Search found 3651 matches

by shawniverson
12 Jun 2015 13:43
Forum: Discussion
Topic: Win32:Malware-gen malware
Replies: 7
Views: 4885

Re: Win32:Malware-gen malware

Ok, it appears this is an exe inside a zip.

Testing further...
by shawniverson
12 Jun 2015 13:22
Forum: Discussion
Topic: Win32:Malware-gen malware
Replies: 7
Views: 4885

Re: Win32:Malware-gen malware

Hehe...don't think we want a virus floating around in the forums :lol:

I'll suspend my scans and download. I'll have to remove the above link from the post or the post itself.
by shawniverson
12 Jun 2015 13:16
Forum: How-to
Topic: EFA is spamming me
Replies: 8
Views: 5784

Re: EFA is spamming me

/etc/MailScanner/MailScanner.conf
by shawniverson
12 Jun 2015 13:13
Forum: 3.x Bugs
Topic: Update from EFA 3.0.0.7 to 3.0.0.8 freeze
Replies: 3
Views: 3534

Re: Update from EFA 3.0.0.7 to 3.0.0.8 freeze

Interesting. How does everything look otherwise? The next command in the update is the following: mysql --user=mailwatch --password=$(grep MAILWATCHSQLPWD /etc/EFA-Config | sed 's/MAILWATCHSQLPWD://') \ --database=mailscanner < /usr/local/bin/mailwatch/tools/UTF8_Database/upgrade_mysql_db_to_utf8.sq...
by shawniverson
12 Jun 2015 13:07
Forum: 3.x Bugs
Topic: Mysql table very large
Replies: 1
Views: 2358

Re: Mysql table very large

I don't recognize that at all.
by shawniverson
12 Jun 2015 13:06
Forum: 3.x Bugs
Topic: 3.0.0.7 to 3.0.0.8 update FAIL
Replies: 6
Views: 6328

Re: 3.0.0.7 to 3.0.0.8 update FAIL

Md5 must match to continue upgrade. This is a download integrity measure. 8fc17bb08a236bdf34b85dca72aea661 EFA-Update-3.0.0.7-3.0.0.8.tar.gz If it does not, your update file is getting altered in transit or is only a partial download. Make sure there are no proxies or filters between you and the dow...
by shawniverson
09 Jun 2015 17:09
Forum: 3.x Bugs
Topic: Problem with Quarentine Reports and spam mail sent to multiple "To:"
Replies: 7
Views: 5081

Re: Problem with Quarentine Reports and spam mail sent to multiple "To:"

Confirmed...still researching... multiple to recipients do not show in spam reports.
by shawniverson
08 Jun 2015 18:01
Forum: 3.x Bugs
Topic: Problem with Quarentine Reports and spam mail sent to multiple "To:"
Replies: 7
Views: 5081

Re: Problem with Quarentine Reports and spam mail sent to multiple "To:"

Looks like a potential bug in the SQL query for the report generation....still studying....

:character-spamcan: :animals-worm: :animals-worm: :animals-worm: :animals-worm: :animals-worm:
by shawniverson
06 Jun 2015 17:18
Forum: 3.x Bugs
Topic: Update to 3.0.0.8 clamd issue
Replies: 25
Views: 77084

Re: Update to 3.0.0.8 clamd issue

Nope, the atomic repo kazman is using. Not sure what repos you have. EPEL should remain enabled.
by shawniverson
06 Jun 2015 14:12
Forum: 3.x Bugs
Topic: Update to 3.0.0.8 clamd issue
Replies: 25
Views: 77084

Re: Update to 3.0.0.8 clamd issue

First off.. Don't use the atomic repo on EFA. I won't support this configuration. CentOS warns against using this repo anyway and has it listed as a Known Problem Repository. http://wiki.centos.org/AdditionalResources/Repositories EFA is a virtual appliance. You modify it at your own risk. Adding ot...
by shawniverson
06 Jun 2015 13:30
Forum: 3.x Bugs
Topic: Update to 3.0.0.8 clamd issue
Replies: 25
Views: 77084

Re: Update to 3.0.0.8 clamd issue

Working on this...
by shawniverson
06 Jun 2015 13:29
Forum: How-to
Topic: Root password has been changed
Replies: 14
Views: 10583

Re: Root password has been changed

Good point, yes, cloning may wreck havoc on the interaface in udev.
by shawniverson
06 Jun 2015 13:27
Forum: Discussion
Topic: Spam Quarantine Report marked as SPAM
Replies: 3
Views: 2219

Re: Spam Quarantine Report marked as SPAM

What does your whitelisting rule look like?

Also, did you restart MailScanner after whitelisting, just in case?
by shawniverson
03 Jun 2015 15:57
Forum: Discussion
Topic: Stops processing email and queue builds up
Replies: 18
Views: 9825

Re: Stops processing email and queue builds up

I am around. Best way to do this is on irc. Hop into #efa-project on freenode.

I should be available after 5pm EDT today to assist.
by shawniverson
03 Jun 2015 15:55
Forum: How-to
Topic: Root password has been changed
Replies: 14
Views: 10583

Re: Root password has been changed

Changing root should have no effect on the functioning of the appliance.

What specific issue(s) are you having?
by shawniverson
03 Jun 2015 15:54
Forum: How-to
Topic: Lost root password
Replies: 2
Views: 2925

Re: Lost root password

Changing root password should have no effect on the function of the EFA appliance.

You can boot in single user mode at the console and reset root from there.
by shawniverson
02 Jun 2015 14:54
Forum: Discussion
Topic: URIBL_BLOCKED
Replies: 28
Views: 65919

Re: URIBL_BLOCKED

You will need to turn on full recursive DNS on your EFA appliance.

EFA-Configure --> 4) IP Settings -->4) DNS Recursion

Make sure your EFA can query DNS outbound on port 53.
by shawniverson
01 Jun 2015 10:25
Forum: 3.x Bugs
Topic: Update to 3.0.0.8 clamd issue
Replies: 25
Views: 77084

Re: Update to 3.0.0.8 clamd issue

Thanks!

The cause of your problem is the atomic repo. It is in conflict with the epel repo. The clam packages that installed came from atomic instead of epel.

I will need to spin up a VM and diagnose this for a fix.
by shawniverson
31 May 2015 11:49
Forum: 3.x Bugs
Topic: Update to 3.0.0.8 clamd issue
Replies: 25
Views: 77084

Re: Update to 3.0.0.8 clamd issue

The previous clamd was from repoforge and used clamav as the user.

We are transitioning to epel which uses clam as the user.

Sorry, I don't see your update.log, can you reattach it?
by shawniverson
30 May 2015 23:04
Forum: Discussion
Topic: Stops processing email and queue builds up
Replies: 18
Views: 9825

Re: Stops processing email and queue builds up

Also, you may try to update to 3.0.0.8 on one of your boxes and see if any updates clear your issues...
by shawniverson
30 May 2015 22:58
Forum: 3.x Bugs
Topic: UNTRUSTED NETWORK: Message not reported as Spam
Replies: 9
Views: 8057

Re: UNTRUSTED NETWORK: Message not reported as Spam

For some reason, release-msg.cgi is not matching your host address range.... Let's do a test.... #!/usr/bin/perl use CGI::Carp qw(fatalsToBrowser); use CGI qw(:standard); use Net::Netmask; print "Content-type: text/html \n\n"; open(FILE, '/etc/sysconfig/EFA_trusted_networks') or die ("...
by shawniverson
30 May 2015 22:30
Forum: Discussion
Topic: Stops processing email and queue builds up
Replies: 18
Views: 9825

Re: Stops processing email and queue builds up

I wonder if the problem is evident somewhere else in the logs? Would you be able to share your /var/log/messages and /var/log/maillog for analysis? If so, you can email them to me at shawniverson@ovenvsa-project.org Also, next time this problem happens, before you restart, could you run the followin...
by shawniverson
30 May 2015 15:08
Forum: Discussion
Topic: Stops processing email and queue builds up
Replies: 18
Views: 9825

Re: Stops processing email and queue builds up

Okay, that sounds like a mailscanner problem.

Mailscanner logs to /var/log/maillog. Were you able to see anything wrong in there?