Spam slipping through

alexhagg

New Member
Sep 30, 2008
8
0
1
Hello,

Lately we have been testing our new Proxmox system in our active Exchange system. We have seen some spam not being filtered out by Proxmox but the overal results seem to be more than satisfactory. However, we would like our system to be more consistent. We have rule that defines spam from spamlevel 4 and up and another rule that takes all spam and marks it so our Exchange server can push the emails to the user's "suspicious email" folder.

As you can see below, one of our employees received an Email in her Inbox, which is sure to be spam. Other users received a similar (not same) email which was actually put under "suspicious". My question: what could cause this inconsistency?
Von: Madore Yontz [mailto:demos@plaskdammen.com]
Gesendet: Mittwoch, 8. Oktober 2008 00:37
An: -------------------------
Betreff: 11 new message!



S
L s PENIS? ERE f E W C T N? W y t MA L CTIL DYSFUN TIO E WILL HELP!
Cheap D t g ra, r lis a W the P r
es viag cia nd o r d ugs!
Click here (removed the link)
http://zgqsgg.blu.livefilestore.com...N9C9AgT9JdhhDXbsPweKIdK7PHHjXg/m07u79o68.html
They governed and as they were the receivers of happy dies
the man or woman whose body will be head looked like a golf
ball. He was a queer, the man. We had to ascertain in that
case, first let alone the price. You must have seen great.



The Tracking Center comes up with this:


Oct 8 00:37:22smtpdconnect from xxxxxxxxxxxxxxxxx[x.x.x.x]Oct 8 00:37:22smtpd315BF388B4: client=xxxxxxxxxxxxxxxxx[x.x.x.x]Oct 8 00:37:22smtpddisconnect from xxxxxxxxxxxxxxxxx[x.x.x.x]Oct 8 00:37:22proxprox388B648EBE4A2513EA: new mail
message-id=<3994240565.20081007222839@plaskdammen.com>
Oct 8 00:37:22cleanup315BF388B4: message-id=<3994240565.20081007222839@plaskdammen.com>Oct 8 00:37:22qmgr315BF388B4: from=<demos@plaskdammen.com>, size=5062, nrcpt=1 (queue active)Oct 8 00:37:28proxprox388B648EBE4A2513EA: SA score=2/5 time=5.830 bayes=2.73026840680313e-06
autolearn=no hits=BAYES_00,HTML_MESSAGE,UNWANTED_LANGUAGE_BODY,URIBL_BLACK
Oct 8 00:37:28proxprox388B648EBE4A2513EA: accept mail to <xxxxxxxx@xxxxxxx> (3E915388BA) Oct 8 00:37:28proxprox388B648EBE4A2513EA: processing time: 5.946 seconds Oct 8 00:37:28lmtp315BF388B4: to=<xxxxxxx@xxxxxxxxxx>, relay=127.0.0.1[127.0.0.1]:10024,
delay=6.2, delays=0.09/0/0.04/6, dsn=2.5.0, status=sent (250 2.5.0 OK
(388B648EBE4A2513EA))
Oct 8 00:37:28qmgr315BF388B4: removedOct 8 00:37:28smtpdconnect from localhost[127.0.0.1]Oct 8 00:37:28smtpd3E915388BA: client=xxxxxxxxxxxxxxxxx[x.x.x.x]Oct 8 00:37:28smtpddisconnect from localhost[127.0.0.1]Oct 8 00:37:28cleanup3E915388BA: message-id=<3994240565.20081007222839@plaskdammen.com>Oct 8 00:37:28qmgr3E915388BA: from=<demos@plaskdammen.com>, size=5233, nrcpt=1 (queue active)Oct 8 00:37:28smtp3E915388BA: to=<xxxxxxxxxxx@xxxxxxxxxxxx>, relay=x.x.x.x[x.x.x.x]:25,
delay=0.32, delays=0.06/0/0/0.25, dsn=2.6.0, status=sent (250 2.6.0
<3994240565.20081007222839@plaskdammen.com> Queued mail for delivery)
Oct 8 00:37:28qmgr3E915388BA: removed
 
addendum

This email was processed before I activated the DCC feature of Proxmox. All other features had already been enabled.
 
My question: what could cause this inconsistency?

different mail header, different content, autowhitelist, ...

Even the same mail can get different scores for different users.

- Dietmar
 
But isn't this obvious spam? Can it be, that DCC will filter out these slip-throughs?
 
But isn't this obvious spam?

its obvious for you, but not for the filter ;-)

Can it be, that DCC will filter out these slip-throughs?

can be, but what is the question? If you want an exact analysis what happens I need the email in raw format (eml file).

- Dietmar
 
I'm very sorry. I exported the email to .eml and guess what the actual contents look like (it explains, why the usual regex doesn't grab it):

S L s PENIS? ERE f E W C T N? W y t
MA L CTIL DYSFUN TIO E WILL HELP!
Cheap D t g ra, r lis a W the P r
es viag cia nd o r d ugs!

Click here <http://zgqsgg.blu.livefilestore.com/y1pUAc41vW3DhsrKSh6ACKVXqLwPastYUF4fp5PwyHqdpmoZTrhZCVuR3P7N9C9AgT9JdhhDXbsPweKIdK7PHHjXg/m07u79o68.html>


They governed and as they were the receivers of happy dies
the man or woman whose body will be head looked like a golf
ball. He was a queer, the man. We had to ascertain in that
case, first let alone the price. You must have seen great.
 
I'm very sorry. I exported the email to .eml and guess what the actual contents look like (it explains, why the usual regex doesn't grab it):
S L s PENIS? ERE f E W C T N? W y t
MA L CTIL DYSFUN TIO E WILL HELP!
Cheap D t g ra, r lis a W the P r
es viag cia nd o r d ugs!

Click here <http://zgqsgg.blu.livefilestore.com/y1pUAc41vW3DhsrKSh6ACKVXqLwPastYUF4fp5PwyHqdpmoZTrhZCVuR3P7N9C9AgT9JdhhDXbsPweKIdK7PHHjXg/m07u79o68.html>


They governed and as they were the receivers of happy dies
the man or woman whose body will be head looked like a golf
ball. He was a queer, the man. We had to ascertain in that
case, first let alone the price. You must have seen great.

if you send us the original email as *eml we can analyse the emails and we see the score on our reference system. so we can see if something is wrong on your configuration or not (you can send the zipped *eml file directly to support@proxmox.com)
 
Better example

To get back to my spam issues: I have another problem. We have defined a rule that adds a spamheader as well as adds "[SPAM]" to the subject of the email. Some emails however seem to just get a header, however, their subjects do not get edited.

The headers contain these values:
X-Spam-Status: Yes, score=12.756 tagged_above=2 required=5
tests=[BAYES_99=3.5, DRUGS_ERECTILE=0.282, FH_HOST_EQ_DYNAMICIP=4.058,
HTML_MESSAGE=0.001, RCVD_IN_PBL=0.905, RCVD_IN_SORBS_DUL=0.877,
RCVD_IN_XBL=3.033, RDNS_DYNAMIC=0.1]
X-Spam-Score: 12.756
X-Spam-Flag: YES
The rule contains the following actions:

dyngraph.pl
Modify Spam Level
dyngraph.pl
Modify Spam Subject


The 2nd subrule contains:
Field Name:
Value:

The rule works most of the time, just not with every email.

 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!