You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@spamassassin.apache.org by Anton Krall <ak...@intruder.com.mx> on 2004/11/06 17:11:15 UTC
Rules List
Guys.
I am using the following rules list but still a lot of spam is going thru..
Any extra rules you recommend adding?
70_sare_adult.cf 70_sare_header1.cf 70_sare_html3.cf
71_sare_bml_pre25x.cf
70_sare_bayes_poison_nxm.cf 70_sare_header2.cf 70_sare_html4.cf
71_sare_redirect_pre3.0.0.cf
70_sare_genlsubj.cf 70_sare_header3.cf 70_sare_html_arc.cf
72_sare_bml_post25x.cf
70_sare_genlsubj0.cf 70_sare_header_arc.cf 70_sare_html_eng.cf
72_sare_redirect_post3.0.0.cf
70_sare_genlsubj1.cf 70_sare_header_eng.cf 70_sare_html_x30.cf
99_sare_fraud_post25x.cf
70_sare_genlsubj2.cf 70_sare_header_x264_x30.cf 70_sare_oem.cf
99_sare_fraud_pre25x.cf
70_sare_genlsubj3.cf 70_sare_header_x30.cf 70_sare_random.cf
RulesDuJour
70_sare_genlsubj_arc.cf 70_sare_highrisk.cf 70_sare_specific.cf
antidrug.cf
70_sare_genlsubj_eng.cf 70_sare_html.cf 70_sare_spoof.cf
bigevil.cf
70_sare_genlsubj_x30.cf 70_sare_html0.cf 70_sare_unsub.cf
bogus-virus-warnings.cf
70_sare_header.cf 70_sare_html1.cf 70_sare_uri.cf
evilnumbers.cf
70_sare_header0.cf 70_sare_html2.cf 70_sc_top200.cf
rules_du_jour
Re: Rules List
Posted by Loren Wilton <lw...@earthlink.net>.
> So SURBL will work even if no .cf files are on any of the site rules or
> config dirs yet? How does SA know about URLs and where to check?
SA comes with a pile of config files as part of the normal install. You
should certainly have the default SA config files installed. Whether these
are the ones you are referring to on CPAN I can't say. But I think you
should find a bunch of cf files probably in etc/mail/spamassassin. The
surbl stuff will be in these rule files.
> Do you recommend still installing some rules like sare and such?
Some of the SARE rules have been subsumed into 3.0, but most haven't. The
general rule is, if spam is leaking through, look to see if there is an
addon ruleset that can fix the problem. If spam isn't leaking through,
generally don't bother. Quite likely the sare general header, general
subject, bml, and fraud rules will help, as probably will some of the
others. However, surbl does quite a good job all by itself.
> Also, do you know any rules that trap vicodin and some other drug spam?
Matt's antidrug rules are part of 3.0, so most of this stuff should be
caught by default.
Loren
RE: Rules List
Posted by Anton Krall <ak...@intruder.com.mx>.
I think I got SURBL working since I see a lot of mails triggered as spam
with comments like URIBL_WS_SURBL
What I did is do a cpan SA3 install and on /root/.cpan/SA3.0/rules, copy all
the .cf files to my site rules dir, since it seems that SURBL is enabled and
net tests is enabled too... I guess by copying the default rules to my site
rules dir enabled the scores and everything else, here is a copy of the
rules I have in place:
8 -rw-r--r-- 1 root root 6002 Nov 6 20:02 10_misc.cf
4 -rw-r--r-- 1 root root 1602 Nov 6 20:02
20_anti_ratware.cf
12 -rw-r--r-- 1 root root 8198 Nov 6 20:02
20_body_tests.cf
4 -rw-r--r-- 1 root root 1613 Nov 6 20:02
20_compensate.cf
12 -rw-r--r-- 1 root root 12083 Nov 6 20:02
20_dnsbl_tests.cf
16 -rw-r--r-- 1 root root 15700 Nov 6 20:02 20_drugs.cf
12 -rw-r--r-- 1 root root 11268 Nov 6 20:02
20_fake_helo_tests.cf
28 -rw-r--r-- 1 root root 27699 Nov 6 20:02
20_head_tests.cf
16 -rw-r--r-- 1 root root 15487 Nov 6 20:02
20_html_tests.cf
12 -rw-r--r-- 1 root root 10939 Nov 6 20:02
20_meta_tests.cf
24 -rw-r--r-- 1 root root 22099 Nov 6 20:02 20_phrases.cf
8 -rw-r--r-- 1 root root 4966 Nov 6 20:02 20_porn.cf
16 -rw-r--r-- 1 root root 14129 Nov 6 20:02 20_ratware.cf
8 -rw-r--r-- 1 root root 5014 Nov 6 20:02 20_uri_tests.cf
4 -rw-r--r-- 1 root root 2334 Nov 6 20:02 23_bayes.cf
12 -rw-r--r-- 1 root root 9114 Nov 6 20:02
25_body_tests_es.cf
4 -rw-r--r-- 1 root root 2735 Nov 6 20:02 25_hashcash.cf
4 -rw-r--r-- 1 root root 2301 Nov 6 20:02 25_spf.cf
8 -rw-r--r-- 1 root root 4700 Nov 6 20:02 25_uribl.cf
56 -rw-r--r-- 1 root root 52290 Nov 6 20:02 30_text_de.cf
40 -rw-r--r-- 1 root root 40682 Nov 6 20:02 30_text_fr.cf
64 -rw-r--r-- 1 root root 57934 Nov 6 20:02 30_text_nl.cf
36 -rw-r--r-- 1 root root 34800 Nov 6 20:02 30_text_pl.cf
32 -rw-r--r-- 1 root root 29375 Nov 6 20:02 50_scores.cf
8 -rw-r--r-- 1 root root 6884 Nov 6 20:02 60_whitelist.cf
4 -rw-r--r-- 1 root root 342 Nov 6 20:02 local.cf
4 -rw-r--r-- 1 root root 2671 Nov 6 20:02
regression_tests.cf
I only have the default rules in place, no other rules from rules_du_jour or
anything... Looks ok to you guys? Should I also put some rules_du_jour in
there?
CPU load is very low and nice :) and seems to be catching a lot of spam...
-----Original Message-----
From: Jeff Chan [mailto:jeffc@surbl.org]
Sent: Domingo, 07 de Noviembre de 2004 12:14 a.m.
To: Anton Krall
Cc: users@spamassassin.apache.org
Subject: Re: Rules List
On Saturday, November 6, 2004, 9:33:47 PM, Anton Krall wrote:
> So SURBL will work even if no .cf files are on any of the site rules
> or config dirs yet? How does SA know about URLs and where to check?
> I see some files under cpan dirs and SA that show some rules about
> SURBL so I thought they might need to be copied under
> /usr/share/spamassassin, where my site rules are.
SURBLs are included in the default rules for SA 3. If you've done a full,
default install, then the rules and scores are probably already installed.
Hopefully a CPAN install does that. If you see rules like URIBL_OB_SURBL
being triggered then SURBLs are working.
> Do you recommend still installing some rules like sare and such?
> Also, do you know any rules that trap vicodin and some other drug spam?
Some of the SARE rules are useful for these. To be honest, I don't have
recommendations about which ones to use. But with SURBLs some are no longer
needed. I'll let the SARE folks explain further, or you may want to search
the list archives about this.
Jeff C.
--
Jeff Chan
mailto:jeffc@surbl.org
http://www.surbl.org/
Re: Rules List
Posted by Jeff Chan <je...@surbl.org>.
On Saturday, November 6, 2004, 9:33:47 PM, Anton Krall wrote:
> So SURBL will work even if no .cf files are on any of the site rules or
> config dirs yet? How does SA know about URLs and where to check?
> I see some files under cpan dirs and SA that show some rules about SURBL so
> I thought they might need to be copied under /usr/share/spamassassin, where
> my site rules are.
SURBLs are included in the default rules for SA 3. If you've
done a full, default install, then the rules and scores are
probably already installed. Hopefully a CPAN install does
that. If you see rules like URIBL_OB_SURBL being triggered
then SURBLs are working.
> Do you recommend still installing some rules like sare and such?
> Also, do you know any rules that trap vicodin and some other drug spam?
Some of the SARE rules are useful for these. To be honest, I
don't have recommendations about which ones to use. But with
SURBLs some are no longer needed. I'll let the SARE folks
explain further, or you may want to search the list archives
about this.
Jeff C.
--
Jeff Chan
mailto:jeffc@surbl.org
http://www.surbl.org/
RE: Rules List
Posted by Anton Krall <ak...@intruder.com.mx>.
So SURBL will work even if no .cf files are on any of the site rules or
config dirs yet? How does SA know about URLs and where to check?
I see some files under cpan dirs and SA that show some rules about SURBL so
I thought they might need to be copied under /usr/share/spamassassin, where
my site rules are.
Do you recommend still installing some rules like sare and such?
Also, do you know any rules that trap vicodin and some other drug spam?
-----Original Message-----
From: Jeff Chan [mailto:jeffc@surbl.org]
Sent: Sábado, 06 de Noviembre de 2004 11:23 p.m.
To: users@spamassassin.apache.org
Subject: Re: Rules List
On Saturday, November 6, 2004, 8:41:00 PM, Anton Krall wrote:
> I just upgraded to 3.0 and using amavisd-new... I removed the old 2.6
> rules and left only 3.0 .. Also, seems 3.0 has builtin support for
> SURBL and its enabled but I was wondering, since I upgraded using
> CPAN, should I copy the rules on /root/.cpan/SA3.0/rules/*.cf to the
> site rules dir to enalble SURBL rules?
> How do I go about setting this up nicely?
SURBLs are supported by default in 3.0. You don't need to copy
any rules or configs. All you need to do is have a current
Net::DNS and make sure network tests are enabled.
http://www.surbl.org/faq.html#nettest
You probably should add a rule for JP however:
urirhssub URIBL_JP_SURBL multi.surbl.org. A 64
body URIBL_JP_SURBL eval:check_uridnsbl('URIBL_JP_SURBL')
describe URIBL_JP_SURBL Has URI in JP at http://www.surbl.org/lists.html
tflags URIBL_JP_SURBL net
score URIBL_JP_SURBL 4.0
See:
http://www.surbl.org/
Jeff C.
--
Jeff Chan
mailto:jeffc@surbl.org
http://www.surbl.org/
Re: Rules List
Posted by Jeff Chan <je...@surbl.org>.
On Saturday, November 6, 2004, 8:41:00 PM, Anton Krall wrote:
> I just upgraded to 3.0 and using amavisd-new... I removed the old 2.6 rules
> and left only 3.0 .. Also, seems 3.0 has builtin support for SURBL and its
> enabled but I was wondering, since I upgraded using CPAN, should I copy the
> rules on /root/.cpan/SA3.0/rules/*.cf to the site rules dir to enalble SURBL
> rules?
> How do I go about setting this up nicely?
SURBLs are supported by default in 3.0. You don't need to copy
any rules or configs. All you need to do is have a current
Net::DNS and make sure network tests are enabled.
http://www.surbl.org/faq.html#nettest
You probably should add a rule for JP however:
urirhssub URIBL_JP_SURBL multi.surbl.org. A 64
body URIBL_JP_SURBL eval:check_uridnsbl('URIBL_JP_SURBL')
describe URIBL_JP_SURBL Has URI in JP at http://www.surbl.org/lists.html
tflags URIBL_JP_SURBL net
score URIBL_JP_SURBL 4.0
See:
http://www.surbl.org/
Jeff C.
--
Jeff Chan
mailto:jeffc@surbl.org
http://www.surbl.org/
Re: Rules List
Posted by Loren Wilton <lw...@earthlink.net>.
> I just upgraded to 3.0 and using amavisd-new... I removed the old 2.6
rules
Then you need to delete the pre25x, pre30 type rules.
> enabled but I was wondering, since I upgraded using CPAN, should I copy
the
> rules on /root/.cpan/SA3.0/rules/*.cf to the site rules dir to enalble
SURBL
> rules?
Can't help you there, I have no idea what those rules files would be.
> How do I go about setting this up nicely?
For surbl you need to make sure you have enough stuff installed that you can
successfully do net tests. Then I believe you have to enable the surbl
plugin in plugins.cf or some such. (I may be wrong, it may be enabled
already.) I think you may also have to track down the surbl rules and
enable them, but again I'm not sure. They will be in one of the stock 3.0
config files somewhere.
But first make sure you have net tests working, or surbl won't do anything
for you. This requires some optional pieces that you may not have
installed. I believe spamassassin -D --lint will show you what you do and
don't have installed and enabled.
Loren
RE: Rules List
Posted by Anton Krall <ak...@intruder.com.mx>.
Loren.
I just upgraded to 3.0 and using amavisd-new... I removed the old 2.6 rules
and left only 3.0 .. Also, seems 3.0 has builtin support for SURBL and its
enabled but I was wondering, since I upgraded using CPAN, should I copy the
rules on /root/.cpan/SA3.0/rules/*.cf to the site rules dir to enalble SURBL
rules?
How do I go about setting this up nicely?
-----Original Message-----
From: Loren Wilton [mailto:lwilton@earthlink.net]
Sent: Sábado, 06 de Noviembre de 2004 09:14 p.m.
To: users@spamassassin.apache.org
Subject: Re: Rules List
> Im using 3.0.. How do I get a hold of SURBLs ? Im still getting a lot
> of the vicodin and medicine spam mail :(
> > 71_sare_bml_pre25x.cf
> > 71_sare_redirect_pre3.0.0.cf
> > 72_sare_redirect_post3.0.0.cf
> 70_sare_html_x30.cf
> > 99_sare_fraud_post25x.cf
> > 70_sare_header_x264_x30.cf
> > 99_sare_fraud_pre25x.cf
> > 70_sare_header_x30.cf
> > 70_sare_genlsubj_x30.cf
Notice anything interesting about the file names I left in the list above?
They all have SA version numbers, indicating which SA versions they apply
to.
I absolutely guarantee that no matter which SA version you are running, at
least one of those files is inappropriate.
Please go back to www.rulesemporium.com/rules and READ the descriptions of
the rule files, and then select the ones that are and ARE NOT appropriate
for your configuration. Delete those that ARE NOT appropriate, as a start.
Loren
Re: Rules List
Posted by Loren Wilton <lw...@earthlink.net>.
> Im using 3.0.. How do I get a hold of SURBLs ? Im still getting a lot of
> the vicodin and medicine spam mail :(
> > 71_sare_bml_pre25x.cf
> > 71_sare_redirect_pre3.0.0.cf
> > 72_sare_redirect_post3.0.0.cf
> 70_sare_html_x30.cf
> > 99_sare_fraud_post25x.cf
> > 70_sare_header_x264_x30.cf
> > 99_sare_fraud_pre25x.cf
> > 70_sare_header_x30.cf
> > 70_sare_genlsubj_x30.cf
Notice anything interesting about the file names I left in the list above?
They all have SA version numbers, indicating which SA versions they apply
to.
I absolutely guarantee that no matter which SA version you are running, at
least one of those files is inappropriate.
Please go back to www.rulesemporium.com/rules and READ the descriptions of
the rule files, and then select the ones that are and ARE NOT appropriate
for your configuration. Delete those that ARE NOT appropriate, as a start.
Loren
RE: Rules List
Posted by Anton Krall <ak...@intruder.com.mx>.
Is this ok?
/root/.cpan/build/Mail-SpamAssassin-3.0.1/rules/init.pre
-----Original Message-----
From: Michele Neylon::Blacknight Solutions
[mailto:michele@blacknightsolutions.com]
Sent: Sábado, 06 de Noviembre de 2004 02:03 p.m.
To: Anton Krall
Cc: rakesh@netcore.co.in; users@spamassassin.apache.org
Subject: RE: Rules List
On Sat, 2004-11-06 at 13:57 -0600, Anton Krall wrote:
> Im using 3.0.. How do I get a hold of SURBLs ? Im still getting a lot
> of the vicodin and medicine spam mail :(
SURBL is a plugin. Look in your init.pre
--
Mr. Michele Neylon
Blacknight Solutions
Hosting, Co-location & Domain Registration http://www.blacknight.ie/ Tel.
+353 (0)59 9137101
--
Email scanned by Blacknight for viruses and dangerous content.
Visit http://www.blacknight.ie for more information
RE: Rules List
Posted by "Michele Neylon::Blacknight Solutions" <mi...@blacknightsolutions.com>.
On Sat, 2004-11-06 at 13:57 -0600, Anton Krall wrote:
> Im using 3.0.. How do I get a hold of SURBLs ? Im still getting a lot of
> the vicodin and medicine spam mail :(
SURBL is a plugin. Look in your init.pre
--
Mr. Michele Neylon
Blacknight Solutions
Hosting, Co-location & Domain Registration
http://www.blacknight.ie/
Tel. +353 (0)59 9137101
--
Email scanned by Blacknight for viruses and dangerous content.
Visit http://www.blacknight.ie for more information
RE: Rules List
Posted by Anton Krall <ak...@intruder.com.mx>.
Im using 3.0.. How do I get a hold of SURBLs ? Im still getting a lot of
the vicodin and medicine spam mail :(
-----Original Message-----
From: Rakesh [mailto:rakesh@netcore.co.in]
Sent: Sábado, 06 de Noviembre de 2004 10:29 a.m.
To: Anton Krall
Cc: users@spamassassin.apache.org
Subject: Re: Rules List
hii,
which version of spamassassin are you using ? I would recommend to remove
uri rulesets like bigevil and sare URI and use SURBLs instead, tht will help
you to get rid of great deal of spams. If you are using older version of
spamassassin like 2.63 then you will have to install the SpamCop URI plugin
or else upgrade to Spamassassin 3.x. Also try to use dcc and razor if you
are not using tht.
Rakesh
On Sat, 2004-11-06 at 21:41, Anton Krall wrote:
> Guys.
>
> I am using the following rules list but still a lot of spam is going
thru..
> Any extra rules you recommend adding?
>
> 70_sare_adult.cf 70_sare_header1.cf 70_sare_html3.cf
> 71_sare_bml_pre25x.cf
> 70_sare_bayes_poison_nxm.cf 70_sare_header2.cf 70_sare_html4.cf
> 71_sare_redirect_pre3.0.0.cf
> 70_sare_genlsubj.cf 70_sare_header3.cf
70_sare_html_arc.cf
> 72_sare_bml_post25x.cf
> 70_sare_genlsubj0.cf 70_sare_header_arc.cf
70_sare_html_eng.cf
> 72_sare_redirect_post3.0.0.cf
> 70_sare_genlsubj1.cf 70_sare_header_eng.cf
70_sare_html_x30.cf
> 99_sare_fraud_post25x.cf
> 70_sare_genlsubj2.cf 70_sare_header_x264_x30.cf 70_sare_oem.cf
> 99_sare_fraud_pre25x.cf
> 70_sare_genlsubj3.cf 70_sare_header_x30.cf 70_sare_random.cf
> RulesDuJour
> 70_sare_genlsubj_arc.cf 70_sare_highrisk.cf
70_sare_specific.cf
> antidrug.cf
> 70_sare_genlsubj_eng.cf 70_sare_html.cf 70_sare_spoof.cf
> bigevil.cf
> 70_sare_genlsubj_x30.cf 70_sare_html0.cf 70_sare_unsub.cf
> bogus-virus-warnings.cf
> 70_sare_header.cf 70_sare_html1.cf 70_sare_uri.cf
> evilnumbers.cf
> 70_sare_header0.cf 70_sare_html2.cf 70_sc_top200.cf
> rules_du_jour
>
Re: Rules List
Posted by Rakesh <ra...@netcore.co.in>.
hii,
which version of spamassassin are you using ? I would recommend to
remove uri rulesets like bigevil and sare URI and use SURBLs instead,
tht will help you to get rid of great deal of spams. If you are using
older version of spamassassin like 2.63 then you will have to install
the SpamCop URI plugin or else upgrade to Spamassassin 3.x. Also try to
use dcc and razor if you are not using tht.
Rakesh
On Sat, 2004-11-06 at 21:41, Anton Krall wrote:
> Guys.
>
> I am using the following rules list but still a lot of spam is going thru..
> Any extra rules you recommend adding?
>
> 70_sare_adult.cf 70_sare_header1.cf 70_sare_html3.cf
> 71_sare_bml_pre25x.cf
> 70_sare_bayes_poison_nxm.cf 70_sare_header2.cf 70_sare_html4.cf
> 71_sare_redirect_pre3.0.0.cf
> 70_sare_genlsubj.cf 70_sare_header3.cf 70_sare_html_arc.cf
> 72_sare_bml_post25x.cf
> 70_sare_genlsubj0.cf 70_sare_header_arc.cf 70_sare_html_eng.cf
> 72_sare_redirect_post3.0.0.cf
> 70_sare_genlsubj1.cf 70_sare_header_eng.cf 70_sare_html_x30.cf
> 99_sare_fraud_post25x.cf
> 70_sare_genlsubj2.cf 70_sare_header_x264_x30.cf 70_sare_oem.cf
> 99_sare_fraud_pre25x.cf
> 70_sare_genlsubj3.cf 70_sare_header_x30.cf 70_sare_random.cf
> RulesDuJour
> 70_sare_genlsubj_arc.cf 70_sare_highrisk.cf 70_sare_specific.cf
> antidrug.cf
> 70_sare_genlsubj_eng.cf 70_sare_html.cf 70_sare_spoof.cf
> bigevil.cf
> 70_sare_genlsubj_x30.cf 70_sare_html0.cf 70_sare_unsub.cf
> bogus-virus-warnings.cf
> 70_sare_header.cf 70_sare_html1.cf 70_sare_uri.cf
> evilnumbers.cf
> 70_sare_header0.cf 70_sare_html2.cf 70_sc_top200.cf
> rules_du_jour
>
RE: Rules List
Posted by Raymond Dijkxhoorn <ra...@prolocation.net>.
Hi!
> What can I use those instead of the lists Im using? Any urls for more info?
> Will using SURBL's sllow me to remove all the other cf and just use SURBL's
> ?
> What version SA are you using. I dont think you are using SURBL's right now.
> I think that will get you going a lot better then the gazillion lists you
> have loaded now. Also will cut down CPU and RAM usage on your machine a lit.
You can use whatever you like, if its smart, thats a completely different
question. If you run SURBL you can get out a lot of the seperate .cf
files, for example bigevil.
Bye,
Raymond.
RE: Rules List
Posted by Anton Krall <ak...@intruder.com.mx>.
What can I use those instead of the lists Im using? Any urls for more info?
Will using SURBL's sllow me to remove all the other cf and just use SURBL's
?
-----Original Message-----
From: Raymond Dijkxhoorn [mailto:raymond@prolocation.net]
Sent: Sábado, 06 de Noviembre de 2004 12:23 p.m.
To: Anton Krall
Cc: users@spamassassin.apache.org
Subject: Re: Rules List
Hi!
>
> I am using the following rules list but still a lot of spam is going
thru..
> Any extra rules you recommend adding?
>
> 70_sare_adult.cf 70_sare_header1.cf 70_sare_html3.cf
> 71_sare_bml_pre25x.cf
> 70_sare_bayes_poison_nxm.cf 70_sare_header2.cf 70_sare_html4.cf
> 71_sare_redirect_pre3.0.0.cf
> 70_sare_genlsubj.cf 70_sare_header3.cf
70_sare_html_arc.cf
> 72_sare_bml_post25x.cf
> 70_sare_genlsubj0.cf 70_sare_header_arc.cf
70_sare_html_eng.cf
> 72_sare_redirect_post3.0.0.cf
> 70_sare_genlsubj1.cf 70_sare_header_eng.cf
70_sare_html_x30.cf
> 99_sare_fraud_post25x.cf
> 70_sare_genlsubj2.cf 70_sare_header_x264_x30.cf 70_sare_oem.cf
> 99_sare_fraud_pre25x.cf
> 70_sare_genlsubj3.cf 70_sare_header_x30.cf 70_sare_random.cf
> RulesDuJour
> 70_sare_genlsubj_arc.cf 70_sare_highrisk.cf
70_sare_specific.cf
> antidrug.cf
> 70_sare_genlsubj_eng.cf 70_sare_html.cf 70_sare_spoof.cf
> bigevil.cf
Bigevil?
What version SA are you using. I dont think you are using SURBL's right now.
I think that will get you going a lot better then the gazillion lists you
have loaded now. Also will cut down CPU and RAM usage on your machine a lit.
Bye,
Raymond.
RE: Rules List
Posted by Anton Krall <ak...@intruder.com.mx>.
BTW I just upgraded to 3.0 and using rules_du_jour
-----Original Message-----
From: Raymond Dijkxhoorn [mailto:raymond@prolocation.net]
Sent: Sábado, 06 de Noviembre de 2004 12:23 p.m.
To: Anton Krall
Cc: users@spamassassin.apache.org
Subject: Re: Rules List
Hi!
>
> I am using the following rules list but still a lot of spam is going
thru..
> Any extra rules you recommend adding?
>
> 70_sare_adult.cf 70_sare_header1.cf 70_sare_html3.cf
> 71_sare_bml_pre25x.cf
> 70_sare_bayes_poison_nxm.cf 70_sare_header2.cf 70_sare_html4.cf
> 71_sare_redirect_pre3.0.0.cf
> 70_sare_genlsubj.cf 70_sare_header3.cf
70_sare_html_arc.cf
> 72_sare_bml_post25x.cf
> 70_sare_genlsubj0.cf 70_sare_header_arc.cf
70_sare_html_eng.cf
> 72_sare_redirect_post3.0.0.cf
> 70_sare_genlsubj1.cf 70_sare_header_eng.cf
70_sare_html_x30.cf
> 99_sare_fraud_post25x.cf
> 70_sare_genlsubj2.cf 70_sare_header_x264_x30.cf 70_sare_oem.cf
> 99_sare_fraud_pre25x.cf
> 70_sare_genlsubj3.cf 70_sare_header_x30.cf 70_sare_random.cf
> RulesDuJour
> 70_sare_genlsubj_arc.cf 70_sare_highrisk.cf
70_sare_specific.cf
> antidrug.cf
> 70_sare_genlsubj_eng.cf 70_sare_html.cf 70_sare_spoof.cf
> bigevil.cf
Bigevil?
What version SA are you using. I dont think you are using SURBL's right now.
I think that will get you going a lot better then the gazillion lists you
have loaded now. Also will cut down CPU and RAM usage on your machine a lit.
Bye,
Raymond.
Re: Rules List
Posted by Raymond Dijkxhoorn <ra...@prolocation.net>.
Hi!
>
> I am using the following rules list but still a lot of spam is going thru..
> Any extra rules you recommend adding?
>
> 70_sare_adult.cf 70_sare_header1.cf 70_sare_html3.cf
> 71_sare_bml_pre25x.cf
> 70_sare_bayes_poison_nxm.cf 70_sare_header2.cf 70_sare_html4.cf
> 71_sare_redirect_pre3.0.0.cf
> 70_sare_genlsubj.cf 70_sare_header3.cf 70_sare_html_arc.cf
> 72_sare_bml_post25x.cf
> 70_sare_genlsubj0.cf 70_sare_header_arc.cf 70_sare_html_eng.cf
> 72_sare_redirect_post3.0.0.cf
> 70_sare_genlsubj1.cf 70_sare_header_eng.cf 70_sare_html_x30.cf
> 99_sare_fraud_post25x.cf
> 70_sare_genlsubj2.cf 70_sare_header_x264_x30.cf 70_sare_oem.cf
> 99_sare_fraud_pre25x.cf
> 70_sare_genlsubj3.cf 70_sare_header_x30.cf 70_sare_random.cf
> RulesDuJour
> 70_sare_genlsubj_arc.cf 70_sare_highrisk.cf 70_sare_specific.cf
> antidrug.cf
> 70_sare_genlsubj_eng.cf 70_sare_html.cf 70_sare_spoof.cf
> bigevil.cf
Bigevil?
What version SA are you using. I dont think you are using SURBL's right
now. I think that will get you going a lot better then the gazillion lists
you have loaded now. Also will cut down CPU and RAM usage on your machine
a lit.
Bye,
Raymond.
RE: Rules List
Posted by "Michele Neylon :: Blacknight Solutions" <mi...@blacknightsolutions.com>.
Get rid of bigevil immediately!! It is no longer updated and kills servers
:)
If you are still running the 2.6* series use spamcop uri to add support for
SURBL
Mr Michele Neylon
Blacknight Internet Solutions Ltd
Hosting, co-location & domains
http://www.blacknight.ie/
Tel. +353 59 9137101
Proud sponsors of MM04 {http://www.mm04.net}
--
Email scanned by Blacknight for viruses and dangerous content.
Visit http://www.blacknight.ie for more information