Here comes something new!
As
@AdamP asked in another thread about adjustments and mentioned over products, I also looked myself once again on how to optimize my whole setup by also reducing the amount of used systems. At this point I came over Warden AntiSpam and AntiVirus for Plesk and it's somehow similar to Proxmox, maybe
@Stoiko Ivanov it would be a great idea to integrate PMG as well into Plesk as PMG looks more clean, professional and somehow nicer (e.g. a bit like MacOS vs. Windows^^). However, it came with some plugins and settings, I checked against my config and finally I decide to activate one more check: Phishing
For updating the feeds you need to signup with PhishTank and register an application (PMG is in use already ^^).
Then the following adjustments need to be done:
Code:
vi /etc/mail/spamassassin/v342.pre
vi /etc/mail/spamassassin/custom.cf
vi /etc/cron.hourly/phishing
chmod +x /etc/cron.hourly/phishing
/etc/cron.hourly/phishing
/etc/mail/spamassassin/v342.pre (uncommenting Phishing):
Code:
# This is the right place to customize your installation of SpamAssassin.
#
# See 'perldoc Mail::SpamAssassin::Conf' for details of what can be
# tweaked.
#
# This file was installed during the installation of SpamAssassin 3.4.1,
# and contains plugin loading commands for the new plugins added in that
# release. It will not be overwritten during future SpamAssassin installs,
# so you can modify it to enable some disabled-by-default plugins below,
# if you so wish.
#
# There are now multiple files read to enable plugins in the
# /etc/mail/spamassassin directory; previously only one, "init.pre" was
# read. Now both "init.pre", "v310.pre", and any other files ending in
# ".pre" will be read. As future releases are made, new plugins will be
# added to new files, named according to the release they're added in.
###########################################################################
# HashBL - Use EBL email blocklist
loadplugin Mail::SpamAssassin::Plugin::HashBL
# ResourceLimits - assure your spamd child processes
# do not exceed specified CPU or memory limit
# loadplugin Mail::SpamAssassin::Plugin::ResourceLimits
# FromNameSpoof - help stop spam that tries to spoof other domains using
# the from name
# loadplugin Mail::SpamAssassin::Plugin::FromNameSpoof
# Phishing - finds uris used in phishing campaigns detected by
# OpenPhish or PhishTank feeds.
loadplugin Mail::SpamAssassin::Plugin::Phishing
# allow URI rules to look at DKIM headers if they exist
parse_dkim_uris 1
Adding the following the lines to the bottom of /etc/mail/spamassassin/custom.cf:
Code:
ifplugin Mail::SpamAssassin::Plugin::Phishing
phishing_openphish_feed /etc/mail/spamassassin/openphish-feed.txt
phishing_phishtank_feed /etc/mail/spamassassin/phishtank-feed.csv
body URI_PHISHING eval:check_phishing()
describe URI_PHISHING Url match phishing in feed
score URI_PHISHING 1.4
endif
/etc/cron.hourly/phishing (replace xxx through your application key):
Code:
#!/bin/sh
wget -O /etc/mail/spamassassin/openphish-feed.txt -q https://openphish.com/feed.txt
wget -O /etc/mail/spamassassin/phishtank-feed.csv.gz -q http://data.phishtank.com/data/xxx/online-valid.csv.gz
gunzip -f /etc/mail/spamassassin/phishtank-feed.csv.gz