Re: [Mimedefang] Including archetypal filters to include in release?

2006-01-11 Thread Kelson Vibber
, because chances are that the resulting FQDN doesn't exist if you're dealing with a home computer named by the end user. This of course can be resolved by requiring SMTP-AUTH, but when you still have half your users on POP-before-SMTP, it limits your options a bit. -- Kelson Vibber SpeedGate

Re: [Mimedefang] Pre-Emptive Greylist entries

2006-01-11 Thread Kelson Vibber
blocked, dropped, or hidden. Why waste the time and bandwidth? It may not be your own connection anymore, but hey, access to those botnets costs money! -- Kelson Vibber SpeedGate Communications, www.speed.net ___ NOTE: If there is a disclaimer or other

Re: [Mimedefang] resending mail sent to /var/spool/mail

2006-01-05 Thread Kelson Vibber
That starts a sendmail process that will run through the queue once. -- Kelson Vibber SpeedGate Communications, www.speed.net ___ NOTE: If there is a disclaimer or other legal boilerplate in the above message, it is NULL AND VOID. You may ignore it. Visit

Re: [Mimedefang] Re: dictionary attacks looking for a valid user

2006-01-03 Thread Kelson Vibber
Kenneth Porter wrote: --On Thursday, December 29, 2005 12:23 PM -0800 Kelson Vibber wrote: There is also confMAX_RCPTS_PER_MESSAGE, which limits the total number of recipients any message can target. But that includes valid recipients. Is that a global setting or can that be configured based

Re: [Mimedefang] Deadline for SPF records *long w/morbid horoscope*

2004-08-12 Thread Kelson Vibber
to a valid address, someone reads it and fires off a complaint to the person they think sent it... Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http

RE: [Mimedefang] Deadline for SPF records

2004-08-09 Thread Kelson Vibber
open relays out there, but these days it's generally considered a misconfiguration rather than a deliberate setup. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list

Re: [Mimedefang] Deadline for SPF records

2004-08-09 Thread Kelson Vibber
At 12:42 PM 8/9/2004, David F. Skoll wrote: So SPF is a good technology to combat joe-jobs providing everyone in the Internet uses it. :-( See http://www.rhyolite.com/anti-spam/you-might-be.html To be fair, SPF has never pushed itself (to my knowledge) as the FUSSP. Kelson Vibber SpeedGate

RE: [Mimedefang] Deadline for SPF records

2004-08-09 Thread Kelson Vibber
on their network boundary. Then the mail will be rejected at RCPT TO time, with no undeliverable message generated. (The ratware and spamware won't generate an undeliverable message when faced with a 550 No such user.) irony Unfortunately, this won't work until the entire Internet does it. /irony Kelson

Re: [Mimedefang] SpamCopURI w/SA2.64 w/Chris' umask Patch

2004-08-05 Thread Kelson Vibber
the SpamCopURI source to SpamAssassin and reinstall SA. -- Kelson Vibber SpeedGate Communications, www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http://lists.roaringpenguin.com

Re: [Mimedefang] TestVirus.org

2004-07-30 Thread Kelson Vibber
. That said, MIMEDefang's default filter_bad_filename should pick this up. It does here. -- Kelson Vibber SpeedGate Communications, www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http

Re: [Mimedefang] staying synced with example filter (was: Re: TestVirus.org)

2004-07-30 Thread Kelson Vibber
for things that would be useful or necessary. We also have a lot of custom functions that we keep in a separate file. Eventually I plan to do a massive cleanup, at which point it should become feasible to maintain the rest of our changes as a diff and keep things more in sync. Kelson Vibber

Re: [Mimedefang] TestVirus.org

2004-07-30 Thread Kelson Vibber
-- particularly since I still have a lot of complicated code left over from older customizations. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http

Re: Re: [Mimedefang] TestVirus.org

2004-07-30 Thread Kelson Vibber
messages. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http://lists.roaringpenguin.com/mailman/listinfo/mimedefang

Re: [Mimedefang] Testing and dictionary attack..

2004-07-09 Thread Kelson Vibber
anyway. Heck, many legit mailing lists don't either. We get lots of mail sent to long-dead accounts, some of which I ended up reactivating, watching for (and unsubscribing from) legit newsletters, and turning into spamtraps. Kelson Vibber SpeedGate Communications www.speed.net

Re: [Mimedefang] grammar nit

2004-07-08 Thread Kelson Vibber
on this issue, if you're interested, is http://groklaw.net . Also informative: http://twiki.iwethey.org/twiki/bin/view/Main/SCOvsIBM and http://www.opensource.org/sco-vs-ibm.html Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http

Re: [Mimedefang] Sender validation

2004-06-24 Thread Kelson Vibber
using VRFY, but so many sites have disabled it to throw a roadblock in front of dictionary attacks. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL

Re: [Mimedefang] grammar nit

2004-06-22 Thread Kelson Vibber
Systems, Inc. and In August 2002, Caldera International changed its name to SCO Group Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http

Re: [Mimedefang] Using DCC in SpamAssassin which is called by MimeDefang

2004-06-17 Thread Kelson Vibber
that it could be worth running two or even all three. In any case, I would recommend using the razor_timeount, pyzor_timeout, and dcc_timeout options in your SA config so that network slowdowns and server outages don't add too much time to your mail processing. Kelson Vibber SpeedGate Communications

Re: [Mimedefang] Using DCC in SpamAssassin which is called by MimeDefang

2004-06-16 Thread Kelson Vibber
called by MD Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http://lists.roaringpenguin.com/mailman/listinfo/mimedefang

Re: Unsafe embedded Perl (was RE: [Mimedefang] [PATCH] Memleak bug in mimedefang found and fixed)

2004-06-07 Thread Kelson Vibber
At 10:35 AM 6/7/2004, David F. Skoll wrote: On Mon, 7 Jun 2004, Kelson Vibber wrote: Does this mean the embedded perl should not be used *at all* on these platforms, or just that the normal reread method will not work? Just that the normal reread method will not work, as far as I know. OK

Re: [Mimedefang] Can I bounce be looking at keywords in the body without using spamassassin?

2004-06-04 Thread Kelson Vibber
, of course, $P@/\/\/\/\ERZ can just D|5GUl$3 orr miiispel there wurdz 2 @V0|D the keyword filter. By the time you put together a sufficiently long list of variations you may as well be using something more elaborate. Kelson Vibber SpeedGate Communications www.speed.net

Re: [Mimedefang] Correction about Autolearn Headers

2004-06-01 Thread Kelson Vibber
pieces, but auto-learn isn't available. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http://lists.roaringpenguin.com/mailman/listinfo

Re: [Mimedefang] /var/spool/MIMEdefang

2004-05-21 Thread Kelson Vibber
high or very low, if you have auto-learning enabled in your SA config. (The key command here is sa-learn). In both cases, information is always being added to the database, so you can expect the files to keep growing until data starts expiring (see the SA docs for more info). Kelson Vibber

Re: [Mimedefang] Want to modify read-receipt img tags in mail

2004-05-20 Thread Kelson Vibber
the text IMAGE - so that the reader knows something was supposed to be there, but there's no risk of the server being contacted. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang

Re: [Mimedefang] Sendmail Queue Runner

2004-05-13 Thread Kelson Vibber
At 10:02 AM 5/13/2004, you wrote: Will Mimedefang cease to work if use it for other tasks? If so, what functions would those be? A queue runner is needed for any situation in which MIMEDefang creates a new message, such as resend_message, action_notify_whoever and stream_by_whatever. Kelson

Re: [Mimedefang] evolution forging HELO?

2004-05-07 Thread Kelson Vibber
with its own IP address. (FWIW, this is Evolution 1.4 as provided by Fedora Core 1.) Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http

[Mimedefang] Detecting bogus AOL addresses

2004-05-07 Thread Kelson Vibber
) { return ('REJECT', 'Forged AOL address detected.'); #md_syslog 'info', $QueueID: Forged AOL address detected.; } return ('CONTINUE', 'ok'); } -- Kelson Vibber SpeedGate Communications, www.speed.net ___ Visit http

Re: [Mimedefang] OT: Sasser info

2004-05-04 Thread Kelson Vibber
. But what about damages *after* the recall, *after* people have had the opportunity to get their car fixed? Assuming they didn't know about the defect when they sold the cars, is Ford still liable legally? Morally? Kelson Vibber SpeedGate Communications www.speed.net

RE: [Mimedefang] Separate Filters for Separate Recipients

2004-05-04 Thread Kelson Vibber
need to run a second instance of Sendmail as a queue runner. See the MIMEDefang README for more detail, but essentially what you need is: sendmail -Ac -q5m This will start a second sendmail process which will run through the submission queue every five minutes. Kelson Vibber SpeedGate

Re: [Mimedefang] Skip MD for some users

2004-04-27 Thread Kelson Vibber
). This has the same disadvantage, but you can work around it using stream_by_recipient in filter_begin - which of course has its own disadvantage (resending the same message once per recipient). Kelson Vibber SpeedGate Communications www.speed.net

Re: [Mimedefang] surbl

2004-04-16 Thread Kelson Vibber
. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http://lists.roaringpenguin.com/mailman/listinfo/mimedefang

RE: [Mimedefang] surbl

2004-04-13 Thread Kelson Vibber
out of the message and queries the domain names against the SURBL zone. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http

Re: [Mimedefang] slave error with razor2

2004-04-01 Thread Kelson Vibber
-admin -discover as your MIMEDefang user. This should pick up a current list of Razor servers. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http

Re: [Mimedefang] bounce without attachment

2004-03-30 Thread Kelson Vibber
that aren't under your control. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http://lists.roaringpenguin.com/mailman/listinfo/mimedefang

RE: [Mimedefang] Getting Error from multiplexor: ERR No response from slave

2004-03-29 Thread Kelson Vibber
-test to make sure there are no syntax errors lying in wait. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http://lists.roaringpenguin.com/mailman

RE: [Mimedefang] Command rejected

2004-03-25 Thread Kelson Vibber
At 11:40 AM 3/25/2004, Kelson Vibber wrote: see the man page for mimedefang_filter for more options. Er, make that mimedefang-filter. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca

Re: OT: Gentoo, Red Hat, etc. (was Re: [Mimedefang] Latest MIME-Tools)

2004-03-22 Thread Kelson Vibber
that is if you can override the PM and tell it, Look, Perl's really installed. I know I can't tell you in detail where all the files are, or what libraries and utilities it depends on, but it's installed, honest! Kelson Vibber SpeedGate Communications www.speed.net

Re: OT: Gentoo, Red Hat, etc. (was Re: [Mimedefang] Latest MIME-Tools)

2004-03-22 Thread Kelson Vibber
At 03:48 PM 3/22/2004, Les Mikesell wrote: There are two approaches that work. One is to keep locally compiled things under /usr/local which is often their default, and adjust your PATH to use them instead of the system version when desired. I used to do this. Actually, I still do this on

Re: [Mimedefang] Latest MIME-Tools

2004-03-22 Thread Kelson Vibber
in the MD source distribution. You can use apt or yum (at least, I *think* I remember setting up yum to use it at one point), or you can just go to http://dag.wieers.com/packages/ and grab the RPMs. Kelson Vibber SpeedGate Communications www.speed.net

Re: [Mimedefang] mount noatime (was: ramdisks on Linux)

2004-03-17 Thread Kelson Vibber
At 07:20 AM 3/17/2004, Chris Myers wrote: Mount /tmp as ramdisk, noatime Unless you're using tmpwatch to clear out old files in /tmp. You can set it to decide based on mtime instead of atime, but atime is the default. Kelson Vibber SpeedGate Communications www.speed.net

Re: [Mimedefang] special use IPv4 addresses to consider: RFC 3330

2004-03-10 Thread Kelson Vibber
can use filter_relay - but remember that locally-submitted mail shows up as being from 127.0.0.1! Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED

Re: [Mimedefang] How can I get this email blocked?

2004-03-09 Thread Kelson Vibber
a SpamAssassin rule to catch them. You'll probably be better off posting this to the SpamAssassin list, though. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL

Re: [Mimedefang] add to sa score for clients that only give hostname in helo.

2004-03-08 Thread Kelson Vibber
can get run by different slaves, so variables defined in filter_relay aren't necessarily going to stick around. (See the Global Variable Lifetime section in the mimedefang-filter man page.) ...unless this has changed between 2.39 and 2.40 (I haven't upgraded yet). Kelson Vibber SpeedGate

RE: [Mimedefang] New way of obfuscating text

2004-02-11 Thread Kelson Vibber
/ci/ci_in.htm ) Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http://lists.roaringpenguin.com/mailman/listinfo/mimedefang

Re: [Mimedefang] action_tempfail and delete_recipient question

2004-02-04 Thread Kelson Vibber
you want. That would accept the message, then resend it locally. As far as the sending machine is concerned, the message will have gotten through. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http

RE: [Mimedefang] Security note: Open port 25 on internal mail se rvers

2004-02-04 Thread Kelson Vibber
as an MX record. Usually B is listed explicity (by DNS name) in the off-campus-client's email client as the Sending Mail Server or SMTP Server - no need to advertise it in DNS, though a portscanner will still find it. Er, shouldn't that be the other way around? Or am I misreading? Kelson Vibber

Re: [Mimedefang] Additional Spamassassin Rules

2004-02-03 Thread Kelson Vibber
number them 70_* or higher, I believe. Of course, this relies on SpamAssassin never changing their numbering system. Better to stick with the recommended location (/etc/mail/spamassassin) than to watch things stop working when you install SpamAssassin 2005. Kelson Vibber SpeedGate Communications

Re: [Mimedefang] Has anyone used fang.pl

2004-01-29 Thread Kelson Vibber
that if you use quarantine_entire_message, it works to call: sendmail -f`cat SENDER` `cat RECIPIENTS` ENTIRE_MESSAGE (source: http://lists.roaringpenguin.com/pipermail/mimedefang/2003-April/014049.html ) Kelson Vibber SpeedGate Communications www.speed.net

[Mimedefang] Using more than one virus scanner is a good idea.

2004-01-28 Thread Kelson Vibber
it, of course!) Now that File::Scan detects it, I'm still seeing a lot of copies slipping past it and getting caught by Clam. So I'd definitely recommend using more than one virus scanner when possible! Kelson Vibber SpeedGate Communications www.speed.net

Re: [Mimedefang] Mimedefang with spamc/spamd

2004-01-28 Thread Kelson Vibber
, so calling out to spamc/spamd would probably slow things down. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http://lists.roaringpenguin.com

Re: [Mimedefang] Anyone else having problems with Clamd 0.65?

2004-01-28 Thread Kelson Vibber
, which is longer than 0.65 seems to have managed. So far, so good. I'm just reluctant to sacrifice the efficiency gains clamd has over clamscan. But if push comes to shove, I'll drop back to clamscan. These days, inefficient virus scanning is better than none at all. Kelson Vibber SpeedGate

Re: [Mimedefang] Tracking down the delay (Razor timeout!)

2004-01-28 Thread Kelson Vibber
just doesn't make sense anymore. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http://lists.roaringpenguin.com/mailman/listinfo/mimedefang

Re: [Mimedefang] Check extensions beforer virus scan

2004-01-27 Thread Kelson Vibber
) block. On one hand, you do scan each entity individually. On the other, you don't scan anything that you're already deleting. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang

Re: [Mimedefang] New .zip virus?

2004-01-26 Thread Kelson Vibber
, Novarg or Mimail.somethingorother, and infected machines are DDOSing SCO's website. Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL PROTECTED] http

Re: [Mimedefang] rejecting on helo,drive-by-relay,forged_sender,

2004-01-16 Thread Kelson Vibber
, then turned it back on with changes on Monday.) Give it a try: dig aol.com TXT or nslookup -type=txt aol.com Kelson Vibber SpeedGate Communications www.speed.net ___ Visit http://www.mimedefang.org and http://www.canit.ca MIMEDefang mailing list [EMAIL