PDA

View Full Version : razor, pyzor, dcc


Ovidiu
6th May 2009, 16:00
any howto we could use to complement ispcfg3 with these tools?

I have some spam getting through, where the spam server behaves perfect, even retries and gets through postgreys delays.

with the current set up, the mail has not been even doubted by amavisd even though it contains absolutely clearly only viagra spam...

till
6th May 2009, 20:10
Nothing special for ispconfig 3, just follow any totorial that you find for spamassassin or amvisd.

Ovidiu
7th May 2009, 09:44
the reason I was asking is that I remember with ispcfg2 I had found different howtos, meaning, some were meant for individual mailusers, while some were kind of for a "single" user, so bayes couldn't be set up.

I'll give this one a try, http://www.freespamfilter.org/FC4.html#_Toc110999208 looks pretty straight forward to implement razor, pyzor and dcc with Sa and amavisd.

Btw. there is another "filter" one can integrate into SA that looks for picture spam, I remember there was a howto on howtoforge but can't remember the name to look for.

And btw. can bayesdb be enabled for SA with ispcfg3? will it then be a global bayesdb as I can't think of a per user one, the mail users being virtual users and such...

admins
7th May 2009, 11:37
Hi Till

May if I take this howto:
http://www.howtoforge.de/howto/amavisd-new-in-postfix-zur-spam-und-virus-uberprufung-integrieren/

The part with /etc/spamassassin/local.cf :In this installation the local.cf will be ignored. Where must I add the part:


#pyzor
use_pyzor 1
pyzor_path /usr/bin/pyzor
pyzor_add_header 1

#razor
use_razor2 1
razor_config /etc/razor/razor-agent.conf

#bayes
use_bayes 1
use_bayes_rules 1
bayes_auto_learn 1



Thanks
admins

till
7th May 2009, 12:05
Restart amavisd after your changes.

Ovidiu
7th May 2009, 13:42
pyzor_add_header 1 doesn't work anymore

falko
7th May 2009, 18:24
Just leave that option out.

Ovidiu
7th May 2009, 18:44
yeah, I know, I was just telling the other guy :-)

besides, I rememebred the pciture spam thinggy: http://howtoforge.com/fight_image_spam_with_fuzzyocr_spamassassin gonna try and mix this in as well...

Ovidiu
8th May 2009, 12:38
ok, razor, pyzor, dcc and FuzzyOCR are running on my system.

still some spams are getting through, what can one do?
I'll post an example here:

RFC822 Message body
Return-Path: <gero.wensezyaz@mikolow.net>
Received: from localhost (localhost [127.0.0.1])
by h1550830.stratoserver.net (Postfix) with ESMTP id 0FD7D2E6022B
for <postmaster@web-designerz.de>; Fri, 8 May 2009 11:13:20 +0200 (CEST)
X-Virus-Scanned: Debian amavisd-new at h1550830.stratoserver.net
Received: from h1550830.stratoserver.net ([127.0.0.1])
by localhost (h1550830.stratoserver.net [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id O9CFcSHeOgeS for <postmaster@web-designerz.de>;
Fri, 8 May 2009 11:13:18 +0200 (CEST)
Received-SPF: none (mikolow.net: No applicable sender policy available) receiver=h1550830.stratoserver.net; identity=mailfrom; envelope-from="gero.wensezyaz@mikolow.net"; helo=mx0.gmx.net; client-ip=213.165.64.100
Received: from mx0.gmx.net (mx0.gmx.de [213.165.64.100])
by h1550830.stratoserver.net (Postfix) with SMTP id 9C1612E60150
for <postmaster@web-designerz.de>; Fri, 8 May 2009 11:13:17 +0200 (CEST)
Received: (qmail 23591 invoked by alias); 8 May 2009 09:13:17 -0000
Delivered-To: GMX delivery to o-v-i@gmx.de
Received: (qmail invoked by alias); 08 May 2009 09:13:16 -0000
Received: from ip-195225037240.mikolow.net (EHLO ip-195225037240.mikolow.net) [195.225.37.240]
by mx0.gmx.net (mx026) with SMTP; 08 May 2009 11:13:16 +0200
Message-ID: <571a01c9cfbc$14516650$d3053cb9@gero.wensezyaz>
From: "Dolly" <gero.wensezyaz@mikolow.net>
To: "Alberta" <c-h-r-i-s-s-i@gmx.de>,
"Albertina" <o-v-i@gmx.de>,
"Albertine" <o.b.i@gmx.de>
Subject: Pill3n ohne Z0ll
Date: Fri, 08 May 2009 09:05:05 -0100
MIME-Version: 1.0
Content-Type: text/plain;
charset="us-ascii"
Content-Transfer-Encoding: 8bit
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
X-GMX-Antispam: -2 (not scanned, spam filter disabled)
X-Resent-By: Forwarder <forwarder@gmx.de>
X-Resent-For: o-v-i@gmx.de
X-Resent-To: postmaster@web-designerz.de

Ihre Freundin ist feucht und bereit... aber Sie koennen nicht?
Moechten Sie wieder knall-harten S_e_x, ohne Errektions-Probleme?

Wir sind Ihre ausgezeichnete Online Apootheke, die auch Orginalware
als auch Genericas zu fairen Preisen verkauft. Mit unseren
Qualitaetsprodukten koennen Sie stundenlang S-e-x mit Ihrem
Maedchen haben und ihr es endlich so richtig geil besorgen.

Moechten Sie weitere Informationen ueber unsere Produkte,
senden Sie einfach "INFO" an diese Email-Adresse:

swisspharmacy@gmail.com


Die Frauen werden Ihre Szandhaftigkeit vergoettern!

Auf Bald
Agna Inc.

it says: X-Virus-Scanned: Debian amavisd-new at h1550830.stratoserver.net

this is an email, that gets forwarded from one of my accounts on an external mail system to an email address on the system running ispcfg3 with all these extensions to Spamassassin.
This email didn't even get tagges as suspicious...