RCVD_IN_RP_SAFE where to report spam? http://www.returnpath.net/commercialsender/certification/

2011-01-26 Thread Michael Scheidell
t under 'support' after searching for 10 mins. you send email to certificat...@returnpath.net <mailto:certificat...@returnpath.net>. to report abuse. not 'abuse@' -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security

Re: spamhaus dbl considered safe for mta blocking?

2011-01-22 Thread Michael Scheidell
2000 user box, got hits. (just using _sender) looked up the sender's name and found 27 spams sent today that SA had to deal with (no more!) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrat

spamhaus dbl considered safe for mta blocking?

2011-01-22 Thread Michael Scheidell
0.1.2 25_uribl.cf:urirhssub URIBL_DBL_ERROR dbl.spamhaus.org. A 127.0.1.255 something like this? header DNS_FROM_DBL eval:check_rbl_envfrom('dbl','dbl.spamhaus.org.','127.0.1.2') tflags DNS_FROM_DBL net domains_only score DNS_FROM_DBL 2.0 -- Micha

Re: Bayes expiration

2011-01-19 Thread Michael Scheidell
clear bayes and reimport. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Executive Alliance * Five-Star Partner Program 2009, VARBusiness *

Re: Bayes expiration

2011-01-19 Thread Michael Scheidell
On 1/19/11 7:56 AM, Helmut Schneider wrote: Michael Scheidell wrote: On 1/19/11 6:04 AM, Helmut Schneider wrote: bayes_auto_expire 1 disable auto expire and run a cronjob. OK...but..why? :) to fix your problem. plus auto expire can seriously degrade the performance

Re: Bayes expiration

2011-01-19 Thread Michael Scheidell
On 1/19/11 6:04 AM, Helmut Schneider wrote: bayes_auto_expire 1 disable auto expire and run a cronjob. make sure you run the cronjob for each user in bayes. mysql mail -AssBbe 'select username from bayes_vars' -- Michael Scheidell, CTO o: 561-999-5000 d: 56

Re: Q about short-circuit over ruling blacklisting rule

2011-01-17 Thread Michael Scheidell
aders. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Executive Alliance * Five-Star Partner Program 2009, VARBusiness * Best in Email Security,2010:

Re: BOTNET rules question

2011-01-05 Thread Michael Scheidell
On 1/5/11 4:52 PM, Michael Monnerie wrote: server88-208-245-26.live- servers.net botnet is NOT an stock SA rule plus, look at the silly DYNAMIC RULE LOOKING rdns. fix rdns. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporat

BOTNET rules question

2011-01-05 Thread Michael Monnerie
Dear list, I received this info from a customer, whose order confirmation from the londontheatredirect.com got marked as spam because of BOTNET* rules. Are those rules too old, or is that server in a botnet? How to find out? Or which rules scores should I tune to optimize? -- Forwarde

Re: How to prevent DOS_OUTLOOK_TO_MX false positive?

2011-01-05 Thread Michael Scheidell
your local ip addresses in internal_networks. you will avoid unnecessary rbl lookups, spf failures and it should set a ALL_TRUSTED flag also. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrator

Re: IPv6 DNSBL/WL design, was Fwd: [Asrg] draft-levine-iprangepub-01

2011-01-04 Thread Michael Scheidell
Funny thing, and I think John Levine remembers 1994: OH MY GOD, THE INTERNET WENT COMMERCIAL, with all these new computers, its the end of the internet. and the oft quoted: "Breaking Story: Death of the Internet, gif at 11" -- Michael Scheidell, CTO o: 561-999-5000 d: 561-94

Re: Excessive junk mail even after upgrade/update

2011-01-04 Thread Michael Scheidell
nd that SA does NOT block spam. it only 'MARKS it'. if your users are getting spam with '***SPAM***' in the subject line, then SA is working. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified

Re: Off topic: best RBLs to use to block at smtp connection?

2011-01-03 Thread Michael Scheidell
On 1/3/11 10:49 AM, Ned Slider wrote: On 03/01/11 15:41, Michael Scheidell wrote: some FN's (hint: verizon's new 4g network has a new /10 block that isn't in spamhaus.org pbl yet.) Please share so we can consider adding it locally. a spot check of rdns shows 'ddd.sub-c

Re: Off topic: best RBLs to use to block at smtp connection?

2011-01-03 Thread Michael Scheidell
compromised accounts. If they didn't, then it will cause FP's if used at mta level. We are evaluating spamhaus.org commercial feed right now, and have a never gotten a FP so far. some FN's (hint: verizon's new 4g network has a new /10 block that isn't in spamhaus.org pbl yet.)

Re: New plugin: DecodeShortURLs

2011-01-01 Thread Michael Scheidell
harvest web sites for email addresses, so, changing it would be good. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Executive Alliance * Five-S

Re: Issuing rollback DBI Mysql

2010-12-27 Thread Michael Scheidell
derator of this list and was trying to help you. you will get exactly what you paid for when you installed spamassassin. or, are you new to opensource software and support? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation

SA incorrectly tries ipv6 lookups with perl 5.10.1 and force_ipv4 can' t be set in ../local.cf possible fixes?

2010-12-24 Thread Michael Scheidell
setting => 'force_ipv4', +default => 0, +type => $CONF_TYPE_STRING, +code => sub { + my ($self, $key, $value, $line) = @_; + if ($value =~ /^(?:yes|1)$/) { +$self->{force_ipv4} = 'yes'; + } + elsif ($value =~ /^(?:no|0)$/) { +

Re: mycingular listed on xbl/pbl

2010-12-21 Thread Michael Scheidell
. you should vpn to your office, use your isp's ip's or use exchange, or submit (again, to your office) Thanks spamhaus for helping keep us safe! All the more reason to use xbl,pbl and zen. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *S

Re: preventing authenticated smtp users from triggering PBL

2010-12-18 Thread Michael Scheidell
On 12/17/10 11:04 PM, Ted Mittelstaedt wrote: It's shit-for-brains young girl administrative assistants at companies who are our customers who apparently have too much time on their hands. Don't hold back,.. how do you REALLY feel about outlook stationary? -- Michael Scheidell,

Re: Two newish RBLs; NXDOMAIN question

2010-12-13 Thread Michael Scheidell
cisco), it will blacklist aol and yahoo addresses on occasion. so, DON'T use it in prequeue. Apologies. C -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Awar

Re: Odd yahoo spam

2010-12-09 Thread Michael Scheidell
y servers so this point may be moot. Can anyone add insight as to how this is happening? http://pastebin.com/WYYLpEJh -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award

Re: Fake MX

2010-12-08 Thread Michael Scheidell
On 12/8/10 6:52 PM, Marc Perkel wrote: punish the spammers. and, punish any senders who follow the RFC's. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Awar

Re: Fake MX

2010-12-08 Thread Michael Scheidell
On 12/8/10 2:46 PM, John Hardin wrote: On Wed, 8 Dec 2010, Toni Mueller wrote: I tried the high MX for some time, but in my experience, spammers usually only hit the first two MXes. I wonder what Marc Perkel's experience in this regard is... You just had to stir up the ants. -- Mi

Re: was and is 'AskDns.pm' on 3.3. FW: Spamhaus Whitelist

2010-12-07 Thread Michael Scheidell
-Original Message- From: Michael Scheidell Sent: Saturday, November 06, 2010 2:59 PM To: users@spamassassin.apache.org Subject: Re: Spamhaus Whitelist found out that below is a violation of the specs, and is NOT recommended to be used. I would assume that the specs detail tighter

Re: use askdns.pm for sa 3.3?

2010-12-06 Thread Michael Scheidell
On 12/6/10 3:45 PM, Michael Scheidell wrote: can we use the askdns.pm for SA 3.3 or do we have some missing dependencies? (I noticed some rules in latest couple of saupdates: I guess I answered my own question: Dec 6 16:20:21.941 [44960] warn: plugin: eval failed: Can't call m

use askdns.pm for sa 3.3?

2010-12-06 Thread Michael Scheidell
cognized response from Spamhaus DWL 50_scores.cf:score DKIMDOMAIN_IN_DWL 0 -3.5 0 -3.5 50_scores.cf:score DKIMDOMAIN_IN_DWL_UNKNOWN 0 -0.01 0 -0.01 looks like it combines an rbl check with a check for a valid dkim signature. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1

Re: Misguided energy

2010-12-02 Thread Michael Scheidell
On 12/1/10 10:37 PM, Karsten Bräckelmann wrote: On Wed, 2010-12-01 at 20:38 -0500, Michael Scheidell wrote: On 12/1/10 7:02 PM, Karsten Bräckelmann wrote: Personally, I have *never* received a legit C/R. Every single one that ended up on my machines have been in response to spam sent with a

Re: Misguided energy

2010-12-01 Thread Michael Scheidell
poster. Guess what? I got a CR. Guess what? luser got blacklisted. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Executive Alliance * Five-S

Re: Do we need a new SMTP protocol? (OT)

2010-12-01 Thread Michael Grant
does someone send you mail if they're not on your contact list? I don't have any magic answers how to solve that beyond what's already out there as in return messages with captchas in them or things like Blue Bottle seem to be quite effective. Michael Grant

Re: Do we need a new SMTP protocol? (OT)

2010-12-01 Thread Michael Scheidell
rd those individual users worked to open up that malware that infected their workstations a while back. Is it a constant battle of wits between the spammers, hackers, phishers? yes. But the technology has matured enough in the last couple of years that its a win able battle. -- Michael Schei

Re: Do we need a new SMTP protocol? (OT)

2010-12-01 Thread Michael Scheidell
olite. ps, I have a new email spec, and if anyone wants to send me email they have to adhere to this new spec. ITS CALLED THE CURRENT RFC'S. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrato

Re: Do we need a new SMTP protocol? (OT)

2010-12-01 Thread Michael Scheidell
ught this battle since 1994. I have personally fought this battle since 1994. How much email do you think you will get if you follow ALL the RFC's? Oh, lets start a NEW spec that no one will follow. Considering how easy it is to force senders to follow the current specs. -- Michael Sch

Problems with DATE_IN_FUTURE_

2010-11-29 Thread Michael Menge
evant headers from 4 example messages where i would say the date header is in the past of any recieved headers. Regards Michael Menge --- Received: from mailserv08.uni-tuebingen.de ([unix socket]) by mailserv08 (Cyrus v2.3.16) with LMTPA; Thu, 11 Nov 20

Re: resolved, but why? Re: SA 3.3.1 performance issues?

2010-11-19 Thread Michael Scheidell
happened again. 1 out of 100, EXACTLY THE SAME SYSTEMS, DOWN TO MD5 CHECKSUMS ON BINARIES, need to remove INET6 perl module. On 11/5/10 4:44 PM, Michael Scheidell wrote: On 11/5/10 4:08 PM, Michael Scheidell wrote: On 11/5/10 4:00 PM, Mark Martinec wrote: It certainly looks like a DNS

Re: facebook phishing, SPF_PASS

2010-11-19 Thread Michael Scheidell
complain of course, if you miss one spam, and complain, of course if you block one legit email. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Executi

Re: facebook phishing, SPF_PASS

2010-11-19 Thread Michael Scheidell
for the domain, but that clearly fails here. SPF is on ENVELOPE address, not header address. Microsoft's patented 'sender id' (which they don't use) can use either. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corpor

Re: facebook phishing, SPF_PASS

2010-11-19 Thread Michael Scheidell
first time, was one of my facebook_forgery rules looked for spf_pass (didn' t whitelist it!) but didn't add the 5 points I assigned for forged facebook, twitter,etc.) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation

facebook phishing, SPF_PASS

2010-11-19 Thread Michael Scheidell
ttp://secnap.pastebin.com/zTmkSc6J> ps, scored a 3.5 here. by now, hopefully, it scores higher with razor/dcc/spamcop, urlbl, etc. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Ho

Re: Blocking Senders with young domains

2010-11-16 Thread Michael Scheidell
elay there was/is a 'DOB' blacklist (day old bread). but I think the dns servers may be overloaded. some people are complaining about timeouts. Thanks for any help Cheers, Liam -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Co

Re: SPF technical problems (was Re: email address forgery)

2010-11-15 Thread Michael Scheidell
LO_FAIL 0 score SPF_HELO_NEUTRAL 0 score SPF_HELO_SOFTFAIL 0 score SPF_NEUTRAL 0 score SPF_SOFTFAIL 0 score FROM_MISSP_SPF_FAIL 0 score TO_EQ_FM_DOM_SPF_FAIL 0 score TO_EQ_FM_SPF_FAIL 0 David. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Se

Re: email address forgery

2010-11-15 Thread Michael Scheidell
s seems to indicate that you are just as likely to receive a SPAM from a VALID SPF_PASS as well as a SOFTFAIL. So, SPF works, if EVERYONE FOLLOWS THE RFC'S AND BEST PRACTICES. Where it fails is when the sender or receiver doesn't follow the RFC's. -- Michael Scheidell, CTO o

Re: sa-compile error

2010-11-12 Thread Michael Scheidell
, i386/amdf64? 6) did you check to make sure you have the latestest SA and re2c? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Executive Alliance * F

Re: email address forgery

2010-11-11 Thread Michael Scheidell
On 11/11/10 5:13 PM, Noel Butler wrote: *and* as an SPF record type, the TXT method is deprecated, but then again, SA doesn't support SPF record type, only TXT type.. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Cor

Re: Does anyone known the braindead anti-spam software "MagicSpam" ?

2010-11-10 Thread Michael Scheidell
host -t a quarantine.spamchek.net quarantine.spamchek.net is an alias for thorium.enidan.ch. thorium.enidan.ch has address 212.25.14.40 # host -t a thorium.enidan.ch thorium.enidan.ch has address 212.25.14.40 -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Net

Re: Spamhaus Whitelist

2010-11-06 Thread Michael Scheidell
net nice scoreSPAMHAUS_SWL -2.5 urirhsbl SPAMHAUS_DWL _vouch.dwl.spamhaus.org. A body SPAMHAUS_DWL eval:check_uridnsbl('SPAMHAUS_DWL') describe SPAMHAUS_DWL Domain is whitelisted by Spamhaus tflags SPAMHAUS_DWL net nice scoreSPAMHAUS_DWL -2.5 Set the scores to your own liki

Re: SA 3.3.1 performance issues?

2010-11-05 Thread Michael Scheidell
On 11/5/10 4:44 PM, Jason Haar wrote: On 11/06/2010 08:39 AM, Michael Scheidell wrote: debug seems to indicate a DNS problem, but, all 'manual' dns tests come back immediately (fine) running a caching dns server, perl 5.10.1, SA 3.3.1. Net::DNS version: 0.66 NOT using ipv6. your de

resolved, but why? Re: SA 3.3.1 performance issues?

2010-11-05 Thread Michael Scheidell
On 11/5/10 4:08 PM, Michael Scheidell wrote: On 11/5/10 4:00 PM, Mark Martinec wrote: It certainly looks like a DNS resolver problem. What is your /etc/resolv.conf? The Net::DNS only uses the first nameserver from that file. To turn on debugging in Net::DNS (assuming bourne-like shell

Re: SA 3.3.1 performance issues?

2010-11-05 Thread Michael Scheidell
uses the first nameserver from that file. To turn on debugging in Net::DNS (assuming bourne-like shell): $ RES_OPTIONS="debug" spamassassin -D -t -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNO

Re: SA 3.3.1 performance issues?

2010-11-05 Thread Michael Scheidell
; expiry 1D ); minimum ;; rcode = 3, ancount=0 Nov 5 16:04:35.475 [16361] dbg: dns: no ipv6 Nov 5 16:04:35.475 [16361] dbg: dns: is Net::DNS::Resolver available? yes Nov 5 16:04:35.476 [16361] dbg: dns: Net::DNS version: 0.66 Nov 5 16:04:35.490 [16361] dbg: conf

SA 3.3.1 performance issues?

2010-11-05 Thread Michael Scheidell
as far as SA is concerned, they arn't cached. from cli, its fine: time host -t txt _adsp._domainkey.cantv.net Host _adsp._domainkey.cantv.net not found: 3(NXDOMAIN) 0.000u 0.005s 0:00.00 0.0%0+0k 0+0io 0pf+0w -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*13

Re: Bayes dbm sync/expire speedup suggestion

2010-11-01 Thread Michael Scheidell
On 11/1/10 1:52 PM, Robert Blayzor wrote: On Nov 1, 2010, at 10:38 AM, Michael Scheidell wrote: Switch to the special mysql bayes. it will also allow you to expire based on time (with some added table). sync is dynamic but don't forget the cronjob to expire bayes daily. Unfortun

Re: Bayes dbm sync/expire speedup suggestion

2010-11-01 Thread Michael Scheidell
On 11/1/10 10:28 AM, Robert Blayzor wrote: lock_method flock Switch to the special mysql bayes. it will also allow you to expire based on time (with some added table). sync is dynamic but don't forget the cronjob to expire bayes daily. -- Michael Scheidell, CTO o: 56

Re: Only running network tests when necessary - feature request

2010-10-29 Thread Michael Parker
lt; 5) { >run_one_network_spam_test() or last NETTEST; > } else { >run_one_network_nonspam_test() or last NETTEST; > } > } > Ok, lets assume that this actually buys you something. Good thing that you can provide your own Check.pm. You can easily provide your own. Michael >

Re: SA 3.3.1 and NetAddr::IP 4.034

2010-10-29 Thread Michael Scheidell
dr-IP-4.02.8 Perl module for working with IP addresses and blocks thereo -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Executive Alliance * Five-Star

Re: SA 3.3.1 and NetAddr::IP 4.034

2010-10-29 Thread Michael Scheidell
8'); $set->add_cidr ('::1'); return $set; } -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Executive Alliance * Five-Star Pa

Re: Collecting IP reputation data from many people

2010-10-22 Thread Michael Scheidell
you have commercial version). and SA 3.2.* has built in support for the results of the ip queries. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Executive

Re: prevent rule from being considered for Bayes auto-learning

2010-10-21 Thread Michael Scheidell
B_MI_CPEARnet nice noautolearn Regards, Lawrence Williams LCWSoft www.lcwsoft.com -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Exe

Re: spamc sometimes complains MISSING_MID sometimes not with same message

2010-10-09 Thread Michael Scheidell
On 10/9/10 11:35 AM, Dennis German wrote: The question is: Has anyone seen unpredictable and different results when processing the same message? Sure. if your setup is messed up, you will get unpredictable results. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300

Re: spamc sometimes complains MISSING_MID sometimes not with same message

2010-10-08 Thread Michael Scheidell
't let you use user-prefs, there is no telling what else they did. I suppose you can't post the spamd options they use when they start SA? what about the contents of the ../share/mail/spamassassin directory? the default local.cf? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-9

Re: Whitelist questions

2010-10-05 Thread Michael Scheidell
r.net. why not just use something like 'ob.lanyon.com', in your HELO, FQDN, and make sure that both FWD and RDNS match? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 > *| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Co

Re: Whitelist questions

2010-10-05 Thread Michael Scheidell
circumstances would this happen? AWL is NOT an 'auto whitelist'. and is not used by default configs anymore. instead of including the massive volume of documentation on what AWL is and is not, just google. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300

Re: Question about link submission

2010-10-04 Thread Michael Scheidell
We mostly concerned about YOUR system getting better. local learning (sa-learn) will bring 'spam' into your local bayes. do both. help out the community as a whole (spamassassin --report-spam) and yourself (sa-learn-r) many thanks in advance Colin -- Michael Scheidell, CTO o: 561

Re: new install

2010-09-30 Thread Michael Scheidell
spamassassin's web site to see current version. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 > *| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Executive Alliance * Five-Star Partner Prog

what in the world is this phish? what is outbind?

2010-09-29 Thread Michael Scheidell
<http://secnap.pastebin.com/iVAySSRR> what in the world is outbind? (I guess if I click on it on my mac, nothing will happen) looks like its a MS thing: <http://www.infosyssec.com/forum/viewtopic.php?t=1374> -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 IS

Re: INVALID_MSGID hitting valid emails

2010-09-22 Thread Michael Scheidell
password and ip address of your server so I can look at the logs. Seriously, not without samples of headers that you claim are valid. better yet, open a bug on bugzilla and document the errors. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 > *| *SECNAP Netw

Re: New plugin: DecodeShortURLs

2010-09-22 Thread Michael Scheidell
e constant HAS_SQLITE => eval { require DBD::SQLite; }; sub dbg { my $msg = shift; Thanks for the tip; I did know about using different delimiters - but using / is force of habit ;-) I'll try and remember to use something different for uri rules. Cheers, Steve. -- Michael

explain DKIM_ADSP_DISCARD?

2010-09-20 Thread Michael Scheidell
ebay... envelope from is members.ebay.com. dkim signature has d=ebay.com is that what adsp_discard means? that even though the dkim signature matched, the domain in the envelope from didn't match the domain that the signature says it signed? -- Michael Scheidell, CTO o: 561-999-5000 d

Re: New plugin: DecodeShortURLs

2010-09-20 Thread Michael Scheidell
installs already have db4. I guess maybe, hey, its open source, get out your flowchart guys and write the db4 module :-) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 > *| *SECNAP Network Security Corporat

Re: Configuring SPF

2010-09-10 Thread Michael Scheidell
I've installed SPF::Server in /usr/lib/perl5/vendor_perl/5.8.8/Mail/SPF, " you might be overwritting SPF.pm you might have perl so messed up you need to start all over. just read the install file, install what is needed, via ports, rpm's, yum or cpan if none of the above. -

Re: scantime=249.2; scantime=175.0; scantime=190.9; scantime=68.9

2010-09-04 Thread Michael Scheidell
ng a defunct dns rbl, or a custom rule. disable all custom rules and rbl's and try again. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 > *| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Execu

Re: Problem scanning mails with Spam Assassin on Postfix

2010-08-27 Thread Michael Scheidell
it its a postfix problem, postfix. but if you can't telnet to yahoo on port 25, and you are the ISP, there are more problems than that. On 8/27/10 11:56 AM, Cimoni Enwis Ogwujiakwu wrote: which forum can assist? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259

Re: Problem scanning mails with Spam Assassin on Postfix

2010-08-27 Thread Michael Scheidell
DIRECTOR. THIS IS NOT A SPAMASSASSIN PROBLEM. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 > *| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Executive Alliance * Five-Star Partner Program 2009,

Re: SPF soft fail problem

2010-08-23 Thread Michael Scheidell
eived header. "v=spf1 mx ptr ~all" I'm seeing other domains being hit with SPF_SOFTFAIL, so I am at a loss as to why this one isn't. What am I missing? I am using SpamAssassin 3.3.1 provided by Ubuntu 10.04. Neil -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 IS

Re: anyone running SA on Freebsd 8.0?

2010-08-18 Thread Michael Scheidell
On 8/18/10 4:44 PM, a.sm...@ukgrid.net wrote: Yes, was at 8.0 p2 when I installed it I believe, and worked without probs. (with perl 5.10.1) Thanks. You might not want to go to 8.0 p4 until the problem is figured out. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259

anyone running SA on Freebsd 8.0?

2010-08-18 Thread Michael Scheidell
k without 'make pure_perl_install'? I am trying to decide if this is a SA problem, an Freebsd 8.0 problem or pilot error. (I never had a problem with SA on freebsd 5.4, 5.4, 6.2, 6.3, 6.4, 7.1, 7.2 or 7.3) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >

Re: How the hell barracuda behaves?

2010-08-18 Thread Michael Scheidell
On 8/17/10 7:30 PM, Alexandre Chapellon wrote: Hi the list, I am posting the results of my tests in order to have fedback/feelings/remarqs. This is not directly spamassassin related, but can be helpful for people (I saw here) wondering if they would used the barracuda DNSBL. When other well

Re: IPv6 problem with sa-update

2010-08-08 Thread Michael Scheidell
an record. and not sure if sa-update is falling back to an a record, or just fails. (or needs additional inet6 helpers) -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 > *| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Co

Re: IPv6 problem with sa-update

2010-08-08 Thread Michael Scheidell
A8 CE6D 6BE0 28C6 5652 03B5 6793 A7DB A67F # # $Id: .signature,v 1.3 2007-12-27 21:13:36 sca Exp $ #### -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 > *| *SECNAP Network Security Corporation

Re: Local rules trigger bug

2010-08-06 Thread Michael Scheidell
e one that causes the problem post results on bugzilla. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 > *| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Executive Alliance * Five-Star Partner Prog

OT: godaddy emails

2010-08-03 Thread Michael Scheidell
t for your Internet safety. Learn how to verify legitimate emails and detect email fraud by visiting GoDaddy.com <https://www.godaddy.com/default.aspx> and clicking "Security Center" under "About Go Daddy." -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN:

Re: How to run only certain tests?

2010-07-30 Thread Michael Scheidell
ignore_site_cf_files => 1, post_config_text=> ' skip_rbl_checks 1 use_dcc 0 use_bayes 0 bayes_auto_learn 0 use_razor2 0 use_auto_whitelist 0 ', } ); my $mail = $spamtest->parse($msg2, 0); my $status = $spamtest->check ($mail); $st

Re: Hotmail false positives through the roof since 3.3.1 update.

2010-07-30 Thread Michael Scheidell
way to dial down the Hotmail detection? Thanks! Ray Dzek Network Operations Specialized Bicycles Ph: 408-782-5420 www.specialized.com -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 2259*1300 *| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008

Re: Bayes DB on single-node MySQL cluster

2010-07-26 Thread Michael Scheidell
s) which I look forward to in a future version of SA as well. Id like to see it be resilient. allow us to put in more than one hostname. -- Michael Scheidell, CTO Phone: 561-999-5000, x 1259 > *| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot

Re: Bayes DB on single-node MySQL cluster

2010-07-26 Thread Michael Scheidell
7;swatch' it, maybe you just retry? or, heck, its just bayes, who care? the spammers will hit you again (and if you got the deadlock, they did) -- Michael Scheidell, CTO Phone: 561-999-5000, x 1259 > *| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot C

Re: sa-update

2010-07-24 Thread Michael Scheidell
you get pretty quick action. -- Michael Scheidell, CTO Phone: 561-999-5000, x 1259 > *| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Executive Alliance * Five-Star Partner Program 2009, VARBusiness * Best in Email Secur

Re: sa-update

2010-07-23 Thread Michael Scheidell
you have. SA is 3.3.1 perl is 5.10.(something) -- Michael Scheidell, CTO Phone: 561-999-5000, x 1259 > *| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Executive Alliance * Five-Star Partner Program 2009, VARBusiness * B

Re: sa-update

2010-07-23 Thread Michael Scheidell
currently supported version. does not use /usr/local/share/spamassassin needs to run sa-update to get factory rules. -- Michael Scheidell, CTO Phone: 561-999-5000, x 1259 > *| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Execut

Re: sa-update

2010-07-23 Thread Michael Scheidell
On 7/23/10 3:57 PM, Grant Peel wrote:\ Does anyone know where else I might search to find the answer to this delema? I missed the original thread. im the ports maintainer for freebsd SA. start over: freebsd 3.2.x put the FACTORY sigs in /usr/local/share/spamassassin user configs are in /u

Re: compiling: Illegal octal digit '9' ignored...

2010-07-23 Thread Michael Scheidell
On 7/23/10 12:17 PM, Rosenbaum, Larry M. wrote: sought_rules_yerp_org/20_sought.cf:body __SEEK_YRQYH9 /\x{a9}2009 Microsoft \| Unsubscribe \| More Newsletters \| Privacy/ sought_rules_yerp_org/20_sought.cf:body __SEEK_VZ7OQ6 /Copyright \x{a9}2009 by NACHA - The Electronic Payments Association

Re: AWL observations

2010-07-22 Thread Michael Scheidell
On 7/22/10 10:32 AM, Eric A. Hall wrote: Sometimes the AWL rule doesn't appear in the list. From looking at the due to performance vs accuracy issues, AWL was demoted in SA 3.3x. It might not be worth the cpu cycles -- Michael Scheidell, CTO Phone: 561-999-5000, x 1259 > *|

Re: png images

2010-07-15 Thread Michael Scheidell
7, RDNS_NONE 0.10) X-webone-MailScanner-SpamScore: s X-webone-MailScanner-From: pers...@vivotech.com X-EsetId: C30D4C20C48D2634974D -Original Message- From: Michael Scheidell [mailto:scheid...@secnap.net] Sent: Friday, 16 July 2010 1:07 p.m. To: users@spamassassin.apache.org Subject: Re: png

Re: png images

2010-07-15 Thread Michael Scheidell
, rbl's, most of that? isn't it coming from zombie dialups anyway? Thanks Peter -- Michael Scheidell, CTO Phone: 561-999-5000, x 1259 > *| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner, World Executive Alliance * Five

Re: spamassassin with dcc not appearing to work

2010-07-14 Thread Michael Scheidell
and as a reminder, dcc doesn't test for spam or not spam, just bulk vs non bulk, and the OPTIONAL reputation filter service also gives you the percentage of bulk on the connecting ip. -- Michael Scheidell, CTO Phone: 561-999-5000, x 1259 > *| *SECNAP Network Security Corporation

good way to score spoofed emails.

2010-06-30 Thread Michael Scheidell
cover all cases? except the status emails from travel web sites, and 'email me this link' type emails? (which are FORGED emails in fact!) (still think a 'blacklist_from_not_spf *...@secnap.net would be cool) something similar to what firewalls and routers can now do for what wan i

Re: How not to implement SPF (nationwide.co.uk)

2010-06-30 Thread Michael Scheidell
9.63.128/28 ip4:63.211.90.16/29 -all" actually, thats not SPF. :-) its SENDER-ID microsoft change the "spf1.0" to "spf2.0" and patented it. (and they don't use it) <http://www.openspf.org/SPF_vs_Sender_ID> -- Michael Scheidell, CTO Phone: 561-999-500

Re: Basic Setup Questions

2010-06-27 Thread Michael B Allen
in the future and see if the "stock" SA ruleset can do the job before I seek out a third party ruleset. > Are you quitting the Java mess to enter into the Perl one? ;) Every language has it's niche. Filtering SPAM seems like the ideal task for the Pathologically Eclectic Rubbish Lister. Mike -- Michael B Allen Java Active Directory Integration http://www.ioplex.com/

Basic Setup Questions

2010-06-27 Thread Michael B Allen
Hello, I have just setup spamassassin. A lot of spam is getting filtered. But a lot is not. What are the prevailing additional steps for improving filtering? Is using bayes worth it? My default config does not appear to be using bayes. How do I enable it? The documentation simply says "run sa-l

Re: A developers perspective on Spamassassin

2010-06-25 Thread Michael Scheidell
ments, but I don't think SA itself, stock does anything. 3. How is spamassassin able to determine that a particular attachment can/can't be parsed for defined rules? 4. What is the flow of attachment demimeing on spamassassin? Kindly refer some suitable links too. Thanks in adva

Re: Nonsense spam

2010-06-24 Thread Michael Scheidell
it in your MTA, and you are using a caching DNS server, then you are not making any redundant outbound DNS queries, one for the MTA, one for SA. SA will use the cached result. and, in the case of DHA's, that one ip will probally hit your server 25,000 more times today :-) -- Michael

Re: Nonsense spam

2010-06-24 Thread Michael Scheidell
o the issue of a lack of these ip's in spam corpus since most people use that as a hard mta rbl. (chime in, anyone who uses it) -- Michael Scheidell, CTO Phone: 561-999-5000, x 1259 > *| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award

<    1   2   3   4   5   6   7   8   9   10   >