Re: Newest spammer trick - non-blank subject lines?

2010-02-12 Thread LuKreme
On 11-Feb-2010, at 15:42, Kris Deugau wrote: Hmm. I'd say the balance is slightly in favour of Mike's system - you CAN NOT *prevent* all false-positives, so providing some way to let senders know relatively quickly that their mail got caught seems to me to be a positive. An NDN means that

Re: MTX plugin created (Re: Spam filtering similar to SPF, less breakage)

2010-02-12 Thread Matus UHLAR - fantomas
On 02/11, Henrik K wrote: method of whitelisting. You can't seriously expect to block on some attribute that not everyone can or bothers to change (DNS). None of this On 11.02.10 16:34, dar...@chaosreigns.com wrote: I am not suggesting that anyone block anything based on MTX at this time.

Re: Pipe characters in From and To's

2010-02-12 Thread Kevin Golding
In article 20100212103757.4dde0...@goof.off.knossos.net.nz, Spiro Harvey sp...@knossos.net.nz writes So I'm just wondering if others encounter this with enough regularity, and if so what your thoughts and advice are. I don't particularly want to add rules into sendmail, so SA is my avenue of

Re: MTX plugin created (Re: Spam filtering similar to SPF, less breakage)

2010-02-12 Thread Justin Mason
On Thu, Feb 11, 2010 at 03:00, dar...@chaosreigns.com wrote: http://www.chaosreigns.com/mtx/ It might be useful to compare with MTA MARK and see what the status of that proposal currently is: http://tools.ietf.org/draft/draft-stumpf-dns-mtamark/

Re: sa-learn error.

2010-02-12 Thread RW
On Thu, 11 Feb 2010 15:16:03 -0800 fchan fc...@molsci.org wrote: I was trying to teach spamassassin 3.3.0 today with a rather large spam message and I got this error message when I did sa-learn: Feb 11 14:47:51.262 [5414] info: archive-iterator: skipping large message The message is

Re: sa-learn error.

2010-02-12 Thread RW
On Fri, 12 Feb 2010 12:58:30 + RW rwmailli...@googlemail.com wrote: On Thu, 11 Feb 2010 15:16:03 -0800 fchan fc...@molsci.org wrote: I was trying to teach spamassassin 3.3.0 today with a rather large spam message and I got this error message when I did sa-learn: Feb 11 14:47:51.262

building SA 3.3.0 with PREFIX

2010-02-12 Thread Robert Nicholson
So in the past I was able to get away with using perl Makefile.PL PREFIX=~/SALOCAL-3.3.0 where all of this versions files would end up in this directory however I also have additional site_perl stuff outside of this tree that I want SA to see such as NetAddr::IP for example. How now is this

How do maintain different versions of with a shared CPAN site_perl?

2010-02-12 Thread Robert Nicholson
So how is it possible then to arrange the installation of the each version of SA into a separate directory but yet still share a common site_perl amongst these versions? The scripts like sa-update etc seem to assume that SA is installed into the site_perl and not a separate directory for this

Re: spamassasin: sa-learn --dump magic intrepretation

2010-02-12 Thread smfabac
Michael Scheidell wrote: Is there a document regarding the interpretation of sa-learn --dump magic config: could not find site rules directory 0.000 03 0 non-token data: bayes db version 0.000 0 261451 0 non-token data: nspam

Re: bayes learning '0 messages found'

2010-02-12 Thread smfabac
tonjg wrote: raq550 server OS: strongbolt2 spamassassin.i386 0:3.2.5-1.el4 I'm trying to run: sa-learn --spam --showdots --dir /path/to...mbox but it fails with: 'Learned tokens from 0 message(s) (0 messages examined)' my spam mail is in a file called mbox but when I run the above

Re: How do maintain different versions of with a shared CPAN site_perl?

2010-02-12 Thread Kris Deugau
Robert Nicholson wrote: So how is it possible then to arrange the installation of the each version of SA into a separate directory but yet still share a common site_perl amongst these versions? The scripts like sa-update etc seem to assume that SA is installed into the site_perl and not a

Re: bayes learning '0 messages found'

2010-02-12 Thread Mark Martinec
tonjg wrote: I'm trying to run: sa-learn --spam --showdots --dir /path/to...mbox but it fails with: 'Learned tokens from 0 message(s) (0 messages examined)' my spam mail is in a file called mbox but when I run the above command to the directory containg mbox it always fails with the '0

Re: bayes learning '0 messages found'

2010-02-12 Thread smfabac
Mark Martinec wrote: tonjg wrote: I'm trying to run: sa-learn --spam --showdots --dir /path/to...mbox but it fails with: 'Learned tokens from 0 message(s) (0 messages examined)' my spam mail is in a file called mbox but when I run the above command to the directory containg mbox it

v3.3.x Rule installs/updates from updates.spamassassin.org sought.rules.yerp.org FAIL @ dns query (NXDOMAIN); other channels resolve work fine.

2010-02-12 Thread Ben DJ
I've installed, spamassassin -V SpamAssassin version 3.3.1-r905461 running on Perl version 5.10.0 Starting with a fresh install, i.e. no Updates ... ls -al /usr/local/var/spamassassin/Updates (empty) Attempts to pull rules from

Re: bayes learning '0 messages found'

2010-02-12 Thread RW
On Fri, 12 Feb 2010 09:17:54 -0800 (PST) smfabac smfa...@att.net wrote: Mark, On UNIX any file is a mbox file if it contains mail messages in the form: ^A^A^A^A mail headers mail body ^A^A^A^A ^A^A^A^A Next Message mail headers mail body ^A^A^A^A I don't know what that is, but

Re: bayes learning '0 messages found'

2010-02-12 Thread RW
On Fri, 12 Feb 2010 17:51:12 + RW rwmailli...@googlemail.com wrote: On Fri, 12 Feb 2010 09:17:54 -0800 (PST) smfabac smfa...@att.net wrote: Mark, On UNIX any file is a mbox file if it contains mail messages in the form: ^A^A^A^A mail headers mail body ^A^A^A^A

Re: Newest spammer trick - non-blank subject lines?

2010-02-12 Thread Bernd Petrovitsch
On Don, 2010-02-11 at 17:42 -0500, Kris Deugau wrote: Bernd Petrovitsch wrote: [...] I proposed the 3rd solution: - repair your spam-detection (change weight/limits, use Bayes, greylistung, etc.) to not generate so many FPs that you actually need an additional workaround. That

SA 3.30 question: redundant index in bayes?

2010-02-12 Thread Michael Scheidell
I looked at our bayes schema and at the schema in ../docs/sql/bayes_mysql.sql and I can't find the redundant index mentioned in the SA 3.30 upgrade/changes documents. did I miss something? or did I remove it years ago anyway? -- Michael Scheidell, CTO Phone: 561-999-5000, x 1259 *| *SECNAP

Re: Pipe characters in From and To's

2010-02-12 Thread SM
Hi Spiro, At 13:37 11-02-10, Spiro Harvey wrote: We're getting a boatload of To and From addresses starting with pipe characters on one of our clients' mailservers. The messages themselves don't appear particularly malicious -- the ones we've seen are just pill spam -- but there are craploads of

X-Relay-Countries can stick?

2010-02-12 Thread Robert Nicholson
Is there anyway to get his header to stick rather than one looks like now where it is removed during check presumably after Bayes has been able to do it's thing? I have no problem with the header staying on my Spam messages.

Re: X-Relay-Countries can stick?

2010-02-12 Thread Robert Nicholson
For instance when I run my test I see Feb 12 17:20:38.634 [16073] dbg: metadata: X-Relay-Countries: RU Feb 12 17:20:38.634 [16073] dbg: message: MIME PARSER START Feb 12 17:20:38.635 [16073] dbg: message: parsing normal part Feb 12 17:20:38.635 [16073] dbg: message: MIME PARSER END

Re: X-Relay-Countries can stick?

2010-02-12 Thread Robert Nicholson
Perhaps my confusion lies in the fact that it looks like headers != metadata? Is there a way or setting that allows metadata to result in headers in the message? On Feb 12, 2010, at 7:24 PM, Robert Nicholson wrote: Is there anyway to get his header to stick rather than one looks like now

Re: X-Relay-Countries can stick?

2010-02-12 Thread Jeff Mincy
From: Robert Nicholson robert.nichol...@gmail.com Date: Fri, 12 Feb 2010 19:32:00 -0600 Perhaps my confusion lies in the fact that it looks like headers != metadata? Is there a way or setting that allows metadata to result in headers in the message? Did you try add_header?

Re: X-Relay-Countries can stick?

2010-02-12 Thread RW
On Fri, 12 Feb 2010 19:32:00 -0600 Robert Nicholson robert.nichol...@gmail.com wrote: Perhaps my confusion lies in the fact that it looks like headers != metadata? Is there a way or setting that allows metadata to result in headers in the message? add_header all Relay-Countries

MTX plugin functionally complete? Re: Spam filtering similar to SPF, less breakage

2010-02-12 Thread Darxus
* Implemented blacklisting. * Clarified current recommendations and added content to the page. * Removed redirect for Microsoft Internet Explorer users and converted the page to HTML 4.01 Strict. Still http://www.chaosreigns.com/mtx/ I think the only thing left to do is to switch from send()

X-Spam-Languages always blank?

2010-02-12 Thread Robert Nicholson
I have Feb 12 19:35:31.669 [81642] dbg: textcat: X-Languages: en, X-Languages-Length: 424 in my testing but the X-Spam-Languages ends up with nothing I have in my user_prefs add_header all Languages _LANGUAGES_

Re: X-Spam-Languages always blank?

2010-02-12 Thread Matt Kettler
On 2/12/2010 10:50 PM, Robert Nicholson wrote: I have Feb 12 19:35:31.669 [81642] dbg: textcat: X-Languages: en, X-Languages-Length: 424 in my testing but the X-Spam-Languages ends up with nothing I have in my user_prefs add_header all Languages _LANGUAGES_ Is the

Re: SA 3.30 question: redundant index in bayes?

2010-02-12 Thread Matt Kettler
On 2/12/2010 2:51 PM, Michael Scheidell wrote: I looked at our bayes schema and at the schema in ../docs/sql/bayes_mysql.sql and I can't find the redundant index mentioned in the SA 3.30 upgrade/changes documents. did I miss something? or did I remove it years ago anyway? A quick diff of