policy for sending ip, whitelist the subjectline, anything but auto learn spammy domains as ham. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * B

Re: Is /var/amavis/tmp cleaned up on any interval?

2012-05-02 Thread Michael Scheidell
On 5/2/12 8:45 AM, Marko Weber wrote: or do i have to do this by custom script? thanks marko custom script. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Prod

Re: "tagged" content class?

2012-04-25 Thread Michael Scheidell
[CONTENT] in Subject line on inbound (like [SPAM] in subject in inbound) can I share EXACTLY how I did it? no, not really. but this should get you started. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Pr

Re: amavis "fails to parse" 'uridnsbl_skip_domain ...' in spamassassin local config ?

2012-04-06 Thread Michael Scheidell
Sorry, one clue rule. You are on your own now. -- Michael Scheidell, CTO >|SECNAP Network Security -Original message- From: "loc...@mm.st" To: Michael Scheidell , "amavis-users@amavis.org" Sent: Fri, Apr 6, 2012 20:03:16 GMT+00:00 Subject: Re:

Re: amavis "fails to parse" 'uridnsbl_skip_domain ...' in spamassassin local config ?

2012-04-06 Thread Michael Scheidell
cal/etc/mail/spamassassin/* /usr/local/etc/mail/spamassassin/aa_scores.cf:uridnsbl_skip_domain mailchimp.com list-manage.com rule18.com ionspam.net com.ionspam.net net.ionspam.net secnap.com hackertrap.net spammertrap.com -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP

Re: Problem with @banned_files_lovers_maps...

2012-03-20 Thread Michael Scheidell
deliver the email without the attachment. amavisd-new does not have any code that would enable it to do this. Since it can't strip out attachments, then it didn't strip out the attachment. These are not the droids you are looking for. -- Michael Scheidell, CTO o: 561-999-5000 d: 56

Re: amavis is not able to work please help

2012-02-01 Thread Michael Scheidell
On 2/1/12 10:23 AM, Mark Martinec wrote: Indeed. The SEGV (signal 11) crash on a smtpd service needs to be investigated and resolved. good chance OP is using a different db for transport/aliases/, etc and needs to recompile the *.db files -- Michael Scheidell, CTO o: 561-999-5000 d: 561

FreeBSD port ja-p5-Mail-SpamAssassin needs adoption

2012-01-14 Thread Michael Scheidell
use email address reference: scheid...@freebsd.org) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Sec

Re: Messages incorrectly getting quarantined

2012-01-09 Thread Michael Scheidell
0.0 HTML_MESSAGE BODY: HTML included in message 1.2 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag 0.1 RDNS_NONE Delivered to internal network by a host with no rDNS

Re: Custom disclaimers

2011-12-19 Thread Michael Scheidell
/auser.txt or such.. Tom -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security Product * Certified SNO

Re: Priority on white/black lists

2011-12-15 Thread Michael Scheidell
her way? How does a domain w/b list affect that domain's recipients? How can we know the priority order in the case we have both domain w/b lists and recipient's w/b lists? Thanks! -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corpora

Re: Headers are not inserted.

2011-12-01 Thread Michael Scheidell
tcpflow and see if you can catch it? being actually BOUNCED to/from the exchange server? are they spam or legit? Thanks, Andi -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusi

Freebsd Users: Mail-SpamAssassin update available

2011-11-29 Thread Michael Scheidell
Freebsd SA port. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security Product * Certifie

Re: central amavis machine for in and outbound

2011-11-17 Thread Michael Scheidell
clustering is REALLY hard if you go past two. Regards, Tobias -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Secur

Re: 2.7.0: bypass clamd scanning when daemon did not respond

2011-10-24 Thread Michael Scheidell
e clamdscan {filename}' then type 'time clamscan {filename}' if you use clamscan as your backup, your cpu will peg with just 3 or for processes, and amavisd will timeout anyway. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corpora

Re: MYNETS not working for mails send from shell

2011-10-16 Thread Michael Scheidell
= qw( 127.0.0.0 [::1] [FE80::]/10 [FEC0::]/10 10.8.0.0/24) shell might be 'special'. try adding 0.0.0.0/32 -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Preventio

Re: amavisd-release not working when message contains empty X-Envelope-To-Blocked

2011-10-10 Thread Michael Scheidell
Well, if they were delivered, they wernt blocked, they were quarantined either . Looks like you were trying to implement something that is not supported by amavis so, I suspect you're not going to get your patch applied. -- Michael Scheidell, CTO SECNAP Network Security -Original me

Re: amavisd-release not working when message contains empty X-Envelope-To-Blocked

2011-10-05 Thread Michael Scheidell
nvelope-To-Blocked in it? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security Product * Certified SNO

Re: OpenSSL error: data too large for key size

2011-09-30 Thread Michael Scheidell
a=rsa-sha256, c=relaxed/relaxed, s=mail, i=@jobmensa.de, invalid (public key: OpenSSL error: too long) What are those errors? sender has a borked dkim public key. <http://dkimcore.org/c/keycheck> put in 'mail' for selector put in jobmensa.de for domain. -- Michael Scheidell, CTO

Re: OpenSSL error: data too large for key size

2011-09-30 Thread Michael Scheidell
PIxE4d0Qfw5i/3h63/wRal6XoJq5OqE+QIO0LxwGXRpMa5fiiEVwWeqmR70FmFUwTFK4NN" -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company

Re: Amavisd-new Error Information

2011-09-23 Thread Michael Scheidell
uickly, ip addresses that start to send out bulk email). example: your ip, looks 100% clean. <http://www.rhyolite.com/cgi-bin/reps.cgi?tgt=76.74.238.135> vs one of the 'ESP' s. (exact target) <http://www.rhyolite.com/cgi-bin/reps.cgi?tgt=207.250.68.26> 68% bulk email.

Re: Spam Score Analysis

2011-09-08 Thread Michael Scheidell
wrong. it his RCVD_IN_PBL rule. since you neglected to include any header information at all, #2 is just a guess. concentrate on #2, google, see FAQ's on amavisd and SA web sites. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation

Re: somitimes occur Blocked BANNED

2011-08-31 Thread Michael Scheidell
SEND THE EMAIL HERE. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security Product * Certified SN

Re: Understanding cutoff-dsn

2011-08-26 Thread Michael Scheidell
if a spam scores < 6.3, the sender gets a 'bounce' (you might be a spammer if) if it also has valid spf or dkim, and its under 18, the sender also gets a bounce. so, forged spammers < 6.3 will create backscatter. spammers who spam from valid accounts will get bounces till

Re: virus name does not appear in maillog

2011-08-25 Thread Michael Scheidell
clamd.log. is there a reason you want the virus name in the mail log? and that the clamd.log isn't good enough? no need to see who virus went TO, its quarantined. no need to know who virus came FROM, since its almost always forged. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2

Re: virus name does not appear in maillog

2011-08-24 Thread Michael Scheidell
tmp/amavis-20110822T144646-26543/parts/p004: *Eicar-Test-Signature * look again -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011

Re: pilot error? or idiots at microsoft?

2011-08-12 Thread Michael Scheidell
ssassin --lint' Aug 12 14:06:00.917 [8635] warn: netset: cannot include 127.0.0.0/8 as it has already been included so, question begs: I think this is in default local.cf: grep networks local.cf internal_networks 192.168/16 172.16/12 10/8 should SA add 169.254/8 by default for completen

Re: amavisd-release twice?

2011-08-12 Thread Michael Scheidell
amavisd-release doesn't care. look at mail logs, see where it went. put a packet trace on (tcpdump/wireshark) see if /where it went. look at logs on receiving mail server. if spam is in filesystem, look at it there. zmore /var/virus/spam/s/spam-mail.gz -- Michael Scheidell, CTO o

Re: pilot error? or idiots at microsoft?

2011-08-10 Thread Michael Scheidell
On 8/10/11 10:33 AM, Michael Orlitzky wrote: On 08/10/11 10:26, Michael Scheidell wrote: so, what brain decided it would be ok to use 169.* addresses for their internal ip's? was it microsoft? (var says that ms uses these for their internal clustering ip's for clustered exchange ser

pilot error? or idiots at microsoft?

2011-08-10 Thread Michael Scheidell
-0400 (EDT) received:from MBX1.client.local ([169.254.1.69]) by MBX2.client.local ([169.254.2.63]) with mapi id 14.01.0289.001; Wed, 10 Aug 2011 09:57:51 -0400 -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011

Re: content classification

2011-08-08 Thread Michael Scheidell
our custom rules, make sure they are uniq names. SPAM_CAT_X (sex SPAM_CAT_P (porn SPAM_CAT_D (drugs) in amavisd.custom, scan the rules triggered and set a new flag in your new field in the msgs table. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Securit

Re: tweaking the SA scores

2011-07-30 Thread Michael Scheidell
27;local.cf' and change scored there. That didn't change anything. I also tried to copy that v330.pre file to /var/lib/amavis/.spamassassin/ , making sure that the file belongs to the amavis user and group. That didn't give any more result... What do I miss? Thanks by advance :)

Fwd: [Clamav-announce] announcing ClamAV 0.97.2

2011-07-25 Thread Michael Scheidell
heads up: mostly to those who had problems with clamav 0.97.1 hanging. also, heads up on the (soon to be missing .UNOFFICIAL suffix on thrd party sigs.. in case you have amavisd-rules to treat these as spam and viruses) Original Message Subject:[Clamav-announce] ann

Re: Performance testing

2011-07-22 Thread Michael Scheidell
group. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security Product * Certified SNORT Integra

broken emails from techtarget/crn mag? omeda communications?

2011-07-22 Thread Michael Scheidell
3-11-12 Ref:http://whois.arin.net/rest/net/NET-205-162-40-0-1 OrgName:Omeda Communications -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product

Re: Crypt-OpenSSL-RSA broken under perl 5.14, consequently DKIM checks in SpamAssassin

2011-07-21 Thread Michael Scheidell
hecks in SpamAssassin and in amavisd fail. Also fixed in the Crypt-OpenSSL-RSA 0.27 release. Very good! Thank you for the information. Mark Q, is 0.27 needed for ANY version of perl to fix this bug? or just perl >= 501400 (5.14.0)? does amavisd-new also need this minimum version? --

Re: Fwd: please unsub fredrick.anderson.Re: selectively NOT archiving

2011-07-20 Thread Michael Scheidell
On 7/20/11 5:30 PM, Benny Pedersen wrote: On Wed, 20 Jul 2011 17:17:49 -0400, Michael Scheidell wrote: for failure to stop stupid ooo messages to an email list. yes its not helping to cry here, only frederik can excuse for not drop ooo msgs on bulk mails unless someone with admin

Fwd: please unsub fredrick.anderson.Re: selectively NOT archiving

2011-07-20 Thread Michael Scheidell
for failure to stop stupid ooo messages to an email list. Received: from www.fc.norrkoping.se (nksupport.fc.norrkoping.se [194.68.142.18]) by smtprelay1.norrkoping.se (Postfix) with ESMTP id 7C3DB12721 for; Wed, 20 Jul 2011 23:12:00 +0200 (CEST) Message-ID: X-FC-Thread-ID: 3b9aca00-e

selectively NOT archiving

2011-07-20 Thread Michael Scheidell
{ if(! $already_quarantined && $clean_quarantine_method =~ /sql:/) { do_log(0, "CUSTOM: UNWANTED = $msg_size"."k > ".($sa_mail_body_size_limit/1024)."k"); # I want to NOT archive if it hits here. } } -- Michael Scheidell, CTO o: 561-999-5000

please unsub fredrik.andersson. Fwd: Re: Fwd: mx1 amavis-logwatch

2011-07-17 Thread Michael Scheidell
you would think email admins would know better than adding to the spam/backscatter. Original Message Subject:Re: Fwd: mx1 amavis-logwatch Date: Sun, 17 Jul 2011 12:43:57 +0200 From: Fredrik Andersson To: Detta är ett automatsvar. Jag har semester och komm

Re: Fwd: mx1 amavis-logwatch

2011-07-17 Thread Michael Scheidell
.conf, which points to the backup clamd scanner. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security

Re: Redirect all dsn to single address?

2011-07-12 Thread Michael Scheidell
s you know of it, maybe you can be of assistance. Hi Lars, For me it seems a bit strange to have this on the master.cf. But I have no idea how your configuration is like. I have it in my main.cf together with all other restriction classes. HTH, Mikael -- Michael Scheidell, CTO o: 561-999-5000

Re: AV timeout?

2011-07-08 Thread Michael Scheidell
table. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security Product * Certified SNORT In

Re: [clamav-users] AV timeout?

2011-07-05 Thread Michael Scheidell
ly.cvd for 0.97.1 builds?) This mean no action needs to be taken for 0.97.1, and I assume a 0.97.2 is in the works? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Pro

Re: Perl warnings after 2.7.0 upgrade

2011-07-04 Thread Michael Scheidell
What version of perl ? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security Product * Certifie

Re: How to perform archiving of headers only?

2011-07-03 Thread Michael Scheidell
interesting hack to only archive the first two chunks might work. but, you need to make sure you only limit the archive, and still store anything quarantined. might be able to do it with a amavisd.custom hack. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Secur

Re: AV timeout?

2011-06-29 Thread Michael Scheidell
nning one gest me this: 30351 clamav 3 440 181M 159M ucond 1 0:00 0.00% clamd (yes, brackets must be something freebsd does every now and than) its the RES of 0K and umtxn when hung, and 159M when NOT hung that is intertesting. where did the ram go? and, no, I didn't run

Re: AV timeout?

2011-06-29 Thread Michael Scheidell
Yeah, same here. I still want to put a timeout in amavisd so that my secondary takes over. anyone help? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot

Re: AV timeout?

2011-06-29 Thread Michael Scheidell
otally kill clamd with a sigsegv. Yeah, same here. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Se

Re: AV timeout?

2011-06-29 Thread Michael Scheidell
--- Original Message Subject: Re: [clamav-users] 0.97.1 rumor pile? bad safebrowsing update file? Date: Tue, 28 Jun 2011 22:23:20 +0300 From: Török Edwin Reply-To: ClamAV users ML To: On 06/28/2011 10:01 PM, Michael Scheidell wrote: On 6/28/11 2:49 PM, Török Edw

AV timeout?

2011-06-28 Thread Michael Scheidell
4_8,1 (amavisd new 2.6.4 with freebsd patches from ports) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot Company Finalist 2011 * Best Email Security

Freebsd Port for SpamAssassin 3.3.2 posted

2011-06-27 Thread Michael Scheidell
you loaded the pre-official port from our web site, you are advised to install the official port. Remember that SA does not come with current rules, so while installing the port you must run sa-update, or you must run sa-update after you install the port. Happy Hunting! -- Michael Scheidell

Re: Amavisd-release sends messages back to quarantine?

2011-06-24 Thread Michael Scheidell
t did this with 2.6.5, advice welcome. diff your amavisd.conf vs the stock one. you might have something set strange. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention

Test port for SpamAssassin for Freebsd

2011-06-24 Thread Michael Scheidell
ake PR's or support requests for older versions, but it looks like it still compiles on 6.4 and 7.3 -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot

Re: soft blacklisting of IP-Ranges with www.xxx.yyy.zzz/aa

2011-06-22 Thread Michael Scheidell
On 6/22/11 11:28 AM, Michael Reincke wrote: Hello, is it possible to soft blacklist mails sent from certain IP-ranges. www.xxx.yyy.zzz/aa just make an SA rule on received, score high enough that it is blacklisted (70? 100?) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259

Re: Spam Scanning Larger Messages

2011-06-14 Thread Michael Scheidell
e scanning giving the attachment and image type spams we see periodically these days? so, you want the spammers to just attach a 500K pdf, or image and you give them a free pass? Just curious, what advantage do you think this will give you? -- Michael Scheidell, CTO o: 561-999-5000 d: 56

Re: bayes causes high queues

2011-06-02 Thread Michael Scheidell
queues drop quickly. Any idea's where to start looking would be appreciated. disable auto expire bayes: bayes_auto_expire 0 use mysql bayes and innodb tables. bayes_store_module Mail::SpamAssassin::BayesStore::MySQL -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >

Re: email with Passed SPAM

2011-05-27 Thread Michael Scheidell
e level at which it is KILLED. if you want suspected spam sent to your MTA to process the headers, then look for the x-spam-flag header. if you want email like this quarantined, then adjust your settings so that anything > 4.5 is quarantined, not just flagged. (read amavis documentation)

Re: Notify Sender when a virus is detected

2011-05-23 Thread Michael Scheidell
point to a perl script that can notify the user when first one is sent. maybe limit 1 per hour. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Hot

Re: Notify Sender when a virus is detected

2011-05-23 Thread Michael Scheidell
ks so we can blacklist you now for backscattering all those forged viruses back to people who didn't send them. it will save us the trouble of reporting you to your ISP and having you blacklisted at backscatter.org. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN:

Re: blocking encrypted zips?

2011-05-17 Thread Michael Scheidell
qr'.*' => 0 ]), ); amavisd does know its protected, the subject line gets changed to *** UNCHECKED *** -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Best Intrusion Prevention Product, Networks Produ

blocking encrypted zips?

2011-05-17 Thread Michael Scheidell
using sql/policy based attachment quarantining in amavisd-new. want to add blocking UNDECIPHERABLE to sql based policy. what is best way to do it? I think I can have clamav do it, or amavisd-do it, right? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SEC

Re: Spamassassin configuration files not working

2011-05-13 Thread Michael Scheidell
On 5/13/11 9:04 AM, Mark Martinec wrote: , bypassing of spam checks, white and blacklisting (basic and DKIM-based), something new? this isn't sql based, is it using mailaddr and wb tables, is it? how does amavis dkim based whitelisting differ from SA whitelist_from_auth? (ish) -- Mi

Re: hi! issues with soft whitelist / amavis / SA

2011-05-10 Thread Michael Scheidell
r and gets quarantined as spam; however, the mail is legitimate. use SA, 'whitelist_rcvd_from' or something like that, in local.cf. or, you whitelist the email address spammers will use. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP N

Re: Spamassassin configuration files not working

2011-04-29 Thread Michael Scheidell
pamd, you start amavis. #2, look for (more config info) in ../etc/amavisd.conf #3, you say 'not using system conf files'.. why do you say that? #4, look for postfix integration docs on amavis web site also. (look for 'filter' in main.cf also) -- Michael Scheidell, CTO o: 561-999-

Re: Message causes amavis to stop processing

2011-04-27 Thread Michael Scheidell
On 4/27/11 3:52 PM, Alex wrote: eval code: rawbody, priority 0 Apr 27 15:49:57.236 [9943] dbg: rules: compiled rawbody tests delete the compiled directory, disable the complied plugin, run again. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Netw

Re: Message causes amavis to stop processing

2011-04-27 Thread Michael Scheidell
How do I debug this? get a 'msg' version of the email (not a postfix, postcat version) so 'spamassassin -D < {msg}' and watch it. are you running caching dns servers? Thanks for any suggestions. Alex -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*13

Re: High CPU usage (need help)

2011-04-25 Thread Michael Scheidell
to parse an email isn't too bad, especially when 54% of it is 'learn' (I assume you are using default db4 plugin for bayes?). if so, switch to mysql plugin. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation

Re: High CPU usage (need help)

2011-04-25 Thread Michael Scheidell
On 4/25/11 12:18 PM, david touzeau wrote: We can found that tests_pri_0 rule take 90% of time, is it possible to disable this rule ? than it is one of your rules. disable compiled rules, and run again, see if you can find out which one. search recent archives for this issue. -- Michael

Re: High CPU usage (need help)

2011-04-25 Thread Michael Scheidell
ry to identify the rules and email that are causing the problem run spamassassin -D against one of the emails. look at timing. identify which part of sa is causing problem and fix it. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Cor

Re: X-Amavis-Alert: BAD HEADER MIME error: error: part did not end with expected boundary

2011-04-11 Thread Michael Scheidell
ch part needs a defined start and end boundary: this one did not have a proper end boundary. send a link to the email RFC's on mime attachments to the sender. , 'part did not end with expected boundary' -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SE

Re: how to enable notification to the virus sender user

2011-04-01 Thread Michael Scheidell
% -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Best Intrusion Prevention Product, Networks Product Guide * Certified SNORT Integrator * Hot Company Award, World Executive Alliance * Best in Email Security, 2010 Netw

Re: how to enable notification to the virus sender user

2011-03-31 Thread Michael Scheidell
lay...@gmail.com> -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Best Intrusion Prevention Product, Networks Product Guide * Certified SNORT Integrator * Hot Company Award, World Executive Alliance * Best

Re: Can't locate version/vpp.pm?

2011-03-21 Thread Michael Scheidell
/SPF.pm /usr/lib/perl5/site_perl/5.12.3/Mail/SPF.pm you have vendor_perl and site_perl.. your perl install is borked. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Best Intrusion Prevention Product, Networks Product Gu

Re: Can't locate version/vpp.pm?

2011-03-21 Thread Michael Scheidell
On 3/21/11 8:28 AM, Michael Scheidell wrote: On 3/21/11 8:20 AM, Ralf Hildebrandt wrote: fetch_modules: error loading optional module Mail/SPF.pm: Can't locate version/vpp.pm in @INC (@INC contains: lib interesting.. what version of Mail::SPF do you have? did you just upgrade to perl

Re: Can't locate version/vpp.pm?

2011-03-21 Thread Michael Scheidell
on any of our systems. and a grep of Mail/SPF.pm doesn't show it looking for it. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Best Intrusion Prevention Product, Networks Product Guide * Certified SNORT I

Re: limit archive size?

2011-03-18 Thread Michael Scheidell
ght have more fields I need to populate. my($conn,$msginfo,$hdr_edits_inherited,$recips_ref, $quarantine_method,@snmp_id) = @_; -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Best Intrusion Prevention Product

Re: limit archive size?

2011-03-11 Thread Michael Scheidell
On 3/11/11 11:54 AM, Mark Martinec wrote: f ($msginfo->msg_size< 1024*1024) { Amavis::do_quarantine($conn,$msginfo, undef, ['archive-quarantine'], 'sql:'); } interesting... ok, so than it just won't archive it. thanks. that should work. -- Mi

limit archive size?

2011-03-10 Thread Michael Scheidell
limit what was archived in the sql-archive? yes, I guess I could add a trigger that deleted everything with chunk_id > 10. but, is there an easier way? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 *| *SECNAP Network Security Corporation * Best Intrusion