RE: Question on Rule

2020-01-27 Thread Charles Amstutz
> > > Hello, > > > > Can someone explain what this actually means and maybe provide an > > example? > > > > Rule Name: FROM_MISSP_DYNIP > > Rule Definition: misspaced + dynamic rDNS > > > > Getting a high score on this and having trouble finding an actual real > > definition and example. I get the

RE: Question on Rule

2020-01-27 Thread Charles Amstutz
> Am 27.01.20 um 17:22 schrieb Charles Amstutz: > > Can someone explain what this actually means and maybe provide an > example? > > > > Rule Name: FROM_MISSP_DYNIP > > > > Rule Definition: misspaced + dynamic rDNS > > > > Getting a high score o

Question on Rule

2020-01-27 Thread Charles Amstutz
Hello, Can someone explain what this actually means and maybe provide an example? Rule Name: FROM_MISSP_DYNIP Rule Definition: misspaced + dynamic rDNS Getting a high score on this and having trouble finding an actual real definition and example. I get the dynamic rDNS I believe, but not sure a

RE: MISSING_SUBJECT rule on email with subject

2019-06-24 Thread Charles Amstutz
> Hi Charles, > > My apologies, I forgot to provide feedback to the mailing list. Bad regex was > the cause of this problem for us, too. As soon as the custom rule was fixed, > the problem went away. If I can ask, was it an incorrectly escaped special character? I think it is the @ symbol break

RE: MISSING_SUBJECT rule on email with subject

2019-06-24 Thread Charles Amstutz
> But as has already been pointed out it has the combination of > MISSING_FROM and HK_RANDOM_FROM, and the latter is based on a > From:addr test. I saw this too, however, I thought I noticed a potentially bad regex (from another custom rule) breaking mine. I think this is the case as when I re

low scoring spam

2017-07-14 Thread Charles Amstutz
Hello, I keep having spam come through that hits on almost zero rules, (or very few) . I get this is definitely possibly, but it's annoying as its obviously spam. I guess my question is, if what we have in place isn't hitting on much, then aside from learning it to Bayes, what do we do? Even t

RE: "bout u" campaign

2017-07-13 Thread Charles Amstutz
I'm starting mine out at 0.5 until I see what happens.     Infinite Systems     Charles Amstutz | Systems Administrator     charl...@infinitesys.com 402.477.2474     134 S 13th Street, Suite 302 | Lincoln, NE 68508   -Original Me

RE: "bout u" campaign

2017-07-13 Thread Charles Amstutz
Hello, For the inexeperienced, what is the difference between lashback and lastexternal.     Infinite Systems     Charles Amstutz | Systems Administrator     charl...@infinitesys.com 402.477.2474     134 S 13th Street, Suite 302 | Lincoln, NE

RE: "bout u" campaign

2017-07-13 Thread Charles Amstutz
Thanks, I was looking at the default RBL lists https://wiki.apache.org/spamassassin/DnsBlocklists But was looking for other things that are free for commercial use. I found this that is possible. http://0spam.fusionzero.com/ but don't know if wanyone had experience with it, or could make othe

RE: "bout u" campaign

2017-07-13 Thread Charles Amstutz
Thanks     Infinite Systems     Charles Amstutz | Systems Administrator     charl...@infinitesys.com 402.477.2474     134 S 13th Street, Suite 302 | Lincoln, NE 68508   -Original Message- From: Alex [mailto:mysqlstud...@gmail.com] Sent

RE: "bout u" campaign

2017-07-13 Thread Charles Amstutz
As a follow up, it says how to do the DNS, just now how to list in the .cf files, maybe I can copy another blacklist syntax?     Infinite Systems     Charles Amstutz | Systems Administrator     charl...@infinitesys.com 402.477.2474     134 S 13th

RE: "bout u" campaign

2017-07-13 Thread Charles Amstutz
How do you use lashback? It says that it is free to use for commercial and non commercial use. How do I set it up?     Infinite Systems     Charles Amstutz | Systems Administrator     charl...@infinitesys.com 402.477.2474     134 S 13th Street

RE: "bout u" campaign

2017-07-13 Thread Charles Amstutz
I find it challenging to constantly keep up with campaign's. My guess with the phone number is to try to make it seem more legitimate. More recent, I try to look for general characteristics and go for that, in order to futureproof rules. However, there are always legitimate emails being sent t

RE: Random word spams and wiki spams

2017-07-07 Thread Charles Amstutz
Mostly autolearn ham and train some spam, have found that one account needed ham though. Most user accounts in question are at least 200/200, most are well over a few thousand each (I believe) >> I need to read up bayes a bit, I was surprised to learn that after >> using sa-learn --spam, the

RE: Random word spams and wiki spams

2017-07-07 Thread Charles Amstutz
>> I find many don't contribute (despite it being open source) for fear of >> spammers using these ideas against us, but the project suffers as a result. I think others don't due to IP rights. I'm glad people do though.

RE: Random word spams and wiki spams

2017-07-07 Thread Charles Amstutz
I need to read up bayes a bit, I was surprised to learn that after using sa-learn --spam, then bayes only tagged it at Bayes_50 instead of Bayes_99, Unless I did something incorrect. Note: I do not use bayes files in user profiles, I use it in mysql database

RE: Random word spams and wiki spams

2017-07-07 Thread Charles Amstutz
Has anyone ever got something like machine learning (I get that is what bayes kind of is) or R working with spam assassin? I’ve seen Books on this and maybe was refering to Bayes, but not sure.

RE: Random word spams and wiki spams

2017-07-07 Thread Charles Amstutz
t use characters to form tables (happens occasionally). The only thing I could think of was to set individual scores lower, but high meta scores. I appreciate the options for postfix, but I do not run that on incoming mail servers.     Infinite Systems     Charles Am

RE: Random word spams and wiki spams

2017-07-07 Thread Charles Amstutz
Thank you everyone for the suggestions, I will look into it. One thing I've noticed is that sometimes it takes a day for any *BL's to pick up some of the spam, and by that time, the run could be done. Greylisting isn't an option. It sometimes feels like always reactive vs pro-active in filtering

Random word spams and wiki spams

2017-07-07 Thread Charles Amstutz
Hello, I am new to the group, but have experience with writing some rules and some meta rules. Has anyone come up with a good way to detect spam that has random words in paragraph forms (usually at the bottom of the message body) or they look like they copy parts from various wiki's or other n