Re: Updated spammy TLD rules - add .date TLD

2017-11-28 Thread RW
On Tue, 28 Nov 2017 09:07:34 -0800 (PST) John Hardin wrote: > On Tue, 28 Nov 2017, RW wrote: > > > On Mon, 27 Nov 2017 17:37:35 -0800 (PST) > > John Hardin wrote: > > > >> The ".date" TLD just started bombarding my inbox... > > > >> score FROM_RARE_TLD3.000 > >> score REPTO_RA

Re: spamd Will Not Create unix:socket

2017-11-28 Thread Bill Cole
On 28 Nov 2017, at 12:15, Colony.three wrote: [...] My God. It's full of stars! This fixed the spamass-milter problem. And it seems to be the correct way to fix the hundreds of other SELinux errors I have. You take this box, and put it through a magic tunnel and see if it looks right. If

HTML_IMAGE_ONLY_* generating too many FP's

2017-11-28 Thread Sebastian Arcus
I'm having more and more problems with the HTML_IMAGE_ONLY_* set of rules recently generating false positives. Plenty of business emails will include a logo at the bottom - and not everybody is a graphics expert to make their logo a tiny optimised gif or png - so some of these are slightly big

Re: spamd Will Not Create unix:socket

2017-11-28 Thread Colony.three
>> First, copy and paste lines from the log into a file called thing0.log where >> thing is a mnemonic name for what you're trying to enable. In this example, >> thing is smartd >> >> root# cd; mkdir selinux; cd selinux >> root# cat > smartd0.log >> type=AVC msg=audit(1425551687.181:491): avc: de

Re: Updated spammy TLD rules - add .date TLD

2017-11-28 Thread John Hardin
On Tue, 28 Nov 2017, RW wrote: On Mon, 27 Nov 2017 17:37:35 -0800 (PST) John Hardin wrote: The ".date" TLD just started bombarding my inbox... score FROM_RARE_TLD3.000 score REPTO_RARE_TLD 3.000 score URI_RARE_TLD 3.000 It's pretty common for the author domain to

Re: spamd Will Not Create unix:socket

2017-11-28 Thread Colony.three
>> On 11/27/2017 10:34 PM, Colony.three wrote: >> ExecStartPre=/bin/chown -R spamd:spamd /run/spamassassin There's a root exploit for the "spamd" user in that last line. Assuming you got the tmpfiles.d thing working, you should delete those ExecStartPre commands. >>> >>> Ca

Re: spamd Will Not Create unix:socket

2017-11-28 Thread Matus UHLAR - fantomas
On 11/27/2017 10:34 PM, Colony.three wrote: ExecStartPre=/bin/chown -R spamd:spamd /run/spamassassin There's a root exploit for the "spamd" user in that last line. Assuming you got the tmpfiles.d thing working, you should delete those ExecStartPre commands. Can you explain further please?

Re: spamd Will Not Create unix:socket

2017-11-28 Thread Michael Orlitzky
On 11/27/2017 10:34 PM, Colony.three wrote: >> ExecStartPre=/bin/chown -R spamd:spamd /run/spamassassin >> >> There's a root exploit for the "spamd" user in that last line. Assuming >> you got the tmpfiles.d thing working, you should delete those >> ExecStartPre commands. > > Can you explain f

Re: Updated spammy TLD rules - add .date TLD

2017-11-28 Thread RW
On Mon, 27 Nov 2017 17:37:35 -0800 (PST) John Hardin wrote: > The ".date" TLD just started bombarding my inbox... > > score FROM_RARE_TLD3.000 > score REPTO_RARE_TLD 3.000 > score URI_RARE_TLD 3.000 It's pretty common for the author domain to be in the body of an email

Re: spamd Will Not Create unix:socket

2017-11-28 Thread Toby Goodwin
>I am really trying to not turn off SELinux with this server, and only have >this one showstopper error. But I don't know what to do with this gibberish: Here's an extract from a page I wrote about SELinux (not currently published, or I could just send you the link). --->8--- This is where it