Re: spamd, postfix & user_prefs [Can you use fetchmail->procmail->maildir?]

2011-11-11 Thread Andrzej Adam Filip
etchmail fetches mail from a remote server, * fetchmail passes email to procmail script (see "mda" option) * procmail script does AV and AS scans * procmail delivers the mail to user's Maildir I use extended variant of the above configuration for years. [Main change avoids delaying e

Re: Spam email many have RCVD_IN_DNSWL_MED

2011-10-11 Thread Andrzej Adam Filip
Alessio Cecchi wrote: > I'm an italian user of spamassassin. During the last 3 weeks many spam > email have rating cut down by the rules "RCVD_IN_DNSWL_MED". Also > BAYES_99 can to nothing against this :-( > > For now I solved the problem by disable this check, but is a common > problems for many

Re: Autowhitelist based on Return-Path: (envelope sender) for mailing list

2011-07-12 Thread Andrzej Adam Filip
Matus UHLAR - fantomas wrote: > On 08.07.11 18:05, Andrzej Adam Filip wrote: >>Would not it make sense to add autowhitelisting based on Return-Path: >>header (envelope sender) to auto whitelist mailing lists? >>[ It may be triggered only when List-Id: header is present. ] &

Re: Autowhitelist based on Return-Path: (envelope sender) for mailing list

2011-07-08 Thread Andrzej Adam Filip
Michelle Konzack wrote: > Hello Andrzej Adam Filip, > > Am 2011-07-08 18:05:11, hacktest Du folgendes herunter: >> Would not it make sense to add autowhitelisting based on Return-Path: >> header (envelope sender) to auto whitelist mailing lists? >> [ It may be triggere

Re: Securing spamd

2011-07-08 Thread Andrzej Adam Filip
gest to isolate spamd from possible outside intrusions? >> > Thanks... >> >> 1: root is needed for any bind ports below 1024 >> >> 2: but the root user do no threads for spamd >> >> same goes for eg apache, maybe i should stop it ? -) > Stop what?

Re: Securing spamd [single (non root) OS user]

2011-07-08 Thread Andrzej Adam Filip
suggest to isolate spamd from possible outside intrusions? > Thanks... Do you need spamd changing OS user ids? (e.g. to access ~/.spamassassin/ ) I have used "personal" [single (non root) OS user] spamd without any problems. -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu I h

Autowhitelist based on Return-Path: (envelope sender) for mailing list

2011-07-08 Thread Andrzej Adam Filip
Would not it make sense to add autowhitelisting based on Return-Path: header (envelope sender) to auto whitelist mailing lists? [ It may be triggered only when List-Id: header is present. ] -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu Fame is a vapor; popularity an accident; the o

Re: Lowering spam threshold [avoid discarding at high cost]

2011-07-08 Thread Andrzej Adam Filip
scarded important message from one of my users and it took a few days for sender *and recipient* to find out that message has been silently discarded: *sender assumed that recipient reads it in silence, * recipient assumed in silence that those [...] longer have not sent it yet I can treat it as funn

Re: TTL and DNSBLs [how to improve DNSBL/DNSWL "cache-ability"]

2011-07-07 Thread Andrzej Adam Filip
"David F. Skoll" wrote: > On Thu, 07 Jul 2011 15:31:47 +0200 > Andrzej Adam Filip wrote: > >> > The point is that by definition, you can't have a per-IP >> > negative-cache TTL. > >> But it is possible to use a wildcard DNS record for "not

Re: Reduce filtering time by white-listing [Mail::SpamAssassin::Plugin::Shortcircuit]

2011-07-07 Thread Andrzej Adam Filip
more than some short network tests... > Does what I desire seem as what can be achieved? Or maybe I got > something wrong? Please let me know... Have you considered using Shortcircuit plugin? Mail::SpamAssassin::Plugin::Shortcircuit IMHO it should be capable to deliver what you want. -- [pl>en

Re: TTL and DNSBLs [per-IP negative-cache TTL]

2011-07-07 Thread Andrzej Adam Filip
; negative-cache TTL. But it is possible to use a wildcard DNS record for "not listed", is not it? :-) The question is: Would it be cost effective? -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu I never met a man I didn't want to fight. -- Lyle Alzado, professional football lineman

Re: DUL/DUL+ redesign to improve DNS cache hit ratio [SA v. MTA]

2011-07-06 Thread Andrzej Adam Filip
"David F. Skoll" wrote: > On Wed, 06 Jul 2011 08:15:47 +0200 > Andrzej Adam Filip wrote: > >> It may improve performance e.g. in case of hundredths mail servers in >> a data/co-location center using shared forwarder and rejecting on >> first DNSBL hit.

Re: DUL/DUL+ redesign to improve DNS cache hit ratio [SA v. MTA]

2011-07-05 Thread Andrzej Adam Filip
"David F. Skoll" wrote: > On Tue, 05 Jul 2011 23:26:16 +0200 > Andrzej Adam Filip wrote: > >> Would you recommend redesigning (mainly) DUL/DUL+ DNSBL lists to >> improve DNS cache hit ratio? > > No, not really. The poor cache hit ratio doesn't seem

DUL/DUL+ redesign to improve DNS cache hit ratio [Was: TTL and DNSBLs]

2011-07-05 Thread Andrzej Adam Filip
ive name server for the DNSBL. Would you recommend redesigning (mainly) DUL/DUL+ DNSBL lists to improve DNS cache hit ratio? -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu The Second Law of Thermodynamics: If you think things are in a mess now, just wait! -- Jim Warner

DUL/DUL+ redesign to improve DNS cache hit ratio [Was: TTL and DNSBLs]

2011-07-05 Thread Andrzej Adam Filip
ive name server for the DNSBL. Would you recommend redesigning (mainly) DUL/DUL+ DNSBL lists to improve DNS cache hit ratio? -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu The Second Law of Thermodynamics: If you think things are in a mess now, just wait! -- Jim Warner

RelayCountry plugin: make it capable to use IP::Country alternatives [Was: Score on sender domain by country]

2011-04-11 Thread Andrzej Adam Filip
does not provide libip-country-perl package (debianized IP::Country module). -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu In the long run, every program becomes rococco, and then rubble. -- Alan Perlis

Re: DNSWL rules downscoring spam

2011-04-05 Thread Andrzej Adam Filip
ams from higher trust levels are quite rare. P.S. I report received spam to spamcop.net and dnswl.org (among others) using "semi automatic" scripts. -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu When a lion meets another with a louder roar, the first lion thinks the last a bore. -- G. B. Shaw

Re: DNSWL abuse reports by domain, over time

2011-04-05 Thread Andrzej Adam Filip
of reports? AFAIK it would be "much less impressive" and "casting doubts about credibility". -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu People think love is an emotion. Love is good sense. -- Ken Kesey

Re: how to disable network tests?

2011-03-11 Thread Andrzej Adam Filip
in spam detection -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu We are what we pretend to be. -- Kurt Vonnegut, Jr.

Re: DNSWL rules downscoring spam [DNSWL reporting automation]

2011-02-20 Thread Andrzej Adam Filip
eally need a method to auto-report violations of > DNSWL. My spam traps receive dozens or more every week. But I don't > have time to file a web form every time it happens. > > Warren Could you redirect/copy spams with DNSWL_* hits to separate maildir? I use quite simple perl script for DNSWL reporting. -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu Almost nothing in Perl serves a single purpose. -- Larry Wall in <199712040054.qaa13...@wall.org>

Re: Off topic: best RBLs to use to block at smtp connection?

2011-01-03 Thread Andrzej Adam Filip
Jari Fredriksson wrote: > On 3.1.2011 20:13, Andrzej Adam Filip wrote: >> Jari Fredriksson wrote: >>> On 3.1.2011 18:33, Bowie Bailey wrote: >>>> >>>> I've been using zen.spamhaus.org as an MTA blacklist for quite a while >>>> now. W

Re: Off topic: best RBLs to use to block at smtp connection?

2011-01-03 Thread Andrzej Adam Filip
understand "limit of free queries" is sufficient for your server, is not it? -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu Television is a medium because anything well done is rare. -- attributed to both Fred Allen and Ernie Kovacs

Re: Worthwhile to scan outgoing?

2010-06-21 Thread Andrzej Adam Filip
anyone here currently scanning their outgoing mail with SA? Good > results? Bad results? Instead of "scanning every outgoing email" you may consider scanning "significantly above average activity" at least with non local tests (bulk detectors). -- [pl>en: Andrew] Andr

Re: DNSWL --report plugin

2010-03-15 Thread Andrzej Adam Filip
s.com/dnswl/dl/DNSWLh.pm to > /usr/share/perl5/Mail/SpamAssassin/Plugin/ (or your equivalent) > [...] Where do you check RCVD_IN_DNSWL_* tests in DNSWLh.pm file? -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu A bachelor is a selfish, undeserving guy who has cheated some woman out of a divorce. -- Don Quinn

Scanning HUGE emails - "headers only" scan

2010-03-08 Thread Andrzej Adam Filip
Do you think it would make sense to introduce options for scanning "headers only" in big messages? I have received recently a new (small) wave of big spams. -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu There is nothing new except what has been forgotten. -- Marie Antoinette

Re: Valid mail from .cn

2009-10-09 Thread Andrzej Adam Filip
dress to "country of origin" e.g. zz.countries.nerd.dk, origin.asn.cymru.com. -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu If a man had a child who'd gone anti-social, killed perhaps, he'd still tend to protect that child. -- McCoy, "The Ultimate Computer", stardate 4731.3

Re: learning from IMAP spam collection

2009-05-17 Thread Andrzej Adam Filip
reporting into one custom perl script. -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu Old men are fond of giving good advice to console themselves for their inability to set a bad example. -- La Rochefoucauld, "Maxims"

Preview with "guessed" encoding

2009-03-16 Thread Andrzej Adam Filip
urn "bushes" and (us ascii) http links * Encode::decode('big5',$status->get_content_preview()) return something auto-translators can translate into "making sense" English but the http links are missing -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu Ad

Re: changing local_test_only between tests

2009-03-09 Thread Andrzej Adam Filip
Karsten Bräckelmann wrote: > On Mon, 2009-03-09 at 17:42 +0100, Andrzej Adam Filip wrote: >> How to change local_tests_only option of Mail::SpamAssassin object >> *between* mail tests? Can it be done safely? >> >> I would like to run "remote" test as default

Re: changing local_test_only between tests

2009-03-09 Thread Andrzej Adam Filip
Justin Mason wrote: > On Mon, Mar 9, 2009 at 16:42, Andrzej Adam Filip wrote: >> How to change local_tests_only option of Mail::SpamAssassin object >> *between* mail tests? Can it be done safely? >> >> I would like to run "remote" test as default in my

changing local_test_only between tests

2009-03-09 Thread Andrzej Adam Filip
How to change local_tests_only option of Mail::SpamAssassin object *between* mail tests? Can it be done safely? I would like to run "remote" test as default in my procmail script but to scan *some* messages in "local tests only" mode as privacy protection. -- [pl>en: And

How to get list of DNSBL/DNSWL DNS services SA is going to query?

2009-03-07 Thread Andrzej Adam Filip
I use SA in milter (MIMEDefang.org). I do some DNS queries (in parallel) before invoking SA scan. I would like to get list of DNS queries SA is going to issue to "preload" them in pre SA invocation DNS queries. How to do it in the easiest way? -- [pl>en: Andrew] Andrzej A

Re: Dealing with low scoring spam - tighter MTA integration

2009-03-05 Thread Andrzej Adam Filip
James Wilkinson wrote: > Andrzej Adam Filip wrote: >> At "RCPT TO:" stage there are available: >> * connecting client IP address (last mail hop) >> so big part of DNSBL and DNSWL tests *CAN* be used >> * envelope sender for SPF based tests >> * enve

Re: Dealing with low scoring spam - tighter MTA integration

2009-03-05 Thread Andrzej Adam Filip
Kenneth Porter wrote: > --On Thursday, March 05, 2009 7:43 AM +0100 Andrzej Adam Filip > wrote: > >> What I would like to see is a option to make spam assassin to produce >> "weighted scores" based on subset of all tests capable to work on subset >>

Re: Dealing with low scoring spam - tighter MTA integration

2009-03-04 Thread Andrzej Adam Filip
Kenneth Porter wrote: > --On Wednesday, March 04, 2009 4:02 PM +0100 Andrzej Adam Filip > wrote: > >> May be spamassassin should create set of tests intended for use before >> replying "RCPT TO:" in SMTP session? > > Check out <http://mimedefang.org/>

Re: Dealing with low scoring spam - tighter MTA integration

2009-03-04 Thread Andrzej Adam Filip
John Hardin wrote: > On Wed, 4 Mar 2009, Andrzej Adam Filip wrote: > >>> This would be an entirely different application, not SA, wouldn't it? >> >> It can be developed using the same "spam score" logic, based subset of >> all tests requiring

Re: Dealing with low scoring spam - tighter MTA integration

2009-03-04 Thread Andrzej Adam Filip
Karsten Bräckelmann wrote: > On Wed, 2009-03-04 at 16:02 +0100, Andrzej Adam Filip wrote: >> Karsten Bräckelmann wrote: > >> > About 98-99% of my spam in-stream scores as high, that any such proposal >> > results in a useless increase of the score. >>

Dealing with low scoring spam - tighter MTA integration [was: 2 + 2 != 4 - Spamassassin needs a new paradigm]

2009-03-04 Thread Andrzej Adam Filip
e" *AND* mail source reputation. Temporary reject in SMTP session should increase chances of DNSBL hits by reducing "blind spot" period of newly created spam sources. -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu The difference between science and the fuzzy subjects is that science requires reasoning while those other subjects merely require scholarship. -- Robert Heinlein

Re: DNSWL as trusted_networks-entries

2009-02-28 Thread Andrzej Adam Filip
Matthias Leisi wrote: > Andrzej Adam Filip schrieb: > >>> Speaking of which, it may actually make sense to use all of >>> dnswl.org's entries as trusted_networks-entries... >> >> Do you want it even for DNSWL trust levels of "none&q

Re: How to disable DNSWL? [DNSWL as trusted_networks-entries]

2009-02-28 Thread Andrzej Adam Filip
) URL(s): http://www.dnswl.org/ -- [pl>en: Andrew] Andrzej Adam Filip : a...@onet.eu When choosing between two evils, I always like to take the one I've never tried before. -- Mae West, "Klondike Annie"

Re: custom post-processing. Howto?

2009-01-08 Thread Andrzej Adam Filip
pt "call" spamassassin? SpamAssassin is a set of perl modules that can be used by your perl script. - use SpamAssassin to extract From: or ReturnPath: header - you can get it easily - this is piece I am would have to dig a little [ my spamassassin experience is limited ]

Re: Processing Outbound Emails Differently

2008-10-12 Thread Andrzej Adam Filip
make MIMEDefang.org milter call SA code differently for incoming and outgoing messages. -- [pl>en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] I must have a prodigious quantity of mind; it takes me as much as a week sometimes to make it up. -- Mark Twain, "The Innocents Abroad"

Re: Trusting TLS for spamfighting purposes?

2008-10-06 Thread Andrzej Adam Filip
g MIMEDefang.org milter -- [pl>en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] You're always thinking you're gonna be the one that makes 'em act different. -- Woody Allen, "Manhattan"

Re: Skip scanning for large mails

2008-09-13 Thread Andrzej Adam Filip
passed to spamd. The maximum message size is 256 MB. The size is specified in bytes, as a positive integer greater than 0. For example, -s 50. -- [pl>en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] :-) your own self. -- Larry Wall in <[EMAIL PROTECTED]>

Re: High load average [sendmail+milter]

2008-08-11 Thread Andrzej Adam Filip
n "country of origin" e.g. lax rules for "near by countries" and picky mode for CN, KR, TW. [requires generating sendmail.cf also from non sendmail.org m4 files] [more hints upon request] 2) Have you considered using MIMEDefang.org milter? 2a) It can do more checks than merely

Re: Sendmail Question [OT]

2008-07-18 Thread Andrzej Adam Filip
epts SMTP connections also on port 587. Port 587 is intended for MUA->MTA communication unlike port 25 intended for MTA->MTA communication. -- [pl>en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] It is a wise father that knows his own child. -- William Shakespeare, "The Merchant of Venice"

Re: Detecting the Registrar of the sending host?

2008-07-03 Thread Andrzej Adam Filip
; The registrars I'm talking about are extremely expensive and very exclusive. > Spammers couldn't afford it. Big sloppy/lousy corporation can afford it. -- [pl>en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] Most people can't understand how others can blow their noses differently than they do. -- Turgenev

Re: blackholes.us ?

2007-12-18 Thread Andrzej Adam Filip
ge "MCSE in a week" boot-camp graduate. I personally would suggest using "generic RDNS" blocks specially tailored for such ISP. -- [pl>en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED]

Re: disable spamhaus rbl?

2007-08-13 Thread Andrzej Adam Filip
is included in XBL.spamhaus.org and gives most hits of XBL. CBL.abuseat.org zone files can be downloaded via rsync. > Alternately, add a "spamhaus.org" zone to your name server w/ no entries so > that queries return "instantly". -- [pl>en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] Home site: http://anfi.homeunix.net/

Re: sa-update and gpg issues

2007-07-09 Thread Andrzej Adam Filip
mand line option specifying gpg path in SA bugzilla. -- [pl>en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] Home site: http://anfi.homeunix.net/

Re: Bayes problem: very large spam/ham ratio

2007-05-22 Thread Andrzej Adam Filip
on with CBL.abuseat.org or a list containing it] Spamassassin is an effective but costly tool for spam defense. It should be used as *the second* line of spam defenses after deploying less effective but much less costly defenses such as DNSBL lookups at MTA level. Such deployment scheme shou

Re: Increase of spam?

2007-05-04 Thread Andrzej Adam Filip
estions to clear the picture: a) Do you block dynamic ip addresses at MTA level? b) Do you block "free" email services? -- [pl>en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] Home site: http://anfi.homeunix.net/

Re: Auto Reporting of Spam to Freemail Vendors

2007-04-30 Thread Andrzej Adam Filip
ome links e.g. BBC/CNN pages with some catastrophe used in 419 scams d) gently handle reporting of reliable mailing list messages as spam [ such "reporting mistakes" are pretty common for *big* mailing lists ] IMHO such "LART relay service" *like* spamcop.net can significantly

Re: Auto Reporting of Spam to Freemail Vendors

2007-04-30 Thread Andrzej Adam Filip
to spamcop.net? It will allow you to send LARTs via spamcop.net web pages. P.S. Sending LARTs can be automated using spamcop-ack or spamcup http://anfi.homeunix.net/perl/spamcop-ack.pl -- [pl>en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] Home site: http://anfi.homeunix.net/

Re: High scoring false positives

2007-01-20 Thread Andrzej Adam Filip
ting personally all messages "classified" as spam and reporting "human confirmed spam" using "spamassassin -r" to DCC/Pyzor/Razor2 and spamcop.net * you can use spamcup or http://anfi.homeunix.net/perl/spamcop-ack.pl to automate sending LARTs using spa

Re: Best / Easiest way to report spam?

2006-12-29 Thread Andrzej Adam Filip
Micke Andersson <[EMAIL PROTECTED]> writes: > Andrzej Adam Filip wrote: >> Anders Norrbring <[EMAIL PROTECTED]> writes: >> >> >>> Micke Andersson wrote: >>> >>>> Anders Norrbring wrote: >>>> >>>>> I have a s

Re: Best / Easiest way to report spam?

2006-12-28 Thread Andrzej Adam Filip
s I understand single public folder for *all* users). 1) IMHO it is not a good idea to use one bayes db for all users unless you service small and homogeneous community. It is not uncommon that one person spam is another person ham. > I guess it would be easier for both me and the users to not have to > scan every users spam folder. -- [pl2en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] Home site: http://anfi.homeunix.net/

Re: Spamcop reporting? Anon or register?

2006-11-26 Thread Andrzej Adam Filip
ocent web site with "crash story" (typically cnn.com and bbc.co.uk). 2) I am ready to modify my spamcop-ack.pl script to exclude "www" and "i-www" reports from *automatic* confirmation. Is somebody interested? P.S. Every spam received constitutes perfect s

Re: Spamcop reporting? Anon or register?

2006-11-26 Thread Andrzej Adam Filip
Jeff Chan <[EMAIL PROTECTED]> writes: > On Saturday, November 25, 2006, 8:11:59 AM, Andrzej Filip wrote: >> "Michael Scheidell" <[EMAIL PROTECTED]> writes: >>> Andrzej Adam Filip writes: >>>> [...] >>>> You may use spamcup or &g

Re: Spamcop reporting? Anon or register?

2006-11-25 Thread Andrzej Adam Filip
"Michael Scheidell" <[EMAIL PROTECTED]> writes: > Andrzej Adam Filip writes: >> [...] >> You may use spamcup or >> http://anfi.homeunix.net/perl/spamcop-ack.pl to automatically >> acknowledge spamcop.net reports submitted by >> "spamassas

Re: Spamcop reporting? Anon or register?

2006-11-25 Thread Andrzej Adam Filip
ggest you registering and sending notifications to responsible netmasters/webmasters. You may use spamcup or http://anfi.homeunix.net/perl/spamcop-ack.pl to automatically acknowledge spamcop.net reports submitted by "spamassassin -r" via SMTP. -- [pl2en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED]

Re: Am I wasting my time with SpamCop?

2006-08-03 Thread Andrzej Adam Filip
[EMAIL PROTECTED] writes: > On Wed, 2 Aug 2006, Andrzej Adam Filip wrote: > >> "Steven W. Orr" <[EMAIL PROTECTED]> writes: >> >> > On Wednesday, Aug 2nd 2006 at 13:50 -0700, quoth Derek Harding: >> > >> > =>On Wed, 2006-08-02 at 16

Re: Am I wasting my time with SpamCop?

2006-08-03 Thread Andrzej Adam Filip
f "zero+ tolerance"] 2) scoring by SpamAssassin [score may be decreased or zeroed] 3) spam *reporting* (automatization of sending LARTs) [*I recomend it*] -- [pl2en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED]

Re: Am I wasting my time with SpamCop?

2006-08-02 Thread Andrzej Adam Filip
e. BTW Are there any plans to include some more spamcop.net helpers into spamassassin distrubution? SpamAssassin can report spam to spamcop.net via SMTP but "after report" acknowlegment is required. It is possible to automate also the second stage (acknowlegment) with an option to post N

Re: Am I wasting my time with SpamCop?

2006-08-02 Thread Andrzej Adam Filip
oring spam and let the > honeypots harvest and report to the various RBLs, or should I keep > reporting spam via SpamCop (which wastes a lot of my time). You should automate spamcop.net reporting to level requiring 1-2s of "manual" verification per spam accepted after RBL filtering

Re: Block direct SMTP [MTA level]

2006-08-02 Thread Andrzej Adam Filip
g messages from DUL ranges *in SMTP session* that gives sending MTA a chance to use fallback relay (smarthost provided by ISP). One suggested approach was to use "in greeting message" 5?? reject. It makes *sendmail* "as it is" use fallback relays. > [...] -- [pl2en: An

Re: Block: Google servers still on RBLs?

2006-06-15 Thread Andrzej Adam Filip
am traps are secret, no reports or evidence are provided by SpamCop) * SpamCop users have reported system as a source of spam less than 10 times in the past week -- [pl2en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] http://anfi.homeunix.net/h

Re: End-user (not administrator) question

2006-05-25 Thread Andrzej Adam Filip
procmail filter for "tagged as spam" messages. It is not the best option but it is the most simple and fastest to implement [option zero]. -- [pl2en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] http://anfi.homeunix.net/ http://www.linkedin.com/in/andfil

Re: Bypassing scan on locally originated mail

2006-05-24 Thread Andrzej Adam Filip
Rich Winkel <[EMAIL PROTECTED]> writes: > According to Andrzej Adam Filip: >> How do you deployed spamassassin? > > I use a milter ... If you use open source milter (or closed source with right option) then it should be possible to exclude some sending hosts (e.g. 127.0.0.1)

Re: Bypassing scan on locally originated mail

2006-05-22 Thread Andrzej Adam Filip
Is there a way to do this? How do you deployed spamassassin? * via a milter integrating SA with sendmail * via procmail (local sendmail mailer) * other method -- [pl2en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] http://anfi.homeunix.net/ http://www.linkedin.com/in/andfil

Re: Who wants my spam - seriously!

2006-05-22 Thread Andrzej Adam Filip
thout any *special* arrangements with spamcop 1) Could you show us moment when you feed was accepted on the charts below? http://www.spamcop.net/spamgraph.shtml?spamweek http://www.spamcop.net/spamgraph.shtml?spammonth -- [pl2en Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] :

Re: Who wants my spam - seriously!

2006-05-22 Thread Andrzej Adam Filip
Michael Monnerie <[EMAIL PROTECTED]> writes: > On Samstag, 20. Mai 2006 12:58 Andrzej Adam Filip wrote: >> You can use *separate* script to make spamcop.net send LARTs >> (munged or unmunged). >> e.g. http://anfi.homeunix.net/perl/spamcop-ack.pl or "previous art&

Re: Who wants my spam - seriously!

2006-05-20 Thread Andrzej Adam Filip
"Kai Schaetzl" <[EMAIL PROTECTED]> writes: > Andrzej Adam Filip wrote on Sat, 20 May 2006 12:58:15 +0200: > >> Have you considered using "spamassassin -r" to report the spam to: > > Well, he says that at least one of his "feeds" isn't 100

Re: Who wants my spam - seriously!

2006-05-20 Thread Andrzej Adam Filip
ipt to make spamcop.net send LARTs (munged or unmunged). e.g. http://anfi.homeunix.net/perl/spamcop-ack.pl or "previous art" mentioned in previous thread about spamcop-ack.pl -- [pl2en Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] http://anfi.homeunix.net/ http://www.linkedin.com/in/andfil

Re: Spam that is nothing but one large image

2006-04-26 Thread Andrzej Adam Filip
ontent is contained in attached image. -- [pl2en Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] http://anfi.homeunix.net/

Re: RelayCountry does not work

2006-04-24 Thread Andrzej Adam Filip
t topmost Received: headers form sample "message from internet"? One possible explanation would be masking IP of the "true relay" e.g. by email gateway to internal mail server transfer. -- [pl2en Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] http://anfi.homeunix.net/

Re: spamcop.net script (auto ack of spam submitted by "spamassassin -r")

2006-03-07 Thread Andrzej Adam Filip
Andrzej Adam Filip wrote: > The perl script is available at: > http://anfi.homeunix.net/perl/spamcop-ack.pl > *It is first public Beta* > > It logs into spamcop.net account (via web) and makes spamcop send LARTs > about all spam previously submitted via SMTP ("spamassassin

spamcop.net script (auto ack of spam submitted by "spamassassin -r")

2006-03-06 Thread Andrzej Adam Filip
pamcop.net login and passwd in the script * first time execute it with maximum tracking ./spamcop-ack.pl -D3 [ -D0 means no tracking at all ] -- [pl2en Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] http://anfi.homeunix.net/

Re: Rejecting emails in procmailrc?

2006-02-27 Thread Andrzej Adam Filip
g. http://mimedefang.org/) and: * reject "spam for (almost) sure" in SMTP session [the final dot reply] It makes sending host responsible for generating bounce message * mark "most likely spam" in headers to allow by recipient verification -- [pl2en Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] http://anfi.homeunix.net/

Re: éèàù.... replaced by X by Spamassa ssin

2005-12-17 Thread Andrzej Adam Filip
part (ensuring the original message is completely preserved, not easily opened, and easier to recover). -- [en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] http://anfi.homeunix.net/ Netcraft Site Rank: 504364 All that is necessary for the triumph of evil is that good m

Re: éčŕů.... replaced by X by cyrus-imapd

2005-12-17 Thread Andrzej Adam Filip
http://www.invoca.ch/pub/packages/cyrus-imapd/ -- [en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] http://anfi.homeunix.net/ Netcraft Site Rank: 504364 All that is necessary for the triumph of evil is that good men do nothing -- Edmund Burke, 18th century

Re: éèàù.... replaced by X by Spamassassin

2005-12-17 Thread Andrzej Adam Filip
Thomas Manson wrote: I've just tried munge8bit:0 and I still have accent issue... [...] 1) I think there should be space after ":" munge8bit: 0 2) Have you restarted cyrus server after changing the configuration? -- [en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [

Re: Do you need a Pop3 Proxy?

2005-11-15 Thread Andrzej Adam Filip
ust a few classes. Have you considered using fetchmail with procmail used in mda option? I use it myself with custom per POP3 account procmail scripts. [ the scripts use spamc ] -- [en: Andrew] Andrzej Adam Filip : [EMAIL PROTECTED] : [EMAIL PROTECTED] http://anfi.homeunix.net/ Netcraft Site

Re: What countries to block ?

2005-11-14 Thread Andrzej Adam Filip
Bowie Bailey wrote: From: Andrzej Adam Filip [mailto:[EMAIL PROTECTED] Have you tried to use AS scoring instead of (or together with) country scoring? [AS = Autonoumous (Routing) System] IMHO it is not a bad idea to give incetives to good ISP in a bad countries. That's an interesting

Re: What countries to block ?

2005-11-12 Thread Andrzej Adam Filip
27;s a handful of rules I'm using atm: [...] Have you tried to use AS scoring instead of (or together with) country scoring? [AS = Autonoumous (Routing) System] IMHO it is not a bad idea to give incetives to good ISP in a bad countries. -- [en: Andrew] Andrzej Adam Filip : [EMAIL PROTECT

Re: sendmail spamassassin milter

2005-02-16 Thread Andrzej Adam Filip
[EMAIL PROTECTED] wrote: I've been playing with getting clamav and spamassassin run from within sendmail and have had a great deal of luck on a fine RHEL box. First go-round, I set up procmail as the LDA, set up an /etc/procmail that ran spamassassin. Next, I used milter instructions to run spama

Re: Outgoing mail scanning

2005-01-31 Thread Andrzej Adam Filip
Kenneth Andresen wrote: How is it possible to make such a sendmail wrapper script? Any links to examples? No but you can modify the script below to fit your needs: #!/bin/sh # temporary directory TMPDIR=/tmp # temporary working file name - unix time and process ID TMPFILE=`/bin/date +%s`.$$ # tempo

Re: Outgoing mail scanning

2005-01-31 Thread Andrzej Adam Filip
Kenneth Andresen wrote: I am looking for a way to spam-check outgoing mail, so the users registered with my server cannot send out spam (or viruses). My server is using squirrelmail for sending e-mail, so the mail is generated on the server and sent directly using SMTP (in squirrelmail you may choo

Re: RelayCountry

2005-01-09 Thread Andrzej Adam Filip
Louis LeBlanc wrote: On 01/08/05 04:56 PM, Bill Landry sat at the `puter and typed: - Original Message - From: "Louis LeBlanc" <[EMAIL PROTECTED]> If you're in North America, you might want to consider using blackholes.us instead. If you're in Europe, nerd.dk will probably be faster. Th

Re: spamcop question [2]

2005-01-04 Thread Andrzej Adam Filip
[EMAIL PROTECTED] wrote: Anyone else having issues with the fact that spamcop has many of Yahoo's bulk servers listed. These servers handle their mailling lists and groups accounts. This is more a blacklist question, but is there anyway to whitelist IP's that are in blacklists? Is there any way t

Re: reporting to bogusmx at rfc-ignorant

2004-12-03 Thread Andrzej Adam Filip
John Hardin wrote: On Fri, 2004-12-03 at 00:21, Andrzej Adam Filip wrote: Would it be possible to make spamassassin sumbit candidates to bogusmx list at RFC-Ingorant.org? How would we use that list in SA? The list is used by SpamAssassin-3: 20_dnsbl_tests.cf: header __RFC_IGNORANT_ENVFROM

Re: reporting to bogusmx at rfc-ignorant

2004-12-03 Thread Andrzej Adam Filip
Daryl C. W. O'Shea wrote: Andrzej Adam Filip wrote: Would it be possible to make spamassassin sumbit candidates to bogusmx list at RFC-Ingorant.org? RFC-Ignorant submissions are supposed to be by hand ONLY. http://www.rfc-ignorant.org/policy.php "Also, before a site is submitted, the

reporting to bogusmx at rfc-ignorant

2004-12-03 Thread Andrzej Adam Filip
Would it be possible to make spamassassin sumbit candidates to bogusmx list at RFC-Ingorant.org? Subissions are possible via web form (HTTP::Form ?) or email. http://www.rfc-ignorant.org/policy-bogusmx.php http://www.rfc-ignorant.org/tools/submit_form.php?table=bogusmx -- Andrzej [en:Andrew] Adam

Re: SPAMASSASSIN ON RELAY HOST ???

2004-11-04 Thread Andrzej Adam Filip
[EMAIL PROTECTED] wrote: If I want to install spamassassin on a SENDMAIL relay host that relays to an internal machine, how do I do ?. You can use one of a few available milters.It will allow your sendmail to reject messages classified as spam in SMTP session. Rejecting in response to the final d

Re: BUG: miltrassassin and parsing Received: header

2004-10-22 Thread Andrzej Adam Filip
Sam Kalet wrote: I observed with miltrassassin (Revision: 1.14 Date: 2003/05/28 18:43:47) from check_local.5.6.tar.gz formerly available at http://www.digitalanswers.org/check_local/check_local.5.6.tar.gz the following bug: I see you mention check_local was formerly available at www.digitalanswer