Re: Detecting the Registrar of the sending host?

2008-07-08 Thread Michele Neylon :: Blacknight
On 7 Jul 2008, at 14:40, Richard Frovarp wrote: Fortune 500's suffer from botnet infections as well. Exactly Mr Michele Neylon Blacknight Solutions Hosting Colocation, Brand Protection http://www.blacknight.com/ http://blog.blacknight.com/ Intl. +353 (0) 59 9183072 US: 213-233-1612

Re: Detecting the Registrar of the sending host?

2008-07-08 Thread Michele Neylon :: Blacknight
On 2 Jul 2008, at 17:30, Yet Another Ninja wrote: Even EUrid is happily supporting pillz spammers on .eu Eurid is a registry NOT a registrar Mr Michele Neylon Blacknight Solutions Hosting Colocation, Brand Protection http://www.blacknight.com/ http://blog.blacknight.com/ Intl. +353 (0)

Re: Being Buried In Returned Email - Need To Mark Certain IPs

2008-07-08 Thread Michelle Konzack
Am 2008-06-29 07:07:58, schrieb thadcoco: servers. Virtually all these emails are being sent from a zombie at a single IP. OK i.e.: All the messages contain the following line somewhere within: Received: from d04m-89-83-98-193.d4.club-internet.fr ([89.83.98.193]) I can't figure out how

Re: Lots of spam with the following snip

2008-07-08 Thread Michelle Konzack
Hi Steven, It is realy worth, to filter this with spamassassin? I get per day over 4 of them... and filter it easyly from procmail since the messages are always generated by the same software. :0B * contains a virus which has .ATTENTION.Anti_Virus_Spam/ Thanks, Greetings and

Re: Being Buried In Returned Email - Need To Mark Certain IPs

2008-07-08 Thread Michelle Konzack
Am 2008-06-29 10:55:19, schrieb thadcoco: I just tried, but it doesn't work either. Recall that the nasty IP is wrapped as part of an attachment. I need to be able to scan the entire raw message with either SA or I suppose procmail. Don't be to complicate and EGREP the BODY for it: :0B

Re: Avoid spam 'La Sante Est Bonne'

2008-07-08 Thread Michelle Konzack
Salut Philippe, Am 2008-07-01 13:44:52, schrieb Philippe Couas: Hi, How could i avoid theses spam ? Avec procmail? It is a EuroPharmacy spam :0B * ! [EMAIL PROTECTED] * EuroPharmac(ie|y) /dev/null i have replace my company name by 'societe' But not infodev? Greetings

Re: Avoid spam 'La Sante Est Bonne'

2008-07-08 Thread Justin Mason
Michelle Konzack writes: Salut Philippe, Am 2008-07-01 13:44:52, schrieb Philippe Couas: Hi, How could i avoid theses spam ? Avec procmail? It is a EuroPharmacy spam :0B * ! [EMAIL PROTECTED] * EuroPharmac(ie|y) /dev/null Hmm. Michelle, is this a SpamAssassin list,

Re: Question about RelayCountry

2008-07-08 Thread Steven W. Orr
On Monday, Jul 7th 2008 at 05:41 -, quoth Justin Mason: = =Matus UHLAR - fantomas writes: = On 06.07.08 23:09, Steven W. Orr wrote: = Should I expect to see X-Relay-Countries as an added header in my = unrejected mail or is that only added to rejected mail? (Right now I do = not see

Re: Question about RelayCountry

2008-07-08 Thread McDonald, Dan
On Tue, 2008-07-08 at 10:00 -0400, Steven W. Orr wrote: On Monday, Jul 7th 2008 at 05:41 -, quoth Justin Mason: = =Matus UHLAR - fantomas writes: = On 06.07.08 23:09, Steven W. Orr wrote: = Should I expect to see X-Relay-Countries as an added header in my = unrejected mail or is

Re: Question about RelayCountry

2008-07-08 Thread Steven W. Orr
On Tuesday, Jul 8th 2008 at 10:18 -, quoth McDonald, Dan: =On Tue, 2008-07-08 at 10:00 -0400, Steven W. Orr wrote: = On Monday, Jul 7th 2008 at 05:41 -, quoth Justin Mason: = = = = =Matus UHLAR - fantomas writes: = = On 06.07.08 23:09, Steven W. Orr wrote: = = Should I expect to see

AWL size reduction (was Re: Bayes database clearance)

2008-07-08 Thread Kris Deugau
(Subject changed to match the OP's question, which wasn't actually about Bayes.) Jared Hall wrote: Try: http://www.deepnet.cx/~kdeugau/spamtools/trim_whitelist and customize the script as per your installation. Hope that helps. FWIW I'm now running this nightly on a pair of systems with a

mysql AWL issue....

2008-07-08 Thread Adam Harrison
I put the following in local.cf (passwords obscured): bayes_store_module Mail::SpamAssassin::BayesStore::MySQL bayes_sql_dsn DBI:mysql:spamassassin:sa-db.intelius.com:3306 bayes_sql_username readwrite bayes_sql_password auto_whitelist_factory

Re: mysql AWL issue....

2008-07-08 Thread Michael Parker
On Jul 8, 2008, at 12:42 PM, Adam Harrison wrote: I put the following in local.cf (passwords obscured): bayes_store_module Mail::SpamAssassin::BayesStore::MySQL bayes_sql_dsn DBI:mysql:spamassassin:sa-db.intelius.com:3306 bayes_sql_username readwrite bayes_sql_password

RE: mysql AWL issue....

2008-07-08 Thread Adam Harrison
Because /var/spool/MIMEDefang/.spamassassin/auto-whitelist is still being updated, but if I go into mysql and do a count on the AWL entries it comes up zero: mysql select count(*) from awl; +--+ | count(*) | +--+ |0 | +--+ 1 row in set (0.00 sec) -Adam

Re: mysql AWL issue....

2008-07-08 Thread Dave O'Neill
On Tue, Jul 08, 2008 at 11:30:30AM -0700, Adam Harrison wrote: Because /var/spool/MIMEDefang/.spamassassin/auto-whitelist is still being updated, but if I go into mysql and do a count on the AWL entries it comes up zero: Your log messages are from 'spamd', but by default, MIMEDefang uses the

RE: mysql AWL issue....

2008-07-08 Thread SM
At 11:30 08-07-2008, Adam Harrison wrote: Because /var/spool/MIMEDefang/.spamassassin/auto-whitelist is still being updated, but if I go into mysql and do a count on the AWL entries it comes up zero: Is your filter (MIMEdefang) reading its settings from local.cf? Regards, -sm

RE: mysql AWL issue....

2008-07-08 Thread Adam Harrison
It seems to be, as the bayes entry in local.cf works fine. -Adsm -Original Message- From: SM [mailto:[EMAIL PROTECTED] Sent: Tuesday, July 08, 2008 11:47 AM To: Adam Harrison Cc: users@spamassassin.apache.org Subject: RE: mysql AWL issue At 11:30 08-07-2008, Adam Harrison wrote:

RE: mysql AWL issue....

2008-07-08 Thread Adam Harrison
I thought I had mimedfang using spamd, but I don't remember where I did that mod. But in case MD is calling the SA modules directly, I added the directives from local.cf to sa-mimedefang.cf and the awl table in MySQL is still not being updated. -Adam -Original Message- From: Dave O'Neill