You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@spamassassin.apache.org by Michelle Konzack <li...@tamay-dogan.net> on 2009/04/20 17:42:19 UTC

spamassassin tags ALL messages as spam for unknown reason

Hello,

I am using "courier", "procmail" and  "spamassassin".  In  my  ~/.corier
file I have had the line:

  |/usr/bin/preline /usr/bin/procmail

which  is  working  fine,  except,  that  I  get  multiple   header   of
Delivered-To:  Which is for some of my tools undesired since I need only
the one from the Mailbox.

So now I have (according to Sam from the courier list) doen following:

  |/usr/bin/formail -I'Delivered-To: |/usr/bin/preline /usr/bin/procmail

and ended up in spamassassin is taging ALL messages as spam:

----[ STDIN ]-----------------------------------------------------------
From michelle.konzack Mon Apr 20 01:17:41 2009
Received: from localhost by vserver1.tamay-dogan.net
	with SpamAssassin (version 3.2.5);
	Mon, 20 Apr 2009 01:17:41 +0200
X-Spam-Flag: YES
X-Spam-Checker-Version: SpamAssassin 3.2.5 (2008-06-10) on
	vserver1.tamay-dogan.net
X-Spam-Level: *****
X-Spam-Status: Yes, score=5.4 required=5.0 tests=CORRUPT_FROM_LINE_IN_HDRS,
	MISSING_DATE,MISSING_HB_SEP,MISSING_HEADERS,MISSING_MID,MISSING_SUBJECT,
	NO_HEADERS_MESSAGE,NO_RECEIVED,NO_RELAYS autolearn=no version=3.2.5
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----------=_49EBB115.13507044"

This is a multi-part message in MIME format.

------------=_49EBB115.13507044
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: 8bit

Spam detection software, running on the system "vserver1.tamay-dogan.net", has
identified this incoming email as possible spam.  The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email.  If you have any questions, see
the administrator of that system for details.

Content preview:  From debian-doc-request@lists.debian.org Mon Apr 20 01:17:40
   2009 Received: from liszt.debian.org (liszt.debian.org [::ffff:82.195.75.100])
   by vserver1.tamay-dogan.net with esmtp; Mon, 20 Apr 2009 01:17:40 +0200 id
   00000A48.49EBB114.00005734 Received: from localhost (localhost [127.0.0.1])
   by liszt.debian.org (Postfix) with QMQP id E745413A6396; Sun, 19 Apr 2009
   23:18:31 +0000 (UTC) Old-Return-Path: <ch...@nurfuerspam.de> X-Spam-Checker-Version:
   SpamAssassin 3.2.3 (2007-08-08) on liszt.debian.org X-Spam-Level: X-Spam-Status:
   No, score=-11.0 required=4.0 tests=LDOSUBSCRIBER,LDO_WHITELIST autolearn=failed
   version=3.2.3 X-Original-To: lists-debian-doc@liszt.debian.org Received:
  from localhost (localhost [127.0.0.1]) by liszt.debian.org (Postfix) with
  ESMTP id 024BA13A638A for <li...@liszt.debian.org>; Sun, 19 Apr
   2009 23:18:23 +0000 (UTC) Received: from liszt.debian.org ([127.0.0.1]) by
   localhost (lists.debian.org [127.0.0.1]) (amavisd-new, port 2525) with ESMTP
   id 32152-89 for <li...@liszt.debian.org>; Sun, 19 Apr 2009 23:18:20
   +0000 (UTC) Received: from mail.gmx.net (mail.gmx.net [213.165.64.20]) by
   liszt.debian.org (Postfix) with SMTP id D734E13A6389 for <de...@lists.debian.org>;
   Sun, 19 Apr 2009 23:18:19 +0000 (UTC) Received: (qmail invoked by alias);
   19 Apr 2009 23:18:17 -0000 Received: from p5B0C2CDA.dip0.t-ipconnect.de (EHLO
   callisto.lan) [91.12.44.218] by mail.gmx.net (mp071) with SMTP; 20 Apr 2009
   01:18:17 +0200 X-Authenticated: #18544399 X-Provags-ID: V01U2FsdGVkX1+j2QhHLFGjCTIOOA2VTLuSg3tWpRqtHQ0cJGod4w
   +GCu8zAdUnuJhr From: Christian Schneider <ch...@nurfuerspam.de> To:
   debian-doc@lists.debian.org Subject: Suggestions for lenny release note Date:
   Mon, 20 Apr 2009 00:58:56 +0200 User-Agent: KMail/1.9.9 MIME-Version: 1.0
   Content-Disposition: inline Content-Type: text/plain; charset="us-ascii"
  Content-Transfer-Encoding: 7bit Message-Id: <20...@nurfuerspam.de>
   X-Y-GMX-Trusted: 0 X-FuHaFi: 0.63 X-Virus-Scanned: at lists.debian.org with
   policy bank [...] 

Content analysis details:   (5.4 points, 5.0 required)

 pts rule name              description
---- ---------------------- --------------------------------------------------
 0.0 MISSING_MID            Missing Message-Id: header
 0.0 MISSING_DATE           Missing Date: header
-0.0 NO_RELAYS              Informational: message was not relayed via SMTP
 2.5 MISSING_HB_SEP         Missing blank line between message header and body
 1.6 MISSING_HEADERS        Missing To: header
 0.0 CORRUPT_FROM_LINE_IN_HDRS Informational: message is corrupt, with a
                            From line in its headers
 1.3 MISSING_SUBJECT        Missing Subject: header
-0.0 NO_RECEIVED            Informational: message has no Received headers
 0.0 NO_HEADERS_MESSAGE     Message appears to be missing most RFC-822 headers



------------=_49EBB115.13507044
Content-Type: message/rfc822; x-spam-type=original
Content-Description: original message before SpamAssassin
Content-Disposition: inline
Content-Transfer-Encoding: 8bit

Return-Path: <bo...@lists.debian.org>
Delivered-To: xxxxxxxx.ml4michelle@tamay-dogan.net
From debian-doc-request@lists.debian.org  Mon Apr 20 01:17:40 2009
Received: from liszt.debian.org (liszt.debian.org [::ffff:82.195.75.100])
  by vserver1.tamay-dogan.net with esmtp; Mon, 20 Apr 2009 01:17:40 +0200
  id 00000A48.49EBB114.00005734
Received: from localhost (localhost [127.0.0.1])
	by liszt.debian.org (Postfix) with QMQP
	id E745413A6396; Sun, 19 Apr 2009 23:18:31 +0000 (UTC)
Old-Return-Path: <ch...@nurfuerspam.de>
X-Spam-Checker-Version: SpamAssassin 3.2.3 (2007-08-08) on liszt.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-11.0 required=4.0 tests=LDOSUBSCRIBER,LDO_WHITELIST
	autolearn=failed version=3.2.3
X-Original-To: lists-debian-doc@liszt.debian.org
Received: from localhost (localhost [127.0.0.1])
	by liszt.debian.org (Postfix) with ESMTP id 024BA13A638A
	for <li...@liszt.debian.org>; Sun, 19 Apr 2009 23:18:23 +0000 (UTC)
Received: from liszt.debian.org ([127.0.0.1])
	by localhost (lists.debian.org [127.0.0.1]) (amavisd-new, port 2525)
	with ESMTP id 32152-89 for <li...@liszt.debian.org>;
	Sun, 19 Apr 2009 23:18:20 +0000 (UTC)
Received: from mail.gmx.net (mail.gmx.net [213.165.64.20])
	by liszt.debian.org (Postfix) with SMTP id D734E13A6389
	for <de...@lists.debian.org>; Sun, 19 Apr 2009 23:18:19 +0000 (UTC)
Received: (qmail invoked by alias); 19 Apr 2009 23:18:17 -0000
Received: from p5B0C2CDA.dip0.t-ipconnect.de (EHLO callisto.lan) [91.12.44.218]
  by mail.gmx.net (mp071) with SMTP; 20 Apr 2009 01:18:17 +0200
X-Authenticated: #18544399
X-Provags-ID: V01U2FsdGVkX1+j2QhHLFGjCTIOOA2VTLuSg3tWpRqtHQ0cJGod4w
	+GCu8zAdUnuJhr
From: Christian Schneider <ch...@nurfuerspam.de>
To: debian-doc@lists.debian.org
Subject: Suggestions for lenny release note
Date: Mon, 20 Apr 2009 00:58:56 +0200
User-Agent: KMail/1.9.9
MIME-Version: 1.0
Content-Disposition: inline
Content-Type: text/plain;
  charset="us-ascii"
Content-Transfer-Encoding: 7bit
Message-Id: <20...@nurfuerspam.de>
X-Y-GMX-Trusted: 0
X-FuHaFi: 0.63
X-Virus-Scanned: at lists.debian.org with policy bank en-lt
X-Amavis-Spam-Status: No, score=-7 tagged_above=3.6 required=5.3 tests=[BAYES_00=-2,
	LDO_WHITELIST=-5]
X-Rc-Virus: 2007-09-13_01
X-Rc-Spam: 2008-11-04_01
Resent-Message-ID: <tQ...@liszt>
Resent-From: debian-doc@lists.debian.org
X-Mailing-List: <de...@lists.debian.org> archive/latest/13704
X-Loop: debian-doc@lists.debian.org
List-Id: <debian-doc.lists.debian.org>
List-Post: <ma...@lists.debian.org>
List-Help: <mailto:debian-doc-request@lists.debian.org?subject=help>
List-Subscribe: <mailto:debian-doc-request@lists.debian.org?subject=subscribe>
List-Unsubscribe: <mailto:debian-doc-request@lists.debian.org?subject=unsubscribe>
Precedence: list
Resent-Sender: debian-doc-request@lists.debian.org
Resent-Date: Sun, 19 Apr 2009 23:18:31 +0000 (UTC)

*** I am not subscribed to this list! Please CC me! ***

Hi,

I just have one further item for the check list "sound does not work" in 
the release notes of lenny:

After an upgrade from etch the sound under KDE may fail to work, because 
of old config files of kmixer, although kmixer is not running in the 
system tray.

In my case I was able to set the mixer levels with alsamixer and 
store/restore them with /etc/init.d/alsa-utils or alsactl, 
respectively. But due to some old kmixer configs KDE reset the levels
during every login (and as a result /etc/init.d/alsa-utils stored these 
strange settings persisting the next reboot if not corrected during the 
KDE session). I did not have any kmixer running in the background.

A second nasty thing was the following problem with kdm:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=439361

On my box X froze on every logout (including keyboard/mouse). Maybe a 
note with the workaround mentioned in the bug report might be helpful 
in the release notes, too.

Cheers,
Christian


-- 
To UNSUBSCRIBE, email to debian-doc-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org


------------=_49EBB115.13507044--

------------------------------------------------------------------------

The question is:    WHY does the "formail" stuff lead
                    to an error in spamassassin?

Thanks, Greetings and nice Day/Evening
    Michelle Konzack
    Systemadministrator
    Tamay Dogan Network
    Debian GNU/Linux Consultant

-- 
Linux-User #280138 with the Linux Counter, http://counter.li.org/
##################### Debian GNU/Linux Consultant #####################
<http://www.tamay-dogan.net/>                 Michelle Konzack
<http://www.can4linux.org/>                   Apt. 917
<http://www.flexray4linux.org/>               50, rue de Soultz
Jabber linux4michelle@jabber.ccc.de           67100 Strasbourg/France
IRC #Debian (irc.icq.com)                     Tel. DE: +49 177 9351947
ICQ #328449886                                Tel. FR: +33  6  61925193

Re: spamassassin tags ALL messages as spam for unknown reason

Posted by Michelle Konzack <li...@tamay-dogan.net>.
Am 2009-04-20 08:57:04, schrieb John Hardin:
> On Mon, 20 Apr 2009, Michelle Konzack wrote:
>
>> So now I have (according to Sam from the courier list) doen following:
>>
>>  |/usr/bin/formail -I'Delivered-To: |/usr/bin/preline /usr/bin/procmail
>
> Unbalanced quotes.

This was a typo be me, since I can not cop-n-past the thing from the
XTerm (whenever I klick with mouse into the XTerm, I see weird chars)

>> X-Spam-Status: Yes, score=5.4 required=5.0 tests=CORRUPT_FROM_LINE_IN_HDRS,
>> 	MISSING_DATE,MISSING_HB_SEP,MISSING_HEADERS,MISSING_MID,MISSING_SUBJECT,
>> 	NO_HEADERS_MESSAGE,NO_RECEIVED,NO_RELAYS autolearn=no version=3.2.5
>
> This isn't SA's fault. That formail command is corrupting all messages.

In the original .courier file I even have NO quotes like:

  |/usr/bin/formail -I Delivered-To: |/usr/bin/preline /usr/bin/procmail

and it does not work.

Thanks, Greetings and nice Day/Evening
    Michelle Konzack
    Systemadministrator
    Tamay Dogan Network
    Debian GNU/Linux Consultant

-- 
Linux-User #280138 with the Linux Counter, http://counter.li.org/
##################### Debian GNU/Linux Consultant #####################
<http://www.tamay-dogan.net/>                 Michelle Konzack
<http://www.can4linux.org/>                   Apt. 917
<http://www.flexray4linux.org/>               50, rue de Soultz
Jabber linux4michelle@jabber.ccc.de           67100 Strasbourg/France
IRC #Debian (irc.icq.com)                     Tel. DE: +49 177 9351947
ICQ #328449886                                Tel. FR: +33  6  61925193

Re: spamassassin tags ALL messages as spam for unknown reason

Posted by John Hardin <jh...@impsec.org>.
On Mon, 20 Apr 2009, Michelle Konzack wrote:

> So now I have (according to Sam from the courier list) doen following:
>
>  |/usr/bin/formail -I'Delivered-To: |/usr/bin/preline /usr/bin/procmail

Unbalanced quotes.

> X-Spam-Status: Yes, score=5.4 required=5.0 tests=CORRUPT_FROM_LINE_IN_HDRS,
> 	MISSING_DATE,MISSING_HB_SEP,MISSING_HEADERS,MISSING_MID,MISSING_SUBJECT,
> 	NO_HEADERS_MESSAGE,NO_RECEIVED,NO_RELAYS autolearn=no version=3.2.5

This isn't SA's fault. That formail command is corrupting all messages.

-- 
  John Hardin KA7OHZ                    http://www.impsec.org/~jhardin/
  jhardin@impsec.org    FALaholic #11174     pgpk -a jhardin@impsec.org
  key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
-----------------------------------------------------------------------
   Gun Control is marketed to the public using the appealing delusion
   that violent criminals will obey the law.
-----------------------------------------------------------------------
  3 days until Max Planck's 151st birthday

Re: spamassassin tags ALL messages as spam for unknown reason

Posted by Michelle Konzack <li...@tamay-dogan.net>.
Grr wrong...

If I use

  |/usr/bin/formail -i Delivered-To: |/usr/bin/preline /usr/bin/procmail

Preline is arring the three TOP headers in the wrong sequence

> > Return-Path: <bo...@lists.debian.org>
> > Delivered-To: xxxxxxxx.ml4michelle@tamay-dogan.net
> > From debian-doc-request@lists.debian.org  Mon Apr 20 01:17:40 2009
> > Received: from liszt.debian.org (liszt.debian.org [::ffff:82.195.75.100])
> >   by vserver1.tamay-dogan.net with esmtp; Mon, 20 Apr 2009 01:17:40 +0200
> >   id 00000A48.49EBB114.00005734

It should be:

From debian-doc-request@lists.debian.org  Mon Apr 20 01:17:40 2009
Return-Path: <bo...@lists.debian.org>
Delivered-To: xxxxxxxx.ml4michelle@tamay-dogan.net
Received: from liszt.debian.org (liszt.debian.org [::ffff:82.195.75.100])
  by vserver1.tamay-dogan.net with esmtp; Mon, 20 Apr 2009 01:17:40 +0200
  id 00000A48.49EBB114.00005734

The question now is: WHY does preline add the header two times different?

Hmmm, have to ask the courier list...

Thanks, Greetings and nice Day/Evening
    Michelle Konzack
    Systemadministrator
    24V Electronic Engineer
    Tamay Dogan Network
    Debian GNU/Linux Consultant

-- 
Linux-User #280138 with the Linux Counter, http://counter.li.org/
##################### Debian GNU/Linux Consultant #####################
<http://www.tamay-dogan.net/>                 Michelle Konzack
<http://www.can4linux.org/>                   Apt. 917
<http://www.flexray4linux.org/>               50, rue de Soultz
Jabber linux4michelle@jabber.ccc.de           67100 Strasbourg/France
IRC #Debian (irc.icq.com)                     Tel. DE: +49 177 9351947
ICQ #328449886                                Tel. FR: +33  6  61925193

Re: spamassassin tags ALL messages as spam for unknown reason

Posted by John Hardin <jh...@impsec.org>.
On Tue, 21 Apr 2009, Michelle Konzack wrote:

> As you can see, "formail" has added the Delivered-To: header on the  top
> of the message, before the  "From_"  header  and  that  it  is  what  is
> corrupting the message.

That is very odd.

> Any suggestions?

Run the formail command in your procmail script.

:0 fhw
| formail -i "Delivered-To:"

-- 
  John Hardin KA7OHZ                    http://www.impsec.org/~jhardin/
  jhardin@impsec.org    FALaholic #11174     pgpk -a jhardin@impsec.org
  key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
-----------------------------------------------------------------------
   A sword is never a killer, it is but a tool in the killer's hands.
                           -- Lucius Annaeus Seneca (Martial) 4BC-65AD
-----------------------------------------------------------------------
  2 days until Max Planck's 151st birthday

Re: spamassassin tags ALL messages as spam for unknown reason

Posted by Michelle Konzack <li...@tamay-dogan.net>.
While investigating, I used now

  |/usr/bin/formail -i Delivered-To: |/usr/bin/preline /usr/bin/procmail

And checked the first message comeing in...

There is a weird problem with formail because if I add/remove  a  header
with "-I" or "-i" it append it to the END of the Headers,  but  NOT,  if
invocked by courier:

> Return-Path: <bo...@lists.debian.org>
> Delivered-To: xxxxxxxx.ml4michelle@tamay-dogan.net
> From debian-doc-request@lists.debian.org  Mon Apr 20 01:17:40 2009
> Received: from liszt.debian.org (liszt.debian.org [::ffff:82.195.75.100])
>   by vserver1.tamay-dogan.net with esmtp; Mon, 20 Apr 2009 01:17:40 +0200
>   id 00000A48.49EBB114.00005734

As you can see, "formail" has added the Delivered-To: header on the  top
of the message, before the  "From_"  header  and  that  it  is  what  is
corrupting the message.

Any suggestions?

Note:   If I invocke formail on the same message manualy
        on the commandline, it works perfectly.

Thanks, Greetings and nice Day/Evening
    Michelle Konzack
    Systemadministrator
    24V Electronic Engineer
    Tamay Dogan Network
    Debian GNU/Linux Consultant

-- 
Linux-User #280138 with the Linux Counter, http://counter.li.org/
##################### Debian GNU/Linux Consultant #####################
<http://www.tamay-dogan.net/>                 Michelle Konzack
<http://www.can4linux.org/>                   Apt. 917
<http://www.flexray4linux.org/>               50, rue de Soultz
Jabber linux4michelle@jabber.ccc.de           67100 Strasbourg/France
IRC #Debian (irc.icq.com)                     Tel. DE: +49 177 9351947
ICQ #328449886                                Tel. FR: +33  6  61925193