Re: [Mimedefang] Discarding fake MXs

2004-03-22 Thread Kenneth Porter
--On Monday, March 22, 2004 7:49 PM -0600 Ben Kamen <[EMAIL PROTECTED]> wrote: Well, we do that for a reason... it sends spammers to the next (unreachable) MX point after failing to send spam to the primary. I used to use 127.0.0.1 - but people like SBC block incoming mail if the remote's have an

Re: [Mimedefang] Greylisting database question

2004-03-22 Thread Kenneth Porter
--On Monday, March 22, 2004 2:10 PM -0500 Todd Aiken <[EMAIL PROTECTED]> wrote: I just implimented on our site the greylisting example as posted to the list by Steven Rocha, which seems to be working. I notice though that the filename of where the database is stored is /var/spool/MIMEDefang/.gr

[Mimedefang] Sendmail Defers when CLAMD scans take too long

2004-03-22 Thread Roland Pope
Hi, I am running MD 2.41 on RedHat 9 with sendmail 8.12.8 (Plus security patches) and ClamAV 0.68. This is running on a Pentium III 1.2GHZ with 1Gb of ram. I am running /var/spool/MIMEDefang on a ramdisk. When a user sends an email with a 13 Mb (encoded), word document attachement, CLAMD starts us

Re: [Mimedefang] Discarding fake MXs

2004-03-22 Thread Justin
On Mon, 22 Mar 2004, Ben Kamen wrote: > Well, we do that for a reason... it sends spammers to the next > (unreachable) MX point after failing to send spam to the primary. I used > to use 127.0.0.1 - but people like SBC block incoming mail if the > remote's have any MX's set like that (poo!)...

RE: [Mimedefang] Re: email wire tap

2004-03-22 Thread Richard Laager
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 > Comments or flames on this design? I think you might be over thinking this... Depending on your setup, you might be able to do something like this: In filter_begin(): -- totally untested # The $RelayAddr check prevents loops. if ($RelayAddr ne

Re: [Mimedefang] Re: email wire tap

2004-03-22 Thread David F. Skoll
On Mon, 22 Mar 2004, Michael Mondy wrote: > Previous replies in this thread have suggested using add_recipient() and > resend_message(). However, neither of these methods will preserve the > actual recipients. That doesn't seem to meet the intent of a wiretap > effort. That's pretty easy to do;

Re: [Mimedefang] Latest MIME-Tools

2004-03-22 Thread Lucas Albers
Justin said: > I almost never use any outward facing daemons that aren't compiled from > source. I compile just about everything from source if given the > opportunity. RH is terrible about keeping up with the latest greatest > unless it involves a critical security fix. RH is also terrible abo

Re: [Mimedefang] Discarding fake MXs

2004-03-22 Thread Ben Kamen
Well, we do that for a reason... it sends spammers to the next (unreachable) MX point after failing to send spam to the primary. I used to use 127.0.0.1 - but people like SBC block incoming mail if the remote's have any MX's set like that (poo!)... Oh well. -Ben Andrea Venturoli wrote: Hell

Re: OT: Gentoo, Red Hat, etc. (was Re: [Mimedefang] Latest MIME-Tools)

2004-03-22 Thread Lucas Albers
Kelson Vibber said: > At 01:28 PM 3/22/2004, Justin wrote: >>RPM is really quite lame. If you ever want to really annoy RPM uninstall >>the very dated version of Perl and all it's various modules that come >> with >>RH and compile and install the latest greatest from source. RPM will >>never for

[Mimedefang] Re: email wire tap

2004-03-22 Thread Michael Mondy
I've been asked the feasibility of doing something similar. There are also commercial products which work by snooping the network traffic. Previous replies in this thread have suggested using add_recipient() and resend_message(). However, neither of these methods will preserve the actual recip

Re: OT: Gentoo, Red Hat, etc. (was Re: [Mimedefang] Latest MIME-Tools)

2004-03-22 Thread Alan Madill
> In the course of the conversation I asked if I was allowed to install the OS on > more than one server or if the update rpms were available for download to a > subscriber. The answer to both questions was NO. Further to that, I did the very rare step of actually reading the subscription lega

Re: OT: Gentoo, Red Hat, etc. (was Re: [Mimedefang] Latest MIME-Tools)

2004-03-22 Thread Alan Madill
> David F. Skoll said: > > Fedora Core 1's actually not too bad. I have Gentoo on a laptop, > > but compiling *everything* from source pretty soon gets tiresome. > Their are some rhel enterprise clones: Taolinux http://taolinux.org/ > Lineox http://www.lineox.com/ Caos linux http://www.caosity

Re: OT: Gentoo, Red Hat, etc. (was Re: [Mimedefang] Latest MIME-Tools)

2004-03-22 Thread Justin
On Mon, 22 Mar 2004, Kelson Vibber wrote: > I don't think it's a failing of RPM so much as it's a failing of package > managers in general - namely, if you install anything that the PM doesn't > know about, it acts as if it isn't there. The only way you can get around > that is if you can over

Re: [Mimedefang] Latest MIME-Tools

2004-03-22 Thread Kelson Vibber
At 02:43 PM 3/22/2004, Les Mikesell wrote: But, it would be great if someone packaged MimeDefang and Clamav for an rpm install... Both are available from the DAG RPM repository at http://dag.wieers.com/home-made/apt/ Alexander mentioned earlier today that Dag's .spec for MD is now included in t

Re: OT: Gentoo, Red Hat, etc. (was Re: [Mimedefang] Latest MIME-Tools)

2004-03-22 Thread Kelson Vibber
At 03:48 PM 3/22/2004, Les Mikesell wrote: There are two approaches that work. One is to keep locally compiled things under /usr/local which is often their default, and adjust your PATH to use them instead of the system version when desired. I used to do this. Actually, I still do this on serve

Re: OT: Gentoo, Red Hat, etc. (was Re: [Mimedefang] Latest MIME-Tools)

2004-03-22 Thread Les Mikesell
On Mon, 2004-03-22 at 17:13, Kelson Vibber wrote: > >RPM is really quite lame. > I don't think it's a failing of RPM so much as it's a failing of package > managers in general - namely, if you install anything that the PM doesn't > know about, it acts as if it isn't there. The only way you can

Re: OT: Gentoo, Red Hat, etc. (was Re: [Mimedefang] Latest MIME-Tools)

2004-03-22 Thread Kelson Vibber
At 01:28 PM 3/22/2004, Justin wrote: RPM is really quite lame. If you ever want to really annoy RPM uninstall the very dated version of Perl and all it's various modules that come with RH and compile and install the latest greatest from source. RPM will never forgive you that one. :) Just out

Re: [Mimedefang] Latest MIME-Tools

2004-03-22 Thread Les Mikesell
On Mon, 2004-03-22 at 13:54, Justin wrote: > I almost never use any outward facing daemons that aren't compiled from > source. I compile just about everything from source if given the > opportunity. RH is terrible about keeping up with the latest greatest > unless it involves a critical securit

Re: [Mimedefang] Embedded Perl problems

2004-03-22 Thread Lucas Albers
Verify it is using the newer embedded version by calling manually. what is the full memory listing for all the mimedefang process? post the result of "ps axuww | grep mimedefang" cut off parts so it doesn't word wrap. Josh Kelley said: > I've verified that the -E is listed in the ps auxwww listin

[Mimedefang] Discarding fake MXs

2004-03-22 Thread Andrea Venturoli
Hello. Lately I'm seeing a lot of very nice people who set their second level domain's MX to something like 192.168.x.y. Obviously no mail will ever reach them, but i'd rather discard it immediately, rathar than having several retries and several error messages in the logs. I don't think sendmai

Re: [Mimedefang] value of $RelayHostname

2004-03-22 Thread David F. Skoll
On Tue, 23 Mar 2004, kamal wrote: > In filter_end, I want to know whether reverse DNS lookup had succeeded. > So I check the value of $RelayHostname. The man page says that it "May > be undef if host name could not be determined". But in my case, (when > reverse DNS fails) the value is IP address

Re: OT: Gentoo, Red Hat, etc. (was Re: [Mimedefang] Latest MIME-Tools)

2004-03-22 Thread Justin
On Mon, 22 Mar 2004, David F. Skoll wrote: > In that case, use the latest PostgreSQL 7.4.x. It's much better than > the 7.3.x series (faster, and better at reclaiming space during a VACUUM.) It sounds like it's worth it. I'll see what I can do about compiling that shortly. I'll see if I can j

Re: OT: Gentoo, Red Hat, etc. (was Re: [Mimedefang] Latest MIME-Tools)

2004-03-22 Thread Lucas Albers
David F. Skoll said: > Fedora Core 1's actually not too bad. I have Gentoo on a laptop, but > compiling *everything* from source pretty soon gets tiresome. Their are some rhel enterprise clones: Taolinux http://taolinux.org/ Lineox http://www.lineox.com/ Caos linux http://www.caosity.org/ Whitebo

Re: [Mimedefang] Latest MIME-Tools

2004-03-22 Thread Stephen Smoogen
On Mon, 2004-03-22 at 12:54, Justin wrote: > On Mon, 22 Mar 2004, Nels Lindquist wrote: > > > Which RedHat distribution are you using? PostgreSQL RPMs have been > > included on the CD (though not necessarily installed by default) at > > least as far back as 6.2, and if you want a more recent ve

Re: [Mimedefang] Embedded Perl problems

2004-03-22 Thread Josh Kelley
Lucas Albers wrote: You should show this sort of command arguments when you run ps axuww|grep mimedefang /usr/bin/mimedefang-multiplexor -p /var/spool/MIMEDefang/mimedefang-multiplexor.pid -E -m 4 -x 9 -U defang -i 30 -b 600 -W 1 -l -q 10 -s /var/spool/MIMEDefang/mimedefang-multiplexor.sock Noti

OT: Gentoo, Red Hat, etc. (was Re: [Mimedefang] Latest MIME-Tools)

2004-03-22 Thread David F. Skoll
On Mon, 22 Mar 2004, Justin wrote: > I almost never use any outward facing daemons that aren't compiled from > source. I compile just about everything from source if given the > opportunity. In that case, use the latest PostgreSQL 7.4.x. It's much better than the 7.3.x series (faster, and bette

[Mimedefang] More Problems with Libraries

2004-03-22 Thread mark
I typed export LC_ALL=C I still get Makefile:91: *** missing separator. Stop. typing setenv LC_ALL C - gets a bash: setenv: command not foundPlease advise ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EM

Re: [Mimedefang] Latest MIME-Tools

2004-03-22 Thread Justin
On Mon, 22 Mar 2004, Nels Lindquist wrote: > Which RedHat distribution are you using? PostgreSQL RPMs have been > included on the CD (though not necessarily installed by default) at > least as far back as 6.2, and if you want a more recent version, > binary and source RPMs can be downloaded di

Re: [Mimedefang] More Problems with Libraries

2004-03-22 Thread Justin
On Mon, 22 Mar 2004, David F. Skoll wrote: > Beware... this is a bashism. We GNU users are spoiled. :-) > > Genuine "sh" will barf at this... you need: > > LC_ALL=C; export LC_ALL I vote for just fixing it at the source (no, not bombing the RH engineering team!): #> /etc/sysconfig/i18n

[Mimedefang] value of $RelayHostname

2004-03-22 Thread kamal
In filter_end, I want to know whether reverse DNS lookup had succeeded. So I check the value of $RelayHostname. The man page says that it "May be undef if host name could not be determined". But in my case, (when reverse DNS fails) the value is IP address surrounded by square brackets. Of course, I

Re: [Mimedefang] Greylisting database question

2004-03-22 Thread David F. Skoll
On Mon, 22 Mar 2004, Todd Aiken wrote: > I created a new directory off of /var/spool and stored the > database file there [so it is on stable storage]. > Was that the right thing to do? Yes. Putting it on ramdisk is OK if you're a performance nut and don't care about losing greylisting info if t

Re: [Mimedefang] More Problems with Libraries

2004-03-22 Thread David F. Skoll
On Mon, 22 Mar 2004, Ole Craig wrote: > Umm... Is this a trick question? > export LC_ALL=C Beware... this is a bashism. We GNU users are spoiled. :-) Genuine "sh" will barf at this... you need: LC_ALL=C; export LC_ALL which is safe in all sh variants. Regards, David. ___

[Mimedefang] Greylisting database question

2004-03-22 Thread Todd Aiken
I just implimented on our site the greylisting example as posted to the list by Steven Rocha, which seems to be working. I notice though that the filename of where the database is stored is /var/spool/MIMEDefang/.greylistdb, but I have /var/spool/MIMEDefang mounted as a ramdisk. I assumed th

Re: [Mimedefang] Need Tip on Filter

2004-03-22 Thread Nels Lindquist
On 21 Mar 2004 at 21:21, Peter A. Cole wrote: > However, I also want to add in a section to get rid of mail with the > "X-Habeas-SWE" type headers as they also only appear to be spam, but > my ISP for some reason seems to let them through as valid messages. Not all mail with Habeas headers is sp

Re: [Mimedefang] More Problems with Libraries

2004-03-22 Thread Ole Craig
On 03/22/04 at 13:34, 'twas brillig and [EMAIL PROTECTED] scrobe: > > When Trying to Install Time-HiRes, I get Makefile:91: *** missing separator > I am suppossed to set the environment variable LC_ALL to C and retry. > > How do i set this variable? Umm... Is this a trick question? ex

[Mimedefang] More Problems with Libraries

2004-03-22 Thread mark
When Trying to Install Time-HiRes, I get Makefile:91: *** missing separator I am suppossed to set the environment variable LC_ALL to C and retry. How do i set this variable? ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing

[Mimedefang] More Problems with Libraries

2004-03-22 Thread mark
When Trying to Install Time-HiRes, I get Makefile:91: *** missing separator I am suppossed to set the environment variable LC_ALL to C and retry. How do i set this variable? ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing

[Mimedefang] MD 2.41 and Clamd socket

2004-03-22 Thread Paul
I just updated MD to 2.41 with SA 2.60 and ClamAV 67-1 on a FreeBSD 4.7 box. I used to have MD run ClamAV but in the 2.41 the code for selecting the virus scanners is no longer in the mimedefang-filter so MD decides to use ClamD. But unfortunately error out with the following message: Mar 22

Re: [Mimedefang]

2004-03-22 Thread Alexander Dalloz
Am Mo, den 22.03.2004 schrieb Mark Penkower um 17:36: > I am running Redhat Linux 9.0 and am setting up Mimedefang 2.39. > At the time, I am logged in as root. > > simply typing - make install works - Is this good enough? > Thanks > Mark Penkower You could even use the spec file inside the Mi

Re: [Mimedefang] Latest MIME-Tools

2004-03-22 Thread Nels Lindquist
On 21 Mar 2004 at 18:14, Justin wrote: > If it's needed then that's what we'll use. I'm hoping to get the demo > info this week so I can try it out during this week of configuration and > next week of testing. If we buy Can-It Pro then hopefully we can get some > help setting up PostgreSQL rig

Re: [Mimedefang]

2004-03-22 Thread Ben Kamen
If you're already root, just 'make install' is what you want. -Ben Mark Penkower wrote: I am running Redhat Linux 9.0 and am setting up Mimedefang 2.39. According to your instructions, to install the various libraries needed Mimedefang, I need to do the following: perl Makefile.PL make make t

[Mimedefang]

2004-03-22 Thread Mark Penkower
I am running Redhat Linux 9.0 and am setting up Mimedefang 2.39. According to your instructions, to install the various libraries needed Mimedefang, I need to do the following: perl Makefile.PL make make test su -c 'make install' When I type - su -c 'make install', linux responds: su -c 'make

Re: [Mimedefang] Large image-only spam

2004-03-22 Thread David F. Skoll
On Mon, 22 Mar 2004, Mike Grau wrote: > Could I get some input on how folks deal with image-only > spam. I tempfail all mail containing images pending human review. This does not scale for large sites. It's probably safe to add points for mail with a 'src="cid:' image tag. Regards, David.

[Mimedefang] OT: or not? Contact Congress

2004-03-22 Thread Ben Kamen
I realize this list crosses national boundaries, but I'm beginning to think it's time to really start hammering our local governmental people (for those of us in the US) with complaints that the CAN-SPAM act has done wonders... the BIG ISP's with money get to sue while we smaller guys just get flo

[Mimedefang] Large image-only spam

2004-03-22 Thread Mike Grau
Hello. Could I get some input on how folks deal with image-only spam. I'm running Sendmail->Mimedefang-2.39->SpamAssassin-2.63. The problem is that I'm getting image-only spams that are well over the threshold message size we've set for scanning messages with spamassassin. My machine has rather li

Re: [Mimedefang] Need Tip on Filter

2004-03-22 Thread Peter A. Cole
On Sun, 21 Mar 2004 09:41:18 -0600 Michael Sims <[EMAIL PROTECTED]> wrote: > Your regex pattern isn't terminated. You need a "/" at the end of it. > Thanks Michael, see I knew it was a simple regex type thing! It's really time I read through the Debian Reference Manual which explains regular ex

Re: [Mimedefang] Using more than one virus scan

2004-03-22 Thread Lucas Albers
Use as many as you can afford cpu and financially. If you run ramdisk and have fast cpu. My external mx runs a fast cpu and having 4 virus scanners does not add any noticable delay time. Depends on your mail volume. The only one I know of that is free and effective is clamav. You can slip by witho