You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@spamassassin.apache.org by Anton Krall <ak...@intruder.com.mx> on 2004/11/06 17:11:15 UTC

Rules List

Guys.

I am using the following rules list but still a lot of spam is going thru..
Any extra rules you recommend adding?

70_sare_adult.cf             70_sare_header1.cf          70_sare_html3.cf
71_sare_bml_pre25x.cf
70_sare_bayes_poison_nxm.cf  70_sare_header2.cf          70_sare_html4.cf
71_sare_redirect_pre3.0.0.cf
70_sare_genlsubj.cf          70_sare_header3.cf          70_sare_html_arc.cf
72_sare_bml_post25x.cf
70_sare_genlsubj0.cf         70_sare_header_arc.cf       70_sare_html_eng.cf
72_sare_redirect_post3.0.0.cf
70_sare_genlsubj1.cf         70_sare_header_eng.cf       70_sare_html_x30.cf
99_sare_fraud_post25x.cf
70_sare_genlsubj2.cf         70_sare_header_x264_x30.cf  70_sare_oem.cf
99_sare_fraud_pre25x.cf
70_sare_genlsubj3.cf         70_sare_header_x30.cf       70_sare_random.cf
RulesDuJour
70_sare_genlsubj_arc.cf      70_sare_highrisk.cf         70_sare_specific.cf
antidrug.cf
70_sare_genlsubj_eng.cf      70_sare_html.cf             70_sare_spoof.cf
bigevil.cf
70_sare_genlsubj_x30.cf      70_sare_html0.cf            70_sare_unsub.cf
bogus-virus-warnings.cf
70_sare_header.cf            70_sare_html1.cf            70_sare_uri.cf
evilnumbers.cf
70_sare_header0.cf           70_sare_html2.cf            70_sc_top200.cf
rules_du_jour


Re: Rules List

Posted by Loren Wilton <lw...@earthlink.net>.
> So SURBL will work even if no .cf files are on any of the site rules or
> config dirs yet? How does SA know about URLs and where to check?

SA comes with a pile of config files as part of the normal install.  You
should certainly have the default SA config files installed.  Whether these
are the ones you are referring to on CPAN I can't say.  But I think you
should find a bunch of cf files probably in etc/mail/spamassassin.  The
surbl stuff will be in these rule files.

> Do you recommend still installing some rules like sare and such?

Some of the SARE rules have been subsumed into 3.0, but most haven't.  The
general rule is, if spam is leaking through, look to see if there is an
addon ruleset that can fix the problem.  If spam isn't leaking through,
generally don't bother.  Quite likely the sare general header, general
subject, bml, and fraud rules will help, as probably will some of the
others.  However, surbl does quite a good job all by itself.


> Also, do you know any rules that trap vicodin and some other drug spam?

Matt's antidrug rules are part of 3.0, so most of this stuff should be
caught by default.

        Loren


RE: Rules List

Posted by Anton Krall <ak...@intruder.com.mx>.
I think I got SURBL working since I see a lot of mails triggered as spam
with comments like URIBL_WS_SURBL

What I did is do a cpan SA3 install and on /root/.cpan/SA3.0/rules, copy all
the .cf files to my site rules dir, since it seems that SURBL is enabled and
net tests is enabled too... I guess by copying the default rules to my site
rules dir enabled the scores and everything else, here is a copy of the
rules I have in place:

   8 -rw-r--r--    1 root     root         6002 Nov  6 20:02 10_misc.cf
   4 -rw-r--r--    1 root     root         1602 Nov  6 20:02
20_anti_ratware.cf
  12 -rw-r--r--    1 root     root         8198 Nov  6 20:02
20_body_tests.cf
   4 -rw-r--r--    1 root     root         1613 Nov  6 20:02
20_compensate.cf
  12 -rw-r--r--    1 root     root        12083 Nov  6 20:02
20_dnsbl_tests.cf
  16 -rw-r--r--    1 root     root        15700 Nov  6 20:02 20_drugs.cf
  12 -rw-r--r--    1 root     root        11268 Nov  6 20:02
20_fake_helo_tests.cf
  28 -rw-r--r--    1 root     root        27699 Nov  6 20:02
20_head_tests.cf
  16 -rw-r--r--    1 root     root        15487 Nov  6 20:02
20_html_tests.cf
  12 -rw-r--r--    1 root     root        10939 Nov  6 20:02
20_meta_tests.cf
  24 -rw-r--r--    1 root     root        22099 Nov  6 20:02 20_phrases.cf
   8 -rw-r--r--    1 root     root         4966 Nov  6 20:02 20_porn.cf
  16 -rw-r--r--    1 root     root        14129 Nov  6 20:02 20_ratware.cf
   8 -rw-r--r--    1 root     root         5014 Nov  6 20:02 20_uri_tests.cf
   4 -rw-r--r--    1 root     root         2334 Nov  6 20:02 23_bayes.cf
  12 -rw-r--r--    1 root     root         9114 Nov  6 20:02
25_body_tests_es.cf
   4 -rw-r--r--    1 root     root         2735 Nov  6 20:02 25_hashcash.cf
   4 -rw-r--r--    1 root     root         2301 Nov  6 20:02 25_spf.cf
   8 -rw-r--r--    1 root     root         4700 Nov  6 20:02 25_uribl.cf
  56 -rw-r--r--    1 root     root        52290 Nov  6 20:02 30_text_de.cf
  40 -rw-r--r--    1 root     root        40682 Nov  6 20:02 30_text_fr.cf
  64 -rw-r--r--    1 root     root        57934 Nov  6 20:02 30_text_nl.cf
  36 -rw-r--r--    1 root     root        34800 Nov  6 20:02 30_text_pl.cf
  32 -rw-r--r--    1 root     root        29375 Nov  6 20:02 50_scores.cf
   8 -rw-r--r--    1 root     root         6884 Nov  6 20:02 60_whitelist.cf
   4 -rw-r--r--    1 root     root          342 Nov  6 20:02 local.cf
   4 -rw-r--r--    1 root     root         2671 Nov  6 20:02
regression_tests.cf

I only have the default rules in place, no other rules from rules_du_jour or
anything... Looks ok to you guys? Should I also put some rules_du_jour in
there?

CPU load is very low and nice :) and seems to be catching a lot of spam...  

-----Original Message-----
From: Jeff Chan [mailto:jeffc@surbl.org] 
Sent: Domingo, 07 de Noviembre de 2004 12:14 a.m.
To: Anton Krall
Cc: users@spamassassin.apache.org
Subject: Re: Rules List

On Saturday, November 6, 2004, 9:33:47 PM, Anton Krall wrote:
> So SURBL will work even if no .cf files are on any of the site rules 
> or config dirs yet? How does SA know about URLs and where to check?

> I see some files under cpan dirs and SA that show some rules about 
> SURBL so I thought they might need to be copied under 
> /usr/share/spamassassin, where my site rules are.

SURBLs are included in the default rules for SA 3.  If you've done a full,
default install, then the rules and scores are probably already installed.
Hopefully a CPAN install does that.  If you see rules like URIBL_OB_SURBL
being triggered then SURBLs are working.

> Do you recommend still installing some rules like sare and such? 

> Also, do you know any rules that trap vicodin and some other drug spam? 

Some of the SARE rules are useful for these.  To be honest, I don't have
recommendations about which ones to use.  But with SURBLs some are no longer
needed.  I'll let the SARE folks explain further, or you may want to search
the list archives about this. 

Jeff C.
--
Jeff Chan
mailto:jeffc@surbl.org
http://www.surbl.org/



Re: Rules List

Posted by Jeff Chan <je...@surbl.org>.
On Saturday, November 6, 2004, 9:33:47 PM, Anton Krall wrote:
> So SURBL will work even if no .cf files are on any of the site rules or
> config dirs yet? How does SA know about URLs and where to check? 

> I see some files under cpan dirs and SA that show some rules about SURBL so
> I thought they might need to be copied under /usr/share/spamassassin, where
> my site rules are.

SURBLs are included in the default rules for SA 3.  If you've
done a full, default install, then the rules and scores are
probably already installed.  Hopefully a CPAN install does
that.  If you see rules like URIBL_OB_SURBL being triggered
then SURBLs are working.

> Do you recommend still installing some rules like sare and such? 

> Also, do you know any rules that trap vicodin and some other drug spam? 

Some of the SARE rules are useful for these.  To be honest, I
don't have recommendations about which ones to use.  But with
SURBLs some are no longer needed.  I'll let the SARE folks
explain further, or you may want to search the list archives
about this. 

Jeff C.
-- 
Jeff Chan
mailto:jeffc@surbl.org
http://www.surbl.org/


RE: Rules List

Posted by Anton Krall <ak...@intruder.com.mx>.
So SURBL will work even if no .cf files are on any of the site rules or
config dirs yet? How does SA know about URLs and where to check? 

I see some files under cpan dirs and SA that show some rules about SURBL so
I thought they might need to be copied under /usr/share/spamassassin, where
my site rules are.

Do you recommend still installing some rules like sare and such? 

Also, do you know any rules that trap vicodin and some other drug spam? 

-----Original Message-----
From: Jeff Chan [mailto:jeffc@surbl.org] 
Sent: Sábado, 06 de Noviembre de 2004 11:23 p.m.
To: users@spamassassin.apache.org
Subject: Re: Rules List

On Saturday, November 6, 2004, 8:41:00 PM, Anton Krall wrote:
> I just upgraded to 3.0 and using amavisd-new... I removed the old 2.6 
> rules and left only 3.0 .. Also, seems 3.0 has builtin support for 
> SURBL and its enabled but I was wondering, since I upgraded using 
> CPAN, should I copy the rules on /root/.cpan/SA3.0/rules/*.cf to the 
> site rules dir to enalble SURBL rules?

> How do I go about setting this up nicely?

SURBLs are supported by default in 3.0.  You don't need to copy
any rules or configs.   All you need to do is have a current
Net::DNS and make sure network tests are enabled.

  http://www.surbl.org/faq.html#nettest

You probably should add a rule for JP however:

urirhssub URIBL_JP_SURBL  multi.surbl.org.        A   64
body      URIBL_JP_SURBL  eval:check_uridnsbl('URIBL_JP_SURBL')
describe  URIBL_JP_SURBL  Has URI in JP at http://www.surbl.org/lists.html
tflags    URIBL_JP_SURBL  net

score URIBL_JP_SURBL    4.0

See:

  http://www.surbl.org/

Jeff C.
--
Jeff Chan
mailto:jeffc@surbl.org
http://www.surbl.org/



Re: Rules List

Posted by Jeff Chan <je...@surbl.org>.
On Saturday, November 6, 2004, 8:41:00 PM, Anton Krall wrote:
> I just upgraded to 3.0 and using amavisd-new... I removed the old 2.6 rules
> and left only 3.0 .. Also, seems 3.0 has builtin support for SURBL and its
> enabled but I was wondering, since I upgraded using CPAN, should I copy the
> rules on /root/.cpan/SA3.0/rules/*.cf to the site rules dir to enalble SURBL
> rules?

> How do I go about setting this up nicely?

SURBLs are supported by default in 3.0.  You don't need to copy
any rules or configs.   All you need to do is have a current
Net::DNS and make sure network tests are enabled.

  http://www.surbl.org/faq.html#nettest

You probably should add a rule for JP however:

urirhssub URIBL_JP_SURBL  multi.surbl.org.        A   64
body      URIBL_JP_SURBL  eval:check_uridnsbl('URIBL_JP_SURBL')
describe  URIBL_JP_SURBL  Has URI in JP at http://www.surbl.org/lists.html
tflags    URIBL_JP_SURBL  net

score URIBL_JP_SURBL    4.0

See:

  http://www.surbl.org/

Jeff C.
-- 
Jeff Chan
mailto:jeffc@surbl.org
http://www.surbl.org/


Re: Rules List

Posted by Loren Wilton <lw...@earthlink.net>.
> I just upgraded to 3.0 and using amavisd-new... I removed the old 2.6
rules

Then you need to delete the pre25x, pre30 type rules.

> enabled but I was wondering, since I upgraded using CPAN, should I copy
the
> rules on /root/.cpan/SA3.0/rules/*.cf to the site rules dir to enalble
SURBL
> rules?

Can't help you there, I have no idea what those rules files would be.


> How do I go about setting this up nicely?

For surbl you need to make sure you have enough stuff installed that you can
successfully do net tests.  Then I believe you have to enable the surbl
plugin in plugins.cf or some such.  (I may be wrong, it may be enabled
already.)  I think you may also have to track down the surbl rules and
enable them, but again I'm not sure.  They will be in one of the stock 3.0
config files somewhere.

But first make sure you have net tests working, or surbl won't do anything
for you.  This requires some optional pieces that you may not have
installed.  I believe spamassassin -D --lint will show you what you do and
don't have installed and enabled.

        Loren


RE: Rules List

Posted by Anton Krall <ak...@intruder.com.mx>.
Loren.

I just upgraded to 3.0 and using amavisd-new... I removed the old 2.6 rules
and left only 3.0 .. Also, seems 3.0 has builtin support for SURBL and its
enabled but I was wondering, since I upgraded using CPAN, should I copy the
rules on /root/.cpan/SA3.0/rules/*.cf to the site rules dir to enalble SURBL
rules?

How do I go about setting this up nicely?

-----Original Message-----
From: Loren Wilton [mailto:lwilton@earthlink.net] 
Sent: Sábado, 06 de Noviembre de 2004 09:14 p.m.
To: users@spamassassin.apache.org
Subject: Re: Rules List

> Im using 3.0.. How do I get a hold of  SURBLs ? Im still getting a lot 
> of the vicodin and medicine spam mail :(

> > 71_sare_bml_pre25x.cf
> > 71_sare_redirect_pre3.0.0.cf
> > 72_sare_redirect_post3.0.0.cf
> 70_sare_html_x30.cf
> > 99_sare_fraud_post25x.cf
> > 70_sare_header_x264_x30.cf
> > 99_sare_fraud_pre25x.cf
> > 70_sare_header_x30.cf
> > 70_sare_genlsubj_x30.cf

Notice anything interesting about the file names I left in the list above?
They all have SA version numbers, indicating which SA versions they apply
to.
I absolutely guarantee that no matter which SA version you are running, at
least one of those files is inappropriate.

Please go back to www.rulesemporium.com/rules and READ the descriptions of
the rule files, and then select the ones that are and ARE NOT appropriate
for your configuration.  Delete those that ARE NOT appropriate, as a start.

        Loren



Re: Rules List

Posted by Loren Wilton <lw...@earthlink.net>.
> Im using 3.0.. How do I get a hold of  SURBLs ? Im still getting a lot of
> the vicodin and medicine spam mail :(

> > 71_sare_bml_pre25x.cf
> > 71_sare_redirect_pre3.0.0.cf
> > 72_sare_redirect_post3.0.0.cf
> 70_sare_html_x30.cf
> > 99_sare_fraud_post25x.cf
> > 70_sare_header_x264_x30.cf
> > 99_sare_fraud_pre25x.cf
> > 70_sare_header_x30.cf
> > 70_sare_genlsubj_x30.cf

Notice anything interesting about the file names I left in the list above?
They all have SA version numbers, indicating which SA versions they apply
to.
I absolutely guarantee that no matter which SA version you are running, at
least one of those files is inappropriate.

Please go back to www.rulesemporium.com/rules and READ the descriptions of
the rule files, and then select the ones that are and ARE NOT appropriate
for your configuration.  Delete those that ARE NOT appropriate, as a start.

        Loren


RE: Rules List

Posted by Anton Krall <ak...@intruder.com.mx>.
Is this ok?

/root/.cpan/build/Mail-SpamAssassin-3.0.1/rules/init.pre 

-----Original Message-----
From: Michele Neylon::Blacknight Solutions
[mailto:michele@blacknightsolutions.com] 
Sent: Sábado, 06 de Noviembre de 2004 02:03 p.m.
To: Anton Krall
Cc: rakesh@netcore.co.in; users@spamassassin.apache.org
Subject: RE: Rules List

On Sat, 2004-11-06 at 13:57 -0600, Anton Krall wrote:
> Im using 3.0.. How do I get a hold of  SURBLs ? Im still getting a lot 
> of the vicodin and medicine spam mail :(

SURBL is a plugin. Look in your init.pre


--
 Mr. Michele Neylon
Blacknight Solutions
Hosting, Co-location & Domain Registration http://www.blacknight.ie/ Tel.
+353 (0)59 9137101


-- 
Email scanned by Blacknight for viruses and dangerous content.
Visit http://www.blacknight.ie for more information



RE: Rules List

Posted by "Michele Neylon::Blacknight Solutions" <mi...@blacknightsolutions.com>.
On Sat, 2004-11-06 at 13:57 -0600, Anton Krall wrote:
> Im using 3.0.. How do I get a hold of  SURBLs ? Im still getting a lot of
> the vicodin and medicine spam mail :(

SURBL is a plugin. Look in your init.pre


-- 
 Mr. Michele Neylon
Blacknight Solutions
Hosting, Co-location & Domain Registration
http://www.blacknight.ie/
Tel. +353 (0)59 9137101


-- 
Email scanned by Blacknight for viruses and dangerous content.
Visit http://www.blacknight.ie for more information


RE: Rules List

Posted by Anton Krall <ak...@intruder.com.mx>.
Im using 3.0.. How do I get a hold of  SURBLs ? Im still getting a lot of
the vicodin and medicine spam mail :(

-----Original Message-----
From: Rakesh [mailto:rakesh@netcore.co.in] 
Sent: Sábado, 06 de Noviembre de 2004 10:29 a.m.
To: Anton Krall
Cc: users@spamassassin.apache.org
Subject: Re: Rules List

hii,

which version of spamassassin are you using ? I would recommend to remove
uri rulesets like bigevil and sare URI and use SURBLs instead, tht will help
you to get rid of great deal of spams. If you are using older version of
spamassassin like 2.63 then you will have to install the SpamCop URI plugin
or else upgrade to Spamassassin 3.x. Also try to use dcc and razor if you
are not using tht.

Rakesh

On Sat, 2004-11-06 at 21:41, Anton Krall wrote:
> Guys.
> 
> I am using the following rules list but still a lot of spam is going
thru..
> Any extra rules you recommend adding?
> 
> 70_sare_adult.cf             70_sare_header1.cf          70_sare_html3.cf
> 71_sare_bml_pre25x.cf
> 70_sare_bayes_poison_nxm.cf  70_sare_header2.cf          70_sare_html4.cf
> 71_sare_redirect_pre3.0.0.cf
> 70_sare_genlsubj.cf          70_sare_header3.cf
70_sare_html_arc.cf
> 72_sare_bml_post25x.cf
> 70_sare_genlsubj0.cf         70_sare_header_arc.cf
70_sare_html_eng.cf
> 72_sare_redirect_post3.0.0.cf
> 70_sare_genlsubj1.cf         70_sare_header_eng.cf
70_sare_html_x30.cf
> 99_sare_fraud_post25x.cf
> 70_sare_genlsubj2.cf         70_sare_header_x264_x30.cf  70_sare_oem.cf
> 99_sare_fraud_pre25x.cf
> 70_sare_genlsubj3.cf         70_sare_header_x30.cf       70_sare_random.cf
> RulesDuJour
> 70_sare_genlsubj_arc.cf      70_sare_highrisk.cf
70_sare_specific.cf
> antidrug.cf
> 70_sare_genlsubj_eng.cf      70_sare_html.cf             70_sare_spoof.cf
> bigevil.cf
> 70_sare_genlsubj_x30.cf      70_sare_html0.cf            70_sare_unsub.cf
> bogus-virus-warnings.cf
> 70_sare_header.cf            70_sare_html1.cf            70_sare_uri.cf
> evilnumbers.cf
> 70_sare_header0.cf           70_sare_html2.cf            70_sc_top200.cf
> rules_du_jour
> 



Re: Rules List

Posted by Rakesh <ra...@netcore.co.in>.
hii,

which version of spamassassin are you using ? I would recommend to
remove uri rulesets like bigevil and sare URI and use SURBLs instead,
tht will help you to get rid of great deal of spams. If you are using
older version of spamassassin like 2.63 then you will have to install
the SpamCop URI plugin or else upgrade to Spamassassin 3.x. Also try to
use dcc and razor if you are not using tht.

Rakesh

On Sat, 2004-11-06 at 21:41, Anton Krall wrote:
> Guys.
> 
> I am using the following rules list but still a lot of spam is going thru..
> Any extra rules you recommend adding?
> 
> 70_sare_adult.cf             70_sare_header1.cf          70_sare_html3.cf
> 71_sare_bml_pre25x.cf
> 70_sare_bayes_poison_nxm.cf  70_sare_header2.cf          70_sare_html4.cf
> 71_sare_redirect_pre3.0.0.cf
> 70_sare_genlsubj.cf          70_sare_header3.cf          70_sare_html_arc.cf
> 72_sare_bml_post25x.cf
> 70_sare_genlsubj0.cf         70_sare_header_arc.cf       70_sare_html_eng.cf
> 72_sare_redirect_post3.0.0.cf
> 70_sare_genlsubj1.cf         70_sare_header_eng.cf       70_sare_html_x30.cf
> 99_sare_fraud_post25x.cf
> 70_sare_genlsubj2.cf         70_sare_header_x264_x30.cf  70_sare_oem.cf
> 99_sare_fraud_pre25x.cf
> 70_sare_genlsubj3.cf         70_sare_header_x30.cf       70_sare_random.cf
> RulesDuJour
> 70_sare_genlsubj_arc.cf      70_sare_highrisk.cf         70_sare_specific.cf
> antidrug.cf
> 70_sare_genlsubj_eng.cf      70_sare_html.cf             70_sare_spoof.cf
> bigevil.cf
> 70_sare_genlsubj_x30.cf      70_sare_html0.cf            70_sare_unsub.cf
> bogus-virus-warnings.cf
> 70_sare_header.cf            70_sare_html1.cf            70_sare_uri.cf
> evilnumbers.cf
> 70_sare_header0.cf           70_sare_html2.cf            70_sc_top200.cf
> rules_du_jour
> 


RE: Rules List

Posted by Raymond Dijkxhoorn <ra...@prolocation.net>.
Hi!

> What can I use those instead of the lists Im using? Any urls for more info?
> Will using SURBL's  sllow me to remove all the other cf and just use SURBL's
> ?

> What version SA are you using. I dont think you are using SURBL's right now.
> I think that will get you going a lot better then the gazillion lists you
> have loaded now. Also will cut down CPU and RAM usage on your machine a lit.

You can use whatever you like, if its smart, thats a completely different 
question. If you run SURBL you can get out a lot of the seperate .cf 
files, for example bigevil.

Bye,
Raymond.

RE: Rules List

Posted by Anton Krall <ak...@intruder.com.mx>.
What can I use those instead of the lists Im using? Any urls for more info?
Will using SURBL's  sllow me to remove all the other cf and just use SURBL's
? 

-----Original Message-----
From: Raymond Dijkxhoorn [mailto:raymond@prolocation.net] 
Sent: Sábado, 06 de Noviembre de 2004 12:23 p.m.
To: Anton Krall
Cc: users@spamassassin.apache.org
Subject: Re: Rules List

Hi!

>
> I am using the following rules list but still a lot of spam is going
thru..
> Any extra rules you recommend adding?
>
> 70_sare_adult.cf             70_sare_header1.cf          70_sare_html3.cf
> 71_sare_bml_pre25x.cf
> 70_sare_bayes_poison_nxm.cf  70_sare_header2.cf          70_sare_html4.cf
> 71_sare_redirect_pre3.0.0.cf
> 70_sare_genlsubj.cf          70_sare_header3.cf
70_sare_html_arc.cf
> 72_sare_bml_post25x.cf
> 70_sare_genlsubj0.cf         70_sare_header_arc.cf
70_sare_html_eng.cf
> 72_sare_redirect_post3.0.0.cf
> 70_sare_genlsubj1.cf         70_sare_header_eng.cf
70_sare_html_x30.cf
> 99_sare_fraud_post25x.cf
> 70_sare_genlsubj2.cf         70_sare_header_x264_x30.cf  70_sare_oem.cf
> 99_sare_fraud_pre25x.cf
> 70_sare_genlsubj3.cf         70_sare_header_x30.cf       70_sare_random.cf
> RulesDuJour
> 70_sare_genlsubj_arc.cf      70_sare_highrisk.cf
70_sare_specific.cf
> antidrug.cf
> 70_sare_genlsubj_eng.cf      70_sare_html.cf             70_sare_spoof.cf
> bigevil.cf

Bigevil?

What version SA are you using. I dont think you are using SURBL's right now.
I think that will get you going a lot better then the gazillion lists you
have loaded now. Also will cut down CPU and RAM usage on your machine a lit.

Bye,
Raymond.


RE: Rules List

Posted by Anton Krall <ak...@intruder.com.mx>.
BTW I just upgraded to 3.0 and using rules_du_jour 

-----Original Message-----
From: Raymond Dijkxhoorn [mailto:raymond@prolocation.net] 
Sent: Sábado, 06 de Noviembre de 2004 12:23 p.m.
To: Anton Krall
Cc: users@spamassassin.apache.org
Subject: Re: Rules List

Hi!

>
> I am using the following rules list but still a lot of spam is going
thru..
> Any extra rules you recommend adding?
>
> 70_sare_adult.cf             70_sare_header1.cf          70_sare_html3.cf
> 71_sare_bml_pre25x.cf
> 70_sare_bayes_poison_nxm.cf  70_sare_header2.cf          70_sare_html4.cf
> 71_sare_redirect_pre3.0.0.cf
> 70_sare_genlsubj.cf          70_sare_header3.cf
70_sare_html_arc.cf
> 72_sare_bml_post25x.cf
> 70_sare_genlsubj0.cf         70_sare_header_arc.cf
70_sare_html_eng.cf
> 72_sare_redirect_post3.0.0.cf
> 70_sare_genlsubj1.cf         70_sare_header_eng.cf
70_sare_html_x30.cf
> 99_sare_fraud_post25x.cf
> 70_sare_genlsubj2.cf         70_sare_header_x264_x30.cf  70_sare_oem.cf
> 99_sare_fraud_pre25x.cf
> 70_sare_genlsubj3.cf         70_sare_header_x30.cf       70_sare_random.cf
> RulesDuJour
> 70_sare_genlsubj_arc.cf      70_sare_highrisk.cf
70_sare_specific.cf
> antidrug.cf
> 70_sare_genlsubj_eng.cf      70_sare_html.cf             70_sare_spoof.cf
> bigevil.cf

Bigevil?

What version SA are you using. I dont think you are using SURBL's right now.
I think that will get you going a lot better then the gazillion lists you
have loaded now. Also will cut down CPU and RAM usage on your machine a lit.

Bye,
Raymond.


Re: Rules List

Posted by Raymond Dijkxhoorn <ra...@prolocation.net>.
Hi!

>
> I am using the following rules list but still a lot of spam is going thru..
> Any extra rules you recommend adding?
>
> 70_sare_adult.cf             70_sare_header1.cf          70_sare_html3.cf
> 71_sare_bml_pre25x.cf
> 70_sare_bayes_poison_nxm.cf  70_sare_header2.cf          70_sare_html4.cf
> 71_sare_redirect_pre3.0.0.cf
> 70_sare_genlsubj.cf          70_sare_header3.cf          70_sare_html_arc.cf
> 72_sare_bml_post25x.cf
> 70_sare_genlsubj0.cf         70_sare_header_arc.cf       70_sare_html_eng.cf
> 72_sare_redirect_post3.0.0.cf
> 70_sare_genlsubj1.cf         70_sare_header_eng.cf       70_sare_html_x30.cf
> 99_sare_fraud_post25x.cf
> 70_sare_genlsubj2.cf         70_sare_header_x264_x30.cf  70_sare_oem.cf
> 99_sare_fraud_pre25x.cf
> 70_sare_genlsubj3.cf         70_sare_header_x30.cf       70_sare_random.cf
> RulesDuJour
> 70_sare_genlsubj_arc.cf      70_sare_highrisk.cf         70_sare_specific.cf
> antidrug.cf
> 70_sare_genlsubj_eng.cf      70_sare_html.cf             70_sare_spoof.cf
> bigevil.cf

Bigevil?

What version SA are you using. I dont think you are using SURBL's right 
now. I think that will get you going a lot better then the gazillion lists 
you have loaded now. Also will cut down CPU and RAM usage on your machine 
a lit.

Bye,
Raymond.

RE: Rules List

Posted by "Michele Neylon :: Blacknight Solutions" <mi...@blacknightsolutions.com>.
Get rid of bigevil immediately!! It is no longer updated and kills servers
:)

If you are still running the 2.6* series use spamcop uri to add support for
SURBL





Mr Michele Neylon
Blacknight Internet Solutions Ltd
Hosting, co-location & domains
http://www.blacknight.ie/
Tel. +353 59 9137101
Proud sponsors of MM04 {http://www.mm04.net}


-- 
Email scanned by Blacknight for viruses and dangerous content.
Visit http://www.blacknight.ie for more information