Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Administrators

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 09-10-2009, 08:50 AM
Special Member
 
Posts: 174
Default spam assassin rules

I need help. I just cant seem to get a good handle on the spam. I followed the wiki on spam settings, I added different .cf files to the /opt/zimbra/conf/spamassassin and then restarted zimbra but I cant for the life of me get it to stop viagara emails! They always go to the inbox also, not to the spam folder. Spam is way down since I went thru the wiki, I mean users are now only getting 3 or 4 spams a day compared to 20 or 30 so I know something is working. So, I need to know, if I download a .cf file into the /conf/spam assassin folder if that is the correct place to put it? I am not by any mean a spam assassin or even a zimbra guru so I would love to be able to not have to spend so much time working on this....... What info can I provide that will help figure this out?
thanks
Bill B
Reply With Quote
  #2 (permalink)  
Old 09-11-2009, 02:08 AM
Moderator
 
Posts: 7,928
Default

Are they emails with a embedded image (flag type) by any chance ? Search the forums for spamassassin and sanesecurity.
__________________
Reply With Quote
  #3 (permalink)  
Old 09-11-2009, 02:10 AM
Outstanding Member
 
Posts: 594
Default

Did you try blocking on word scan for ****** ?
Reply With Quote
  #4 (permalink)  
Old 09-11-2009, 02:15 AM
Moderator
 
Posts: 7,928
Default

If you could post a example of one of the emails, including all headers, then I can run it through my setup. I have multiple SPAM blocking techniques in place and will be in a better position to advice.
__________________
Reply With Quote
  #5 (permalink)  
Old 09-11-2009, 02:24 AM
Outstanding Member
 
Posts: 594
Default

Also you might want to tune scores for some rules.
Reply With Quote
  #6 (permalink)  
Old 09-11-2009, 03:15 AM
Moderator
 
Posts: 7,928
Default

Until we know what type of SPAM it is very difficult to tune SA scores without the potential of introducing FPs.
__________________
Reply With Quote
  #7 (permalink)  
Old 09-13-2009, 11:22 AM
Special Member
 
Posts: 174
Default didnt see replies

Quote:
Originally Posted by uxbod View Post
Until we know what type of SPAM it is very difficult to tune SA scores without the potential of introducing FPs.
Sorry about that. I didnt see any replies and thought no one was looking to help. I will have to log into the server and get some examples to post. I did notice that one of the spams with viagara was a gif.
I will get some info and post it here soon.
thank you
Bill
Reply With Quote
  #8 (permalink)  
Old 09-13-2009, 11:50 AM
Special Member
 
Posts: 174
Default viagara example that made it thru

Return-Path: tbarrons@stmarysstclair.org
Received: from ms1.stmarysstclair.org (LHLO ms1.stmarysstclair.org)
(192.168.3.5) by ms1.stmarysstclair.org with LMTP; Sat, 12 Sep 2009
21:40:56 -0400 (EDT)
Received: from localhost (localhost.localdomain [127.0.0.1])
by ms1.stmarysstclair.org (Postfix) with ESMTP id A736E264004
for <tbarrons@stmarysstclair.org>; Sat, 12 Sep 2009 21:40:56 -0400 (EDT)
X-Quarantine-ID: <rIaaMvwOdDgc>
X-Virus-Scanned: amavisd-new at ms1.stmarysstclair.org
X-Amavis-Alert: BAD HEADER, Non-encoded 8-bit data (char A9 hex): From: \251
****** \256 Offic[...]
Received: from ms1.stmarysstclair.org ([127.0.0.1])
by localhost (ms1.stmarysstclair.org [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id rIaaMvwOdDgc for <tbarrons@stmarysstclair.org>;
Sat, 12 Sep 2009 21:40:49 -0400 (EDT)
Received: from 198-236-124-91.pool.ukrtel.net (198-236-124-91.pool.ukrtel.net [91.124.236.198])
by ms1.stmarysstclair.org (Postfix) with SMTP id C2AF8264003
for <tbarrons@stmarysstclair.org>; Sat, 12 Sep 2009 21:40:48 -0400 (EDT)
From: � ****** � Official Site <tbarrons@stmarysstclair.org>
To: tbarrons@stmarysstclair.org
Subject: Dear tbarrons@stmarysstclair.org 74% 0FF on Pfizer !
MIME-Version: 1.0
Content-Type: text/html; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Message-Id: <20090913014048.C2AF8264003@ms1.stmarysstclair.org >
Date: Sat, 12 Sep 2009 21:40:48 -0400 (EDT)


http://www.gsexeyuk.cn/1.gif
Reply With Quote
  #9 (permalink)  
Old 09-13-2009, 11:55 AM
Special Member
 
Posts: 174
Default

here is a screenshot of my admin graphs..... how does this compare to others?Screenshot-1.jpg
Reply With Quote
  #10 (permalink)  
Old 09-13-2009, 11:38 PM
Moderator
 
Posts: 7,928
Default

Not seen one of those image SPAMs for a while ... They are one of the first iterations and can easily be caught by using FuzzyOCR.
__________________
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.