[sniffer] False

2005-05-10 Thread Frederick Samarelli
I am finding that most if not all email from Comcast senders are failing Sniffer. Fred This E-Mail came from the Message Sniffer mailing list. For information and (un)subscription instructions go to http://www.sortmonster.com/MessageSniffer/Help/Help.html

RE: [sniffer] False Positives.

2005-05-10 Thread Judy Burnett
Pete, Can you send these kinds of emails to Hamed instead of me please. thanks Judy Burnett Everyones Internet, Ltd. 835 Greens Parkway, Suite 150 Houston, TX 77067 713-579-2802 Fax: 713-942-8621 -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Pete McNei

Re: [sniffer] False

2005-05-10 Thread Pete McNeil
On Tuesday, May 10, 2005, 9:35:59 AM, Frederick wrote: FS> I am finding that most if not all email from Comcast senders are failing FS> Sniffer. Please submit a false positive report to false@ and include matching SNF log entries if possible. Thanks, _M This E-Mail came from the Message Sni

Re[2]: [sniffer] False Positives.

2005-05-10 Thread Pete McNeil
On Tuesday, May 10, 2005, 9:37:29 AM, Judy wrote: JB> Pete, JB> Can you send these kinds of emails to Hamed instead of me please. JB> thanks I have changed your subscription. Please note you can alter your sniffer@ list subscription at any time. Information is on our help page: http://www.sort

[sniffer] Rule 353039 - .comcast.net

2005-05-10 Thread Pete McNeil
Hello Sniffer Folks, A rule was created today by one of the robots which targets .comcast.net -- This happened when a number of blacklists including SBL listed comcast IPs causing the robot to be convinced that a message in the spamtrap warranted tagging the domain. The rule has been re

Re: [sniffer] Rule 353039 - .comcast.net

2005-05-10 Thread Computer House Support
Whew! Just got done forwarding 90 false positives to mail clients. Sure glad you caught it! Michael Stein Computer House - Original Message - From: "Pete McNeil" <[EMAIL PROTECTED]> To: Sent: Tuesday, May 10, 2005 10:27 AM Subject: [sniffer] Rule 353039 - .comcast.net Hello Sniffer

Re: [sniffer] Rule 353039 - .comcast.net

2005-05-10 Thread Computer House Support
Comcast messages still getting caught. Even after adding the panic rule. Even this mail from the list got caught. Can you update my rulebase? Thank you, Mike Stein - Original Message - From: "Computer House Support" <[EMAIL PROTECTED]> To: Sent: Tuesday, May 10, 2005 11:57 AM Subj

RE: [sniffer] Rule 353039 - .comcast.net

2005-05-10 Thread Colbeck, Andrew
Thanks for the quick work, Pete. I put in the Rule-panic entry as soon as you sent the email to this list. For what it's worth, I just finished with all my held mail for the last two days, and I had no false positives from messages with a mailfrom that included "c o m c a s t". Lots of mail that

RE: [sniffer] Rule 353039 - .comcast.net

2005-05-10 Thread Erik
Pete, Is this in the "beta"/"free" release of Sniffer rules? Erik -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Colbeck, Andrew Sent: Tuesday, May 10, 2005 6:20 PM To: sniffer@SortMonster.com Subject: RE: [sniffer] Rule 353039 - .comcast.net Thanks f

Re: [sniffer] Rule 353039 - .comcast.net

2005-05-10 Thread Matt
Warning! When you add a RulePanic entry and are running Sniffer in persistent mode, you have to restart the service for it to take effect. I changed this earlier and it had no effect until I restarted the service on my box. Maybe I'm wrong about this, but just changing my config file had no e

Re[2]: [sniffer] Rule 353039 - .comcast.net

2005-05-10 Thread Pete McNeil
On Tuesday, May 10, 2005, 12:12:40 PM, Computer wrote: CHS> Comcast messages still getting caught. Even after adding the panic rule. CHS> Even this mail from the list got caught. Can you update my rulebase? Hmmm... Be sure the format is correct and that it is not commented out. All rulebases a

Re: [sniffer] Rule 353039 - .comcast.net

2005-05-10 Thread Computer House Support
Mail from Comcast is still getting caught, even with the panic rule in place. Any suggestions? Mike Stein This E-Mail came from the Message Sniffer mailing list. For information and (un)subscription instructions go to http://www.sortmonster.com/MessageSniffer/Help/Help.html

Re[2]: [sniffer] Rule 353039 - .comcast.net

2005-05-10 Thread Pete McNeil
On Tuesday, May 10, 2005, 12:31:18 PM, Erik wrote: E> Pete, E> Is this in the "beta"/"free" release of Sniffer rules? It may not be --- it's new enough that it may have been excluded from the demo rulebase. To make sure you should make a quick scan of your SNF log file for that rule number. In an

Re: [sniffer] Rule 353039 - .comcast.net

2005-05-10 Thread Matt
See my message below...restart your Sniffer service and it should work. Matt Computer House Support wrote: Mail from Comcast is still getting caught, even with the panic rule in place. Any suggestions? Mike Stein This E-Mail came from the Message Sniffer mailing list. For information and (un)s

Re[2]: [sniffer] Rule 353039 - .comcast.net

2005-05-10 Thread Pete McNeil
On Tuesday, May 10, 2005, 12:45:53 PM, Computer wrote: CHS> Mail from Comcast is still getting caught, even with the panic rule in CHS> place. Any suggestions? * be sure you have updated .cfg * be sure your entry is in the correct format. You will find examples at the bottom of your .cfg file w

Re[2]: [sniffer] Rule 353039 - .comcast.net

2005-05-10 Thread Pete McNeil
On Tuesday, May 10, 2005, 12:41:42 PM, Matt wrote: M> Warning! M> When you add a RulePanic entry and are running Sniffer in persistent M> mode, you have to restart the service for it to take effect. You can also issue ".exe reload" M> Pete, when you send out these notifications, would you ple

Re: [sniffer] Rule 353039 - .comcast.net

2005-05-10 Thread Computer House Support
Matt, Restarting the sniffer service seems to have done the trick. Thank you for the suggestion! Michael Stein Computer House [EMAIL PROTECTED] - Original Message - From: "Matt" <[EMAIL PROTECTED]> To: Sent: Tuesday, May 10, 2005 12:46 PM Subject: Re: [sniffer] Rule 353039 - .comca

Re: [sniffer] Rule 353039 - .comcast.net

2005-05-10 Thread Matt
Pete, My config file was completely unedited, i.e. every setting was commented out. I verified that one and a half hours after the config change this rule was still hitting until I had restarted the service. Maybe there is a bug in the persistent engine reloading the config without interventi

Re[2]: [sniffer] Rule 353039 - .comcast.net

2005-05-10 Thread Pete McNeil
On Tuesday, May 10, 2005, 1:03:18 PM, Matt wrote: M> Pete, M> My config file was completely unedited, i.e. every setting was commented M> out. I verified that one and a half hours after the config change this M> rule was still hitting until I had restarted the service. Maybe there M> is a bug i