Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 323155 - Some e-mail not processed by spamassassin
Summary: Some e-mail not processed by spamassassin
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Infrastructure
Classification: Unclassified
Component: Dev box issues (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Infrastructure
URL: https://forums.gentoo.org/viewtopic-p...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2010-06-08 10:12 UTC by Tom Knight (RETIRED)
Modified: 2010-09-30 07:33 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments
Example spam e-mail header (spam_header,623 bytes, text/plain)
2010-06-08 10:12 UTC, Tom Knight (RETIRED)
Details
spam_header2 (spam_header2,570 bytes, text/plain)
2010-09-29 09:11 UTC, Tom Knight (RETIRED)
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Tom Knight (RETIRED) gentoo-dev 2010-06-08 10:12:05 UTC
Some obvious spam gets through to my inbox on woodpecker and checking the headers shows it has not been processed by spamassassin. It all seems to be for the forum-mods alias, but some f-mods mail does get processed correctly and that could just because that's where most of the spam I get is delivered to.
Comment 1 Tom Knight (RETIRED) gentoo-dev 2010-06-08 10:12:53 UTC
Created attachment 234519 [details]
Example spam e-mail header
Comment 2 Tom Knight (RETIRED) gentoo-dev 2010-06-20 10:27:32 UTC
I've noticed that they all have a forged FROM address of forums-mods@g.o so maybe there's some whitelist that means that mail that's apparently from you doesn't get scanned?
Comment 3 Tom Knight (RETIRED) gentoo-dev 2010-09-27 13:28:06 UTC
Added potential solution to URL, seems it could be amavisd rather than spamassassin that needs its config tweaked.
Comment 4 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2010-09-27 20:04:10 UTC
I've changed @local_domains_maps in amavisd.conf now, please see if it works.
Comment 5 Jeremy Olexa (darkside) (RETIRED) archtester gentoo-dev Security 2010-09-28 13:15:50 UTC
(In reply to comment #4)
> I've changed @local_domains_maps in amavisd.conf now, please see if it works.
> 

Previous qa@g.o emails were not checked by SA, now they are.
Comment 6 Jeremy Olexa (darkside) (RETIRED) archtester gentoo-dev Security 2010-09-28 13:18:40 UTC
(In reply to comment #5)
> (In reply to comment #4)
> > I've changed @local_domains_maps in amavisd.conf now, please see if it works.
> > 
> 
> Previous qa@g.o emails were not checked by SA, now they are.
> 

Strike that comment. That was *my* SA instance. Sorry.
Comment 7 Tom Knight (RETIRED) gentoo-dev 2010-09-28 19:21:54 UTC
(In reply to comment #4)
> I've changed @local_domains_maps in amavisd.conf now, please see if it works.
> 

Nope :( Just got some spam through that hadn't been scanned by spamassassin or amavisd.
Comment 8 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2010-09-28 19:45:37 UTC
Ok, i've tweaked the amavis config that it should hopefully add a header to every message it's seeing.

Then we can figure out if some mail is bypassing amavis maybe.
Comment 9 Tom Knight (RETIRED) gentoo-dev 2010-09-29 09:11:29 UTC
Created attachment 248950 [details]
spam_header2

(In reply to comment #8)
> Then we can figure out if some mail is bypassing amavis maybe.
> 
This is the header of one that's bypassed amavis.
Comment 10 Tom Knight (RETIRED) gentoo-dev 2010-09-29 10:29:55 UTC
tove pointed me at /etc/postfix/sender_access_control-aliases.pcre which says that mail from /^forum-mods@gentoo.org$/ gets an OK. Maybe this needs to be DUNNO so that the mails with a forged 'From: forum-mods' get scanned?
Comment 11 Christian Ruppert (idl0r) gentoo-dev 2010-09-29 19:55:59 UTC
Return-Path: <bugzilla@gentoo.org>
X-Original-To: bugzilla@gentoo.org
Delivered-To: bugzilla@gentoo.org
Received: from gprs5e1bdf6d.pool.t-umts.hu (gprs5e1bdf6d.pool.t-umts.hu [94.27.223.109])
	by smtp.gentoo.org (Postfix) with ESMTP id ED6BA1B414D
	for <bugzilla@gentoo.org>; Wed, 29 Sep 2010 19:41:29 +0000 (UTC)
Content-Return: allowed
X-Mailer: CME-V6.5.4.3; MSN
Message-Id: <20100929194112.3020.qmail@gprs5e1bdf6d.pool.t-umts.hu>
To: <bugzilla@gentoo.org>
Subject: Dear bugzilla@gentoo.org LOVE YOU!
From: <bugzilla@gentoo.org>
Reply-to: MSN Featured Offers <qwnmd@mail.msadcenter.msn.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit

Find Your Love Now bugzilla@gentoo.org

http://groups.yahoo.com/group/xajidhgxrteh/message
Comment 12 Tom Knight (RETIRED) gentoo-dev 2010-09-29 20:03:08 UTC
/^bugzilla@gentoo.org$/ is in /etc/postfix/sender_access_control-aliases.pcre too which would explain why isn't not been scanned either. Doesn't explain qa@ which isn't in the file but maybe that's been solved by the actions in comment 8.
Comment 13 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2010-09-29 23:35:44 UTC
Ok, I've revamped the whitelist code that generates that list, please check for new spam that's not marked.
Comment 14 Jeremy Olexa (darkside) (RETIRED) archtester gentoo-dev Security 2010-09-30 03:00:23 UTC
(In reply to comment #12)
Ignore the qa noise, I was incorrect. Sorry.
Comment 15 Tom Knight (RETIRED) gentoo-dev 2010-09-30 07:33:01 UTC
Looks like it's working, no spam in my inbox this morning and there's one in my spam folder 'from' forum-mods with an X-Spam-Score: 18.778.

Marking as fixed.