List Info

Thread: spamtrap not working




spamtrap not working
user name
2006-11-17 14:53:31
>
> Message: 1
> Date: Thu, 16 Nov 2006 10:57:25 -0600
> From: David Morton <mortondadgrmm.net>
> Subject: Re: [Maia-users] spamtrap not working
> To: "Maia-usersrenaissoft.com List"
<maia-usersrenaissoft.com>
> Cc: F?l?p Szil?rd <silasfornax.hu>
> Message-ID:
<D20B8855-88AA-4FFB-89CE-67A38CE16399dgrmm.net>
> Content-Type: text/plain; charset=US-ASCII; delsp=yes;
format=flowed
>
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> I didn't see the whole thread this came from and that
Robert had  
> replied about this already;
>
> could you show a log of sending email to spamtrapfornax.hu
 now that  
> you have created
> spamtrapmail.fornax.hu  ?   IIRC, mail from fornax.hu
was being  
> rewritten to the mail.fornax.hu form, but you still need to
use the  
> first as the address you send to.
>
>
> On Nov 16, 2006, at 10:06 AM, David Morton wrote:
>
>   
>> > -----BEGIN PGP SIGNED MESSAGE-----
>> > Hash: SHA1
>> >
>> > silasfornax.hu wrote:
>>     
>>> >>
>>> >> Hi David,
>>> >>
>>> >> It is possible that I misunderstand
something but I used in RC5 this
>>> >> address to forward spam mails from
users to teaching our bayes and it
>>> >> worked well! I asked reply or forward
only, because I remember in  
>>> >> old RC5
>>>       
>> >
>> > That was never the intended use for a spamtrap
address.  As we've  
>> > said before,
>> > that introduces extra elements to the message
which trains your  
>> > bayes in a
>> > somewhat incorrect fashion.
>>     
>
> David Morton
> Maia Mailguard http://www.maiamailguard
.com
> mortondadgrmm.net
>
>
>
>   
Dear David and Robert,

There is the detaild log of my spamtrap processing after I
added the 
mail.fornax.hu domain.

Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06)
ESMTP::10024 
/var/lib/amavis/amavis-20061117T153152-11503: <roo
tmail.fornax.hu> -> <spamtrapmail.fornax.hu> Received: SIZE=76063 from 
cthulhu.fornax.hu ([127.0.0.1]) by local
host (cthulhu [127.0.0.1]) (amavisd-new, port 10024) with
ESMTP id 
11503-06 for <spamtrapmail.fornax.hu>; Fri, 1
7 Nov 2006 15:38:59 +0100 (CET)
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) body hash:

b7a33aed2499b19ab7052e6dd8d51320
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Checking: 
<rootmail.fornax.hu> -> <spamtrapmail.fornax.hu>
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Maia:
[connect_to_sql] 
Connecting to SQL database server
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Maia:
[connect_to_sql] 
'DBI:mysql:maia:mysql.fornet' succeeded
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Maia:
[connect] 
Database type is MySQL
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Maia: 
[read_system_config] False negative management is ENABLED
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Maia: 
[read_system_config] Virus scanning is ENABLED
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Maia: 
[read_system_config] Spam filtering is ENABLED
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Maia: 
[read_system_config] Bad header checking is ENABLED
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Maia: 
[read_system_config] Banned files checking is ENABLED
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Maia: 
[read_system_config] User autocreation is DISABLED
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Maia: 
[read_system_config] Internal authentication mechanism is
 DISABLED
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Maia: 
[read_system_config] Stats tracking is ENABLED
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Maia: 
[read_system_config] Spam traps are ENABLED
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Maia: 
[read_system_config] Mail larger than 1000000 bytes will
be PASSED
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Maia: 
[read_system_config] The system default user (.) WILL
NO
T apply to non-local recipients
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Maia: 
[read_system_config] Blowfish encryption is ENABLED
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Maia: 
[get_mysql_size_limit] MySQL max_allowed_packet size is 5
241856 bytes
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) p001 1
Content-Type: 
text/plain, size: 74592 B, name:
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Checking
for banned 
types and filenames
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) p.path: 
"P=p001,L=1,M=text/plain,T=asc"
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Using Clam

Antivirus-clamd: (built-in interface)
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Using
(Clam 
Antivirus-clamd) on dir: CONTSCAN /var/lib/amavis/a
mavis-20061117T153152-11503/partsn
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Clam
Antivirus-clamd: 
Connecting to socket  /var/run/clamav/cla
md.ctl
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Clam
Antivirus-clamd: 
Sending CONTSCAN /var/lib/amavis/amavis-2
0061117T153152-11503/partsn to UNIX socket
/var/run/clamav/clamd.ctl
Nov 17 15:38:59 cthulhu postfix/smtp[11475]: 6C4F69A52: 
to=<kazar.viktoriafornax.hu>, relay=iroda.fornet[192.168
.62.8], delay=1, status=sent (250 Message accepted for
delivery)
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) ask_av
(Clam 
Antivirus-clamd): /var/lib/amavis/amavis-20061117T
153152-11503/parts CLEAN
Nov 17 15:38:59 cthulhu amavis[11503]: (11503-06) Clam
Antivirus-clamd 
result: clean
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) spam_scan:
hits=-0.061 
tests=AWL,BAYES_05,MISSING_SUBJECT,NO_RE
LAYS,SARE_GIF_ATTACH,SARE_RMML_Stock9,TW_EG
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia: 
[recipient_is_local] Recipient spamtrapmail.fornax.hu is
 local
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia: 
[get_recipient_id] Recipient spamtrapmail.fornax.hu (id
= 199)
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia:
[store_mail] 
Stored mail item 845151 (74904 bytes)
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia: 
[recipient_is_local] Recipient spamtrapmail.fornax.hu is
 local
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia: 
[get_recipient_id] Recipient spamtrapmail.fornax.hu (id
= 199)
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia: 
[recipient_is_local] Recipient spamtrapmail.fornax.hu is
 local
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia: 
[get_recipient_id] Recipient spamtrapmail.fornax.hu (id
= 199)
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia:
[record_tests] 
SpamAssassin is using score set 2
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia:
[record_tests] 
Triggered SpamAssassin rule AWL (id = 1098
, set = 2, score = 1.000)
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia:
[record_tests] 
Linking SpamAssassin test 1098 to mail ite
m 845151
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia:
[record_tests] 
Triggered SpamAssassin rule BAYES_05 (id =
 1076, set = 2, score = -1.110)
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia:
[record_tests] 
Linking SpamAssassin test 1076 to mail ite
m 845151
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia:
[record_tests] 
Triggered SpamAssassin rule MISSING_SUBJEC
T (id = 971, set = 2, score = 2.035)
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia:
[record_tests] 
Linking SpamAssassin test 971 to mail item
 845151
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia:
[record_tests] 
Triggered SpamAssassin rule NO_RELAYS (id
= 7069, set = 2, score = -0.001)
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia:
[record_tests] 
Linking SpamAssassin test 7069 to mail ite
m 845151
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia:
[record_tests] 
Triggered SpamAssassin rule SARE_GIF_ATTAC
H (id = 2021, set = 2, score = 0.750)
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia:
[record_tests] 
Linking SpamAssassin test 2021 to mail ite
m 845151
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia:
[record_tests] 
Triggered SpamAssassin rule TW_EG (id = 13
59, set = 2, score = 0.077)
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia:
[record_tests] 
Linking SpamAssassin test 1359 to mail ite
m 845151
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia:
[record_tests] 
Assigning mail item 845151 a final score o
f -0.061
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia: 
[set_mail_status] Recording mail item 845151 as CONFIRMED
 SPAM for recipient 199
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia: 
[recipient_is_local] Recipient spamtrapmail.fornax.hu is
 local
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) SPAM-TAG, 
<rootmail.fornax.hu> -> <spamtrapmail.fornax.hu>, N
o, hits=-0.061 tagged_above=-999 required=2.3 tests=AWL,
BAYES_05, 
MISSING_SUBJECT, NO_RELAYS, SARE_GIF_ATTACH, S
ARE_RMML_Stock9, TW_EG
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) FWD via
SMTP: 
[127.0.0.1]:10025 <rootmail.fornax.hu> ->
<spamt
rapmail.fornax.hu>
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06)
mail_via_smtp: 250 
2.6.0 Ok, id=11503-06, from MTA: 250 Ok: que
ued as 4A96E9A51
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Passed, 
<rootmail.fornax.hu> -> <spamtrapmail.fornax.hu>, Mes
sage-ID: <20061117143859.0FE4B9A7Fcthulhu.fornax.hu>,
Hits: -0.061
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Passed
CLEAN, 
<rootmail.fornax.hu> -> <spamtrapmail.fornax.hu
 >, Hits: -0.061, tag=-999, tag2=2.3, kill=2.3, L/Y/0/0
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) Maia:
[disconnect] 
Disconnecting from SQL database
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) TIMING
[total 11260 
ms] - SMTP EHLO: 2 (0%), SMTP pre-MAIL: 0 (
0%), lookup_sql: 4 (0%), SMTP pre-DATA-flush: 1 (0%), SMTP
DATA: 39 
(0%), body_hash: 1 (0%), maia_connect: 4 (0%)
, maia_read_system_config: 3 (0%),
maia_get_mysql_size_limit: 1 (0%), 
lookup_sql: 2 (0%), mime_decode: 12 (0%), g
et-file-type1: 48 (0%), decompose_part: 3 (0%),
parts_decode: 0 (0%), 
AV-scan-1: 94 (1%), lookup_sql: 4 (0%), loo
kup_sql: 3 (0%), lookup_sql: 3 (0%), spam-wb-list: 1 (0%),
SA msg read: 
5 (0%), SA parse: 7 (0%), SA check: 10694
 (95%), update_cache: 1 (0%), maia_store_mail: 108 (1%), 
deal_with_mail_size: 2 (0%), maia_record_tests: 83 (1%),
 maia_set_mail_status: 7 (0%), fwd-connect: 5 (0%),
fwd-mail-from: 1 
(0%), fwd-rcpt-to: 1 (0%), write-header: 1 (
0%), fwd-data: 4 (0%), fwd-data-end: 108 (1%), fwd-rundown:
1 (0%), 
main_log_entry: 6 (0%), update_snmp: 0 (0%),
maia_cleanup: 1 (0%), maia_disconnect: 0 (0%),
unlink-1-files: 1 (0%), 
rundown: 0 (0%)
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) extra
modules loaded: 
/etc/mail/spamassassin/FuzzyOcr.pm, Crypt
/Blowfish.pm, Crypt/CBC.pm, String/Approx.pm
Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06) load: 9 %,
total idle 
398.767 s, busy 39.452 s
Nov 17 15:39:10 cthulhu postfix/smtp[11571]: 0FE4B9A7F: 
to=<spamtrapmail.fornax.hu>,
relay=127.0.0.1[127.0.0.1],
 delay=12, status=sent (250 2.6.0 Ok, id=11503-06, from MTA:
250 Ok: 
queued as 4A96E9A51)
Nov 17 15:39:10 cthulhu postfix/local[11654]: 4A96E9A51: 
to=<spamtrapmail.fornax.hu>, relay=local, delay=0,
stat
us=sent (delivered to mailbox)


SilaS

-- 
Fulop Szilard
IT support director
Fornax ZRt.

H-1123 Budapest
Taltos u. 1., Hungary

Tel: (36) 1 457-3021
Fax: (36) 1 212-0111
GSM: (36) 70 457-3021
mailto:fulop.szilardfornax.hu
http://www.fornax.hu/

_______________________________________________
Maia-users mailing list
Maia-usersrenaissoft.com
http://www.renaissoft.com/mailman/listinfo/maia-users
spamtrap not working
user name
2006-11-17 15:44:15
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


On Nov 17, 2006, at 8:53 AM, Fülöp Szilárd wrote:


> Nov 17 15:39:10 cthulhu amavis[11503]: (11503-06)
SPAM-TAG,
> <rootmail.fornax.hu> -> <spamtrapmail.fornax.hu>, N
> o, hits=-0.061 tagged_above=-999 required=2.3
tests=AWL, BAYES_05,
> MISSING_SUBJECT, NO_RELAYS, SARE_GIF_ATTACH, S
> ARE_RMML_Stock9, TW_EG

I was able to duplicate this on my server.   If I leave the
initial  
settings alone and select spamtrap, it lets low scoring
items through.

Looks like in addition to marking as a spamtrap, it needs to
have the  
levels set low...  All of these settings need to be set:

Add X-Spam: Headers when Score is >= 	-999
Consider mail 'Spam' when Score is >= 	 -999
Quarantine Spam when Score is >= 	-999

Robert, should this be set automatically when the spamtrap
is  
selected, or is there something missing in amavisd-maia?



David Morton
Maia Mailguard http://www.maiamailguard
.com
mortondadgrmm.net



-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (Darwin)

iD8DBQFFXdjPUy30ODPkzl0RAq2fAJ0Swkkppvp24DWQrmyNIZZ5kit+IACg
pxHf
hL/IhediFxRwgThB8+qHMkc=
=ir35
-----END PGP SIGNATURE-----
_______________________________________________
Maia-users mailing list
Maia-usersrenaissoft.com
http://www.renaissoft.com/mailman/listinfo/maia-users
spamtrap not working
user name
2006-11-17 16:21:46
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

David Morton wrote:

> I was able to duplicate this on my server.   If I leave
the initial
> settings alone and select spamtrap, it lets low scoring
items through.
> 
> Looks like in addition to marking as a spamtrap, it
needs to have the
> levels set low...  All of these settings need to be
set:
> 
> Add X-Spam: Headers when Score is >= 	-999
> Consider mail 'Spam' when Score is >= 	 -999
> Quarantine Spam when Score is >= 	-999
> 
> Robert, should this be set automatically when the
spamtrap is
> selected, or is there something missing in
amavisd-maia?

If the Maia user account is marked as a spamtrap, everything
it receives
is supposed to get marked as confirmed spam (type 'C' in the
database).
 There's no need for any spam checking (or virus checking,
or bad header
checking, or banned attachment checking) at all.  Just the
fact that
mail was /received/ at a spamtrap address is enough to label
it
"confirmed spam"--that's the nature of a spamtrap.

The fact that a spam check is being performed at all
suggests that
either the Maia user in question doesn't have the spamtrap
flag set, or
that something spamtrap-related was broken at some point in
more recent
versions of amavisd-maia.

- --
Robert LeBlanc <rjlrenaissoft.com>
Renaissoft, Inc.
Maia Mailguard <http://www.maiamail
guard.com/>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iD8DBQFFXeGaGmqOER2NHewRAgc9AKCb6R1AnUdAQ/RBBJmXNB51/TgYBACf
f6N0
nCgZ7tI8LAYQLVQSwOPhzds=
=ybQL
-----END PGP SIGNATURE-----
_______________________________________________
Maia-users mailing list
Maia-usersrenaissoft.com
http://www.renaissoft.com/mailman/listinfo/maia-users
[1-3]

about | contact  Other archives ( Real Estate discussion Medical topics )