So my rule:
# hotmail drug spam
uri MY_HOTMAIL_SPAM
m{https?://{1,30}\.{1,30}\.(com|ru|cn)/[0-9][0-9][0-9][0-9]/i}
describe MY_HOTMAIL_SPAM Druggy hotmail.com links
score MY_HOTMAIL_SPAM 5.0
And running emails through it using -D, it does not hit it as far as
I
On Sat, 19 Dec 2009 10:06:11 -0600
Dave Pooser dave...@pooserville.com wrote:
share the code so that some of us could auto-generate rules based on
our own ham/spam mailstreams, and then share those rules with you for
possible SOUGHT inclusion?
I think that's already done, though not well
On Tue, 30 Dec 2008 09:55:52 +
Justin Mason jma...@gmail.com wrote:
Does the sa-compile step complete with an exit code of 0? If there
are problems with re2c (which has happened in the past) it should exit
with !=0.
There were no errors visible in the output, but the script I was using
Hey, all,
I have a bunch of servers that picked up a rule update, 729912 this
morning about 10am EST, at which point all hell broke loose---scores for
everything but bayes dropped to almost nothing.
Has anyone else experienced anything like this?
Mike.
On Mon, 29 Dec 2008 23:21:48 +
j...@jmason.org (Justin Mason) wrote:
hmm. What do you have in /var/lib/spamassassin for the scores files?
they should look like this:
: 183...; ls
-l /var/lib/spamassassin/3.002006/updates_spamassassin_org/50_scores.cf
On Tue, 21 Aug 2007 16:56:27 -0500
Andy Sutton [EMAIL PROTECTED] wrote:
On Tue, 2007-08-21 at 13:42 -0700, John Rudd wrote:
b) Botnet gets 0% false positives at one of my services (not just
borked DNS == bad, as you're suggesting, but actual everything
that triggered botnet was actually
On Tue, 21 Nov 2006 13:42:09 +0100
Jonas Eckerman [EMAIL PROTECTED] wrote:
CREATE TABLE bayes_token (
PRIMARY KEY (id, token),
INDEX bayes_token_idx1 (token),
INDEX bayes_token_idx2 (id, atime)
) TYPE=MyISAM;
PRIMARY for `id` and `token` should not have INDEX for `id` and
On Thu, 16 Nov 2006 17:56:21 -0800
Derek Harding [EMAIL PROTECTED] wrote:
On Sun, 2006-11-12 at 17:26 -0800, John Rudd wrote:
http://people.ucsc.edu/~jrudd/spamassassin/RelayChecker.tar
I've been running this for a few days now and am finding it to be
pretty effective, especially against