feedback would very much be appreciated...

View: New views
2 Messages — Rating Filter:   Alert me  

feedback would very much be appreciated...

by mourik jan heupink :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Hi all!

I have searched the complete internet (well...kind of...) and I'm still very much lost...

I'm trying to setup postfix/dspam/dovecot and I don't think it's working as it should, even though I'm rather close, i think...

What I have now:

- mails for my (6, and all local, real users with Maildir mailboxes) users are fetched from various remote pop3 boxes using fetchmail, and then 'injected' in my local server, via port 25. (where postfix is listening) This works.
- postfix is configured with "mailbox_command = /usr/sbin/dspam –deliver=innocent –user $USER", so mail is 'handed over' to dspam. This also seems to work.
- dspam classifies each email into spam or ham. This is where things seem to go wrong, because I'm basically only seeing "X-DSPAM-Result: Innocent". I'll paste a full example below.
- I have trained dspam according to the instructions here: http://www.directadmin.com/forum/showthread.php?t=16015
- I have composed a message with only capitals, lot's a exclamation marks, $3.000.000, www.viagra.com, etc, etc, and it classifies as innocent. Even when I re-train dspam, it STILL sees a new message with the same content, sent from the same machine/account as innocent. This can never be right...

My system is OpenSUSE 10.3 x64. In /var/lib/dspam/system.log I see all messages being logged, like this: http://pastebin.com/m6a765191 (so no errors, just information)

I would like to have one global anti-spam database, shared with all users. Nothing fancy. I'm using mysql backend. (suse10.3 comes with mysql5)

Could the problem be related to the fact that all mails seem to come from localhost, as this is where fetchmail 'injects' them?

I have the feeling I'm soo close, but missing some vital steps. If anyone could help me I'd be really grateful!

Kind regards,
mj

from here: a sample 'innocent' message:
Return-Path: <mj@...>
X-Original-To: mailing@localhost
Delivered-To: mailing@...
Received: from ml310.hidden.com (localhost [127.0.0.1])
    by ml310.hidden.com (Postfix) with ESMTP id 572C81801A36
    for <mailing@localhost>; Fri,  8 Aug 2008 17:46:01 +0200 (CEST)
X-Original-To: mailing@...
Delivered-To: mailing@...
Received: from mail.narfum.org [62.133.194.66]
    by ml310.hidden.com with POP3 (fetchmail-6.3.8)
    for <mailing@localhost> (single-drop); Fri, 08 Aug 2008 17:46:01 +0200 (CEST)
Received: from localhost (server02 [127.0.0.1])
    by mx1.narfum.net (Narfum Inc. Mail Service) with ESMTP id 97DB927ECFF
    for <mailing@...>; Fri,  8 Aug 2008 17:44:45 +0200 (CEST)
X-Virus-Scanned: by Narfum Inc.
Received: from mx1.narfum.net ([62.133.194.66])
    by localhost (server02.bw110.nl.narfum.net [127.0.0.1]) (amavisd-new, port 10024)
    with ESMTP id 5uOyJkpsGyTU for <mailing@...>;
    Fri,  8 Aug 2008 17:44:39 +0200 (CEST)
Received: from rv-out-0708.google.com (rv-out-0708.google.com [209.85.198.246])
    by mx1.narfum.net (Narfum Inc. Mail Service) with ESMTP id C9C3927ECFA
    for <mailing@...>; Fri,  8 Aug 2008 17:44:38 +0200 (CEST)
Received: by rv-out-0708.google.com with SMTP id b17so1437668rvf.44
        for <mailing@...>; Fri, 08 Aug 2008 08:44:37 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=gmail.com; s=gamma;
        h=domainkey-signature:received:received:message-id:date:from:to
         :subject:in-reply-to:mime-version:content-type:references;
        bh=ZOXek0FdWfQahTgeCSjqzkUtgP79I0WJVMGrc5Q8DzM=;
        b=hwgSFDeQpaiRT19SmfvhS7LR9X7bviWqSN3QOZZBIFtLWysScyr1EX11nXudvRoUEW
         jgHqtEEEPr9asMLVO4k8+r3SY08wdm3A9nTMjueB6FJv2TnXCg1OEFJfb6cb66jOmJzc
         paDTipGEQ/1m0IivmJzVtS4XlJyO3XNJ7SeE8=
DomainKey-Signature: a=rsa-sha1; c=nofws;
        d=gmail.com; s=gamma;
        h=message-id:date:from:to:subject:in-reply-to:mime-version
         :content-type:references;
        b=WzHAZdjU0bVNViw/+X1yOqbasS/f8IEjkiV5gWC9yuvA/ha3U4gNVAwWIl7vzgAkFD
         yRdQZJB3JFhQ++LuVtu0Z1v/fm5bK8tGU1kEHvZw8WjcKDRWTO/vS2lB+NaqrmDvZdqg
         UBNuabAR9GxzWf1n7T2C1vzdG6AYa6xawDicA=
Received: by 10.114.124.1 with SMTP id w1mr2113078wac.73.1218210276334;
        Fri, 08 Aug 2008 08:44:36 -0700 (PDT)
Received: by 10.114.194.10 with HTTP; Fri, 8 Aug 2008 08:44:36 -0700 (PDT)
Message-ID: <bcbe9cff0808080844lf876558n6638997fc3e8b881@...>
Date: Fri, 8 Aug 2008 17:44:36 +0200
From: "mj" <mj@...>
To: mailing <mailing@...>
Subject: Fwd: EARN CASH
In-Reply-To: <bcbe9cff0808080644o45de5c3yc6668d7c8e220649@...>
MIME-Version: 1.0
Content-Type: multipart/alternative;
    boundary="----=_Part_18250_1706566.1218210276356"
References: <bcbe9cff0808080644o45de5c3yc6668d7c8e220649@...>
X-DSPAM-Result: Innocent
X-DSPAM-Processed: Fri Aug  8 17:46:01 2008
X-DSPAM-Confidence: 0.5672
X-DSPAM-Improbability: 1 in 132 chance of being spam
X-DSPAM-Probability: 0.0473
br> X-DSPAM-Factors: 27,
    From*"mj" <mj@...>, 0.25926,
    From*gmail.com>, 0.25926,
    From*mj"+<mj, 0.25926,
    Url*http, 0.25926,
    Url*href=", 0.25926,
    From*jan+mj", 0.25926,
    From*<mj+gmail.com>, 0.25926,
    Date*2008+17, 0.73684,
    *17, 0.73684,
    Received*17, 0.73684,
    Received*17, 0.73684,
    Date*17, 0.73684,
    *8+17, 0.73684,
    Received*2008+17, 0.73684,
    Received*2008+17, 0.73684,
    Received*with+HTTP, 0.28571,
    Received*10.114.194.10+with, 0.28571,
    DKIM-Signature*h=domainkey+signature, 0.28571,
    DomainKey-Signature*h=message+id, 0.28571,
    Content-Disposition*inline, 0.28571,
    Content-Disposition*inline, 0.28571,
    DKIM-Signature*s=gamma, 0.28571,
    DKIM-Signature*a=rsa+sha256, 0.28571,
    Content-Type*text/plain+charset=UTF, 0.28571,
    Return-Path*gmail.com>, 0.28571,
    DKIM-Signature*c=relaxed/relaxed, 0.28571,
    DKIM-Signature*d=gmail.com, 0.28571

------=_Part_18250_1706566.1218210276356
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

---------- Forwarded message ----------
From: mj <mj@...>
Date: 2008/8/8
Subject: EARN CASH
To: mailing <mailing@...>


HI!

WAIT NO LONGER!!!!

$1.000.000

WWW.VIAGRA.COM

------=_Part_18250_1706566.1218210276356
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

<div dir="ltr"><br><br><div class="gmail_quote">---------- Forwarded message ----------<br>From: <b class="gmail_sendername">mj</b> <span dir="ltr">&lt;<a href="mailto:mj@...">mj@...</a>&gt;</span><br>
Date: 2008/8/8<br>Subject: EARN CASH<br>To: mailing &lt;<a href="mailto:mailing@...">mailing@...</a>&gt;<br><br><br><div dir="ltr">HI!<br><br>WAIT NO LONGER!!!!<br><br>$1.000.000<br><br><a href="http://WWW.VIAGRA.COM" target="_blank">WWW.VIAGRA.COM</a><br>
</div>
</div><br></div>

------=_Part_18250_1706566.1218210276356--



!DSPAM:1011,489c9083150925134319821!

Re: feedback would very much be appreciated...

by mourik jan heupink :: Rate this Message:

Reply to Author | View Threaded | Show Only this Message

Hi,

I think I finally made progress...! :-)

Amongst other things that I don't quite remember, I added "postfix" as
a trusted user in dspam.conf, and made the dspam binary
world-executable.

This seems to have helped. I guess it's now time to start training
dspam. (for which I'm using
http://johannes.sipsolutions.net/Projects/dovecot-antispam, and this
works beautifully!)

regards!

mj

2008/8/8 mourik jan heupink <heupink@...>

>
> Hi all!
>
> I have searched the complete internet (well...kind of...) and I'm still very much lost...
>
> I'm trying to setup postfix/dspam/dovecot and I don't think it's working as it should, even though I'm rather close, i think...
>
> What I have now:
>
> - mails for my (6, and all local, real users with Maildir mailboxes) users are fetched from various remote pop3 boxes using fetchmail, and then 'injected' in my local server, via port 25. (where postfix is listening) This works.
> - postfix is configured with "mailbox_command = /usr/sbin/dspam –deliver=innocent –user $USER", so mail is 'handed over' to dspam. This also seems to work.
> - dspam classifies each email into spam or ham. This is where things seem to go wrong, because I'm basically only seeing "X-DSPAM-Result: Innocent". I'll paste a full example below.
> - I have trained dspam according to the instructions here: http://www.directadmin.com/forum/showthread.php?t=16015
> - I have composed a message with only capitals, lot's a exclamation marks, $3.000.000, www.viagra.com, etc, etc, and it classifies as innocent. Even when I re-train dspam, it STILL sees a new message with the same content, sent from the same machine/account as innocent. This can never be right...
>
> My system is OpenSUSE 10.3 x64. In /var/lib/dspam/system.log I see all messages being logged, like this: http://pastebin.com/m6a765191 (so no errors, just information)
>
> I would like to have one global anti-spam database, shared with all users. Nothing fancy. I'm using mysql backend. (suse10.3 comes with mysql5)
>
> Could the problem be related to the fact that all mails seem to come from localhost, as this is where fetchmail 'injects' them?
>
> I have the feeling I'm soo close, but missing some vital steps. If anyone could help me I'd be really grateful!
>
> Kind regards,
> mj
>
> from here: a sample 'innocent' message:
> Return-Path: <mj@...>
> X-Original-To: mailing@localhost
> Delivered-To: mailing@...
> Received: from ml310.hidden.com (localhost [127.0.0.1])
>     by ml310.hidden.com (Postfix) with ESMTP id 572C81801A36
>     for <mailing@localhost>; Fri,  8 Aug 2008 17:46:01 +0200 (CEST)
> X-Original-To: mailing@...
> Delivered-To: mailing@...
> Received: from mail.narfum.org [62.133.194.66]
>     by ml310.hidden.com with POP3 (fetchmail-6.3.8)
>     for <mailing@localhost> (single-drop); Fri, 08 Aug 2008 17:46:01 +0200 (CEST)
> Received: from localhost (server02 [127.0.0.1])
>     by mx1.narfum.net (Narfum Inc. Mail Service) with ESMTP id 97DB927ECFF
>     for <mailing@...>; Fri,  8 Aug 2008 17:44:45 +0200 (CEST)
> X-Virus-Scanned: by Narfum Inc.
> Received: from mx1.narfum.net ([62.133.194.66])
>     by localhost (server02.bw110.nl.narfum.net [127.0.0.1]) (amavisd-new, port 10024)
>     with ESMTP id 5uOyJkpsGyTU for <mailing@...>;
>     Fri,  8 Aug 2008 17:44:39 +0200 (CEST)
> Received: from rv-out-0708.google.com (rv-out-0708.google.com [209.85.198.246])
>     by mx1.narfum.net (Narfum Inc. Mail Service) with ESMTP id C9C3927ECFA
>     for <mailing@...>; Fri,  8 Aug 2008 17:44:38 +0200 (CEST)
> Received: by rv-out-0708.google.com with SMTP id b17so1437668rvf.44
>         for <mailing@...>; Fri, 08 Aug 2008 08:44:37 -0700 (PDT)
> DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
>         d=gmail.com; s=gamma;
>         h=domainkey-signature:received:received:message-id:date:from:to
>          :subject:in-reply-to:mime-version:content-type:references;
>         bh=ZOXek0FdWfQahTgeCSjqzkUtgP79I0WJVMGrc5Q8DzM=;
>         b=hwgSFDeQpaiRT19SmfvhS7LR9X7bviWqSN3QOZZBIFtLWysScyr1EX11nXudvRoUEW
>          jgHqtEEEPr9asMLVO4k8+r3SY08wdm3A9nTMjueB6FJv2TnXCg1OEFJfb6cb66jOmJzc
>          paDTipGEQ/1m0IivmJzVtS4XlJyO3XNJ7SeE8=
> DomainKey-Signature: a=rsa-sha1; c=nofws;
>         d=gmail.com; s=gamma;
>         h=message-id:date:from:to:subject:in-reply-to:mime-version
>          :content-type:references;
>         b=WzHAZdjU0bVNViw/+X1yOqbasS/f8IEjkiV5gWC9yuvA/ha3U4gNVAwWIl7vzgAkFD
>          yRdQZJB3JFhQ++LuVtu0Z1v/fm5bK8tGU1kEHvZw8WjcKDRWTO/vS2lB+NaqrmDvZdqg
>          UBNuabAR9GxzWf1n7T2C1vzdG6AYa6xawDicA=
> Received: by 10.114.124.1 with SMTP id w1mr2113078wac.73.1218210276334;
>         Fri, 08 Aug 2008 08:44:36 -0700 (PDT)
> Received: by 10.114.194.10 with HTTP; Fri, 8 Aug 2008 08:44:36 -0700 (PDT)
> Message-ID: <bcbe9cff0808080844lf876558n6638997fc3e8b881@...>
> Date: Fri, 8 Aug 2008 17:44:36 +0200
> From: "mj" <mj@...>
> To: mailing <mailing@...>
> Subject: Fwd: EARN CASH
> In-Reply-To: <bcbe9cff0808080644o45de5c3yc6668d7c8e220649@...>
> MIME-Version: 1.0
> Content-Type: multipart/alternative;
>     boundary="----=_Part_18250_1706566.1218210276356"
> References: <bcbe9cff0808080644o45de5c3yc6668d7c8e220649@...>
> X-DSPAM-Result: Innocent
> X-DSPAM-Processed: Fri Aug  8 17:46:01 2008
> X-DSPAM-Confidence: 0.5672
> X-DSPAM-Improbability: 1 in 132 chance of being spam
> X-DSPAM-Probability: 0.0473
> > X-DSPAM-Factors: 27,
>     From*"mj" <mj@...>, 0.25926,
>     From*gmail.com>, 0.25926,
>     From*mj"+<mj, 0.25926,
>     Url*http, 0.25926,
>     Url*href=", 0.25926,
>     From*jan+mj", 0.25926,
>     From*<mj+gmail.com>, 0.25926,
>     Date*2008+17, 0.73684,
>     *17, 0.73684,
>     Received*17, 0.73684,
>     Received*17, 0.73684,
>     Date*17, 0.73684,
>     *8+17, 0.73684,
>     Received*2008+17, 0.73684,
>     Received*2008+17, 0.73684,
>     Received*with+HTTP, 0.28571,
>     Received*10.114.194.10+with, 0.28571,
>     DKIM-Signature*h=domainkey+signature, 0.28571,
>     DomainKey-Signature*h=message+id, 0.28571,
>     Content-Disposition*inline, 0.28571,
>     Content-Disposition*inline, 0.28571,
>     DKIM-Signature*s=gamma, 0.28571,
>     DKIM-Signature*a=rsa+sha256, 0.28571,
>     Content-Type*text/plain+charset=UTF, 0.28571,
>     Return-Path*gmail.com>, 0.28571,
>     DKIM-Signature*c=relaxed/relaxed, 0.28571,
>     DKIM-Signature*d=gmail.com, 0.28571
>
> ------=_Part_18250_1706566.1218210276356
> Content-Type: text/plain; charset=UTF-8
> Content-Transfer-Encoding: 7bit
> Content-Disposition: inline
>
> ---------- Forwarded message ----------
> From: mj <mj@...>
> Date: 2008/8/8
> Subject: EARN CASH
> To: mailing <mailing@...>
>
>
> HI!
>
> WAIT NO LONGER!!!!
>
> $1.000.000
>
> WWW.VIAGRA.COM
>
> ------=_Part_18250_1706566.1218210276356
> Content-Type: text/html; charset=UTF-8
> Content-Transfer-Encoding: 7bit
> Content-Disposition: inline
>
> <div dir="ltr"><br><br><div class="gmail_quote">---------- Forwarded message ----------<br>From: <b class="gmail_sendername">mj</b> <span dir="ltr"><<a href="mailto:mj@...">mj@...</a>></span><br>
> Date: 2008/8/8<br>Subject: EARN CASH<br>To: mailing <<a href="mailto:mailing@...">mailing@...</a>><br><br><br><div dir="ltr">HI!<br><br>WAIT NO LONGER!!!!<br><br>$1.000.000<br><br><a href="http://WWW.VIAGRA.COM" target="_blank">WWW.VIAGRA.COM</a><br>
> </div>
> </div><br></div>
>
> ------=_Part_18250_1706566.1218210276356--
>
>
>

!DSPAM:1011,489d5e13150921008211710!


LightInTheBox - Buy quality products at wholesale price!