You can subscribe to this list here.
2002 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
(7) |
---|---|---|---|---|---|---|---|---|---|---|---|---|
2003 |
Jan
(26) |
Feb
(29) |
Mar
(27) |
Apr
(61) |
May
(179) |
Jun
(176) |
Jul
(243) |
Aug
(270) |
Sep
(147) |
Oct
(161) |
Nov
(110) |
Dec
(132) |
2004 |
Jan
(161) |
Feb
(114) |
Mar
(190) |
Apr
(79) |
May
(265) |
Jun
(269) |
Jul
(176) |
Aug
(159) |
Sep
(138) |
Oct
(45) |
Nov
(85) |
Dec
(80) |
2005 |
Jan
(145) |
Feb
(65) |
Mar
(49) |
Apr
(80) |
May
(136) |
Jun
(134) |
Jul
(408) |
Aug
(107) |
Sep
(75) |
Oct
(32) |
Nov
(42) |
Dec
(28) |
2006 |
Jan
(74) |
Feb
(134) |
Mar
(804) |
Apr
(984) |
May
(829) |
Jun
(427) |
Jul
(397) |
Aug
(745) |
Sep
(176) |
Oct
(564) |
Nov
(748) |
Dec
(1052) |
2007 |
Jan
(984) |
Feb
(678) |
Mar
(568) |
Apr
(434) |
May
(644) |
Jun
(396) |
Jul
(655) |
Aug
(693) |
Sep
(497) |
Oct
(411) |
Nov
(316) |
Dec
(310) |
2008 |
Jan
(192) |
Feb
(169) |
Mar
(141) |
Apr
(55) |
May
(143) |
Jun
(157) |
Jul
(136) |
Aug
(187) |
Sep
(131) |
Oct
(228) |
Nov
(227) |
Dec
(144) |
2009 |
Jan
(205) |
Feb
(211) |
Mar
(302) |
Apr
(186) |
May
(99) |
Jun
(127) |
Jul
(74) |
Aug
(18) |
Sep
(110) |
Oct
(61) |
Nov
(149) |
Dec
(186) |
2010 |
Jan
(108) |
Feb
(135) |
Mar
(85) |
Apr
(109) |
May
(115) |
Jun
(176) |
Jul
(81) |
Aug
(210) |
Sep
(76) |
Oct
(41) |
Nov
(69) |
Dec
(78) |
2011 |
Jan
(65) |
Feb
(48) |
Mar
(78) |
Apr
(34) |
May
(78) |
Jun
(92) |
Jul
(42) |
Aug
(40) |
Sep
(175) |
Oct
(26) |
Nov
(22) |
Dec
(15) |
2012 |
Jan
(20) |
Feb
(24) |
Mar
(20) |
Apr
(13) |
May
(29) |
Jun
(22) |
Jul
(12) |
Aug
(14) |
Sep
(22) |
Oct
(51) |
Nov
(74) |
Dec
(45) |
2013 |
Jan
(10) |
Feb
(40) |
Mar
(17) |
Apr
(59) |
May
(186) |
Jun
(67) |
Jul
(25) |
Aug
(51) |
Sep
(67) |
Oct
(47) |
Nov
(70) |
Dec
(39) |
2014 |
Jan
(41) |
Feb
(32) |
Mar
(67) |
Apr
(58) |
May
(89) |
Jun
(36) |
Jul
(59) |
Aug
(50) |
Sep
(86) |
Oct
(43) |
Nov
(43) |
Dec
(31) |
2015 |
Jan
(43) |
Feb
(40) |
Mar
(35) |
Apr
(23) |
May
(24) |
Jun
(45) |
Jul
(26) |
Aug
(38) |
Sep
(38) |
Oct
(17) |
Nov
(15) |
Dec
(21) |
2016 |
Jan
(28) |
Feb
(81) |
Mar
(157) |
Apr
(59) |
May
(9) |
Jun
(30) |
Jul
(77) |
Aug
(44) |
Sep
(64) |
Oct
(31) |
Nov
(26) |
Dec
(59) |
2017 |
Jan
(27) |
Feb
(56) |
Mar
(24) |
Apr
(14) |
May
(31) |
Jun
(35) |
Jul
(19) |
Aug
(7) |
Sep
(11) |
Oct
(2) |
Nov
(15) |
Dec
(22) |
2018 |
Jan
(13) |
Feb
(9) |
Mar
|
Apr
(4) |
May
(8) |
Jun
(11) |
Jul
(26) |
Aug
(14) |
Sep
(5) |
Oct
(2) |
Nov
(11) |
Dec
(7) |
2019 |
Jan
(5) |
Feb
(4) |
Mar
(5) |
Apr
(1) |
May
(7) |
Jun
(15) |
Jul
|
Aug
(4) |
Sep
|
Oct
(6) |
Nov
(20) |
Dec
(14) |
2020 |
Jan
(11) |
Feb
|
Mar
(32) |
Apr
(3) |
May
(14) |
Jun
(8) |
Jul
|
Aug
(9) |
Sep
(14) |
Oct
(5) |
Nov
(1) |
Dec
|
2021 |
Jan
(13) |
Feb
|
Mar
(6) |
Apr
(6) |
May
(18) |
Jun
(3) |
Jul
(7) |
Aug
(20) |
Sep
(20) |
Oct
(3) |
Nov
(5) |
Dec
|
2022 |
Jan
(7) |
Feb
(4) |
Mar
(7) |
Apr
(2) |
May
(1) |
Jun
|
Jul
|
Aug
(3) |
Sep
(4) |
Oct
(1) |
Nov
|
Dec
|
2023 |
Jan
(5) |
Feb
(2) |
Mar
|
Apr
(3) |
May
(3) |
Jun
(3) |
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(2) |
Dec
|
2024 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
(3) |
Aug
(8) |
Sep
(2) |
Oct
(3) |
Nov
(7) |
Dec
(4) |
2025 |
Jan
(4) |
Feb
(5) |
Mar
|
Apr
(3) |
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
S | M | T | W | T | F | S |
---|---|---|---|---|---|---|
|
|
|
1
(14) |
2
(26) |
3
(29) |
4
(2) |
5
(6) |
6
(30) |
7
(36) |
8
(27) |
9
(12) |
10
(9) |
11
(1) |
12
|
13
(23) |
14
(15) |
15
(22) |
16
(13) |
17
(55) |
18
(16) |
19
(6) |
20
(29) |
21
(27) |
22
(58) |
23
(34) |
24
(47) |
25
(24) |
26
(12) |
27
(66) |
28
(41) |
29
(39) |
30
(29) |
|
|
From: Micheal E. Jr <mi...@es...> - 2006-11-30 22:46:47
|
This is happening again (51). The message in question should have been rejected for HELO as well as a BombRE. ---------- Nov-30-06 16:55:41 24.165.176.125 <ps...@fi...> adding new triplet: (24.165.176.0,ps...@fi...,us...@do...d) Nov-30-06 16:55:41 24.165.176.125 <ps...@fi...> recipient delayed: us...@do...d Nov-30-06 16:55:41 24.165.176.125 <ps...@fi...> is disconnected ---------- Nov-30-06 17:17:20 Delaying greeting for 24.165.176.125 - duration 2 seconds Nov-30-06 17:17:22 Connected: 24.165.176.125:3248 -> 127.0.0.1:25 -> 127.0.0.1:26 Nov-30-06 17:17:22 24.165.176.125 <ps...@fi...> whitelisting triplet: (24.165.176.0,ps...@fi...,us...@do...d) waited: 21m 41s Nov-30-06 17:17:23 24.165.176.125 <ps...@fi...> to: us...@do...d passing if safe because testmode, otherwise Bayesian spam Nov-30-06 17:17:23 24.165.176.125 <ps...@fi...> to: us...@do...d spam determined to be safe, passing on to recipient decorum_ -> c:/assp/corpus/normal/spam/12961.eml Nov-30-06 17:17:23 24.165.176.125 <ps...@fi...> to: us...@do...d deleting spamming whitelisted tuplet: (24.165.176.0,fiatlux-production.com) age: 1s Nov-30-06 17:17:24 24.165.176.125 <ps...@fi...> to: us...@do...d is disconnected ---------- |
From: B. C. <bc...@po...> - 2006-11-30 21:56:53
|
Hello, I'm trying to understand what this means and how to deal with it.. X-Assp-Bayes-Confidence: 0.00000 X-Assp-Spam-Prob: 1.00000 X-Assp-Envelope-From: Wm...@xx... X-Assp-Intended-For: ae...@yy... X-Assp-Spam: YES X-Assp-Spam-Reason: Bayesian spam X-Assp-Bayes-Confidence: 0.97851 X-Assp-Spam-Prob: 1.00000 X-Assp-Envelope-From: 2.2...@ac... X-Assp-Intended-For: be...@yy... X-Assp-Spam: YES X-Assp-Spam-Reason: Bayesian spam The message with the Confidence closer to 1 is more accurate.. The gui says this about confidence: "Spam-Mails having a confidence below this value are passed in testmode and those above are blocked. Set this only above 0 if you are familiar with the bayesian statistics used in ASSP." So would this be correct in the assp.cfg? baysConfidence:=0.70000 Thanks in advance. |
From: Micheal E. Jr <mi...@es...> - 2006-11-30 21:05:44
|
Micheal Espinola Jr wrote: > I have since deleted my pbdb.black.db file, and it seems to be > repopulating properly. But, I believe I have found another issue: > > I am now seeing in the logs (since upgraded to (51) ) that if an email > is NP, it's session IP is automatically added to PB White *before* > analysis. During the analysis, if it fails for SPF it is not getting a > PB Black score, and after the analysis it is not being removed from PB > White. Things I am seeing log PB scores: YES - forged HELO YES - invalid HELO YES - invalid address YES - Bayesian YES - bombRe Things I am seeing not log PB scores: NO - failed RBL checks NO - failed SPF checks NO - blacklisted domain This is while running (51). Can anyone else confirm? |
From: Graziano <dre...@li...> - 2006-11-30 20:55:17
|
you should also change the way to start the perl assp file (on start file) such as on the start file attached on my first message. > I think I can make that a little clearer. All of the below could be > compiled into one 'install-linux' script for distribution with the full > package. > > 1: type "ren /usr/local/assp/rc/start.dat > /usr/local/assp/rc/asspstart.dat". Do the same for stop.dat > 1: type "ln -s /usr/local/assp/rc/*.dat /etc/init.d/" > 2: type "chmod +x /usr/local/assp/rc/*.dat" > 3: Open the assp web interface, goto: "Network Setup" and check "As a > Daemon". Click "Apply Changes" > > > > > Here is are a couple useful scripts for *nix utilizing the configuration > above: > > A quick restartassp script: > > 1: edit a new file called /usr/local/assp/restartassp > 2: put the lines "/etc/init.d/asspstop.dat", and > "/etc/init.d/asspstart.dat" in it. > 3: save and type "chmod +x /usr/local/assp/restartassp" > 4: type "ln -s /usr/local/assp/restartassp /usr/bin" to put it in your > system path. > > Restarting all mail services. > 1: edit a new file called /usr/local/assp/restartallmail > 2: Do the same as above, replacing the command in step 2 with those > below. You will need to change the sendmail lines, replacing them with > whatever MTA you have. Remove the SMA line if you do not use sendmail. > 3: repeat steps 3 and 4 above using the related script name. > > /etc/init.d/crond stop > /etc/init.d/sendmail stop > /etc/init.d/clamsmtpd stop > /etc/init.d/asspstop.dat > killall sendmail > killall -w sma > killall -w perl > /etc/init.d/asspstart.dat > /etc/init.d/sendmail start > /etc/init.d/clamsmtpd start > /etc/init.d/crond start > > > Check to see if ASSP is running, and if not, restart. NOTE: this only > works if assp is the only perl process on the server. > > 1: Follow all steps above, placing the commands below in a new file > called "/usr/local/assp/checkprocess". > *NOTE* the line beginning with "echo" and ending with ",$OPSEMAIL" is > all one line. Make sure it is saved as such/no line wrap. > > 2: Configure cron to run this process every five minutes(or more > frequently if you like). Cron configuration varies by distribution, and > is beyond the scope of these instruction. A suggested place to start > looking is in "/etc/crontab". Also run "man crontab" for crontab > documentation. > > #!/bin/sh > > # This file checks for clam av, and any other process you want, to see > if it is running. It will restart it if it is not. > checkproc() > { > # checkproc <process name> <restart command> > > BASEN=`/bin/basename $1` > > if [ $# -lt 2 ] > then > echo "Not enough parmeters passed to $0" > else > > PK=`ps -ax | grep -v grep | grep -c "$1"` > if [ "$PK" == "0" ] > then > > if [ -f /var/run/checkprocess/$BASEN ] > then > CNT=`cat /var/run/checkprocess/$BASEN` > if [ "$CNT" == "" ] > then > CNT=0 > fi > else > CNT=0 > fi > if [ $CNT -gt $RESTARTLIMIT ] > then > echo "We have attempted to restart the > process $1 on `/bin/hostname` at least $CNT times but it does not appear > to be running still. Please check into this on `/bin/hostname`" | > /bin/mail -s "Error restarting process: $1 at `/bin/date` on > `/bin/hostname`" $ALERTEMAIL,$OPSEMAIL > /usr/bin/logger -t "$0" "Process not > running: $1 - Restart limit reached - $CNT" > else > > $2 | mail -s "$1 was not running at > `/bin/date` on `/bin/hostname`. Process restarted" $ALERTEMAIL > /usr/bin/logger -t "$0" "Process not > running: $1 - Attempted automatic restart" > CNT=`/usr/bin/expr $CNT + 1` > fi > else > CNT=0 > fi > echo $CNT > /var/run/checkprocess/$BASEN > fi > } > > # start of main - # > export ALERTEMAIL=add...@yo... > export OPSEMAIL=add...@yo... > export RESTARTLIMIT=10 > > if [ ! -f /var/run/checkprocess ] > then > mkdir -p /var/run/checkprocess > fi > > > checkproc clamd "/etc/rc.d/init.d/clamav restart" > #checkproc clamav-milter "/etc/rc.d/init.d/clamav restart" > #checkproc clamsmtpd "/usr/local/bin/restartclamsmtpd" > checkproc freshclam "/etc/rc.d/init.d/clamav restart" > checkproc perl "/etc/init.d/assprestart.dat" > checkproc sendmail "/etc/rc.d/init.d/sendmail restart" > > > > -----Original Message----- > From: ass...@li... > [mailto:ass...@li...] On Behalf Of Micheal > Espinola Jr > Sent: Thursday, November 30, 2006 12:55 PM > To: Questions and Answers for users of ASSP Anti-Spam SMTP Proxy > Subject: Re: [Assp-user] how to use assp such as service on linux > > This would be great as part of a Quick Start article on the Wiki. > > For instance: > > http://www.asspsmtp.org/wiki/Quick_Start_for_Linux?action=edit > > You could use the Win32 article as a reference for format, etc: > > http://www.asspsmtp.org/wiki/Quick_Start_for_Win32 > > > Graziano wrote: > >> For me this works perfectly >> >> -requirements >> assp should be installed on /usr/local/assp >> >> >> 1) upload start and stop on /usr/local/assp >> 2) chmod 755 start and stop >> 3) upload assp on /etc/rc.d/init.d 4) chmod 755 assp >> 5) on assp web interface select to run assp as a demom >> 6) kill all assp processes >> >> now try if it works with >> service assp start >> and >> service assp status >> and >> service assp restart >> >> 7) if all works you can add to your startup list with >> chkconfig --add assp >> >> done. >> >> I am writing this guide because the files on /usr/local/assp/rc seems >> to be outdated and didn't work for me. >> >> Graziano >> >> >> >> >> > ------------------------------------------------------------------------ > >> #!/bin/sh >> # >> # 'stop' - Shell script a la RedHat initialization routines >> # R. Toth - May/2003 >> # V1.00 - Initial attempt at creating a fully compatible and compliant >> # shutdown script that's called out of '/etc/init.d' (linked >> > appropriately > >> # to the rc-level you are running in. You can link this as 'K31assp', >> > so that ASSP is > >> # terminated just after 'sendmail', in case you are also >> # running sendmail locally for your Email needs. >> # >> >> if [ "$1" = "" ] >> then >> BASE=/usr/local/assp; >> else >> BASE=$1; >> fi >> export BASE >> echo Starting ASSP Anti-SPAM Proxy server in $BASE >> trap '' 1 >> LANG= >> export LANG >> exec /usr/bin/perl $BASE/assp.pl $BASE >> >> >> > ------------------------------------------------------------------------ > >> #!/bin/sh >> if [ "$1" = "" ] >> then >> BASE=/usr/local/assp; >> else >> BASE=$1; >> fi >> export BASE >> echo Stopping ASSP Anti-SPAM Proxy server in $BASE >> pidfile=$BASE/pid >> kill `cat $pidfile` >> >> >> > ------------------------------------------------------------------------ > >> > ------------------------------------------------------------------------ > - > >> Take Surveys. Earn Cash. Influence the Future of IT >> Join SourceForge.net's Techsay panel and you'll get the chance to >> > share your > >> opinions on IT & business topics through brief surveys - and earn cash >> >> > http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDE > V > > ------------------------------------------------------------------------ > >> _______________________________________________ >> Assp-user mailing list >> Ass...@li... >> https://lists.sourceforge.net/lists/listinfo/assp-user >> >> > > > > ------------------------------------------------------------------------ > - > Take Surveys. Earn Cash. Influence the Future of IT > Join SourceForge.net's Techsay panel and you'll get the chance to share > your > opinions on IT & business topics through brief surveys - and earn cash > http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDE > V > _______________________________________________ > Assp-user mailing list > Ass...@li... > https://lists.sourceforge.net/lists/listinfo/assp-user > > ------------------------------------------------------------------------- > Take Surveys. Earn Cash. Influence the Future of IT > Join SourceForge.net's Techsay panel and you'll get the chance to share your > opinions on IT & business topics through brief surveys - and earn cash > http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV > _______________________________________________ > Assp-user mailing list > Ass...@li... > https://lists.sourceforge.net/lists/listinfo/assp-user > > |
From: Micheal E. Jr <mi...@es...> - 2006-11-30 20:31:20
|
Micheal Espinola Jr wrote: > The logging no longer says"message proxied without processing", but I > still dont see a PB score being logged for SPF. I do see others PB > action being logged as normal. > > To verify, I just checked my pbdb.black.db which I found to contain only > a single <CRLF>. It seems that my PB Black has been wiped out for some > unknown reason. PB White and RBL appear OK. > > Any suggestions? I have since deleted my pbdb.black.db file, and it seems to be repopulating properly. But, I believe I have found another issue: I am now seeing in the logs (since upgraded to (51) ) that if an email is NP, it's session IP is automatically added to PB White *before* analysis. During the analysis, if it fails for SPF it is not getting a PB Black score, and after the analysis it is not being removed from PB White. |
From: Micheal E. Jr <mi...@es...> - 2006-11-30 19:48:23
|
Fritz Borgstedt wrote: > please try (51) The logging no longer says"message proxied without processing", but I still dont see a PB score being logged for SPF. I do see others PB action being logged as normal. To verify, I just checked my pbdb.black.db which I found to contain only a single <CRLF>. It seems that my PB Black has been wiped out for some unknown reason. PB White and RBL appear OK. Any suggestions? |
From: Kevin <ass...@la...> - 2006-11-30 19:42:06
|
B. Cook wrote: > > My point was that there was -no- activity for the 3 minutes assp was > trying to find a -non existent- ptr record.. and as soon as a "3 minute" > timer elapsed (i.e. giving up) the system once again started to process > mail. > > How do you figure? There are 2 totally different connections in that log snippet. ASSP did delay the first connection but the second was totally unrelated to the first. If you enable connection logging and show that there was a 3 min delay from the connection to the missing PTR record thats different and a real issue. But as far as I can tell there is nothing wrong with those logs you posted the messages were simply 3 min apart. Kevin |
From: Scott M. <im...@ne...> - 2006-11-30 19:35:55
|
I sent this email yesterday, however it did not get sent to the list due to my own stupidity. I found the solution to the problem, and for archive's sake, I thought I would post it. The problem actually had nothing to do with addresses not being on whitelists - it had to do with report files not being in the correct directory. It was looking for /reports/spamreport.txt but not finding it, so it just reported that the addresses were not on the whitelist. >Date: Wed, 29 Nov 2006 11:33:32 -0500 >Subject: Can't get email interface to operate correctly > >I installed and configured ASSP for the first time today on an IMail >setup. It all seems to work great, and my 500-odd spams an hour from >the various admin accounts across a couple hundred domains have gone >down to about 3. Wow! > >I can't seem to get the email interface to work. I can forward an >email to ass...@my... and ASSP intercepts it, however it >always sends back the same email: > >Bid...@sl...: not on whitelist >my...@my...: not on whitelist > >In this case, the Bid...@sl... address is from the spam, >and the my...@my... is actually my real email address that >is being used to send the email. My address is a local domain, and >it is part of a list that is in the Local Addresses in the "Validate >Local Addresses" page. > >I've been bashing my head over this one for hours, and searched all >over for an idea, with no luck. Anyone have a suggestion as to what >I might be missing? |
From: Dickson, P. <pdi...@fr...> - 2006-11-30 19:15:03
|
I think I can make that a little clearer. All of the below could be compiled into one 'install-linux' script for distribution with the full package. =20 1: type "ren /usr/local/assp/rc/start.dat /usr/local/assp/rc/asspstart.dat". Do the same for stop.dat 1: type "ln -s /usr/local/assp/rc/*.dat /etc/init.d/" 2: type "chmod +x /usr/local/assp/rc/*.dat" 3: Open the assp web interface, goto: "Network Setup" and check "As a Daemon". Click "Apply Changes" Here is are a couple useful scripts for *nix utilizing the configuration above: A quick restartassp script: 1: edit a new file called /usr/local/assp/restartassp 2: put the lines "/etc/init.d/asspstop.dat", and "/etc/init.d/asspstart.dat" in it. 3: save and type "chmod +x /usr/local/assp/restartassp" 4: type "ln -s /usr/local/assp/restartassp /usr/bin" to put it in your system path. Restarting all mail services. =20 1: edit a new file called /usr/local/assp/restartallmail 2: Do the same as above, replacing the command in step 2 with those below. You will need to change the sendmail lines, replacing them with whatever MTA you have. Remove the SMA line if you do not use sendmail. 3: repeat steps 3 and 4 above using the related script name. /etc/init.d/crond stop /etc/init.d/sendmail stop /etc/init.d/clamsmtpd stop /etc/init.d/asspstop.dat killall sendmail killall -w sma killall -w perl /etc/init.d/asspstart.dat /etc/init.d/sendmail start /etc/init.d/clamsmtpd start /etc/init.d/crond start Check to see if ASSP is running, and if not, restart. NOTE: this only works if assp is the only perl process on the server. 1: Follow all steps above, placing the commands below in a new file called "/usr/local/assp/checkprocess". *NOTE* the line beginning with "echo" and ending with ",$OPSEMAIL" is all one line. Make sure it is saved as such/no line wrap. 2: Configure cron to run this process every five minutes(or more frequently if you like). Cron configuration varies by distribution, and is beyond the scope of these instruction. A suggested place to start looking is in "/etc/crontab". Also run "man crontab" for crontab documentation. #!/bin/sh # This file checks for clam av, and any other process you want, to see if it is running. It will restart it if it is not. checkproc() { # checkproc <process name> <restart command> BASEN=3D`/bin/basename $1` if [ $# -lt 2 ] then echo "Not enough parmeters passed to $0" else PK=3D`ps -ax | grep -v grep | grep -c "$1"` if [ "$PK" =3D=3D "0" ] then if [ -f /var/run/checkprocess/$BASEN ] then CNT=3D`cat /var/run/checkprocess/$BASEN` if [ "$CNT" =3D=3D "" ] then CNT=3D0 fi else CNT=3D0 fi if [ $CNT -gt $RESTARTLIMIT ] then echo "We have attempted to restart the process $1 on `/bin/hostname` at least $CNT times but it does not appear to be running still. Please check into this on `/bin/hostname`" | /bin/mail -s "Error restarting process: $1 at `/bin/date` on `/bin/hostname`" $ALERTEMAIL,$OPSEMAIL /usr/bin/logger -t "$0" "Process not running: $1 - Restart limit reached - $CNT" else $2 | mail -s "$1 was not running at `/bin/date` on `/bin/hostname`. Process restarted" $ALERTEMAIL /usr/bin/logger -t "$0" "Process not running: $1 - Attempted automatic restart" CNT=3D`/usr/bin/expr $CNT + 1` fi else CNT=3D0 fi echo $CNT > /var/run/checkprocess/$BASEN fi } # start of main - # export ALERTEMAIL=3Da...@yo... export OPSEMAIL=3Da...@yo... export RESTARTLIMIT=3D10 if [ ! -f /var/run/checkprocess ] then mkdir -p /var/run/checkprocess fi checkproc clamd "/etc/rc.d/init.d/clamav restart" #checkproc clamav-milter "/etc/rc.d/init.d/clamav restart" #checkproc clamsmtpd "/usr/local/bin/restartclamsmtpd" checkproc freshclam "/etc/rc.d/init.d/clamav restart" checkproc perl "/etc/init.d/assprestart.dat" checkproc sendmail "/etc/rc.d/init.d/sendmail restart" -----Original Message----- From: ass...@li... [mailto:ass...@li...] On Behalf Of Micheal Espinola Jr Sent: Thursday, November 30, 2006 12:55 PM To: Questions and Answers for users of ASSP Anti-Spam SMTP Proxy Subject: Re: [Assp-user] how to use assp such as service on linux This would be great as part of a Quick Start article on the Wiki. For instance: http://www.asspsmtp.org/wiki/Quick_Start_for_Linux?action=3Dedit You could use the Win32 article as a reference for format, etc: http://www.asspsmtp.org/wiki/Quick_Start_for_Win32 Graziano wrote: > For me this works perfectly > > -requirements > assp should be installed on /usr/local/assp > > > 1) upload start and stop on /usr/local/assp > 2) chmod 755 start and stop > 3) upload assp on /etc/rc.d/init.d 4) chmod 755 assp > 5) on assp web interface select to run assp as a demom > 6) kill all assp processes > > now try if it works with > service assp start > and > service assp status > and > service assp restart > > 7) if all works you can add to your startup list with > chkconfig --add assp > > done. > > I am writing this guide because the files on /usr/local/assp/rc seems > to be outdated and didn't work for me. > > Graziano > > > > ------------------------------------------------------------------------ > > #!/bin/sh > # > # 'stop' - Shell script a la RedHat initialization routines > # R. Toth - May/2003 > # V1.00 - Initial attempt at creating a fully compatible and compliant > # shutdown script that's called out of '/etc/init.d' (linked appropriately > # to the rc-level you are running in. You can link this as 'K31assp', so that ASSP is=20 > # terminated just after 'sendmail', in case you are also > # running sendmail locally for your Email needs. > # > > if [ "$1" =3D "" ] > then=20 > BASE=3D/usr/local/assp; > else > BASE=3D$1; > fi > export BASE > echo Starting ASSP Anti-SPAM Proxy server in $BASE > trap '' 1 > LANG=3D > export LANG > exec /usr/bin/perl $BASE/assp.pl $BASE > =20 > ------------------------------------------------------------------------ > > #!/bin/sh > if [ "$1" =3D "" ] > then > BASE=3D/usr/local/assp; > else > BASE=3D$1; > fi > export BASE > echo Stopping ASSP Anti-SPAM Proxy server in $BASE > pidfile=3D$BASE/pid > kill `cat $pidfile` > =20 > ------------------------------------------------------------------------ > > ------------------------------------------------------------------------ - > Take Surveys. Earn Cash. Influence the Future of IT > Join SourceForge.net's Techsay panel and you'll get the chance to share your > opinions on IT & business topics through brief surveys - and earn cash > http://www.techsay.com/default.php?page=3Djoin.php&p=3Dsourceforge&CID=3D= DEVDE V > ------------------------------------------------------------------------ > > _______________________________________________ > Assp-user mailing list > Ass...@li... > https://lists.sourceforge.net/lists/listinfo/assp-user > =20 ------------------------------------------------------------------------ - Take Surveys. Earn Cash. Influence the Future of IT Join SourceForge.net's Techsay panel and you'll get the chance to share your opinions on IT & business topics through brief surveys - and earn cash http://www.techsay.com/default.php?page=3Djoin.php&p=3Dsourceforge&CID=3D= DEVDE V _______________________________________________ Assp-user mailing list Ass...@li... https://lists.sourceforge.net/lists/listinfo/assp-user |
From: Eric B. <eb...@ho...> - 2006-11-30 18:15:35
|
"Wim Borghs" <wim...@gm...> wrote in message news:cf5...@ma...... > 2006/11/30, Micheal Espinola Jr > <mi...@es...>: >> What I think might be useful as a way to PB score these, is if all >> delayed connection automatically get a PB score applied, and that score >> only gets subtracted once the connection is retried and a triplet is >> finally created. > > Too bad delay-records are hashed or we could do it when the waittime is > over? > In sub DoCleanDelayDB in this codeblock?: > if ($t-$v>=$DelayEmbargoTime*60+$DelayWaitTime*3600) { > delete $Delay{$k}; > $keys_deleted++; > } I remember Fritz saying that if you removed the Digest::MD5 package, the records won't be hashed any longer. Haven't tried it myself, however. Eric |
From: Eric B. <eb...@ho...> - 2006-11-30 18:11:08
|
>>Since it doesn't make sense to have both >>a "No Processing" list and a "Process Only" list (they are mutually >>exclusive), > > They are not mutually exclusive. Somebody can be on the "process" > list, but what messages he process can depend on the np-list. Fritz - I sent you an updated patch on this idea off-list yesterday, but am not sure if the address I sent to was valid or not. Can you confirm if you received it please? Thanks, Eric |
From: Graziano <dre...@li...> - 2006-11-30 17:56:57
|
I forgotten the assp file . It's the assp.dat file on /rc folder. Move it to /etc/rc.d/init.d and rename it to assp . > For me this works perfectly > > -requirements > assp should be installed on /usr/local/assp > > > 1) upload start and stop on /usr/local/assp > 2) chmod 755 start and stop > 3) upload assp on /etc/rc.d/init.d 4) chmod 755 assp > 5) on assp web interface select to run assp as a demom > 6) kill all assp processes > > now try if it works with > service assp start > and > service assp status > and > service assp restart > > 7) if all works you can add to your startup list with > chkconfig --add assp > > done. > > I am writing this guide because the files on /usr/local/assp/rc seems > to be outdated and didn't work for me. > > Graziano > > > > ------------------------------------------------------------------------ > > #!/bin/sh > # > # 'stop' - Shell script a la RedHat initialization routines > # R. Toth - May/2003 > # V1.00 - Initial attempt at creating a fully compatible and compliant > # shutdown script that's called out of '/etc/init.d' (linked appropriately > # to the rc-level you are running in. You can link this as 'K31assp', so that ASSP is > # terminated just after 'sendmail', in case you are also > # running sendmail locally for your Email needs. > # > > if [ "$1" = "" ] > then > BASE=/usr/local/assp; > else > BASE=$1; > fi > export BASE > echo Starting ASSP Anti-SPAM Proxy server in $BASE > trap '' 1 > LANG= > export LANG > exec /usr/bin/perl $BASE/assp.pl $BASE > > ------------------------------------------------------------------------ > > #!/bin/sh > if [ "$1" = "" ] > then > BASE=/usr/local/assp; > else > BASE=$1; > fi > export BASE > echo Stopping ASSP Anti-SPAM Proxy server in $BASE > pidfile=$BASE/pid > kill `cat $pidfile` > > ------------------------------------------------------------------------ > > ------------------------------------------------------------------------- > Take Surveys. Earn Cash. Influence the Future of IT > Join SourceForge.net's Techsay panel and you'll get the chance to share your > opinions on IT & business topics through brief surveys - and earn cash > http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV > ------------------------------------------------------------------------ > > _______________________________________________ > Assp-user mailing list > Ass...@li... > https://lists.sourceforge.net/lists/listinfo/assp-user > |
From: Micheal E. Jr <mi...@es...> - 2006-11-30 17:55:31
|
This would be great as part of a Quick Start article on the Wiki. For instance: http://www.asspsmtp.org/wiki/Quick_Start_for_Linux?action=edit You could use the Win32 article as a reference for format, etc: http://www.asspsmtp.org/wiki/Quick_Start_for_Win32 Graziano wrote: > For me this works perfectly > > -requirements > assp should be installed on /usr/local/assp > > > 1) upload start and stop on /usr/local/assp > 2) chmod 755 start and stop > 3) upload assp on /etc/rc.d/init.d 4) chmod 755 assp > 5) on assp web interface select to run assp as a demom > 6) kill all assp processes > > now try if it works with > service assp start > and > service assp status > and > service assp restart > > 7) if all works you can add to your startup list with > chkconfig --add assp > > done. > > I am writing this guide because the files on /usr/local/assp/rc seems > to be outdated and didn't work for me. > > Graziano > > > > ------------------------------------------------------------------------ > > #!/bin/sh > # > # 'stop' - Shell script a la RedHat initialization routines > # R. Toth - May/2003 > # V1.00 - Initial attempt at creating a fully compatible and compliant > # shutdown script that's called out of '/etc/init.d' (linked appropriately > # to the rc-level you are running in. You can link this as 'K31assp', so that ASSP is > # terminated just after 'sendmail', in case you are also > # running sendmail locally for your Email needs. > # > > if [ "$1" = "" ] > then > BASE=/usr/local/assp; > else > BASE=$1; > fi > export BASE > echo Starting ASSP Anti-SPAM Proxy server in $BASE > trap '' 1 > LANG= > export LANG > exec /usr/bin/perl $BASE/assp.pl $BASE > > ------------------------------------------------------------------------ > > #!/bin/sh > if [ "$1" = "" ] > then > BASE=/usr/local/assp; > else > BASE=$1; > fi > export BASE > echo Stopping ASSP Anti-SPAM Proxy server in $BASE > pidfile=$BASE/pid > kill `cat $pidfile` > > ------------------------------------------------------------------------ > > ------------------------------------------------------------------------- > Take Surveys. Earn Cash. Influence the Future of IT > Join SourceForge.net's Techsay panel and you'll get the chance to share your > opinions on IT & business topics through brief surveys - and earn cash > http://www.techsay.com/default.php?page=join.php&p=sourceforge&CID=DEVDEV > ------------------------------------------------------------------------ > > _______________________________________________ > Assp-user mailing list > Ass...@li... > https://lists.sourceforge.net/lists/listinfo/assp-user > |
From: Graziano <dre...@li...> - 2006-11-30 17:49:39
|
For me this works perfectly -requirements assp should be installed on /usr/local/assp 1) upload start and stop on /usr/local/assp 2) chmod 755 start and stop 3) upload assp on /etc/rc.d/init.d 4) chmod 755 assp 5) on assp web interface select to run assp as a demom 6) kill all assp processes now try if it works with service assp start and service assp status and service assp restart 7) if all works you can add to your startup list with chkconfig --add assp done. I am writing this guide because the files on /usr/local/assp/rc seems to be outdated and didn't work for me. Graziano |
From: Micheal E. Jr <mi...@es...> - 2006-11-30 17:24:24
|
Wim Borghs wrote: > Too bad delay-records are hashed or we could do it when the waittime is over? > In sub DoCleanDelayDB in this codeblock?: > if ($t-$v>=$DelayEmbargoTime*60+$DelayWaitTime*3600) { > delete $Delay{$k}; > $keys_deleted++; > } That's an interesting idea too - but it you get multiple attempts delayed before the embargo time expires, you could block the IP all that much faster by accumulating the PB score as the attempts happen. |
From: Wim B. <wim...@gm...> - 2006-11-30 16:40:27
|
2006/11/30, Micheal Espinola Jr <mi...@es...>: > What I think might be useful as a way to PB score these, is if all > delayed connection automatically get a PB score applied, and that score > only gets subtracted once the connection is retried and a triplet is > finally created. Too bad delay-records are hashed or we could do it when the waittime is over? In sub DoCleanDelayDB in this codeblock?: if ($t-$v>=$DelayEmbargoTime*60+$DelayWaitTime*3600) { delete $Delay{$k}; $keys_deleted++; } |
From: Fritz B. <fb...@iw...> - 2006-11-30 13:51:22
|
> is there a way that I can do the opposite with hosts that >I have on the whiteListedDomains or whitelistdb or noDelay? Put the IP in <Accept All Mail> in Relaying. |
From: Micheal E. Jr <mi...@es...> - 2006-11-30 13:40:57
|
Fritz Borgstedt wrote: >> ASSP v1.2.6(44) >> > > That report was exactly what i was hoping for -> > > > please try (51) I do try to be more helpful than a pain. ))) Will do, thanks! |
From: Fritz B. <fb...@iw...> - 2006-11-30 13:33:32
|
>ASSP v1.2.6(44) That report was exactly what i was hoping for -> > please try (51) Fritz |
From: B. C. <bc...@po...> - 2006-11-30 13:32:11
|
Is this possible? As a way to build up my 'spamdb' I have a domain that hasn't been used in 8+ years; I've figured out how to make assp take all mail and send it to the bad bayes.. is there a way that I can do the opposite with hosts that I have on the whiteListedDomains or whitelistdb or noDelay? Is that even a 'good idea'(tm) ? Thanks in advance.. |
From: Micheal E. Jr <mi...@es...> - 2006-11-30 13:00:25
|
ASSP v1.2.6(44) When checking my logs for inconsistencies, I noticed issues regarding PB scoring and session logging. This is most noticeable for me regarding PayPal spoofs. First, messages that matched NP but failed SPF are not accumulating a PB score. Second, although the message was rejected for SPF fail, "message proxied without processing" is being logged: ---------- Nov-30-06 03:26:25 Connected: 207.59.120.226:39844 -> 127.0.0.1:25 -> 127.0.0.1:26 Nov-30-06 03:26:25 207.59.120.226 <se...@pa...> whitelisting triplet: (207.59.120.0,se...@pa...,us...@do...d) waited: 15m 21s Nov-30-06 03:26:25 207.59.120.226 <se...@pa...> to: us...@do...d Noprocessing RE: 'From: "PayPal Service"<service@pa' Nov-30-06 03:26:27 207.59.120.226 <se...@pa...> to: us...@do...d failed SPF checks IMPORTANT_PayPal_Security_Measures_PP_052_CA_788_ Nov-30-06 03:26:27 207.59.120.226 <se...@pa...> to: us...@do...d deleting spamming whitelisted tuplet: (207.59.120.0,paypal.com) age: 2s Nov-30-06 03:26:27 207.59.120.226 <se...@pa...> to: us...@do...d message proxied without processing - (no bad attachments) ---------- If it is any help, the SPF fail in this example is a softfail - but I have SPFsoftfail <./,DanaInfo=parcel.massbar.org,Port=55555+#SPFsoftfail> enabled. Is anyone else seeing this? |
From: Micheal E. Jr <mi...@es...> - 2006-11-30 12:41:11
|
What I think might be useful as a way to PB score these, is if all delayed connection automatically get a PB score applied, and that score only gets subtracted once the connection is retried and a triplet is finally created. In my logs I see a lot of repeated connection from the same IPs trying to send spam once a minute, being delayed. Each attempt they rotate the HELO as well as the sending address, although rarely the recipient. I'm sure a lot of us are seeing this. Delaying works great, but using this method of penalizing the IP, I think this would be a relatively safe way to apply PB functionality to repeated delayed connections, and allow ASSP to terminate these connects even earlier. Any thoughts? |
From: B. C. <bc...@po...> - 2006-11-30 12:23:46
|
On Wed, November 29, 2006 6:28 pm, pa...@bl... wrote: > On 29 Nov 2006 at 13:48, B. Cook wrote: > >> Notice the 3 minute delay.. > > Eh? 3 minutes between 2 different emails from different ip. The first was > delayed, the second had > a missing ptr. > > paul > My point was that there was -no- activity for the 3 minutes assp was trying to find a -non existent- ptr record.. and as soon as a "3 minute" timer elapsed (i.e. giving up) the system once again started to process mail. |
From: Marrco <as...@mi...> - 2006-11-30 12:08:22
|
> that was a bug for one version, try the newest one (49). thx fritz. I'll do some tests today with (49) |
From: Fritz B. <fb...@iw...> - 2006-11-30 11:43:16
|
>I think this vould be very useful for new installations > >I'm not a byesian guru so i don't know if I'm missing something... But the idea here is to increase confidence by training. The user should report the message as "notspam", he cannot do it, if there is no marking. An idea might be to have different markings like spam? and spam! |