Re: [Mimedefang] KAM for MIMEDefang Leadership Role

2019-10-21 Thread alan premselaar
On 10/22/2019 07:19, Dianne Skoll wrote: > On 10/21/19 5:51 PM, Kevin A. McGrail wrote: >> Good Evening everyone, >> My name is Kevin A. McGrail. I've been a long-time user of MIMEDefang >> and I'd like to put myself forward to take the mantle of leadership from >> DFS now that she has moved on

Re: [Mimedefang] Logwatch stopped gleening as much useful (MdF) info following FC5 upgrade

2006-12-24 Thread alan premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Philip Prindeville wrote: I used to get some useful Logwatch info when I was running FC3: ...snip... Then I upgraded the OS to FC5 (but kept everything else the same), and now I hardly get anything useful at all: ...snip... So... Anyone

Re: [Mimedefang] My semi-cached version of md_check_against_smtp_server

2006-12-08 Thread alan premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Yizhar Hurwitz wrote: HI. Here is my cached implementation of md_check_against_smtp_server. I publish it here for other to look at, and for tips on improving it. [...snip...] sub filter_recipient { my($recip, $sender, $ip, $host, $first,

Re: [Mimedefang] spamassassin config files - I'm confused

2006-12-06 Thread alan premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Delahunty, Mark wrote: When I run spamassassin manually it seems to behave differently from when MIMEdefang runs it. ...snip... I've attached my local.cf, init.pre and the full output from spamassassin --lint -debug What am I missing/doing

Re: [Mimedefang] Spamassassin detailed score in message header

2006-11-29 Thread Alan Premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Tim Boyer wrote: action_change_header(X-Spam-Score, $hits ($score) $names); works great, and gives me the total score. It would be great, however, if I could get more detail, e.g., X-Spam-Score: 8.152 () AWL,BAYES_99

Re: [Mimedefang] What services need to be started?

2006-11-21 Thread Alan Premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 megaspaz wrote: ...snip... I'm only really interested in mimedefang for the antivirus integration, so setting up mimedefang to process only emails with suspicious attachments and letting spamassassin process everything else would be fine, but it

[Mimedefang] Re: netset: cannot include w.x.y.z as it has already been included

2006-11-08 Thread Alan Premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Matt Kettler wrote: Gilles Hamel wrote: Hello, We are running v3.1.5 with mimedefang. Here is our setup : our own MTA with spamassassin ---/-- MTA at our ISP, our MX is HERE w.x.y.z / INTERNET In the local.cf file we have :

Re: [Mimedefang] Rejecting forged senders - comments?

2006-09-20 Thread alan premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cormack, Ken wrote: I'd like to see if anyone has any comments on an idea to block spam from forged senders who claim my domain in the sender address. I'm assuming something like this could (or should?) be done for both the SMTP MAIL FROM: and

Re: [Mimedefang] Rejecting forged senders - comments?

2006-09-20 Thread alan premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cormack, Ken wrote: I'd like to see if anyone has any comments on an idea to block spam from forged senders who claim my domain in the sender address. I'm assuming something like this could (or should?) be done for both the SMTP MAIL FROM: and

Re: Fwd: Re: [Mimedefang] Should I try to do MIMEDefang with Mailscanner forbackup MX

2006-06-23 Thread alan premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Steve, Steve Campbell wrote: ...snip... Why don't you just use sendmail to trow them away? As others already pointed that out, you could provision your primary access database(s) to the secondary (or make the secondary use the primary's

Re: [Mimedefang] Should I try to do MIMEDefang with Mailscanner forbackup MX

2006-06-23 Thread alan premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Atanas wrote: ...snip... I primarily deal with non-standard sendmail setups hosting virtual domains (e.g. multiple mailboxes and multiple domains per single user) via local delivery agent (LDA) like procmail and maildrop, where sendmail acts as

Re: [Mimedefang] Should I try to do MIMEDefang with Mailscanner for backup MX

2006-06-20 Thread Alan Premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Steve, Steve Campbell wrote: [snip] a) MIMEDefang does things like relay checks, sender checks, and recipient checks that MailScanner doesn't do. This is where I want to remove the backup MX senders. This type of scenario has been debated

Re: [Mimedefang] Warning: unable to close filehandle LOGF properly.

2006-06-07 Thread Alan Premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Tory Blue wrote: Did a search and a few people see this but no answers. Did I miss something running Mime 2.44/clamav/sendmail 8.13 on a Linux box mimedefang-multiplexor[15477]: Slave 1 stderr: Warning: unable to close filehandle LOGF

Re: [Mimedefang] Warning: unable to close filehandle LOGF properly.

2006-06-07 Thread Alan Premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Alan Premselaar wrote: Just to kind of raise this issue again... I've googled and haven't found any definitive information (yet) ... I just upgraded to SA 3.1.3 and just now started seeing this problem (i.e. i wasn't having this problem up

Re: [Mimedefang] DNS and MX records

2006-05-11 Thread Alan Premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Les Mikesell wrote: ..snip.. The place this is likely to be a problem is where you have virtual web servers with names in lots of domains pointing to the same box and you do want to accept mail for some of those names. Note that CNAMES take

Re: [Mimedefang] DNS and MX records

2006-05-10 Thread Alan Premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Kris Deugau wrote: netguy wrote: Receintly I updated DNS for a few domains. My registrar gives the option of assigning an IP addy for domain.tld without having an alias: mail.domain.tld Ok, says I, lets give it a go. Bam! Slam, Spam started

Re: [Mimedefang] exempt user problem

2006-05-02 Thread alan premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Luke Worthy wrote: Sorry about my previous post, I now realize that we need to keep some other features of this filter (it keeps a copy of everyones email as well as the exemption thinggy). So below is my original post, and the listing of the

Re: [Mimedefang] Filter not working (properly)

2006-04-13 Thread Alan Premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Ashley M. Kirchner wrote: Anyone have any idea why this piece of my mimedefang filter suddenly quit working? if ($FoundVirus) { md_graphdefang_log('virus', $VirusName, $RelayAddr); md_syslog('warning', Discarding because

Re: [Mimedefang] MD 2.51/clamav .88.1 failure

2006-04-10 Thread Alan Premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Richard J. Kieran wrote: On Friday, 4/7, I updated clamav from version .88 to .88.1. When I did so, virus scanning broke. Maillog was filled with entries like: Apr 7 15:49:23 hoover mimedefang.pl[66764]: Problem running virus scanner: code=999,

Re: [Mimedefang] sa-mimedefang.cf

2006-03-03 Thread Alan Premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [EMAIL PROTECTED] wrote: Mickey Hill wrote: On Thu, 2006-03-02 at 11:12 -0500, webmaster wrote: Well, sa-mimedefang.cf doesn't exist. Where can I obtain it and what does it say? I believe it's in /etc/mail now. I concur. Although I softlink

Re: [Mimedefang] MIMEDefang and mailman

2006-02-21 Thread Alan Premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Daniel O'Connor wrote: [snip] Hmm but mail that is destined to pass through mailman is handled by MIMEDefang first - I want to tell MD to treat all mail to my lists as for the mailman user (ie use the mailman user's Bayes DB). I don't

Re: [Mimedefang] OT: Disclaimer Madness

2006-02-14 Thread Alan Premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ya, if you gather all the disclaimers and then send them to the originating companies all at once, can you cause a disclaimer paradox and thus the universe to explode? Dave Williss wrote: I hope you sent a copy of the combined disclaimers to them.

Re: [Mimedefang] poor performence from SA

2006-01-12 Thread Alan Premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [EMAIL PROTECTED] wrote: [snip] I have upgraded to SA 3.1 but i get strange actions... I think that the SA is now checked before mimedefang filters and skips other filters...(but i'm not 100% sure about that? how can check?) Did you install

Re: [Mimedefang] disclamer only for out going mails.

2005-12-20 Thread alan premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Joseph Brennan wrote: ...snip... No, since I have not been asked to do such a thing. The question just got me started thinking about how difficult it is to define what outgoing mail is. I didn't even mention the situation we have here, and

Re: [Mimedefang] Error message:Problem running virus scanner: code=2

2005-12-06 Thread Alan Premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [EMAIL PROTECTED] wrote: Mathew, Sorry for not answering your exact question...BUT What should should sertainly do is upgrade mimedefang to latest 2.54 and SA 3.0.3 and clamAV 0.87 Actually, SA 3.0.3 is still susceptable to a remote

Re: [Mimedefang] Creating live graph for monitoring the mail systems

2005-12-01 Thread Alan Premselaar
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Mathew Thomas wrote: Hi I use some Perl script to analyse the syslog which produces a lot of information like total mail, no. inbound/outbound mail, no. of spam, no. of mail with viruses, dropped mail, etc daily via a cron job. I would like to

Re: [Mimedefang] Suggestions please ... ;)

2005-11-10 Thread alan premselaar
Garry Glendown wrote: Oh how easy life would be if customers just bought services and stopped complaining about missing features ... ;) OK, here we go ... after some advice from the list, I installed MD to add special filtering capabilities to a customer mailserver. So far so good ...

Re: [Mimedefang] (no subject)

2005-09-26 Thread alan premselaar
[EMAIL PROTECTED] wrote: I'm confused... I got a mailbox call spamdrop, where all spam detected by Mimedefang-SA is quarantined. Some of the emails subject is altered to contain:'*SPAM*', some '[SPAM]', and some are not changed???!!!??? I still have the problem of honest spam endup in

Re: [Mimedefang] Rejecting some recipients

2005-09-15 Thread alan premselaar
Jeff Grossman wrote: [snip] Sorry for the run on message before. I have MIMEDefang set up with the md_check_against_smtp_server setting. So, it checks my server first to see if the address is valid or not. So, do you think it is still a problem with just putting the addresses I want to

Re: [Mimedefang] exiting the filter before any processing

2005-09-05 Thread alan premselaar
Rolf wrote: hello I've tried so many combinations and none work. Feeling a bit silly. Where can I put in mimedefang-filter a statement so that the filter exits before any processing happens based on $RelayAddr ?? I've tried a simple: return if ($RelayAddr eq ip address); in various parts

Re: [Mimedefang] Checking origin of sender

2005-09-02 Thread alan premselaar
Ian Mitchell wrote: ...snip... HELO junkmail.com MAIL FROM: [EMAIL PROTECTED] RCTP TO: [EMAIL PROTECTED] DATA From: [EMAIL PROTECTED] [EMAIL PROTECTED] To: [EMAIL PROTECTED] [EMAIL PROTECTED] ... Why would this make it past your SPAM filter? Unless you're doing something like whitelisting

Re: [Mimedefang] Mimedefang, spamassassin and /etc/mail/spamassassin

2005-08-17 Thread Alan Premselaar
Rudy Attias wrote: Hey all, I'm quite new with this configuration but I seem to get the hang of it. I'm running a mail relay(no local account) that forward to an exchange 2003 server in the lan. The relay is running sendmail and mimedafang that scan using spamassassin and clamav. I have 2 main

Re: [Mimedefang] Spam with more than one recipient - reject or not?

2005-08-17 Thread Alan Premselaar
Michal Jankowski wrote: There are two users - user A and user B. User A wants to receive everything, user B wants to have all spam mail rejected (with action_bounce, so in case of a false positive the sender is notified). There comes a mail addressed to both A and B. What should mimedefang do?

Re: [Mimedefang] RE: Filtering on sender, recipient, and subject at the same time

2005-07-18 Thread alan premselaar
Craig Green wrote: ...snip... Note that since you're in filter_end, the HEADERS file *is* available, so you can just parse that if you'd prefer. There was nothing wrong with your initial logic; it's just that parsing the file on disk is slower *and* it takes more code than using the MIME

Re: [Mimedefang] Blatent spam getting X-Spam-Score: 0 ()

2005-07-08 Thread alan premselaar
Bill Curtis wrote: So any idea why these aren't getting any scores at all? Bill, If it were I, I'd put some debuging md_syslog calls in. right after you receive the results from the sa check and then also write before you write those values to the header. chances are somewhere in

Re: [Mimedefang] ClamAV's Worm/Trojan/Joke/W97M classifications

2005-07-01 Thread alan premselaar
Chris Gauch wrote: Alan wrote: One of the reasons I use 550 rejects for viruses is that I also scan outgoing mail... so if by some chance one of my users gets infected with a virus (regardless of the fact that we have desktop antivirus software installed on all our machines as well as ClamAV

Re: [Mimedefang] Timeouts when filter-sender is employed

2005-06-15 Thread alan premselaar
Dirk the Daring wrote: ...snip... ## sub filter_sender { my($sender, $hostip, $hostname, $helo) = @_; # Can't be psicorps.org unless it's one of our IP's. if ($helo =~ /(^|\.)psicorps\.org$/i) { if ($hostip ne 127.0.0.1 and $hostip ne 209.170.141.XXX and

Re: [Mimedefang] Start order for sendmail, MD and Clam

2005-06-07 Thread alan premselaar
Dirk the Daring wrote: Is there a particular order in which I should start sendmail, MD and Clam? That is, are there any dependencies, or reason that one should be running before the other (seems that sendmail will gripe about a missing socket if MD is not running, so I start MD first, but

Re: [Mimedefang] 4.7.1 sendmail error

2005-05-20 Thread alan premselaar
Greg Schlut wrote: Still bringing back that error. Spamassassin was not scanning the files and I did increase the delay. Any other ideas? I may try upgrading mimedefang this weekend, and see if that solves it, but it really does look like a timeout issue. Thanks for the help. --Greg Greg,

Re: [Mimedefang] Sober virus highlights problem

2005-05-19 Thread alan premselaar
David F. Skoll wrote: ...snip... Interesting idea. I wonder how easy it would be to maintain local signatures for Clam, just to catch this kind of thing? I'll have to investigate. I've never personally done it, but from following the conversations on the clamav users list, it seems like it's

Re: [Mimedefang] [possibly off-topic] ALL TRUSTED SA Problem

2005-05-18 Thread alan premselaar
Kevin A. McGrail wrote: I am trying to assist with a problem where emails coming through an anti-spam gateway are getting scored with ALL_TRUSTED. I don't see a reason why they should be. I've looked at the SA Source code but still at a loss and I'm worried it's something in the mimedefang

Re: [Mimedefang] Incorrect required_hits setting

2005-05-14 Thread alan premselaar
Richard J. Kieran wrote: Thanks for the thoughts. The required_hits setting is in sa-mimedefang.cf only. SpamAssassin figures it out and MIMEDefang doesn't. hmmm... I restarted MIMEDefang every time I made a change to the setting. No change. The same .cf files work on the old server. Definitely

Re: [Mimedefang] SMTP

2005-05-10 Thread Alan Premselaar
Christopher Roberts wrote: Ben wrote: You literally telnet on P:25 to their SMTP server and type the commands by hand. If you still get the error - something is wrong on their end. You live and learn! I have tried doing this for mailgate01.barclays.co.uk and mailgate02.barclays.co.uk and 90% of

Re: [Mimedefang] Tiny Text

2005-05-10 Thread alan premselaar
-ray wrote: [snip] No, but I have seen 2.5 points before. :) Silly question, where would i put a new rule like that? I'm already changing some scores in /etc/mail/mimedefang/sa-mimedefang.cf, but not sure where to add a new rule. ray Ray, you should be able to create a file in

Re: [Mimedefang] canonicalize_email error

2005-05-09 Thread Alan Premselaar
Jan Pieter Cornet wrote: [snip] sub canonicalize_email ($) { my ($email) = @_; $email =~ s/^//; $email =~ s/$//; return lc($email); } basically all it does is remove any or from the email and return it in lowercase. Actually, looking at this code again (with a clear

Re: [Mimedefang] Using Stream_by_recipient

2005-05-06 Thread alan premselaar
Mack wrote: When i stream by recipient, the email get's discarded and resent to each recipient as expected, however the new email doesn't pass through mimedefang (specifically filter begin/part/end). This results in not being virus chk/spam chk/boilerplated. It just seems to get sent directly

Re: [Mimedefang] canonicalize_email error

2005-05-04 Thread alan premselaar
Tim Boyer wrote: I tried putting in one of the subroutines that David presented at the Lisa '03 session. It's got the line $recipient = canonicalize_email($recipient); in filter_recipient. But when I run it, I get this in the logs: ...snip... Have I typed it wrong? Spelled it wrong? Tim,

Re: [Mimedefang] Foreign Character Sets.

2005-04-18 Thread alan premselaar
Keith Patton wrote: Yes sendmail accepts it, then it passes it to netscape and it rejects it.. Funny thing is that sometimes it works other is doesn't.I have noticed that nearly all the bounces I have seen has the content in foreign character set ( chineese or Korean )... That is why I asked

Re: [Mimedefang] Compliance

2005-04-15 Thread Alan Premselaar
Josh Kelley wrote: alan premselaar wrote: I'd be interested in at least looking at it. Currently I'm using procmail for local delivery and its Quota handling is kludgey at best. I'd really like to get something working within MD. Since the method Jan uses calls the perl module for Quota

Re: [Mimedefang] Compliance

2005-04-12 Thread Alan Premselaar
Jan Pieter Cornet wrote: We're not using it for any compliance testing (mainly because we're an ISP), but we do use it for other things: - rejecting on quota exceeded earlier than sendmail detects it How are you checking quota? Sounds interesting. Using the perl interface to quotactl, the Quota

Re: [Mimedefang] Compliance

2005-04-12 Thread alan premselaar
Jan Pieter Cornet wrote: [snip] You probably have direct attached storage on the linux box? Apparently that makes a difference. As a workaround, you could either run the mimedefang slaves as root (not recommended) or run a specialised quota daemon, as root, that can perform the quota queries for

Re: [Mimedefang] Compliance

2005-04-12 Thread alan premselaar
Josh Kelley wrote: [snip] We use a setuid copy of /usr/bin/quota to do quota checking on our Red Hat server. (We use a copy rather than making /usr/bin/quota setuid since any updates to the quota package would reset the setuid bit.) It's probably not the most efficient setup, but I thought

Re: [Mimedefang] Compliance

2005-04-07 Thread alan premselaar
Jan Pieter Cornet wrote: ...snip... Anyway, I consider it a feature :) It makes users more likely to clean up their act, instead of inadvertently using your system as a rain barrel. are you using stream_by_recipient to do this? or are you rejecting the mail for every recipient if just one of the

Re: [Mimedefang] configuring mimedefang

2005-04-06 Thread alan premselaar
Speedy Sweedy wrote: Ok, based on what you guys are saying in here, I am now only scanning with mimedefang and using it to call clamav. I've tested my install with the resource from testvirus.org and it catches everything jut fine. How do I get mimedefang to test for spam now? I have

Re: [Mimedefang] Integrating SPF...

2005-03-29 Thread Alan Premselaar
John Von Essen wrote: [snip] I am looking into SPF plugin for SA now. Does anyone know how it handles domains with no SPF record? I would assume that if no SPF exists, then forgeries are not penalized for that domain. Just need to make sure before I turn this plugin ON in production. basically

[Mimedefang] interesting problem with SQL backend

2005-03-24 Thread alan premselaar
Today I had an interesting situation. This is more of an FYI in case anyone else has run into similar problems. (cross-posted to MIMEDefang list as well) I use SpamAssassin with MIMEDefang. I got notified by one of my users that they were unable to send mail suddenly. after checking the logs I

Re: [Mimedefang] Re: mimedefang error mimedefang.sock unsafe??

2005-03-23 Thread alan premselaar
James Ebright wrote: As far as directories go.. the x bit simply means you can get a directory listing if you have privledges. For files it turns on execute allowing the file to be run as a program. I do not believe that should affect the operation of MimeDefang in any way as MD does not need the

Re: [Mimedefang] Re: mimedefang error mimedefang.sock unsafe??

2005-03-23 Thread alan premselaar
alan premselaar wrote: [...snip...] I just encountered this same problem on a system that has been running flawlessly until today. I was seeing a bunch of Mar 24 09:44:04 mail mimedefang-multiplexor[21236]: Killing busy slave 17 (pid 10445): Busy timeout Mar 24 09:44:04 mail mimedefang[21249

Re: [Mimedefang] Re: mimedefang error mimedefang.sock unsafe??

2005-03-23 Thread alan premselaar
David F. Skoll wrote: alan premselaar wrote: So, to reply to my own post, I've been toying around and determined that Embedded Perl appears to be the culprit. That kind of makes sense. If the multiplexor is very slow to initialize, mimedefang waits a bit before entering the main loop. The code

Re: [Mimedefang] Re: mimedefang error mimedefang.sock unsafe??

2005-03-23 Thread alan premselaar
David F. Skoll wrote: alan premselaar wrote: So, to reply to my own post, I've been toying around and determined that Embedded Perl appears to be the culprit. ...snip... something's *really* hosed. I copied the mimedefang-filter.example file, and just changed the email addresses of the admin

Re: [Mimedefang] This mail's for you... NOT!

2005-03-04 Thread alan premselaar
[EMAIL PROTECTED] wrote: David F. Skoll wrote: Most of the spam messages that I receive are addresses to non-existing users... Mailing list I guess... Can I setup a way to accept mail for only a list of e-mail addresses? Yes, there are a number of ways to do this. Search the list archives for

Re: [Mimedefang] Anyone using File::Scan?

2005-02-16 Thread alan premselaar
David F. Skoll wrote: Hi, Does anyone use File::Scan with MIMEDefang? It seems to cause a lot of problems with false positives. For the next release, I'm considering removing the auto-detection of File::Scan. In other words, if you want File::Scan, you'll have to specifically ask for it in your

Re: [Mimedefang] Perl help: quarantine and bounce criteria

2005-01-24 Thread alan premselaar
Kenneth Porter wrote: I've got the following function for bouncing spam/viri in my office server. This gets invoked whenever the filter would bounce or discard, such as when the spam score is over 10. If the mail was addressed to a legitimate local mailbox (other than info or hostmaster) I

Re: [Mimedefang] Need help with filter

2004-12-15 Thread alan premselaar
Ronald Vazquez NLM wrote: Hello list: I have the following code as part of my: ...snip... my %trustedSubnets = ( ^^ # Looopback '127.0.0.1' = '255.255.255.255', # Home Network

Re: [Mimedefang] Mimedefang - japanese emails

2004-12-11 Thread alan premselaar
Marco Supino wrote: Hi, I am running mimedefang (2.48) on solaris, through the milter, and have problem with scanning japanese emails, it seems mimedefang strips the japanese mime parts, I dont know where to start in order for this not to happen, and i am still new to mimedefang, any help is

Re: [Mimedefang] Need help with virus notifications

2004-12-10 Thread alan premselaar
Ronald Vazquez NLM wrote: Hello: I have been tasked with configuring MIMEDefang to allow a virus to come in thru the first instance, tag it with X-RrestrictedAttachment to allow our virus scanner to process it. The idea is that once Trend Micro drops the attachment, we

Re: [Mimedefang] MD 2.48 , SA 3.0001 CHARSET_FARAWAY_HEADERS

2004-11-16 Thread alan premselaar
Paul Murphy wrote: Alan, Check that you are running "spamassassin -D -p /etc/mail/spamassassin/sa-mimedefang.cf" or whatever to make sure that MD and your manual check are using the same config. If this is the issue, then carefully compare the default SA config with the

Re: [Mimedefang] MD 2.48 , SA 3.0001 CHARSET_FARAWAY_HEADERS

2004-11-16 Thread alan premselaar
Aleksandar Milivojevic wrote: ...snip... Starting with MD 2.46 (or 2.47?) location of sa-mimedefang.cf was moved from /etc/mail/spamassassin to /etc/mail. Try moving the file, or making symbolic link, and see if that is going to make any difference. sweeet. that was it. not sure why i missed

[Mimedefang] MD 2.48 , SA 3.0001 CHARSET_FARAWAY_HEADERS

2004-11-15 Thread alan premselaar
I'm having an interesting problem. I have: MD 2.48 SA 3.0x (happens with 3.00 and 3.01) perl 5.8.5 5.6.1 (happens on two seperate systems) RedHat ES 3.0 RedHat 7.2 when mail passes through MIMEDefang and calls SpamAssassin, even though I've got ok_locales and ok_languages set to en ja (to also

Re: [Mimedefang] Frustration...

2004-11-04 Thread alan premselaar
Lisa, Lisa Casey wrote: Hi Folks, ...snip... I'ld also like to drop, bounce, whatever mail that has certain words in the subject, such as rolex, penis, viagra, etc. I know I can do the above with MIMEDefang/Spamassassin, but I'll be darned if I can figure out how. And the more I try to figure it

Re: [Mimedefang] Re: VERY Newbie Question

2004-10-31 Thread alan premselaar
Jeff Rife wrote: On 30 Oct 2004 at 0:16, David F. Skoll wrote: ...and the RFC pretty clearly says that an IP address should *never* be used as the argument to HELO, so that rule *should* reject all e-mail. Umm... reread his code. ...snip... Jeff, I think what David was trying to point out is

Re: [Mimedefang] Installed Modules

2004-10-28 Thread alan premselaar
Trevor Dodds wrote: Hi, Can someone please tell me the command that will display all the modules mimedefang is using. Thanks Trevor Trevor, I believe what you're looking for is mimedefang.pl -features alan ___ Visit http://www.mimedefang.org and

Re: [Mimedefang] Spamassassin not using SURBL

2004-10-12 Thread alan premselaar
Kris Deugau wrote: alan premselaar wrote: I just recently installed a system with MD 2.45 and SA 3. and while doing some testing to see if the network tests were running, I determined that the -C option to spamassassin does not work as expected. the man pages are a little hazey about

Re: [Mimedefang] Spamassassin not using SURBL

2004-10-07 Thread alan premselaar
[EMAIL PROTECTED] wrote: Graham Dunn wrote: What options are required when running spamassassin from the command line to get the same behaviour as you would see when run in mimedefang? Other than using -C /usr/local/etc/mimedefang/spamassassin/sa-mimedefang.cf Also should run as the defang user

Re: [Mimedefang] mimedefang-2.45 and dual opteron

2004-09-30 Thread alan premselaar
Bill Maidment wrote: I've had mimedefang-2.45 spamassassin-3.0.0 clamav-0.80rc2 running for about a week OK on a dual opteron. Then yesterday a friendly bz2 file came in as an attachment and clamav threw a fit. I upgraded to clamav-0.80rc3 and still had the same problem, so I went back to

Re: [Mimedefang] OFF TOPIC - Need a product to block spyware

2004-09-30 Thread alan premselaar
Johann wrote: [snip] http://fedora.redhat.com/download/ It is the only thing that will get rid of all the malware you have now, including Windows 2000. :-) a good pair of wire cutters will prevent spyware too. ___ Visit http://www.mimedefang.org and

Re: [Mimedefang] Deadline for SPF records

2004-08-11 Thread alan premselaar
Ben Kamen wrote: ...snip... But seriously, it's so easy to set up StartTLS on the client side... you know, you would think that... but, as an example, Microsoft Entourage (part of Office 2000) for OS X doesn't support STARTTLS, only SSMTP. sure you can use SMTP AUTH, but you'd have to configure

Re: [Mimedefang] MIMEDefang not scanning for Spam??

2004-08-03 Thread alan premselaar
Sven Schuster wrote: ...snip... This rule usually does work, even when I reinject this mail (as present in the users mbox) into sendmail (port 25). I also don't have any rules to skip spam scanning for certain senders or recipients or the like. Any idea what's going wrong here?? are you using the

Re: [Mimedefang] Sendmail 8.10 and MIMEDefang

2004-08-02 Thread alan premselaar
Kenneth Chan wrote: Hi, I have a raq4 with sendmail 8.10. Which is the most recent version that will work with sendmail 8.10? Is there an archive of previous versions available for download? Thanks Ken. Kenneth, If I'm not mistaken (and this is off the top of my head after a long day at

Re: [Mimedefang] Relaying denied

2004-07-22 Thread alan premselaar
Les Mikesell wrote: On Thu, 2004-07-22 at 10:24, Vivek Kumar wrote: Yes its gorave not gorav (typo error). I was trying to send it to lists related to mail as I was not getting porper answer for that. Sorry for any inconvenience. [snip] Note that by doing this you lose the ability to check valid

Re: [Mimedefang] Reversing the process

2004-07-22 Thread alan premselaar
Ashley M. Kirchner wrote: Not that I really want to do this, but I have a mail server right now on which I want to remove MIMEDefang all together, and just leave sendmail running. The folks on that machine actually WANT all their spam and viruses, so...who the hell am I to tell them no.

Re: [Mimedefang] Globals

2004-07-13 Thread alan premselaar
Rich West wrote: Thanks to all of those that responded. Based upon all of the ideas, I came up with the following code to do the trick. -Rich sub filter_begin () { ... %lists = get_lists(); ...snip... open (LISTS, /var/mailman/bin/list_lists -b|) or die Could not execute

Re: [Mimedefang] Still outbound messages are getting blocked by s pamassassin

2004-07-09 Thread alan premselaar
[EMAIL PROTECTED] wrote: From: Jim McCullars [mailto:[EMAIL PROTECTED] On Fri, 9 Jul 2004, Vivek Kumar wrote: Hi Matthew, I tried both the following syntax you suggested but I got compliation error. How about just: if ($hostip =~ /^191\.0\.(?:0|1)/) {

Re: [Mimedefang] white listing $senders

2004-07-07 Thread alan premselaar
Jeffrey Goldberg wrote: [snip...] To mimedefang-filter I've added the following two functions sub filter_sender { my ($sender, $ip, $hostname, $helo) = @_; return('ACCEPT_AND_NO_MORE_FILTERING', Sender whitelisted) if is_whitelisted($sender, $ip); return ('CONTINUE', ok); } sub

Re: [Mimedefang] file descriptor scope and embedded perl

2004-07-05 Thread alan premselaar
Chris Masters wrote: Hi All, Since upgrading to the latest MIMEDefang today I have bad file descriptor errors - I assume this is an embedded perl scope issue. So, I currently do the following: 1) I do *not* use filer_initialise 2) The file descriptor are global and are declared *outside* of any

Re: [Mimedefang] block based on outgoing recipient

2004-07-05 Thread alan premselaar
Lucas Albers wrote: Would this item; in filter_end exclude all further mail filtering, on mail going from localhost to this a particular recipient? #in filter_end. if ($recipient =~ /[EMAIL PROTECTED]/) { exit; } Does not appear to be working... Lucas, if you just want to bypass all

Re: [Mimedefang] Mimedefang/Spamassassin/bayesian

2004-02-17 Thread alan premselaar
On 2/17/04 9:31 PM, "Paul Murphy" [EMAIL PROTECTED] wrote: ...snip... debug: bayes: 29638 tie-ing to DB file R/O /var/spool/spamassassin/bayes_toks debug: bayes: 29638 tie-ing to DB file R/O /var/spool/spamassassin/bayes_seen debug: bayes: found bayes db version 2 debug:

Re: [Mimedefang] Problem running clamd but not clamscan

2004-01-28 Thread alan premselaar
On 1/29/04 1:44 AM, "Ole Craig" [EMAIL PROTECTED] wrote: On 01/28/04 at 08:32, 'twas brillig and Scott Harris scrobe: Subject: RE: [Mimedefang] Problem running clamd but not clamscan Scott, et al - I had similar issues with clamd versus clamscan (see

[Mimedefang] clamav and $VirusName variable

2004-01-27 Thread alan premselaar
Hi, I recently installed clamav 0.65 on my machine (in conjunction with File::Scan) and I've noticed that ocassionally clamav is returning that it's found a virus, but $VirusName is empty. any ideas as to why this might be happening? or where to look for this? i'm

[Mimedefang] filter timing out

2004-01-20 Thread alan premselaar
I'm sure this has been covered before, but i couldn't find it in the archives (could just be i'm tired) ... anyways, lately i've been seeing A LOT of 4.7.1 failures in my log file. I've got my MIMEDefang spool dir on a tmpfs, and i haven't made any changes to my filter recently.