qmail-scanner-general Mailing List for Qmail-Scanner: Content/Anti-virus Scanne
AV/content filter for Qmail
Brought to you by:
jhaar
You can subscribe to this list here.
2000 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
(28) |
Sep
(50) |
Oct
(17) |
Nov
(43) |
Dec
(31) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2001 |
Jan
(46) |
Feb
(54) |
Mar
(68) |
Apr
(28) |
May
(29) |
Jun
(16) |
Jul
(80) |
Aug
(129) |
Sep
(153) |
Oct
(96) |
Nov
(87) |
Dec
(143) |
2002 |
Jan
(124) |
Feb
(154) |
Mar
(101) |
Apr
(124) |
May
(273) |
Jun
(182) |
Jul
(217) |
Aug
(233) |
Sep
(131) |
Oct
(142) |
Nov
(174) |
Dec
(115) |
2003 |
Jan
(142) |
Feb
(143) |
Mar
(138) |
Apr
(131) |
May
(156) |
Jun
(154) |
Jul
(80) |
Aug
(269) |
Sep
(371) |
Oct
(217) |
Nov
(243) |
Dec
(300) |
2004 |
Jan
(234) |
Feb
(302) |
Mar
(433) |
Apr
(227) |
May
(286) |
Jun
(239) |
Jul
(134) |
Aug
(146) |
Sep
(113) |
Oct
(121) |
Nov
(139) |
Dec
(115) |
2005 |
Jan
(80) |
Feb
(111) |
Mar
(51) |
Apr
(47) |
May
(48) |
Jun
(98) |
Jul
(56) |
Aug
(34) |
Sep
(42) |
Oct
(31) |
Nov
(40) |
Dec
(26) |
2006 |
Jan
(39) |
Feb
(45) |
Mar
(13) |
Apr
(45) |
May
(25) |
Jun
(34) |
Jul
(31) |
Aug
(25) |
Sep
(23) |
Oct
(17) |
Nov
(37) |
Dec
(29) |
2007 |
Jan
(42) |
Feb
(25) |
Mar
(9) |
Apr
(12) |
May
(36) |
Jun
(11) |
Jul
(9) |
Aug
(11) |
Sep
(24) |
Oct
(19) |
Nov
(27) |
Dec
(2) |
2008 |
Jan
(14) |
Feb
(10) |
Mar
(11) |
Apr
(17) |
May
(11) |
Jun
(27) |
Jul
(4) |
Aug
(2) |
Sep
(5) |
Oct
(17) |
Nov
(12) |
Dec
(7) |
2009 |
Jan
(12) |
Feb
(8) |
Mar
(4) |
Apr
(4) |
May
(11) |
Jun
(5) |
Jul
(7) |
Aug
|
Sep
(2) |
Oct
(6) |
Nov
(3) |
Dec
|
2010 |
Jan
(5) |
Feb
(12) |
Mar
(1) |
Apr
|
May
|
Jun
(5) |
Jul
|
Aug
(2) |
Sep
(2) |
Oct
(1) |
Nov
(2) |
Dec
|
2011 |
Jan
(4) |
Feb
|
Mar
(23) |
Apr
|
May
(2) |
Jun
|
Jul
|
Aug
(10) |
Sep
(7) |
Oct
(1) |
Nov
(4) |
Dec
|
2012 |
Jan
|
Feb
(11) |
Mar
(6) |
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
|
Oct
|
Nov
(11) |
Dec
|
2013 |
Jan
|
Feb
|
Mar
(9) |
Apr
(4) |
May
(9) |
Jun
(5) |
Jul
|
Aug
|
Sep
(13) |
Oct
|
Nov
|
Dec
|
2015 |
Jan
|
Feb
(9) |
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(3) |
Dec
|
2016 |
Jan
(3) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(7) |
Oct
|
Nov
|
Dec
(2) |
2017 |
Jan
|
Feb
|
Mar
(4) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
(4) |
2021 |
Jan
(8) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
From: Jason H. <jas...@tr...> - 2021-01-21 22:26:40
|
That might be a good idea :-) On Fri, Jan 22, 2021 at 11:22 AM Robert A Wooldridge < bob...@ed...> wrote: > On 1/21/21 2:55 PM, Jason Haar wrote: > > I've seen the same segfault on Fedora - really implies reformime is > > broken - probably unmaintained (at least at the distro level). Try > > using ripmime instead - that is also supported (see "./configure --help") > Excellent! Got it working now, thanks Jason! Perhaps you could release > a new version with fixes for tolower and warning about reformime? > > -- > Bob Wooldridge EDM Incorporated > > > _______________________________________________ > Qmail-scanner-general mailing list > Qma...@li... > https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general > -- Cheers Jason Haar Information Security Manager, Trimble Navigation Ltd. Phone: +1 408 481 8171 PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1 |
From: Robert A W. <bob...@ed...> - 2021-01-21 22:22:51
|
On 1/21/21 2:55 PM, Jason Haar wrote: > I've seen the same segfault on Fedora - really implies reformime is > broken - probably unmaintained (at least at the distro level). Try > using ripmime instead - that is also supported (see "./configure --help") Excellent! Got it working now, thanks Jason! Perhaps you could release a new version with fixes for tolower and warning about reformime? -- Bob Wooldridge EDM Incorporated |
From: Jason H. <jas...@tr...> - 2021-01-21 21:19:09
|
I've seen the same segfault on Fedora - really implies reformime is broken - probably unmaintained (at least at the distro level). Try using ripmime instead - that is also supported (see "./configure --help") On Fri, Jan 22, 2021 at 8:56 AM Robert A Wooldridge < bob...@ed...> wrote: > When you install maildrop 3.x it needs the pcre library. I cannot seem to > find a Debian package for that. Do you know of one or did you install pcre > from source? > > > On 1/20/21 12:06 PM, Kimmo Sinkko wrote: > > My message earlier this year did not make it to the mailing list, but it > gives some clues: > > *Lähettäjä: *Kimmo Sinkko <kim...@me...> > *Aihe: Debian 10 (buster) and qmail-scanner-queue.pl > <http://qmail-scanner-queue.pl>* > *Päivämäärä: *28. helmikuuta 2020 klo 13.56.52 UTC+2 > *Vastaanottaja: *qma...@li... > > Hi! > > Not sure if there are too many users for qmail and qmail-scanner-queue > anymore, but I am. I run into trouble when upgrading from Debian 9 > (Stretch) to Debian 10 (Buster). Just wanted to let you know that these > were the problems and some workarounds: > > 1) Since perl5.26 POSIX::tolower is depricated (removed) > > Possible fix is to use perl lc() function instead > > Simply substitute 25 occurances of tolower with lc. > > 2) Reformime -x broken with the Buster maildrop version > (maildrop 2.9.3-2+b1) > > Reformime will segfault with command line option -x without -s. > > Possible fix is to user latest maildrop version 3.0.0. > > Note that maildrop installation from the source goes into /usr/local/bin, > so remember to update your $mimeunpacker_binary variable > > Cheers, > > Kimmo Sinkko > ki...@si... > > Robert A Wooldridge <bob...@ed...> kirjoitti 20.1.2021 > kello 18.52: > > On 1/20/21 1:45 AM, Kimmo Sinkko wrote: > > If I remember correctly, tolower() is deprecated as of Perl 5.26.0. Use > function lc() instead: > > Example: > > $qsmsgid=tolower("$V_HEADER-message-id"); > => > $qsmsgid=lc("$V_HEADER-message-id"); > > Ok, got that to work but now I'm getting a strange message when it begins > scanning: > > error_condition: X-Qmail-Scanner-2.11: d_m: output spotted from > /usr/bin/reformime -x/var/spool/qscan/tmp/mail2161116140158812663/ > (Segmentation fault > ) - that shouldn't happen! > > Any ideas on what's causing this? I have plenty of disc space. > > > > -- > Bob Wooldridge EDM Incorporated > _______________________________________________ > Qmail-scanner-general mailing list > Qma...@li... > https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general > > > -- > Bob Wooldridge EDM Incorporated > > _______________________________________________ > Qmail-scanner-general mailing list > Qma...@li... > https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general > -- Cheers Jason Haar Information Security Manager, Trimble Navigation Ltd. Phone: +1 408 481 8171 PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1 |
From: Robert A W. <bob...@ed...> - 2021-01-21 21:19:06
|
On 1/21/21 2:28 PM, Kimmo Sinkko wrote: > Hmm. I don't remember installing pcre separately. I did install newer > maildrop from source. > > On my Debian Buster I seem to have installed: > > libpcre16-3/stable,now 2:8.39-12 amd64 [installed,automatic] > libpcre2-8-0/stable,now 10.32-5 amd64 [installed,automatic] > libpcre3-dev/stable,now 2:8.39-12 amd64 [installed] > libpcre32-3/stable,now 2:8.39-12 amd64 [installed,automatic] > libpcre3/stable,now 2:8.39-12 amd64 [installed,automatic] > libpcrecpp0v5/stable,now 2:8.39-12 amd64 [installed,automatic] No luck. I have all of those installed already. I also tried install the pcre source from www.pcre.org but maildrop can still not find pcre.h. -- Bob Wooldridge EDM Incorporated |
From: Robert A W. <bob...@ed...> - 2021-01-21 19:56:01
|
When you install maildrop 3.x it needs the pcre library. I cannot seem to find a Debian package for that. Do you know of one or did you install pcre from source? On 1/20/21 12:06 PM, Kimmo Sinkko wrote: > My message earlier this year did not make it to the mailing list, but > it gives some clues: > > *Lähettäjä: *Kimmo Sinkko <kim...@me... > <mailto:kim...@me...>> > *Aihe: Debian 10 (buster) and qmail-scanner-queue.pl* > *Päivämäärä: *28. helmikuuta 2020 klo 13.56.52 UTC+2 > *Vastaanottaja: *qma...@li... > <mailto:qma...@li...> > > Hi! > > Not sure if there are too many users for qmail and qmail-scanner-queue > anymore, but I am. I run into trouble when upgrading from Debian 9 > (Stretch) to Debian 10 (Buster). Just wanted to let you know that > these were the problems and some workarounds: > > 1) Since perl5.26 POSIX::tolower is depricated (removed) > > Possible fix is to use perl lc() function instead > > Simply substitute 25 occurances of tolower with lc. > > 2) Reformime -x broken with the Buster maildrop version > (maildrop 2.9.3-2+b1) > > Reformime will segfault with command line option -x without -s. > > Possible fix is to user latest maildrop version 3.0.0. > > Note that maildrop installation from the source goes into > /usr/local/bin, so remember to update your $mimeunpacker_binary variable > > Cheers, > > Kimmo Sinkko > ki...@si... <mailto:ki...@si...> > >> Robert A Wooldridge <bob...@ed... >> <mailto:bob...@ed...>> kirjoitti 20.1.2021 kello 18.52: >> >> On 1/20/21 1:45 AM, Kimmo Sinkko wrote: >>> If I remember correctly, tolower() is deprecated as of Perl 5.26.0. >>> Use function lc() instead: >>> >>> Example: >>> >>> $qsmsgid=tolower("$V_HEADER-message-id"); >>> => >>> $qsmsgid=lc("$V_HEADER-message-id"); >> >> Ok, got that to work but now I'm getting a strange message when it >> begins scanning: >> >> error_condition: X-Qmail-Scanner-2.11: d_m: output spotted from >> /usr/bin/reformime -x/var/spool/qscan/tmp/mail2161116140158812663/ >> (Segmentation fault >> ) - that shouldn't happen! >> >> Any ideas on what's causing this? I have plenty of disc space. >> >> >> >> -- >> Bob Wooldridge EDM Incorporated >> _______________________________________________ >> Qmail-scanner-general mailing list >> Qma...@li... >> <mailto:Qma...@li...> >> https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general > > -- > Bob Wooldridge EDM Incorporated |
From: Adam G. <mai...@we...> - 2021-01-21 02:32:20
|
On 21/1/21 03:52, Robert A Wooldridge wrote: > On 1/20/21 1:45 AM, Kimmo Sinkko wrote: >> If I remember correctly, tolower() is deprecated as of Perl 5.26.0. >> Use function lc() instead: >> >> Example: >> >> $qsmsgid=tolower("$V_HEADER-message-id"); >> => >> $qsmsgid=lc("$V_HEADER-message-id"); > > Ok, got that to work but now I'm getting a strange message when it > begins scanning: > > error_condition: X-Qmail-Scanner-2.11: d_m: output spotted from > /usr/bin/reformime -x/var/spool/qscan/tmp/mail2161116140158812663/ > (Segmentation fault > ) - that shouldn't happen! > > Any ideas on what's causing this? I have plenty of disc space. > How much memory are you allowing QS to use? You might need to increase this. Regards, Adam |
From: Robert A W. <bob...@ed...> - 2021-01-20 16:52:54
|
On 1/20/21 1:45 AM, Kimmo Sinkko wrote: > If I remember correctly, tolower() is deprecated as of Perl 5.26.0. > Use function lc() instead: > > Example: > > $qsmsgid=tolower("$V_HEADER-message-id"); > => > $qsmsgid=lc("$V_HEADER-message-id"); Ok, got that to work but now I'm getting a strange message when it begins scanning: error_condition: X-Qmail-Scanner-2.11: d_m: output spotted from /usr/bin/reformime -x/var/spool/qscan/tmp/mail2161116140158812663/ (Segmentation fault ) - that shouldn't happen! Any ideas on what's causing this? I have plenty of disc space. -- Bob Wooldridge EDM Incorporated |
From: Robert A W. <bob...@ed...> - 2021-01-19 22:46:12
|
I'm running qmail-scanner on Debian Buster and using the sqmail system provided by Erwin Hoffmann (https://www.fehcom.de/sqmail/sqmail.html). I have been using qmail-scanner for many years on the John Simpson patch set. I'm trying to get familiar with sqmail right now. I have compiled the wraper script offered in contrib and set up QMAILQUEUE to use qmail-scanner in the run script. When qmail-scanner is called I get the following error: Undefined subroutine &main::tolower called at /var/qmail/bin/qmail-scanner-queue.pl line 90. This error also shows up when running the test script supplied in contrib. Any ideas on what might be causing this? -- Bob Wooldridge EDM Incorporated |
From: kip p. <ki...@ya...> - 2017-12-14 06:56:33
|
Hi Jason, at Line 514 of qmail-scanner-queue.pl after: if ($headers{'MAILFROM'} eq "" || $headers{'subject'} =~ /Returned mail:|Mail Transaction Failed/) { &debug("This is a bounce message - better assume there's an attachment in it",5); $plain_text_msg=0; } I have added the following code which seems to do the trick by setting $plain_text_msg=1. I hope it doesn't break anything though. if ($headers{'MAILFROM'} eq 'ki...@ya...') { &debug("This sender is excluded from AV Scanning"); $plain_text_msg=1; } Στις 12:05 π.μ. Πέμπτη, 14 Δεκεμβρίου 2017, ο/η Jason Haar <jas...@tr...> έγραψε: That won't whitelist for AV: AV is always on (assuming it's enabled of course). Qmail-Scanner itself skips SpamAssassin via IP address filters - I can't think of any way of doing it per email address On Thu, Dec 14, 2017 at 5:49 AM, Bobber <bo...@kc...> wrote: -------- Original Message -------- Subject: [Qmail-scanner-general] Qmail-scanner Whitelist From: kip papa via Qmail-scanner-general <qmail-scanner-general@lists. sourceforge.net> To: qmail-scanner-general@lists. sourceforge.net <qmail-scanner-general@lists. sourceforge.net> Date: 12/13/2017 07:50 AM Hi, is there a way to whitelist a specific email address or domain in Qmail-scanner in order to bypass AV Scanning and Spamassassin ? Thanks This can be done through spamassassin: https://wiki.apache.org/ spamassassin/ManualWhitelist -- Bob Wooldridge Blog: http://kc0dxf.net/blog/ ------------------------------ ------------------------------ ------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot ______________________________ _________________ Qmail-scanner-general mailing list Qmail-scanner-general@lists. sourceforge.net https://lists.sourceforge.net/ lists/listinfo/qmail-scanner- general -- Cheers Jason HaarInformation Security Manager, Trimble Navigation Ltd.Phone: +1 408 481 8171PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot_______________________________________________ Qmail-scanner-general mailing list Qma...@li... https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general |
From: Jason H. <jas...@tr...> - 2017-12-13 22:05:41
|
That won't whitelist for AV: AV is always on (assuming it's enabled of course). Qmail-Scanner itself skips SpamAssassin via IP address filters - I can't think of any way of doing it per email address On Thu, Dec 14, 2017 at 5:49 AM, Bobber <bo...@kc...> wrote: > -------- Original Message -------- > Subject: [Qmail-scanner-general] Qmail-scanner Whitelist > From: kip papa via Qmail-scanner-general <qmail-scanner-general@lists. > sourceforge.net> <qma...@li...> > To: qma...@li... > <qma...@li...> > <qma...@li...> > Date: 12/13/2017 07:50 AM > > Hi, is there a way to whitelist a specific email address or domain in > Qmail-scanner in order to bypass AV Scanning and Spamassassin ? Thanks > > This can be done through spamassassin: > https://wiki.apache.org/spamassassin/ManualWhitelist > > -- > *Bob Wooldridge* > Blog: http://kc0dxf.net/blog/ > > ------------------------------------------------------------ > ------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > _______________________________________________ > Qmail-scanner-general mailing list > Qma...@li... > https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general > > -- Cheers Jason Haar Information Security Manager, Trimble Navigation Ltd. Phone: +1 408 481 8171 PGP Fingerprint: 7A2E 0407 C9A6 CAF6 2B9F 8422 C063 5EBB FE1D 66D1 |
From: Bobber <bo...@kc...> - 2017-12-13 17:15:55
|
-------- Original Message -------- Subject: [Qmail-scanner-general] Qmail-scanner Whitelist From: kip papa via Qmail-scanner-general <qma...@li...> To: qma...@li... <qma...@li...> Date: 12/13/2017 07:50 AM > Hi, is there a way to whitelist a specific email address or domain in > Qmail-scanner in order to bypass AV Scanning and Spamassassin ? Thanks This can be done through spamassassin: https://wiki.apache.org/spamassassin/ManualWhitelist -- *Bob Wooldridge* Blog: http://kc0dxf.net/blog/ |
From: kip p. <ki...@ya...> - 2017-12-13 13:50:25
|
Hi, is there a way to whitelist a specific email address or domain in Qmail-scanner in order to bypass AV Scanning and Spamassassin ? Thanks |
From: Rejaine M. <re...@bh...> - 2017-03-15 12:23:36
|
I agree with your posting .. however most of my users relay me anyway any spam received to analyze (they are in doubt about how to proceed and insecure when they receive some malware) II'd rather not take the risk of leaving this analysis if done by them. :) But it might be a good idea to use sa-reject to return the question to the sender (I'll check this out next time) Em 15-03-2017 05:42, John Puttergill escreveu: > > As a general point I think that a score of 5.1 to trigger quarantine a > little low ... it means you are going to have to monitor that > quarantine account very actively. > > I much prefer using sa-reject which places the onus on the sender of > the e-mail ... but ! use a score of 7.7 as my trigger point. > > When you quarantine neither the sender nor the recipient is aware that > this has taken place. > > By using qmail-scanner with settings per domain feature you could > deliver the mails between say 5.1 and 7.7 to a specific Spam folder in > the recipients Maildir ... this relieves you of having to monitor your > quarantine events and any mails that are not delivered are rejected > during the smtp ... so the sender is aware of the delivery failure ... > and if the mail is genuine can choose some other method of communicating. > > > > On 14/03/2017 22:23, Rejaine Monteiro wrote: >> >> >> The problem was the sa_quarantine_over parameter .. I think I was >> interpreting it incorrectly .. as in my case I want for everything >> that spam classifies above 5 in quarantine, then the value should be >> 0.1 and not 5, as was before. >> because this line: >> >> if ($sa_quarantine_over > 0 && ($sa_score - $sa_required_hits) >= >> $sa_quarantine_over) { >> &debug("SA: seriously spammy - quarantine and don't deliver"); >> >> thanks!! >> >> Em 14-03-2017 18:32, Rejaine Monteiro escreveu: >>> >>> >>> qmail-scanner seems crazy here... >>> >>> >>> Tue, 14 Mar 2017 17:40:00 BRT:3511: qmail-scanner: >>> Clear:RC:0(194.67.222.61):SA:1(7.7/5.0): 1.740696 9914 >>> tle...@pa... us...@my... >>> Instantly_erect,_instant_respect >>> <qyr1-q3qRwMXNPUJCgCOwtrdjcUswVS9bDzzxpXOejs.nsuEl60B9RNjQ0A-GTBbeE2CgXdDS2525pG >>> .... >>> >>> >>> Why "Clear" if SA score is 7.7 ?? Why not going to quaratine ( my >>> $sa_quarantine_over='5'; ) >>> >>> >>> qmail-queue.log is: >>> >>> >>> Tue, 14 Mar 2017 17:40:00 BRT:3511: SA: yup, this smells like SPAM >>> (score=7.7 required=5.0) >>> Tue, 14 Mar 2017 17:40:00 BRT:3511: spamassassin: finished scan of >>> dir "/var/spool/qscan/tmp/server14895239985893511" in 1.698798 secs >>> Tue, 14 Mar 2017 17:40:00 BRT:3511: scanloop: finished scan of >>> "/var/spool/qscan/tmp/server14895239985893511"... >>> Tue, 14 Mar 2017 17:40:00 BRT:3511: ini_sc: scanning message took >>> 1.735613 seconds >>> Tue, 14 Mar 2017 17:40:00 BRT:3511: q_r: fork off child into >>> /var/qmail/bin/qmail-queue... >>> Tue, 14 Mar 2017 17:40:00 BRT:3525: q_r: xstatus=0 >>> Tue, 14 Mar 2017 17:40:00 BRT:3511: qmail-scanner: >>> Clear:RC:0(194.67.222.61):SA:1(7.7/5.0): 1.740696 9914 >>> tle...@pa... us...@my... >>> Instantly_erect,_instant_respect >>> <qyr1-q3qRwMXNPUJCgCOwtrdjcUswVS9bDzzxpXOejs.nsuEl60B9RNjQ0A-GTBbeE2CgXdDS2525pG >>> 1489523999.3513-0.server:3508 1489523999.3513-1.server:5515 >>> Tue, 14 Mar 2017 17:40:00 BRT:3511: cleanup: /usr/bin/rm -rf >>> /var/spool/qscan/tmp/server14895239985893511/ >>> /var/spool/qscan/working/new/server14895239985893511 >>> Tue, 14 Mar 2017 17:40:00 BRT:3511: all finished. Total of 1.783561 secs >>> >>> I have several cases of messages with score by SA above 5 that >>> should be quarantined, but that are being delivered normally .. >>> >>> I'm going crazy here. Any idea? >>> >>> >>> ------------------------------------------------------------------------------ >>> Check out the vibrant tech community on one of the world's most >>> engaging tech sites, Slashdot.org!http://sdm.link/slashdot >>> >>> >>> _______________________________________________ >>> Qmail-scanner-general mailing list >>> Qma...@li... >>> https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general >> >> -- >> Rejaine da Silveira Monteiro >> Suporte-TI >> Tel: (31) 2102-8854 >> Jamef Encomendas Urgentes - Matriz - Belo Horizonte/MG >> www.jamef.com.br >> >> >> ------------------------------------------------------------------------------ >> Check out the vibrant tech community on one of the world's most >> engaging tech sites, Slashdot.org!http://sdm.link/slashdot >> >> >> _______________________________________________ >> Qmail-scanner-general mailing list >> Qma...@li... >> https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general > -- Rejaine da Silveira Monteiro Suporte-TI Tel: (31) 2102-8854 Jamef Encomendas Urgentes - Matriz - Belo Horizonte/MG www.jamef.com.br |
From: John P. <jo...@it...> - 2017-03-15 09:09:42
|
As a general point I think that a score of 5.1 to trigger quarantine a little low ... it means you are going to have to monitor that quarantine account very actively. I much prefer using sa-reject which places the onus on the sender of the e-mail ... but ! use a score of 7.7 as my trigger point. When you quarantine neither the sender nor the recipient is aware that this has taken place. By using qmail-scanner with settings per domain feature you could deliver the mails between say 5.1 and 7.7 to a specific Spam folder in the recipients Maildir ... this relieves you of having to monitor your quarantine events and any mails that are not delivered are rejected during the smtp ... so the sender is aware of the delivery failure ... and if the mail is genuine can choose some other method of communicating. On 14/03/2017 22:23, Rejaine Monteiro wrote: > > > The problem was the sa_quarantine_over parameter .. I think I was > interpreting it incorrectly .. as in my case I want for everything > that spam classifies above 5 in quarantine, then the value should be > 0.1 and not 5, as was before. > because this line: > > if ($sa_quarantine_over > 0 && ($sa_score - $sa_required_hits) >= > $sa_quarantine_over) { > &debug("SA: seriously spammy - quarantine and don't deliver"); > > thanks!! > > Em 14-03-2017 18:32, Rejaine Monteiro escreveu: >> >> >> qmail-scanner seems crazy here... >> >> >> Tue, 14 Mar 2017 17:40:00 BRT:3511: qmail-scanner: >> Clear:RC:0(194.67.222.61):SA:1(7.7/5.0): 1.740696 9914 >> tle...@pa... us...@my... >> Instantly_erect,_instant_respect >> <qyr1-q3qRwMXNPUJCgCOwtrdjcUswVS9bDzzxpXOejs.nsuEl60B9RNjQ0A-GTBbeE2CgXdDS2525pG >> .... >> >> >> Why "Clear" if SA score is 7.7 ?? Why not going to quaratine ( my >> $sa_quarantine_over='5'; ) >> >> >> qmail-queue.log is: >> >> >> Tue, 14 Mar 2017 17:40:00 BRT:3511: SA: yup, this smells like SPAM >> (score=7.7 required=5.0) >> Tue, 14 Mar 2017 17:40:00 BRT:3511: spamassassin: finished scan of >> dir "/var/spool/qscan/tmp/server14895239985893511" in 1.698798 secs >> Tue, 14 Mar 2017 17:40:00 BRT:3511: scanloop: finished scan of >> "/var/spool/qscan/tmp/server14895239985893511"... >> Tue, 14 Mar 2017 17:40:00 BRT:3511: ini_sc: scanning message took >> 1.735613 seconds >> Tue, 14 Mar 2017 17:40:00 BRT:3511: q_r: fork off child into >> /var/qmail/bin/qmail-queue... >> Tue, 14 Mar 2017 17:40:00 BRT:3525: q_r: xstatus=0 >> Tue, 14 Mar 2017 17:40:00 BRT:3511: qmail-scanner: >> Clear:RC:0(194.67.222.61):SA:1(7.7/5.0): 1.740696 9914 >> tle...@pa... us...@my... >> Instantly_erect,_instant_respect >> <qyr1-q3qRwMXNPUJCgCOwtrdjcUswVS9bDzzxpXOejs.nsuEl60B9RNjQ0A-GTBbeE2CgXdDS2525pG >> 1489523999.3513-0.server:3508 1489523999.3513-1.server:5515 >> Tue, 14 Mar 2017 17:40:00 BRT:3511: cleanup: /usr/bin/rm -rf >> /var/spool/qscan/tmp/server14895239985893511/ >> /var/spool/qscan/working/new/server14895239985893511 >> Tue, 14 Mar 2017 17:40:00 BRT:3511: all finished. Total of 1.783561 secs >> >> I have several cases of messages with score by SA above 5 that should >> be quarantined, but that are being delivered normally .. >> >> I'm going crazy here. Any idea? >> >> >> ------------------------------------------------------------------------------ >> Check out the vibrant tech community on one of the world's most >> engaging tech sites, Slashdot.org!http://sdm.link/slashdot >> >> >> _______________________________________________ >> Qmail-scanner-general mailing list >> Qma...@li... >> https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general > > -- > Rejaine da Silveira Monteiro > Suporte-TI > Tel: (31) 2102-8854 > Jamef Encomendas Urgentes - Matriz - Belo Horizonte/MG > www.jamef.com.br > > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > > > _______________________________________________ > Qmail-scanner-general mailing list > Qma...@li... > https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general |
From: Rejaine M. <re...@bh...> - 2017-03-14 22:21:17
|
The problem was the sa_quarantine_over parameter .. I think I was interpreting it incorrectly .. as in my case I want for everything that spam classifies above 5 in quarantine, then the value should be 0.1 and not 5, as was before. because this line: if ($sa_quarantine_over > 0 && ($sa_score - $sa_required_hits) >= $sa_quarantine_over) { &debug("SA: seriously spammy - quarantine and don't deliver"); thanks!! Em 14-03-2017 18:32, Rejaine Monteiro escreveu: > > > qmail-scanner seems crazy here... > > > Tue, 14 Mar 2017 17:40:00 BRT:3511: qmail-scanner: > Clear:RC:0(194.67.222.61):SA:1(7.7/5.0): 1.740696 9914 > tle...@pa... us...@my... > Instantly_erect,_instant_respect > <qyr1-q3qRwMXNPUJCgCOwtrdjcUswVS9bDzzxpXOejs.nsuEl60B9RNjQ0A-GTBbeE2CgXdDS2525pG > .... > > > Why "Clear" if SA score is 7.7 ?? Why not going to quaratine ( my > $sa_quarantine_over='5'; ) > > > qmail-queue.log is: > > > Tue, 14 Mar 2017 17:40:00 BRT:3511: SA: yup, this smells like SPAM > (score=7.7 required=5.0) > Tue, 14 Mar 2017 17:40:00 BRT:3511: spamassassin: finished scan of dir > "/var/spool/qscan/tmp/server14895239985893511" in 1.698798 secs > Tue, 14 Mar 2017 17:40:00 BRT:3511: scanloop: finished scan of > "/var/spool/qscan/tmp/server14895239985893511"... > Tue, 14 Mar 2017 17:40:00 BRT:3511: ini_sc: scanning message took > 1.735613 seconds > Tue, 14 Mar 2017 17:40:00 BRT:3511: q_r: fork off child into > /var/qmail/bin/qmail-queue... > Tue, 14 Mar 2017 17:40:00 BRT:3525: q_r: xstatus=0 > Tue, 14 Mar 2017 17:40:00 BRT:3511: qmail-scanner: > Clear:RC:0(194.67.222.61):SA:1(7.7/5.0): 1.740696 9914 > tle...@pa... us...@my... > Instantly_erect,_instant_respect > <qyr1-q3qRwMXNPUJCgCOwtrdjcUswVS9bDzzxpXOejs.nsuEl60B9RNjQ0A-GTBbeE2CgXdDS2525pG > 1489523999.3513-0.server:3508 1489523999.3513-1.server:5515 > Tue, 14 Mar 2017 17:40:00 BRT:3511: cleanup: /usr/bin/rm -rf > /var/spool/qscan/tmp/server14895239985893511/ > /var/spool/qscan/working/new/server14895239985893511 > Tue, 14 Mar 2017 17:40:00 BRT:3511: all finished. Total of 1.783561 secs > > I have several cases of messages with score by SA above 5 that should > be quarantined, but that are being delivered normally .. > > I'm going crazy here. Any idea? > > > ------------------------------------------------------------------------------ > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > > > _______________________________________________ > Qmail-scanner-general mailing list > Qma...@li... > https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general -- Rejaine da Silveira Monteiro Suporte-TI Tel: (31) 2102-8854 Jamef Encomendas Urgentes - Matriz - Belo Horizonte/MG www.jamef.com.br |
From: Rejaine M. <re...@bh...> - 2017-03-14 21:57:29
|
qmail-scanner seems crazy here... Tue, 14 Mar 2017 17:40:00 BRT:3511: qmail-scanner: Clear:RC:0(194.67.222.61):SA:1(7.7/5.0): 1.740696 9914 tle...@pa... us...@my... Instantly_erect,_instant_respect <qyr1-q3qRwMXNPUJCgCOwtrdjcUswVS9bDzzxpXOejs.nsuEl60B9RNjQ0A-GTBbeE2CgXdDS2525pG .... Why "Clear" if SA score is 7.7 ?? Why not going to quaratine ( my $sa_quarantine_over='5'; ) qmail-queue.log is: Tue, 14 Mar 2017 17:40:00 BRT:3511: SA: yup, this smells like SPAM (score=7.7 required=5.0) Tue, 14 Mar 2017 17:40:00 BRT:3511: spamassassin: finished scan of dir "/var/spool/qscan/tmp/server14895239985893511" in 1.698798 secs Tue, 14 Mar 2017 17:40:00 BRT:3511: scanloop: finished scan of "/var/spool/qscan/tmp/server14895239985893511"... Tue, 14 Mar 2017 17:40:00 BRT:3511: ini_sc: scanning message took 1.735613 seconds Tue, 14 Mar 2017 17:40:00 BRT:3511: q_r: fork off child into /var/qmail/bin/qmail-queue... Tue, 14 Mar 2017 17:40:00 BRT:3525: q_r: xstatus=0 Tue, 14 Mar 2017 17:40:00 BRT:3511: qmail-scanner: Clear:RC:0(194.67.222.61):SA:1(7.7/5.0): 1.740696 9914 tle...@pa... us...@my... Instantly_erect,_instant_respect <qyr1-q3qRwMXNPUJCgCOwtrdjcUswVS9bDzzxpXOejs.nsuEl60B9RNjQ0A-GTBbeE2CgXdDS2525pG 1489523999.3513-0.server:3508 1489523999.3513-1.server:5515 Tue, 14 Mar 2017 17:40:00 BRT:3511: cleanup: /usr/bin/rm -rf /var/spool/qscan/tmp/server14895239985893511/ /var/spool/qscan/working/new/server14895239985893511 Tue, 14 Mar 2017 17:40:00 BRT:3511: all finished. Total of 1.783561 secs I have several cases of messages with score by SA above 5 that should be quarantined, but that are being delivered normally .. I'm going crazy here. Any idea? |
From: Salvatore T. <to...@pu...> - 2016-12-07 16:42:25
|
Hi Have you check the logs to verify if the message pass through qmail-scanner? Do you know how Roundcube sends the messages, through sendmail, qmail-inject...? You should need to set QMAILQUEUE variable for qmail-scanner in the process that Roudcube uses to send emails to ensure that they pass through qmail-scanner. For example with Sqwebmail is done like this: ---------------------------- more /usr/sqwebmail/share/sqwebmail/sendit.sh #!/bin/sh # # $1 will contain the return (or bounce) address for this mailboxid, as # specified by auth.c # # $2 will contain the sqwebmail mailboxid of the sender (note that we're # executing under whatever id auth.c sets for this mailboxid). Furthermore, # $REMOTE_ADDR will contain the IP address where the client is coming from # (the rest of the CGI vars are available too). # QMAILQUEUE="/var/qmail/bin/qmail-scanner-queue.pl" export QMAILQUEUE # If you want to run spamassassin #QS_SPAMASSASSIN="on" #export QS_SPAMASSASSIN QMAILUSER="$1" export QMAILUSER exec /var/qmail/bin/qmail-inject -hf "$1" ---------------------------- Kind regards ST At 23:03 +0000 5-12-2016, Petre wrote: >Hi, > >I successfully use qmail and Qmail-Scanner, with clamav and spamassassin. >I use courier-authlib, courier-imap and users are kept in ldap. >I tried a few days ago roundcube as a webmail application and >observed a strange behavior: I can send emails with viruses and spam >in attachments. Squirrelmail and rainloop (and also other clients >like thunderbird) behaves normally, meaning that dangereous >attachments are successfully blocked by qmail-scanner. >In logs I did't observe unusual things. > >Why the attachments are not blocked ? > > >10x >Pit |
From: Petre <cp...@ya...> - 2016-12-05 23:03:58
|
Hi, I successfully use qmail and Qmail-Scanner, with clamav and spamassassin.I use courier-authlib, courier-imap and users are kept in ldap.I tried a few days ago roundcube as a webmail application and observed a strange behavior: I can send emails with viruses and spam in attachments. Squirrelmail and rainloop (and also other clients like thunderbird) behaves normally, meaning that dangereous attachments are successfully blocked by qmail-scanner.In logs I did't observe unusual things. Why the attachments are not blocked ? 10xPit |
From: Salvatore T. <to...@pu...> - 2016-09-27 07:27:06
|
So it seems that qmail-scanner is Ok, I would look for the memory limit (softlimit). If Plesk is starting qmail through 'daemon-tools', this is what I'am using: --------- more /var/qmail/supervise/qmail-smtpd/run #!/bin/sh exec /usr/bin/softlimit -m 64000000 \ /usr/bin/tcpserver -c 20 -v -R -l 0 -H -x /etc/tcp.smtp.cdb \ -u 181 -g 181 0 smtp /var/qmail/bin/qmail-smtpd 2>&1 --------- Regards ST At 21:07 +0300 26-09-2016, turgut kalfaoglu wrote: >Many thanks.. Here is what that command shows: > >qmail-scanner-queue.pl > >Version: 2.10st (20111118) > >Perl: Summary of my perl5 (revision 5 version >10 subversion 1) configuration: > >Settings per domain: enabled > >Scanners installed: clamdscan_scanner, spamassassin, perlscan_scanner, > >Scanners default: clamdscan_scanner, spamassassin, perlscan_scanner, > >Scanner versioning: clamdscan: 0.99.2/22252. >spamassassin: 3.3.2. perlscan: 2.10st. > >Spamassassin settings: > Mode: fast_spamassassin > sa_timeout = 120 / sa_fault_tolerant = 1 / sa_maxsize = 1024000 > sa_alt: enabled / sa_debug = 0 / sa_hdr_report_site = 1 > sa_subject_site = '****SPAM****' > sa_delta_site = 1 > sa_quarantine_site = 0 > sa_delete_site = 2 / sa_reject_site = 0 > >Operating System: Linux, 2.6.32-642.4.2.el6.x86_64 >Hardware: x86_64 |
From: turgut k. <tu...@ka...> - 2016-09-26 18:08:02
|
Many thanks.. Here is what that command shows: qmail-scanner-queue.pl Version: 2.10st (20111118) Perl: Summary of my perl5 (revision 5 version 10 subversion 1) configuration: Settings per domain: enabled Scanners installed: clamdscan_scanner, spamassassin, perlscan_scanner, Scanners default: clamdscan_scanner, spamassassin, perlscan_scanner, Scanner versioning: clamdscan: 0.99.2/22252. spamassassin: 3.3.2. perlscan: 2.10st. Spamassassin settings: Mode: fast_spamassassin sa_timeout = 120 / sa_fault_tolerant = 1 / sa_maxsize = 1024000 sa_alt: enabled / sa_debug = 0 / sa_hdr_report_site = 1 sa_subject_site = '****SPAM****' sa_delta_site = 1 sa_quarantine_site = 0 sa_delete_site = 2 / sa_reject_site = 0 Operating System: Linux, 2.6.32-642.4.2.el6.x86_64 Hardware: x86_64 |
From: Salvatore T. <to...@pu...> - 2016-09-26 15:24:58
|
Hi I guess that no e-mail is being delivered now... Plesk doesn't use an standard qmail installation and it does some strange things... What is the output of the command? /var/qmail/bin/qmail-scanner-queue.pl -V If it returns an error there is some syntax error in it, if not, maybe the problem is that the process doesn't have enough memory to run. I don't know where Plesk sets the memory limit for the qmail-smtpd process, try to increase it. And increase the debug level in qmail-scanner... ST At 14:17 +0300 26-09-2016, turgut kalfaoglu wrote: >Actually the log file has some interesting stuff: > >Mon, 26 Sep 2016 13:09:18 CEST:12013: ------ >Process 12013 finished. Total of 1.05858 secs >Mon, 26 Sep 2016 13:09:21 CEST:12040: +++ >starting debugging for process 12040 >(ppid=12038) by uid=2020 >Mon, 26 Sep 2016 13:09:21 CEST:12040: g_e_h: >return-path='cha...@si...', >recips='pr...@ek...' >Mon, 26 Sep 2016 13:09:21 CEST:12040: >from='Silyonshipping Mersin ><cha...@si...>', >subj='SILYON CARGOES', via SMTP from >mail-eopbgr30049.outbound.protection.outlook.com >Mon, 26 Sep 2016 13:09:21 CEST:12048: +++ >starting debugging for process 12048 >(ppid=12036) by uid=2020 >Mon, 26 Sep 2016 13:09:21 CEST:12048: g_e_h: >return-path='bu...@du...', >recips='cha...@er...' >Mon, 26 Sep 2016 13:09:21 CEST:12048: >from='"cha...@ay..." ><cha...@ay...>', subj='OPEN FULLY >BOX VESSEL', via SMTP from n48.mxout.mta4.net >Mon, 26 Sep 2016 13:09:22 CEST:12040: >error_condition: X-Qmail-Scanner-2.10st: Unable >to open pipe to /var/qmail/bin/qmail-queue.orig >[61] (#4.3.0) - >Mon, 26 Sep 2016 13:09:22 CEST:12040: ------ >Process 12040 finished. Total of 1.365748 secs >Mon, 26 Sep 2016 13:09:22 CEST:12040: >error_condition: X-Qmail-Scanner-2.10st: Unable >to close pipe to /var/qmail/bin/qmail-queue.orig >[61] (#4.3.0) - Illegal seek >Mon, 26 Sep 2016 13:09:22 CEST:12040: ------ >Process 12040 finished. Total of 1.367859 secs >Mon, 26 Sep 2016 13:09:23 CEST:12066: +++ >starting debugging for process 12066 >(ppid=12063) by uid=2020 >Mon, 26 Sep 2016 13:09:23 CEST:12066: g_e_h: >return-path='g-6...@bo...', >recips='pe...@ma...' >Mon, 26 Sep 2016 13:09:23 CEST:12066: >from='SME_260916 ><teb...@ne...>', >subj='Kobi'ler ne isterse', via SMTP from >unusquattuornovem.beta.ecm-cluster.com >Mon, 26 Sep 2016 13:09:23 CEST:12048: >error_condition: X-Qmail-Scanner-2.10st: Unable >to open pipe to /var/qmail/bin/qmail-queue.orig >[61] (#4.3.0) - >Mon, 26 Sep 2016 13:09:23 CEST:12048: ------ >Process 12048 finished. Total of 1.645631 secs >Mon, 26 Sep 2016 13:09:23 CEST:12048: >error_condition: X-Qmail-Scanner-2.10st: Unable >to close pipe to /var/qmail/bin/qmail-queue.orig >[61] (#4.3.0) - Illegal seek >Mon, 26 Sep 2016 13:09:23 CEST:12048: ------ >Process 12048 finished. Total of 1.648269 secs > > >Any ideas how to fix the "unable to open/close pipe" errors? >Many thanks, -turgut |
From: turgut k. <tu...@ka...> - 2016-09-26 11:17:18
|
Actually the log file has some interesting stuff: Mon, 26 Sep 2016 13:09:18 CEST:12013: ------ Process 12013 finished. Total of 1.05858 secs Mon, 26 Sep 2016 13:09:21 CEST:12040: +++ starting debugging for process 12040 (ppid=12038) by uid=2020 Mon, 26 Sep 2016 13:09:21 CEST:12040: g_e_h: return-path='cha...@si...', recips='pr...@ek...' Mon, 26 Sep 2016 13:09:21 CEST:12040: from='Silyonshipping Mersin <cha...@si...>', subj='SILYON CARGOES', via SMTP from mail-eopbgr30049.outbound.protection.outlook.com Mon, 26 Sep 2016 13:09:21 CEST:12048: +++ starting debugging for process 12048 (ppid=12036) by uid=2020 Mon, 26 Sep 2016 13:09:21 CEST:12048: g_e_h: return-path='bu...@du...', recips='cha...@er...' Mon, 26 Sep 2016 13:09:21 CEST:12048: from='"cha...@ay..." <cha...@ay...>', subj='OPEN FULLY BOX VESSEL', via SMTP from n48.mxout.mta4.net Mon, 26 Sep 2016 13:09:22 CEST:12040: error_condition: X-Qmail-Scanner-2.10st: Unable to open pipe to /var/qmail/bin/qmail-queue.orig [61] (#4.3.0) - Mon, 26 Sep 2016 13:09:22 CEST:12040: ------ Process 12040 finished. Total of 1.365748 secs Mon, 26 Sep 2016 13:09:22 CEST:12040: error_condition: X-Qmail-Scanner-2.10st: Unable to close pipe to /var/qmail/bin/qmail-queue.orig [61] (#4.3.0) - Illegal seek Mon, 26 Sep 2016 13:09:22 CEST:12040: ------ Process 12040 finished. Total of 1.367859 secs Mon, 26 Sep 2016 13:09:23 CEST:12066: +++ starting debugging for process 12066 (ppid=12063) by uid=2020 Mon, 26 Sep 2016 13:09:23 CEST:12066: g_e_h: return-path='g-6...@bo...', recips='pe...@ma...' Mon, 26 Sep 2016 13:09:23 CEST:12066: from='SME_260916 <teb...@ne...>', subj='Kobi'ler ne isterse', via SMTP from unusquattuornovem.beta.ecm-cluster.com Mon, 26 Sep 2016 13:09:23 CEST:12048: error_condition: X-Qmail-Scanner-2.10st: Unable to open pipe to /var/qmail/bin/qmail-queue.orig [61] (#4.3.0) - Mon, 26 Sep 2016 13:09:23 CEST:12048: ------ Process 12048 finished. Total of 1.645631 secs Mon, 26 Sep 2016 13:09:23 CEST:12048: error_condition: X-Qmail-Scanner-2.10st: Unable to close pipe to /var/qmail/bin/qmail-queue.orig [61] (#4.3.0) - Illegal seek Mon, 26 Sep 2016 13:09:23 CEST:12048: ------ Process 12048 finished. Total of 1.648269 secs Any ideas how to fix the "unable to open/close pipe" errors? Many thanks, -turgut |
From: turgut k. <tu...@ka...> - 2016-09-26 09:53:53
|
Many thanks; mine was set for my $sa_maxsize='1024000'; So I doubt that's the cause. Regards, -turgut On 09/26/2016 11:05 AM, Salvatore Toribio wrote: > Hi > > This could happen when the e-mail is bigger than > the max_size set for spamassassin client. The > default is 500 KB. > > There is variable in qmail-scanner-queue.pl where > you can set this value 'sa_maxsize' to whatever > you need. > > Kind regards > > ST > > > > At 9:46 +0300 23-09-2016, turgut kalfaog˜lu wrote: >> Hello.. >> >> I often see scan logs saying SA:0(?/?) I am wondering why the question >> marks. >> >> This is a PLESK 12.0.18 server, and I was testing some local.cf changes >> to spamassassin and I noticed that some mail was skipping the spam check. >> For example: >> >> qmail-scanner-queue.pl: qmail-scanner[5438]: >> Clear:RC:0(217.131.39.69):SA:0(?/?): 2.615015 3594898 >> cen...@eb... cen...@BL... >> HATIRLATMA-EBSO_KOBI™_OKULU-UYUMSUZ_REKABET_SEMI™NERI™ >> <120...@eb...> >> 1474455315.7315-1.pluto.kalfaoglu.net:1431 eortulu.jpg:172939 >> orig-pluto.kalfaoglu.net14744552667975438:3594898 >> 1474455315.7315-0.pluto.kalfaoglu.net:301 duyuru.pdf:2484473 >> >> (I modified the mail addresses above) .. A user complained about getting >> these mails so I wrote a rule for it in local.cf, but some of these mass >> mailings are still sliding through. >> >> The SA:0(?/?) does not happen every time; for most mails it works fine, >> such as SA:0(2.0/8.0) >> >> Any ideas why it might skip some mails and check others? >> Many thanks, -turgut >> >> >> ------------------------------------------------------------------------------ >> _______________________________________________ >> Qmail-scanner-general mailing list >> Qma...@li... >> https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general > > ------------------------------------------------------------------------------ > _______________________________________________ > Qmail-scanner-general mailing list > Qma...@li... > https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general > |
From: Salvatore T. <to...@pu...> - 2016-09-26 08:32:26
|
Hi This could happen when the e-mail is bigger than the max_size set for spamassassin client. The default is 500 KB. There is variable in qmail-scanner-queue.pl where you can set this value 'sa_maxsize' to whatever you need. Kind regards ST At 9:46 +0300 23-09-2016, turgut kalfaoglu wrote: >Hello.. > >I often see scan logs saying SA:0(?/?) I am wondering why the question >marks. > >This is a PLESK 12.0.18 server, and I was testing some local.cf changes >to spamassassin and I noticed that some mail was skipping the spam check. >For example: > >qmail-scanner-queue.pl: qmail-scanner[5438]: >Clear:RC:0(217.131.39.69):SA:0(?/?): 2.615015 3594898 >cen...@eb... cen...@BL... >HATIRLATMA-EBSO_KOBI_OKULU-UYUMSUZ_REKABET_SEMINERI ><120...@eb...> >1474455315.7315-1.pluto.kalfaoglu.net:1431 eortulu.jpg:172939 >orig-pluto.kalfaoglu.net14744552667975438:3594898 >1474455315.7315-0.pluto.kalfaoglu.net:301 duyuru.pdf:2484473 > >(I modified the mail addresses above) .. A user complained about getting >these mails so I wrote a rule for it in local.cf, but some of these mass >mailings are still sliding through. > >The SA:0(?/?) does not happen every time; for most mails it works fine, >such as SA:0(2.0/8.0) > >Any ideas why it might skip some mails and check others? >Many thanks, -turgut > > >------------------------------------------------------------------------------ >_______________________________________________ >Qmail-scanner-general mailing list >Qma...@li... >https://lists.sourceforge.net/lists/listinfo/qmail-scanner-general |
From: turgut k. <tu...@ka...> - 2016-09-23 07:14:39
|
Hello.. I often see scan logs saying SA:0(?/?) I am wondering why the question marks. This is a PLESK 12.0.18 server, and I was testing some local.cf changes to spamassassin and I noticed that some mail was skipping the spam check. For example: qmail-scanner-queue.pl: qmail-scanner[5438]: Clear:RC:0(217.131.39.69):SA:0(?/?): 2.615015 3594898 cen...@eb... cen...@BL... HATIRLATMA-EBSO_KOBİ_OKULU-UYUMSUZ_REKABET_SEMİNERİ <120...@eb...> 1474455315.7315-1.pluto.kalfaoglu.net:1431 eortulu.jpg:172939 orig-pluto.kalfaoglu.net14744552667975438:3594898 1474455315.7315-0.pluto.kalfaoglu.net:301 duyuru.pdf:2484473 (I modified the mail addresses above) .. A user complained about getting these mails so I wrote a rule for it in local.cf, but some of these mass mailings are still sliding through. The SA:0(?/?) does not happen every time; for most mails it works fine, such as SA:0(2.0/8.0) Any ideas why it might skip some mails and check others? Many thanks, -turgut |