cancel
Showing results for 
Search instead for 
Did you mean: 

Spam platform problem

Be3G
Grafter
Posts: 6,111
Thanks: 1
Registered: ‎05-04-2007

Spam platform problem

I noticed this morning that I was getting an unusually large amount of spam, and sure enough, having looked at a few headers, I'm seeing lots of instances of 'X-Dspam-Improbability: 1 in 98689409 chance of being spam' - which has come up before when the spam-checking wasn't functioning on the mail server in question. It only seems to be happening on mxcores 01 and 18 - could someone look in to this please?
Thanks,
Thomas
15 REPLIES 15
bobpullen
Community Gaffer
Community Gaffer
Posts: 16,893
Thanks: 4,986
Fixes: 316
Registered: ‎04-04-2007

Re: Spam platform problem

Hi Thomas,
Can you supply me with the headers from a few of these please? IIRC, the last time this happened alot of the X-DSPAM headers were defaulting to 0.4 (or is it 0.04 - I forget?) - Is this happening again?
Edit: We've been working on the mx.lasts this morning but sunmxcore18 is one of the mx.cores.

Bob Pullen
Plusnet Product Team
If I've been helpful then please give thanks ⤵

jelv
Seasoned Hero
Posts: 26,785
Thanks: 971
Fixes: 10
Registered: ‎10-04-2007

Re: Spam platform problem

Here's one from my mailbox:
Envelope-to: abc@xyz.plus.com
Delivery-date: Tue, 18 Sep 2007 10:55:44 +0000
Received:  by pih-sunmxcore18.plus.net with spam-scanned (PlusNet MXCore v2.00) id 1IXak3-00033r-If
  for abc@xyz.plus.com; Tue, 18 Sep 2007 10:55:44 +0000
X-Daemon-Classification: INNOCENT
Received: from 71-80-3-048.dhcp.sffl.va.charter.com ([71.80.3.48])
  by pih-sunmxcore18.plus.net with esmtp (PlusNet MXCore v2.00) id 1IXajw-0002ip-FV
  for abc@xyz.plus.com; Tue, 18 Sep 2007 10:55:43 +0000
Received: from [71.80.3.48] by eforward4.name-services.com; Tue, 18 Sep 2007 05:56:27 -0500
Message-ID: <01c7f9e2$8fb97690$30035047@fernan>
From: "Will Mcrae" <fernan@plugvoip.com>
To: <abc@xyz.plus.com>
Subject: US $ 99.95 buy now Viagra 100mg x 30 pills
Date: Tue, 18 Sep 2007 05:56:27 -0500
MIME-Version: 1.0
Content-Type: multipart/related;
type="multipart/alternative";
boundary="----=_NextPart_000_0006_01C7F9E2.8FB97690"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1409
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1409
X-PN-VirusFiltered: by PlusNet MXCore (v4.00)
X-DSPAM-Result: Innocent
X-DSPAM-Processed: Tue Sep 18 11:55:43 2007
X-DSPAM-Confidence: 1.0000
X-DSPAM-Improbability: 1 in 98689409 chance of being spam
X-DSPAM-Probability: 0.0023
X-DSPAM-Factors: 27,
vanishing+Dim, 0.40000,
vanishing+Dim, 0.40000,
X-PN-VirusFiltered*MXCore, 0.40000,
Received*Sep, 0.40000,
Received*Sep, 0.40000,
Subject*Viagra, 0.40000,
hspace=0+src="cid, 0.40000,
Content-Type*charset="us, 0.40000,
Content-Type*charset="us, 0.40000,
equiv=Content+Type, 0.40000,
ends?+From, 0.40000,
ends?+From, 0.40000,
face=Arial+size=2>XVI, 0.40000,
watch, 0.40000,
watch, 0.40000,
endless, 0.40000,
endless, 0.40000,
Message-ID*<01c7f9e2$8fb97690$30035047+fernan>, 0.40000,
ends?, 0.40000,
ends?, 0.40000,
Received*Tue, 0.40000,
Received*Tue, 0.40000,
Received*2007+10, 0.40000,
What+is, 0.40000,
What+is, 0.40000,
from, 0.40000,
from, 0.40000
jelv (a.k.a Spoon Whittler)
   Why I have left Plusnet (warning: long post!)   
Broadband: Andrews & Arnold Home::1 (FTTC 80/20)
Line rental: Pulse 8 Home Line Rental (£14.40/month)
Mobile: iD mobile (£4/month)
Be3G
Grafter
Posts: 6,111
Thanks: 1
Registered: ‎05-04-2007

Re: Spam platform problem

Yep, to save me editing out addresses etc., I'll just say that mine look exactly the same as John's, complete with all the 0.40000s. (Although I will post the headers if you do particularly need them.)
bobpullen
Community Gaffer
Community Gaffer
Posts: 16,893
Thanks: 4,986
Fixes: 316
Registered: ‎04-04-2007

Re: Spam platform problem

Thanks guys, I've raised problem 46487.
Seems reminiscent of this.
Edit: Should now be fixed. It would appear that a problem with last night's training caused the Bayesian spam database on two of the 22 mail delivery servers to 'forget' what they had learnt with regards to spam email. They've been 're-educated' and should be behaving themselves now Wink

Bob Pullen
Plusnet Product Team
If I've been helpful then please give thanks ⤵

Be3G
Grafter
Posts: 6,111
Thanks: 1
Registered: ‎05-04-2007

Re: Spam platform problem

Well, I haven't seen anything slip through the net in the last couple of hours so it looks like you're right. Thanks for sorting it out quickly.
Be3G
Grafter
Posts: 6,111
Thanks: 1
Registered: ‎05-04-2007

Re: Spam platform problem

Sunmxcore18's now doing exactly the same thing, so could it be looked in to please.
Chris
Legend
Posts: 17,724
Thanks: 600
Fixes: 169
Registered: ‎05-04-2007

Re: Spam platform problem

I'll get this looked into, have you got any headers of this? PM them to me if you prefer.
Former Plusnet Staff member. Posts after 31st Jan 2020 are not on behalf of Plusnet.
Be3G
Grafter
Posts: 6,111
Thanks: 1
Registered: ‎05-04-2007

Re: Spam platform problem

Ok, will do in a tic, though the problem's exactly the same as last time - improbability's 1 in 98689409, factors are 0.40000, etc..
Chris
Legend
Posts: 17,724
Thanks: 600
Fixes: 169
Registered: ‎05-04-2007

Re: Spam platform problem

Cheers, got them. Will raise a problem asap.
Former Plusnet Staff member. Posts after 31st Jan 2020 are not on behalf of Plusnet.
bobpullen
Community Gaffer
Community Gaffer
Posts: 16,893
Thanks: 4,986
Fixes: 316
Registered: ‎04-04-2007

Re: Spam platform problem

This should now be fixed (we've restarted Dspam).
Thanks for bringing it to our attention again Thomas.
We're working on a script that will run to periodically copy and clean the spam database before reinserting it and restarting Dspam. We'll try this once a week to begin with and see if the problem crops up again.

Bob Pullen
Plusnet Product Team
If I've been helpful then please give thanks ⤵

zubel
Community Veteran
Posts: 3,793
Thanks: 4
Registered: ‎08-06-2007

Re: Spam platform problem

Surely one could script a Nagios job to test for this on each relay?
Script an event that sends a mail through each particular relay to a specified mailbox, sleep for a short while, then check each mailbox, parse the headers for 0.40000 and respond with a pass/fail.
At least it would get the "flachenblinkenlights" going to alert someone Wink
B.
Be3G
Grafter
Posts: 6,111
Thanks: 1
Registered: ‎05-04-2007

Re: Spam platform problem

Thanks Bob (that was quick), and no problem.
zubel
Community Veteran
Posts: 3,793
Thanks: 4
Registered: ‎08-06-2007

Re: Spam platform problem

Quote from: Barry
Surely one could script a Nagios job to test for this on each relay?
Script an event that sends a mail through each particular relay to a specified mailbox, sleep for a short while, then check each mailbox, parse the headers for 0.40000 and respond with a pass/fail.
At least it would get the "flachenblinkenlights" going to alert someone Wink
B.

Damn, I'm having a quiet day at work today.
So, I found a nicely updated version of Mailping here
That does the mail delivery part.  Simply modifying the .pl script to check for the 0.4000000 headers would give you a lovely, handy Nagios script to tell you before your customers do Wink
B.
bobpullen
Community Gaffer
Community Gaffer
Posts: 16,893
Thanks: 4,986
Fixes: 316
Registered: ‎04-04-2007

Re: Spam platform problem

Thanks Barry, look interesting.
I'll flag it to the Net Ops guys. I know Si was working on a script that runs on DSpam and raises an alert if an unnatural volume of messages are accepted as clean but this may be a better way of doing things.

Bob Pullen
Plusnet Product Team
If I've been helpful then please give thanks ⤵