Re: pay attention if you use unrar

2022-06-29 Thread Martin
Thanks for sharing, Pedro. Useful information. Unrar updated asap. ;-) Martin sorry for the semi off-topic but worths so share... important unrar bug... https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/ Regards, Pedro.

Re: shit from serverion

2022-06-29 Thread John Hardin
On Wed, 29 Jun 2022, Vincent Lefevre wrote: On 2022-06-29 13:14:58 +, Marc wrote: Today I decided to spend some time getting all the ip's[1] (these are all /24 thus you have to add 164.215.103.1-164.215.103.255) of serverion, who is sending out constant stream of crap. I thought about posti

Re: RBL via Spamassasin configuration

2022-06-29 Thread Bill Cole
META: The message below seems to be a reply to a message by Harald Reindl, who was blocked from posting to this mailing list in the past for chronic unreasonably combative behavior. Unfortunately, there's no way to stop him from reading this mailing list via any of the public archives or a 's

Re: shit from serverion

2022-06-29 Thread Pedro David Marco
On our side it is a huge list as well... does Serverion send anything clean? Pedro. On Wednesday, June 29, 2022, 04:02:05 PM GMT+2, Matus UHLAR - fantomas wrote: On 29.06.22 13:14, Marc wrote: >Today I decided to spend some time getting all the ip's[1] (these are all > /24 thus you ha

Re: shit from serverion

2022-06-29 Thread Vincent Lefevre
On 2022-06-29 13:14:58 +, Marc wrote: > Today I decided to spend some time getting all the ip's[1] (these > are all /24 thus you have to add 164.215.103.1-164.215.103.255) of > serverion, who is sending out constant stream of crap. I thought > about posting it here so you do not need to do this

Re: shit from serverion

2022-06-29 Thread Matus UHLAR - fantomas
On 29.06.22 13:14, Marc wrote: Today I decided to spend some time getting all the ip's[1] (these are all /24 thus you have to add 164.215.103.1-164.215.103.255) of serverion, who is sending out constant stream of crap. I thought about posting it here so you do not need to do this work. If you

shit from serverion

2022-06-29 Thread Marc
Today I decided to spend some time getting all the ip's[1] (these are all /24 thus you have to add 164.215.103.1-164.215.103.255) of serverion, who is sending out constant stream of crap. I thought about posting it here so you do not need to do this work. If you do some random checks, you can s

pay attention if you use unrar

2022-06-29 Thread Pedro David Marco
sorry for the semi off-topic but worths so share... important unrar bug... https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/ Regards, Pedro.

Re: RBL via Spamassasin configuration

2022-06-29 Thread Matus UHLAR - fantomas
On 2022-06-29 10:25, Matus UHLAR - fantomas wrote: Since SpamAssassin does deep header scanning, it's more effective than just use incoming IP at MTA level. On 29.06.22 10:58, Benny Pedersen wrote: this is not good, its a sign of forwarding that forwards spam in the first place, that make the

Re: RBL via Spamassasin configuration

2022-06-29 Thread Benny Pedersen
On 2022-06-29 11:05, Marc wrote: I don't really get what you wrote. There is something for blocking at ip level, least resource intensive, and there is an application for doing the advanced header/body scans at a later stage. dont use deap ip scanning on dnsbl use deap content scanning is ok,

RE: RBL via Spamassasin configuration

2022-06-29 Thread Marc
> > On 2022-06-29 10:25, Matus UHLAR - fantomas wrote: > > Since SpamAssassin does deep header scanning, it's more effective than > > just use incoming IP at MTA level. > > this is not good, its a sign of forwarding that forwards spam in the > first place, that make the forwarding ip grey, not wh

Re: RBL via Spamassasin configuration

2022-06-29 Thread Benny Pedersen
On 2022-06-29 10:25, Matus UHLAR - fantomas wrote: Since SpamAssassin does deep header scanning, it's more effective than just use incoming IP at MTA level. this is not good, its a sign of forwarding that forwards spam in the first place, that make the forwarding ip grey, not white/wellcommed,

Re: RBL via Spamassasin configuration

2022-06-29 Thread Matus UHLAR - fantomas
Is this actually going out and doing a DNS query or reading from the header of the message? I think I want to actually do the DNS query and I will cache locally to avoid issues and increase performance. That is what dns servers do, cache. If you have your local dns, these requests are probably