Re: Whitelist questions

2010-10-05 Thread Karsten Bräckelmann
On Wed, 2010-10-06 at 00:35 -0400, Alex wrote: > > > We _really_ need to change that rule's description... > > > > Uhm, while I would never argue that naming to be unfortunate in > > hindsight, despite most of the time actually matching its stated goal... > > > > I blame this one on Alex (the other

Re: Whitelist questions

2010-10-05 Thread Alex
Hi, >> We _really_ need to change that rule's description... > > Uhm, while I would never argue that naming to be unfortunate in > hindsight, despite most of the time actually matching its stated goal... > > I blame this one on Alex (the otherwise anonymous $mysqlstudent). He's > been around long

Re: new install

2010-10-05 Thread Karsten Bräckelmann
On Fri, 2010-10-01 at 04:27 +0200, Karsten Bräckelmann wrote: > On Thu, 2010-09-30 at 21:09 -0400, dhottin...@... wrote: > > [...] I did have some mail going to /opt/spam, however it was > > internal mail. So I added our domain to the local.cf file: > > whitelist_from *...@harrisonburg.k12.v

Re: Whitelist questions

2010-10-05 Thread Karsten Bräckelmann
On Tue, 2010-10-05 at 13:09 -0700, John Hardin wrote: > On Tue, 5 Oct 2010, Michael Scheidell wrote: > > AWL is NOT an 'auto whitelist'. and is not used by default configs anymore. > > instead of including the massive volume of documentation on what AWL is and > > is not, just google. > > We _r

Re: Whitelist questions

2010-10-05 Thread Karsten Bräckelmann
On Tue, 2010-10-05 at 13:16 -0700, John Hardin wrote: > On Tue, 5 Oct 2010, Karsten Bräckelmann wrote: Your MUA still can't handle UTF-8, eh? Fixed my name. ;) > > If there really is no way to use whitelist_from_rcvd, you of course > > always can write custom header rules, matching against the ps

Re: Whitelist questions

2010-10-05 Thread Joseph Brennan
David B Funk wrote: Notice also that the rule checks the header From:, not the envelope, and they could be different. When did that change? Sorry. I am wrong. Joseph Brennan Columbia University Information Technology

Re: New plugin: DecodeShortURLs

2010-10-05 Thread Brent Gardner
René Berber wrote: On 10/5/2010 3:42 PM, Yet Another Ninja wrote: On 2010-10-05 22:35, Brent Gardner wrote: [snip] Using URLs like these: http://goo.gl/foo http://bit.ly/foo http://2chap.it/foo I consistently hit on these rules: HAS_SHORT_URL SHORT_URL_404 SHORT_URL_CHAINED SHO

Re: New plugin: DecodeShortURLs

2010-10-05 Thread René Berber
On 10/5/2010 3:42 PM, Yet Another Ninja wrote: > On 2010-10-05 22:35, Brent Gardner wrote: [snip] >> Using URLs like these: >> >> http://goo.gl/foo >> http://bit.ly/foo >> http://2chap.it/foo >> >> I consistently hit on these rules: >> >> HAS_SHORT_URL >> SHORT_URL_404 >> SHORT_URL_CHAINED >> SHO

Re: New plugin: DecodeShortURLs

2010-10-05 Thread Yet Another Ninja
On 2010-10-05 22:35, Brent Gardner wrote: Steve Freegard wrote: Hi All, On 17/09/10 14:11, Steve Freegard wrote: Hi All, Recently I've been getting a bit of filter-bleed from a bunch of spams injected via Hotmail/Yahoo that contain shortened URLs e.g. bit.ly/foo that upon closer inspection wo

Re: New plugin: DecodeShortURLs

2010-10-05 Thread Brent Gardner
Steve Freegard wrote: Hi All, On 17/09/10 14:11, Steve Freegard wrote: Hi All, Recently I've been getting a bit of filter-bleed from a bunch of spams injected via Hotmail/Yahoo that contain shortened URLs e.g. bit.ly/foo that upon closer inspection would have been rejected with a high score if

Re: Whitelist questions

2010-10-05 Thread Yet Another Ninja
On 2010-10-05 22:16, John Hardin wrote: On Tue, 5 Oct 2010, Karsten Br�ckelmann wrote: If there really is no way to use whitelist_from_rcvd, you of course always can write custom header rules, matching against the pseudo header X-Spam-Relays-Internal or friends, carefully constructing the RE to

Re: Whitelist questions

2010-10-05 Thread John Hardin
On Tue, 5 Oct 2010, Karsten Br?ckelmann wrote: If there really is no way to use whitelist_from_rcvd, you of course always can write custom header rules, matching against the pseudo header X-Spam-Relays-Internal or friends, carefully constructing the RE to match a specific Received header by cons

Re: Whitelist questions

2010-10-05 Thread John Hardin
On Tue, 5 Oct 2010, Michael Scheidell wrote: On 10/5/10 10:40 AM, Alex wrote: * 0.7 AWL AWL: From: address is in the auto white-list AWL is NOT an 'auto whitelist'. and is not used by default configs anymore. instead of including the massive volume of documentation on what AWL

Re: Whitelist questions

2010-10-05 Thread David B Funk
On Tue, 5 Oct 2010, Joseph Brennan wrote: > > --On Tuesday, October 5, 2010 10:40 -0400 Alex > wrote: > > > I have an email that I'm trying to whitelist using whitelist_from_rcvd > > and it's not working as I expect. I've created an entry: > > [snip..] > > Notice also that the rule checks the hea

Re: Whitelist questions

2010-10-05 Thread Alex
Hi, >> $ host 209.16.192.170 >> 170.192.16.209.in-addr.arpa domain name pointer Lanyon.com. > > but they don't match: > host Lanyon.com > Lanyon.com has address 97.74.177.132 > > 97.74.177.132 > 132.177.74.97.in-addr.arpa domain name pointer > ip-97-74-177-132.ip.secureserver.net. Ah, right, I se

Re: Whitelist questions

2010-10-05 Thread Michael Scheidell
On 10/5/10 12:45 PM, Alex wrote: $ host 209.16.192.170 170.192.16.209.in-addr.arpa domain name pointer Lanyon.com. but they don't match: host Lanyon.com Lanyon.com has address 97.74.177.132 97.74.177.132 132.177.74.97.in-addr.arpa domain name pointer ip-97-74-177-132.ip.secureserver.net. wh

Re: Whitelist questions

2010-10-05 Thread Alex
Hi, >> $ host S253906HZ1EW06.usstls6-hosting.savvis.net >> Host S253906HZ1EW06.usstls6-hosting.savvis.net not found: 3(NXDOMAIN) > > Err, you're doing rDNS lookup for the connecting host's IP, not the > rather arbitrary HELO as you just did. Okay, understood. I'm able to resolve that IP, though:

Re: New plugin: DecodeShortURLs

2010-10-05 Thread Jason Bertoch
On 2010/10/04 6:35 PM, Martin Gregorie wrote: Just a data point for you. I'm running DecodeShortURLs with the as-issued .cf file (log,cache,syslog options commented out). I initially tried running the plugin with these options commented out, but it just doesn't work. It needs those defined.

Re: Whitelist questions

2010-10-05 Thread Karsten Bräckelmann
On Tue, 2010-10-05 at 11:51 -0400, Alex wrote: > > As the documentation [1] clearly states, the second value (a) is a > > string matched against the relay's rDNS in the Received headers, and > > (b) it is your MX's responsibility to perform the rDNS lookup and add it > > to the header. > > $ hos

Re: Whitelist questions

2010-10-05 Thread Alex
Hi, >> X-Envelope-From: >> Received: from S253906HZ1EW06.usstls6-hosting.savvis.net (unknown >> [209.16.192.170]) >> >> Is it because there is no reverse DNS entry? > > As the documentation [1] clearly states, the second value  (a) is a > string matched against the relay's rDNS in the Received he

Re: Whitelist questions

2010-10-05 Thread Karsten Bräckelmann
On Tue, 2010-10-05 at 10:40 -0400, Alex wrote: > I have an email that I'm trying to whitelist using whitelist_from_rcvd > and it's not working as I expect. I've created an entry: > > whitelist_from_rcvd u...@lanyon.com savvis.net > > Here is the corresponding received header: > > X-Envelope-From

Re: Whitelist questions

2010-10-05 Thread Joseph Brennan
--On Tuesday, October 5, 2010 10:40 -0400 Alex wrote: I have an email that I'm trying to whitelist using whitelist_from_rcvd and it's not working as I expect. I've created an entry: whitelist_from_rcvd u...@lanyon.com savvis.net Here is the corresponding received header: X-Envelope-From:

Re: Whitelist questions

2010-10-05 Thread Michael Scheidell
On 10/5/10 10:40 AM, Alex wrote: Hi, I have an email that I'm trying to whitelist using whitelist_from_rcvd and it's not working as I expect. I've created an entry: whitelist_from_rcvd u...@lanyon.com savvis.net Here is the corresponding received header: X-Envelope-From: Received: from S2539

Re: Whitelist questions

2010-10-05 Thread RW
On Tue, 5 Oct 2010 10:40:07 -0400 Alex wrote: > Hi, > > I have an email that I'm trying to whitelist using whitelist_from_rcvd > and it's not working as I expect. I've created an entry: > >... > > Is it because there is no reverse DNS entry? Yes. It would be nice to have the option look it up

Whitelist questions

2010-10-05 Thread Alex
Hi, I have an email that I'm trying to whitelist using whitelist_from_rcvd and it's not working as I expect. I've created an entry: whitelist_from_rcvd u...@lanyon.com savvis.net Here is the corresponding received header: X-Envelope-From: Received: from S253906HZ1EW06.usstls6-hosting.savvis.ne

Re: New plugin: DecodeShortURLs

2010-10-05 Thread John Horne
On Mon, 2010-10-04 at 22:55 +0100, John Horne wrote: > > I grabbed a copy of the above plugin and tried it this afternoon (on a > CentOS 5.5 system). We log all our spamd messages to /var/log/maillog > via syslog. For the plugin I disabled all the options except > 'url_shortener_syslog' which was s

Re: New plugin: DecodeShortURLs

2010-10-05 Thread David Touzeau
Many thanks ADDED in Artica web Open Source Interface !! http://www.artica.fr/index.php/menudocmessaging/39-manage-filters-anti-spam-content-filters/391--shorturls-spam-checking-plugin-with-spamassassin On 17/09/2010 15:11, Steve Freegard wrote: Hi All, Recently I've been getting a bit of f