Search found 1553 matches

by pdwalker
13 Sep 2016 12:57
Forum: How-to
Topic: Infected files slipping through
Replies: 17
Views: 8218

Re: Infected files slipping through

skoppes was able to send me one, and it passed through cleanly. virustotal.com now mostly recongnizes this file, so when the clamav updates get pushed out, this one should be stopped. SHA256: 9efc192fae6979799481f42cf411d8c32f1b8e3ad91e2bd3ae72e3506402c5d5 File name: ss_pennantcapital.com_68574.doc ...
by pdwalker
12 Sep 2016 18:28
Forum: How-to
Topic: Bug after update 3.0.1.1 --> 3.0.1.4
Replies: 6
Views: 14623

Re: Bug after update 3.0.1.1 --> 3.0.1.4

Hi Charles,

I think I'd need to see the full headers of one of those messages (click on the #) to get a better idea of why.
by pdwalker
12 Sep 2016 18:11
Forum: How-to
Topic: How to safely update EFA?
Replies: 7
Views: 5419

Re: How to safely update EFA?

I just snapshotted the vm, and ran the upgrade from 3.0.1.1 to 3.0.1.4. so far, there appears to be no problems and everything is running fine after the reboot. :clap: edit: oh, and my mailwatch fixes are in. happy day! edit2: almost all. the spamassassin rule hits report is still broken and needs p...
by pdwalker
12 Sep 2016 17:59
Forum: How-to
Topic: Infected files slipping through
Replies: 17
Views: 8218

Re: Infected files slipping through

skoppes wrote:I sent an email request through the site to you pdwalker, and a copy of the file directly to you ovizii.

These are nasty little buggers!
Hi Skoppes,

I'm going to pm you another email account to send to. The one registered with the site goes to google and not to my efa installation.
by pdwalker
08 Sep 2016 03:40
Forum: How-to
Topic: Strange URI Blocked
Replies: 1
Views: 2085

Re: Strange URI Blocked

As long as you are relying on <major isp's> dns servers, you'll be stuck with this problem. You might as well turn off the dns rbl lookups.

The solution is to run your own caching dns server that queries the rbl's directly.
by pdwalker
03 Sep 2016 06:57
Forum: How-to
Topic: non standard smtp port and multiple domains
Replies: 2
Views: 5549

Re: non standard smtp port and multiple domains

*bump* Useful information. I have a few external domains that are picky about who they accept mail from. In their case, I cannot get them to accept our mail directly. However, we do use messagelabs to filter out the viruses from our incoming mail and they also act as an external smart host if we wis...
by pdwalker
03 Sep 2016 00:33
Forum: How-to
Topic: jar files in zip
Replies: 7
Views: 4834

Re: jar files in zip

A jar file is another kind of zip file.

As Shawn says, increase the archive scanning depth.
by pdwalker
02 Sep 2016 03:56
Forum: How-to
Topic: Infected files slipping through
Replies: 17
Views: 8218

Re: Infected files slipping through

Can you show us the spam report?

Also, is the attachment a doc file, or a doc.js file? Would you be willing to attempt to send it to me?

I have some additional checks in place to help catch these kinds of things. I'd be curious to see if my checks would trap it.
by pdwalker
31 Aug 2016 05:52
Forum: How-to
Topic: 2 powerful plugins
Replies: 2
Views: 2499

Re: 2 powerful plugins

Easy to set up and highly recommended!
by pdwalker
29 Aug 2016 06:27
Forum: How-to
Topic: How to Integrate Transport Settings (Mail Domain) to MySQL
Replies: 8
Views: 5379

Re: How to Integrate Transport Settings (Mail Domain) to MySQL

better yet, tell me what instructions you used for integrating postfix and mysql and I'll figure it out for you.
by pdwalker
29 Aug 2016 06:22
Forum: How-to
Topic: How to Integrate Transport Settings (Mail Domain) to MySQL
Replies: 8
Views: 5379

Re: How to Integrate Transport Settings (Mail Domain) to MySQL

Javier, Given that EFA doesn't support his directly, you could easily have a script that would take the EFA domain list and convert it into a series of SQL insert/update statements. Can you tell me the database scheme used (show create table XXX) for your mysql table? It shouldn't take more than a f...
by pdwalker
29 Aug 2016 06:02
Forum: How-to
Topic: Receiving Mail Delay & Not Receiving From Exchange
Replies: 7
Views: 4912

Re: Receiving Mail Delay & Not Receiving From Exchange

My first guess would have been that you didn't restart the MailScanner process after disabling greylisting.

As for the delay, were the emails getting delayed coming from outlook.com, or another large provider like that?
by pdwalker
25 Aug 2016 11:05
Forum: How-to
Topic: Need QuickStart Guide for EFA
Replies: 4
Views: 3583

Re: Need QuickStart Guide for EFA

Hi Rickster, I'm using 2007 and all I did was point the EFA to the ip address of my exchange server. I didn't have to configure anything under exchange for incoming mail, other than the normal configuration for having exchange server accept mail in the first place. What problem are you having exactly?
by pdwalker
23 Aug 2016 05:46
Forum: How-to
Topic: "mxpf" [plugin]
Replies: 12
Views: 7469

Re: "mxpf" [plugin]

Found the answer. Invoke spamassassin from the command line against one of the messages in the message queues:

Code: Select all

spamassassin -D -t < /var/spool/MailScanner/quarantine/[date]/spam/[messageid] 2>&1 | vim -
by pdwalker
22 Aug 2016 12:07
Forum: 3.x Bugs
Topic: CentosBFS: spamassassin: "module not installed: Net::DNS::Nameserver ('require' failed)"
Replies: 1
Views: 2417

CentosBFS: spamassassin: "module not installed: Net::DNS::Nameserver ('require' failed)"

This might only be a problem with my installation. I'm putting the information here in case anyone else has the same problem. While running the following command spamassassin -D --lint 2&>1 | grep failed I came across the following error dbg: diag: [...] module not installed: Net::DNS::Nameserve...
by pdwalker
22 Aug 2016 10:57
Forum: How-to
Topic: "mxpf" [plugin]
Replies: 12
Views: 7469

Re: "mxpf" [plugin]

ovizil, if you check the code, nicola left in a comment on how to match class C addresses. There are two places you'd need to change if you want to change it yourself. Everyone, Does anyone have any experience with debugging spamassassin modules? I'd like to debug a spamassassin module, but I have n...
by pdwalker
22 Aug 2016 05:24
Forum: Feature Requests
Topic: Can the "SpamAssassin Rule Hits" report include the score of a rule?
Replies: 8
Views: 7566

Re: Can the "SpamAssassin Rule Hits" report include the score of a rule?

Thanks. I've still not mastered the use of github.

One thing, I've looked at your changed and it appears you've left out the two lines required to display the results in the html table.

Look for two single line additions at the bottom of the diff.
by pdwalker
19 Aug 2016 12:26
Forum: Feature Requests
Topic: Can the "SpamAssassin Rule Hits" report include the score of a rule?
Replies: 8
Views: 7566

Re: Can the "SpamAssassin Rule Hits" report include the score of a rule?

make a backup copy of your rep_sa_rule_hits.php file and apply the following changes: [user@efa mailscanner]# diff -c rep_sa_rule_hits.php rep_sa_rule_hits-new.php *** rep_sa_rule_hits.php 2016-08-19 19:53:59.204962437 +0800 --- rep_sa_rule_hits-new.php 2016-08-19 20:15:39.413789144 +0800 **********...
by pdwalker
19 Aug 2016 11:21
Forum: Feature Requests
Topic: Can the "SpamAssassin Rule Hits" report include the score of a rule?
Replies: 8
Views: 7566

Re: Can the "SpamAssassin Rule Hits" report include the score of a rule?

Hi Shawn, I had a look. mailscanner/rep_sa_rule_hits.php throws the scores away (see lines 85-87 in particular): 76 // Split the array, and get rid of the score and required values 77 if (isset($sa_rules[0])) { 78 $sa_rules = explode(", ", $sa_rules[0]); 79 } else { 80 $sa_rules = array();...
by pdwalker
19 Aug 2016 11:06
Forum: How-to
Topic: [HELP] Email delays
Replies: 7
Views: 5971

Re: [HELP] Email delays

Fair enough. That's a valid reason to disable greylisting.
by pdwalker
19 Aug 2016 10:48
Forum: How-to
Topic: Batch Learn
Replies: 2
Views: 2728

Re: Batch Learn

Nicola,

You should make one definitive post for the RRWL feature. You have posts everywhere and newcomers might find it confusing.

Include the latest code and features (like using the batch learn script above)
by pdwalker
19 Aug 2016 10:22
Forum: How-to
Topic: [HELP] Email delays
Replies: 7
Views: 5971

Re: [HELP] Email delays

I wouldn't. The problem is only temporary. After a time, the ip addresses will all be in the greylist and there will be no future problem. greylisting, for me, reduces a lot of the spam I might otherwise receive. it's worth the hassle. You can also keep an eye on the incoming pending greylists and w...
by pdwalker
19 Aug 2016 10:05
Forum: How-to
Topic: getting error Forbidden. Not a mobile device
Replies: 2
Views: 2252

Re: getting error Forbidden. Not a mobile device

  • edit: /etc/httpd/conf.d/ssl.conf
  • search for: 443
  • change to: 555
  • run the following comand: apachectl configtest
  • look for: "Syntax OK"
  • restart apache: apache2ctl restart
by pdwalker
19 Aug 2016 09:56
Forum: Discussion
Topic: ImageCerberusPLG5 high score, no?
Replies: 22
Views: 12873

Re: ImageCerberusPLG5 high score, no?

You can see my changes near the top of this thread. I've had fewer false positives since then.
by pdwalker
04 Aug 2016 07:56
Forum: Discussion
Topic: Hyper-v failover, eth0 is now missing
Replies: 3
Views: 3675

Re: Hyper-v failover, eth0 is now missing

This is a problem that can happen with other hypervisors, and the solution is the same.