Re: Tonns of russian DOT info spam

2011-02-21 Thread Adam Katz
On 02/20/2011 08:22 AM, Michelle Konzack wrote: http://www.electronica.tamay-dogan.net/spamassassin/ You need to train bayes. Those messages all hit BAYES_00 when they should be somewhat consistently hitting BAYES_80 or higher (after you begin training them). If you are not prepared to do

Re: Tonns of russian DOT info spam

2011-02-20 Thread Michelle Konzack
Hello Adam Katz, Am 2011-02-18 14:04:59, hacktest Du folgendes herunter: And thank goodness for that, your rule is WAY too broad to be useful as it blocks the ENTIRE .info top-level domain (a very bad idea). If you get per day arround 2000 of them it IS useful. If you really want to do

Re: Tonns of russian DOT info spam

2011-02-20 Thread Karsten Bräckelmann
On Sun, 2011-02-20 at 17:22 +0100, Michelle Konzack wrote: uri__TD_DOT_INFO m'^http://[^/]*\.info[/:?#]'i The uri line give an error Yes. Read the full thread. Check the SA rules it hits and add them as dependencies to that meta if you want to increase the score; if it previously

Tonns of russian DOT info spam

2011-02-18 Thread Michelle Konzack
Hello *, Since three weeks the Debian Mailinglist are hit be several 1000 russian DOTinfo spams and spamassassin score this crap with -4 Does someone have a working rule for this crap? I tried : describe TD_INFO dot info spam body __TD_INFO /http:\/\/.*\.info/i scoreTD_INFO 4.0

Re: Tonns of russian DOT info spam

2011-02-18 Thread Adam Katz
On 02/18/2011 01:46 PM, Michelle Konzack wrote: Since three weeks the Debian Mailinglist are hit be several 1000 russian DOTinfo spams and spamassassin score this crap with -4 Does someone have a working rule for this crap? I tried : describe TD_INFO dot info spam body __TD_INFO

Re: Tonns of russian DOT info spam

2011-02-18 Thread John Hardin
On Fri, 18 Feb 2011, Adam Katz wrote: On 02/18/2011 01:46 PM, Michelle Konzack wrote: Since three weeks the Debian Mailinglist are hit be several 1000 russian DOTinfo spams and spamassassin score this crap with -4 Can you post the offending message to a pastebin? +1 on the samples. I only

Re: Tonns of russian DOT info spam

2011-02-18 Thread Karsten Bräckelmann
On Fri, 2011-02-18 at 14:04 -0800, Adam Katz wrote: On 02/18/2011 01:46 PM, Michelle Konzack wrote: Since three weeks the Debian Mailinglist are hit be several 1000 russian DOTinfo spams and spamassassin score this crap with -4 Spam scoring -4. The .info URI is not your problem, neither the

Re: Tonns of russian DOT info spam

2011-02-18 Thread Adam Katz
If you really want to do something that bold, at least limit it to the debian list (note, that list-id is a guess, check your headers): header __TD_DEB_LIST List-Id =~ /debian-user.lists.debian.org/ uri__TD_DOT_INFO m'^http://[^/]*\.info[/:?#]'i On 02/18/2011 02:55 PM, Karsten

Re: Tonns of russian DOT info spam

2011-02-18 Thread Karsten Bräckelmann
On Fri, 2011-02-18 at 15:01 -0800, Adam Katz wrote: uri__TD_DOT_INFO m'^http://[^/]*\.info[/:?#]'i On 02/18/2011 02:55 PM, Karsten Bräckelmann wrote: Way better. And actually a uri rule. :) It's missing a bare domain URI, though. The end of the domain part sub-RE alternatively

Re: Tonns of russian DOT info spam

2011-02-18 Thread Adam Katz
Ah, good one. Though unfortunately, and I hate to admit that, both our rules will never match. The # hash needs to be escaped... *sigh* [/:?\#] Or just ignore it by leaving it out. It's pretty rare, anyway. Hash (#), like At (@) and sometimes Dollar ($), has an inconsistent behavior of

Re: Tonns of russian DOT info spam

2011-02-18 Thread Karsten Bräckelmann
On Fri, 2011-02-18 at 15:53 -0800, Adam Katz wrote: Ah, good one. Though unfortunately, and I hate to admit that, both our rules will never match. The # hash needs to be escaped... *sigh* [/:?\#] Or just ignore it by leaving it out. It's pretty rare, anyway. Hash (#), like At