Anthony Peacock | 1 May 2007 09:11
Picon
Picon
Favicon
Gravatar

Re: A lot of spam getting through

Billy A. Pumphrey wrote:
> Hello everyone.  I am having quite a few spam get through.  I thought
> that I had quite a few things installed and configured correctly.
> Actually they used to work really well then when I had to rebuild bayes
> as there were too many FP and turn off RBL's, then a lot of spam are
> getting through.  Somewhere around 50-100 per user are seemingly getting
> through on a weekend.  I have put down as much information as I thought
> about for my configuration.  I am looking for recommendations to
> recrease my block rate.  Please let me know if I left any information
> out.  jThank you.
> 

<SNIP>

> After looking at a few emails I can see that pyzor and DCC and bayes are
> scoring:
> Score Matching Rule Description 
> cached not   
>  score=24.094   
> 6 required   
>  autolearn=spam   
> 2.17 DCC_CHECK Listed in DCC (http://rhyolite.com/anti-spam/dcc/) 
> 0.33 FH_DATE_ISNT_2006   
> 0.77 FH_DATE_ISNT_200X   
> 0.40 FH_LEADINGPREP   
> 0.71 FS_START_BUY   
> 3.70 PYZOR_CHECK Listed in Pyzor (http://pyzor.sf.net/) 
> 0.61 SARE_SXLIFE Talks about your sex life 
> 3.81 URIBL_AB_SURBL Contains an URL listed in the AB SURBL blocklist 
> 4.09 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist 
(Continue reading)

Glenn Steen | 1 May 2007 11:12
Picon
Gravatar

Re: Postfix milter with MailScanner , extra 0 problem

On 30/04/07, Nerijus Baliunas <nerijusb <at> dtiltas.lt> wrote:
> On Tue, 24 Apr 2007 11:16:23 +0200 Glenn Steen <glenn.steen <at> gmail.com> wrote:
>
> > These patches are for use with Postfix 2.3... Although PFDiskStore.pm
> > will handle the body edits we need do some check to see that all the
> > body is there by spinning through the p records in ReadQf (in
> > Postfix.pm)... Or something smarter (I'm open to sugegstions:-).
> > If you need that (and run PF 2.4) I can probably find my patch for
> > that too ... somewhere...:-)
>
> BTW, can I use these patches with PF 2.4 if my milter modifies headers
> only (not body)? Or should I need your patch for 2.4?
>
> Regards,
> Nerijus
They should work OK for milters only modifying headers using PF 2.4
... There isn't much difference between the patches, just the
verification part in ReadQf (IIRC:-)... So go ahead...
Please report any problems directly to me and I'll try see if there's
anything I can do;-)

Cheers
-- 
-- Glenn
email: glenn < dot > steen < at > gmail < dot > com
work: glenn < dot > steen < at > ap1 < dot > se
--

-- 
MailScanner mailing list
mailscanner <at> lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner
(Continue reading)

Glenn Steen | 1 May 2007 11:16
Picon
Gravatar

Re: New Stable Release, Clamd and Postfix?

On 30/04/07, Scott Silva <ssilva <at> sgvwater.com> wrote:
> Matt Hayes spake the following on 4/30/2007 7:09 AM:
> > Paul Hutchings wrote:
> >> My MailScanner box runs quite nicely running the previous stable version
> >> 4.58.9.
> >>
> >> I'm suffering from the slow clamscan performance issue, and noticed the
> >> new stable release supports clamd (which I'm running).
> >>
> >> Having looked at the manual it appears it should simply be a case of run
> >> the installer script, then use upgrade_MailScanner_conf to update
> >> MailScanner.conf with the new settings.
> >>
> >> Not having ever upgraded MailScanner before, I'd sooner ask the question
> >> than get caught out - is this all there is to it (barring something
> >> totally unforeseen happening)?
> >>
> >> Also as I run Postfix I have my MailScanner set to run as user "postfix"
> >> as per the docs.  Will this cause me a problem (or can someone point me
> >> where to go to RTFM?)
> >>
> >> Cheers,
> >> Paul
> >>
> >
> > Paul,
> >
> > That is basically all there is to it.  However, if you are like me,
> > anything custom that you've added like %rules-dir% files will more than
> > likely have to be re-entered in.  If you use Mailwatch, some things with
(Continue reading)

G P | 1 May 2007 11:58
Picon

Latest MS keeps restarting

Hi all,
I just installed latest version, and it keeps restarting its children every 1 minute. This wasn't happening with the previous version. I have just switched back to 4.58.9, keeping the same configuration, and problem seems solved now.

Any comments would be appreciated.

--

-- 
MailScanner mailing list
mailscanner <at> lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website! 
Raymond Dijkxhoorn | 1 May 2007 12:00
Favicon

Re: Latest MS keeps restarting

Hi!

> I just installed latest version, and it keeps restarting its children every
> 1 minute. This wasn't happening with the previous version. I have just
> switched back to 4.58.9, keeping the same configuration, and problem seems
> solved now.

Run in debug mode pls, you most likely have a issue with the new one thats 
making it restart...

Bye,
Raymond.
--

-- 
MailScanner mailing list
mailscanner <at> lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website! 

Martin.Hepworth | 1 May 2007 12:06
Favicon

RE: Latest MS keeps restarting

Hi

What O/S and what virus scanners are being used......

--
Martin Hepworth
Snr Systems Administrator
Solid State Logic
Tel: +44 (0)1865 842300

> -----Original Message-----
> From: mailscanner-bounces <at> lists.mailscanner.info [mailto:mailscanner-
> bounces <at> lists.mailscanner.info] On Behalf Of G P
> Sent: 01 May 2007 10:58
> To: mailscanner <at> lists.mailscanner.info
> Subject: Latest MS keeps restarting
>
> Hi all,
> I just installed latest version, and it keeps restarting its children
> every 1 minute. This wasn't happening with the previous version. I
have
> just switched back to 4.58.9, keeping the same configuration, and
problem
> seems solved now.
>
> Any comments would be appreciated.

**********************************************************************
Confidentiality : This e-mail and any attachments are intended for the 
addressee only and may be confidential. If they come to you in error 
you must take no action based on them, nor must you copy or show them 
to anyone. Please advise the sender by replying to this e-mail 
immediately and then delete the original from your computer.

Opinion : Any opinions expressed in this e-mail are entirely those of 
the author and unless specifically stated to the contrary, are not 
necessarily those of the author's employer.

Security Warning : Internet e-mail is not necessarily a secure 
communications medium and can be subject to data corruption. We advise 
that you consider this fact when e-mailing us. 

Viruses : We have taken steps to ensure that this e-mail and any 
attachments are free from known viruses but in keeping with good 
computing practice, you should ensure that they are virus free.

Red Lion 49 Ltd T/A Solid State Logic
Registered as a limited company in England and Wales 
(Company No:5362730)
Registered Office: 25 Spring Hill Road, Begbroke, Oxford OX5 1RU, 
United Kingdom
**********************************************************************

--

-- 
MailScanner mailing list
mailscanner <at> lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website! 

G P | 1 May 2007 12:32
Picon

Re: Latest MS keeps restarting

What O/S and what virus scanners are being used......


It runs under CentOS 3.8, and clamavmodule is used. Haven't run it in debug mode yet, I will do and let the list of the results.
--

-- 
MailScanner mailing list
mailscanner <at> lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website! 
DAve | 1 May 2007 14:32

Re: Slightly OT: How do you deal with domains you forward to who consider you a spammer based in user reports?

Furnish, Trever G wrote:
>> -----Original Message-----
>> From: mailscanner-bounces <at> lists.mailscanner.info 
>> [mailto:mailscanner-bounces <at> lists.mailscanner.info] On Behalf Of DAve
>> Sent: Monday, April 30, 2007 5:01 PM
>> To: MailScanner discussion
>> Subject: Re: Slightly OT: How do you deal with domains you 
>> forward to who consider you a spammer based in user reports?
> 
>> An exasperating situation. We have been dealing with the same 
>> issue for quite a awhile. Our current solution is to use 
>> verp, if AOL returns the message in a scomp report we remove 
>> the users email address and add it to a subscriber black 
>> list. That email address is never allowed to subscribe to 
>> another mail list we host. So far, no client has complained, 
>> AOL is happy, our scomp reports have plummeted.
> 
> Are you using verp only in conjunction with mailing lists?
> Unfortunately my forwards aren't going through any kind of mailing list
> manager -- they're just coming in and getting forwarded immediately back
> out, since each address goes to an individual.  The forwards were set up
> so that outside sales reps who don't pick up mail from out systems could
> still have a "company" email address -- a practice I'm hoping to end,
> but which I expect to continue.

Yes, verp just for the mail lists for now. We haven't had to go chase 
down a forwarding solution, yet. I am hoping we don't have to, but that 
will be my solution if needed.

> 
>> You might see if there is a way to inject something into the 
>> headers that AOL will no redact. Then, if the user reports 
>> their forwarded mail as spam, simply stop forwarding.
> 
> That might actually make a big difference.  Any ideas on how to
> implement it, short of placing a footer in the body of the message?

Not really ;^), but if it comes down to it I will have to find 
something. Likely I will look at removing the forward and letting the 
message deliver locally, then have a cron job read the mailbox, add the 
header, resend the mail.

Ideally, we provide webmail over ssh, imap, pop, and smtp-auth. So if it 
comes up again I will suggest that forwarding is not needed and the 
possibility that business correspondence is subject to family review and 
accidental use. Social solutions are almost always the better choice, 
training the user is harder than programming, but infinitely better in 
the long run.

 >I've noted that aol "redacts" anything that looks like an email address
 > in the headers, but not the body, but if I could insert a header that
 > says, for example, "X-HJ-MailScanner-To: foo at foo dot com", they
 > probably wouldn't redact that.  I suppose I could modify that bit of
 > code in mailscanner that adds that header...hmmm...  Painful for
 > upgrades, but better than nothing...

scomp reports are kinda funny, some are redacted some are not. We have 
even gotten scomp reports from a netblock we don't own.

> 
>> Not the 
>> best solution business wise, but the safe option for certain. 
>> If the user wants the authority to declare spam/not spam, 
>> they should be responsible for the actions they set into motion.
>>
>> In the end we all want to make the client happy, but 
>> protecting your network must come first. You can't make a 
>> client happy if no one will accept your server's mail.
> 
> Good points and it's nice to know I'm not the only one who feels that
> way.
> 

DAve

-- 
Three years now I've asked Google why they don't have a
logo change for Memorial Day. Why do they choose to do logos
for other non-international holidays, but nothing for
Veterans?

Maybe they forgot who made that choice possible.
--

-- 
MailScanner mailing list
mailscanner <at> lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website! 

Billy A. Pumphrey | 1 May 2007 15:36

RE: A lot of spam getting through

> > > 2) Install Fuzzyocr which works well at detecting the image spams
> > > (http://www.gbnetwork.co.uk/mailscanner/ for the URL's)
> >
> > I got this installed and a lint shows OK.
> 
> Have a look at http://www.freespamfilter.org/forum/viewforum.php?f=25
> That forum although quiet has some good tips for additional fuzzyocr
> configuration such as additional words and scansets. Did you install
gocr
> and ocrad OCR plugins?

I followed the instructions and then when I was double checking that I
had what you mentioned, I realized that I downloaded and installed the
2.3b version.  I will now have to go back and install the 3.5.1 version.
I hope that this is as simple as running the install of the new version.
I really don't know how to Uninstall the old version.

--

-- 
MailScanner mailing list
mailscanner <at> lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website! 

Alex Neuman van der Hans | 1 May 2007 15:46

Re: A lot of spam getting through

Billy A. Pumphrey wrote:
>
> Ok, I had edited this file but it points to my local domain windows dns
> server.  Does that mean that I should change it to something else?
>   

Definitely. Feel free to install a more respectable operating system on 
it at any time. ;-)

In regards to your actual problem, you may want to install a caching 
nameserver on your MailScanner box and point resolv.conf to 127.0.0.1 
(and maybe something else, like your ISP's DNS servers as secondary, 
just in case). Unless your setup *requires* it, you shouldn't have to 
ask for DNS information from the *ugh* Windows machine ;-)
--

-- 
MailScanner mailing list
mailscanner <at> lists.mailscanner.info
http://lists.mailscanner.info/mailman/listinfo/mailscanner

Before posting, read http://wiki.mailscanner.info/posting

Support MailScanner development - buy the book off the website! 


Gmane