Web Hosting Talk







View Full Version : Cobalt Raq 4 and SPAM


hci
01-22-2002, 11:31 AM
Is there anyway to get the cobalt Raq 4 to use Maps or Orbs or something to filter spam? Also, anyway to block messages with *.vbs or *.exe attachments?

Thanks

Matt

merlin
01-24-2002, 05:21 PM
use ordb.org to protect yourself from SPAM........

You need to edit the file /etc/mail/sendmail.cf, make a copy first. Find the block of code which says:-

#########################################################
# check_mail -- check SMTP `MAIL FROM:' command argument
#########################################################

Just above this block of code type of following:-

# DNS based IP address spam list relays.orbd.org
R$* $: $&{client_addr}
R$-.$-.$-.$- $: <?> $(host $4.$3.$2.$1.relays.ordb.org. $: OK $)
R<?>OK $: OKSOFAR
R<?>$+ $#error $@ 5.7.1 $: "Mail from " $&{client_addr}" refused by ordb.org open relay database"

Make sure that you use TABS not SPACES between the first and second columns.

Omair Haroon
01-25-2002, 07:42 AM
[root@www mail]# ls
access access.db popip.db sendmail.ct sendmail.hf


It seems that I don't have any sendmail.cf file. Any idea why?


Salam,
-Omair

hypernatic.net
01-25-2002, 09:57 AM
Try
locate sendmail.cf

Omair Haroon
01-25-2002, 10:26 AM
Here is my output:


[root@www /root]# locate sendmail.cf
locate: decode_db() aborted. Corrupt database?



:confused:


Salam,
-Omair

hypernatic.net
01-25-2002, 10:29 AM
run as root:

updatedb
locate sendmail.cf

Omair Haroon
01-25-2002, 10:54 AM
Still no use:


[root@www /root]# updatedb
[root@www /root]# locate sendmail.cf
locate: decode_db() aborted. Corrupt database?




Salam,
-Omair

Juan
01-27-2002, 02:28 PM
I guess you installed some RPM's which you couldn't update so easy. If I remember correctly it has something to do with libdb or something like that....

Omair Haroon
01-27-2002, 02:53 PM
Any idea what would be the solutions? Any URL or Links even files?


Salam,
-Omair

Juan
01-27-2002, 05:07 PM
deinstall the libdb RPM and replace it with the original....

jjma
01-31-2002, 07:31 AM
Originally posted by merlin

#########################################################
# check_mail -- check SMTP `MAIL FROM:' command argument
#########################################################

Just above this block of code type of following:-

# DNS based IP address spam list relays.orbd.org
R$* $: $&{client_addr}
R$-.$-.$-.$- $: <?> $(host $4.$3.$2.$1.relays.ordb.org. $: OK $)
R<?>OK $: OKSOFAR
R<?>$+ $#error $@ 5.7.1 $: "Mail from " $&{client_addr}" refused by ordb.org open relay database"


Isn't relays.orbd.org now changed to inputs.ordz.org ?

Would I be able to also add relays.osirusoft.com to this list like this:

R$-.$-.$-.$- $: <?> $(host $4.$3.$2.$1.relays.ordb.org. relays.osirusoft.com $: OK $)

Cheers

Ja

bobbyt
01-31-2002, 12:12 PM
Below is what I've placed in /etc/procmailrc to filter out nasty files except exes but a lot of valid exes are sent to people. I still seem to get that dumb .com virus on and off. so I've also added a subject filter along with some common unwanted subjects.

:0
*^Content-type: (multipart/mixed|application/octet-stream)
{
:0 HB
*^Content-Disposition: (attachment|inline);
*filename=".*\.(vbs|bat|wsf|shs|com|nws|chm|pif|vbe|hta|scr)"
{
SHELL=/bin/bash
:0 fhbw
|/bin/sed -e \
's/\([nN][aA][mM][eE]=".*\.[vV][bB][sS]\)"/\1.txt"/' \
-e \
's/\([nN][aA][mM][eE]=".*\.[bB][aA][tT]\)"/\1.txt"/' \
-e \
's/\([nN][aA][mM][eE]=".*\.[wW][sS][fF]\)"/\1.txt"/' \
-e \
's/\([nN][aA][mN][eE]=".*\.[nN][wW][sS]\)"/\1.txt"/' \
-e \
's/\([nN][aA][mM][eE]=".*\.[sS][hH][sS]\)"/\1.txt"/' \
-e \
's/\([nN][aA][mM][eE]=".*\.[cC][oO][mM]\)"/\1.not"/' \
-e \
's/\([nN][aA][mM][eE]=".*\.[cC][hH][mM]\)"/\1.txt"/' \
-e \
's/\([nN][aA][mM][eE]=".*\.[pP][iI][fF]\)"/\1.txt"/' \
-e \
's/\([nN][aA][mM][eE]=".*\.[hH][tT][aA]\)"/\1.txt"/' \
-e \
's/\([nN][aA][mM][eE]=".*\.[vV][bB][eE]\)"/\1.txt"/' \
-e \
's/\([nN][aA][mM][eE]=".*\.[sS][cC][rR]\)"/\1.txt"/' \
-e \
{
:0:
/home/tmp/crap
}
}
:0:
* ! ^X-BeenThere: procmail@lists.RWTH-Aachen.DE
* 1^0 B ?? I send you this file in order to have your advice
* 1^0 B ?? I hope you like the file that I send( t)?o you
* 1^0 B ?? This is the file with the information that you ask for
* B ?? See you later(\.|=2E) Thanks
/home/tmp/sircam
:0
* ^Subject: Enlarge Your Penis
/dev/null

:0
* ^Subject: new photos from my party!
/dev/null

:0
* ^Subject: Lose weight
/dev/null

:0
* ^Subject: Viagra
/dev/null

:0
* ^Subject: your own DVD
/dev/null

:0
* ^Subject: Ejaculation
/dev/null

jjma
01-31-2002, 02:03 PM
Could you use both the procmail and sendmail flavours to filter spam?

Ja

Pingu
01-31-2002, 06:53 PM
Is it possible to junkify mail based on emailaddresses to?

I'm getting sick and tired of receiving mails from:
namenumber@domain.tld
Like meme372652@aol.com (just an example, although most junk seems to originate from aol.com addressess)

Is it possible to make some kind of rule(s) that would deal with these bogus addresses?
Come to think of it, I'm even considering blocking "free webmail addresses" all together. Anybody have a list?

jjma
02-01-2002, 06:38 AM
Originally posted by Pingu
Is it possible to junkify mail based on emailaddresses to?


Yes - Go into the GUI and click on Email Server. Their is a box called " Reject the following Users/Hosts/Domains ". Within their you can put meme372652@aol.com and all other spamers.


Come to think of it, I'm even considering blocking "free webmail addresses" all together. Anybody have a list? [

Not sure if you can add wildard email address like *@hotmail.com or *@aol.com?

You could try, and if it fails pull it out.

Ja