spam mail defined but can't tell

hkimac

Verified User
Joined
Jun 8, 2004
Messages
15
Hi,

My spam assasin doesn't write spam into the subject anymore, however, it gives me the following:

Please help for what to configure...

My spam assasin give me this in the email body
"


Spam detection software, running on the system "host.hkimac.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or block
similar future email. If you have any questions, see
the administrator of that system for details.

Content preview: <> Cheap softtwares for you, all are Original Genuine!
Major titles from MICR0S0FT and AD0BE for Rock Bottom prriice Great
Bargaain Sa1e! Variety discoount softtwares at wholesale chaeap
pricing! Micros0ft Wind0ws XP PR0fessional - my price: $50 ; normal :
$299.00 ; you saave $249.00 Ad0be Ph0toshop CS V 8.O PC - my price: $80
; normal : $609.99 ; you save $529.99 <> Micros0ft 0ffice XP
PR0fessional - my price: $100 ; normal : $ 499.95; you saave $399.95
Ad0be Acrobaat V 6.O Professional PC - my price: $100 ; normal :
$449.95 ; you saave $349.95 Micros0ft 0ffice 2OO3 Professional - my
price: $80 ; normal : $499.95 ; you saave $419.95 N0rton Antivirus 2OO4
Professional - my price: $15 ; normal : $69.95 ; you saave $54.95
CorelDraw Graphics Suite V 12 PC - my price: $100 ; normal : $349.95 ;
you saave $249.95 Ad0be Pagemaker V 7.O PC - my price: $80 ; normal :
$599.95 ; you saave $519.95 & many more titles [...]

Content analysis details: (9.8 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
1.3 MSGID_NO_HOST Message-Id has no hostname
0.3 NO_REAL_NAME From: does not include a real name
0.3 RCVD_NUMERIC_HELO Received: contains a numeric HELO
0.5 HTML_40_50 BODY: Message is 40% to 50% HTML
1.2 MIME_HTML_MOSTLY BODY: Multipart message mostly text/html MIME
0.0 HTML_MESSAGE BODY: HTML included in message
0.1 HTML_FONT_BIG BODY: HTML has a big font
0.0 LINES_OF_YELLING BODY: A WHOLE LINE OF YELLING DETECTED
0.6 SUBJ_ALL_CAPS Subject is all capitals
3.0 FORGED_RCVD_NET_HELO Host HELO'd using the wrong IP network
1.8 INVALID_MSGID Message-Id is not valid, according to RFC 2822
0.8 MSGID_FROM_MTA_HEADER Message-Id was added by a relay

The original message was not completely plain text, and may be unsafe to
open with some email clients; in particular, it may contain a virus,
or confirm that your address can receive spam. If you wish to view
it, it may be safer to save it to a file and open it with an editor.

"

And here is the header "


Return-path: <[email protected]>
Envelope-to: [email protected]
Delivery-date: Tue, 10 Aug 2004 14:07:00 +0800
Received: from mail by host.hkimac.com with spam-scanned (Exim 4.34)
id 1BuPml-0001Qs-Qz
for [email protected]; Tue, 10 Aug 2004 14:07:00 +0800
Received: from localhost by host.hkimac.com
with SpamAssassin (2.63 2004-01-11);
Tue, 10 Aug 2004 14:06:59 +0800
From: "" <[email protected]>
To: [email protected]
Subject: 0FFICE 2003 $8O! XP PR0 $5O; AD0BE PH0TOSH0P $8O; NORT0N 2004 $15; 0FFICE XP $100
Date: Tue, 10 Aug 2004 00:59:15 -0600
Message-Id: <xAMUsLsl0lrSkHDXJR8BABpjB@>
X-Spam-Flag: YES
X-Spam-Checker-Version: SpamAssassin 2.63 (2004-01-11) on host.hkimac.com
X-Spam-Level: *********
X-Spam-Status: Yes, hits=9.8 required=5.0 tests=FORGED_RCVD_NET_HELO,
HTML_40_50,HTML_FONT_BIG,HTML_MESSAGE,INVALID_MSGID,LINES_OF_YELLING,
MIME_HTML_MOSTLY,MSGID_FROM_MTA_HEADER,MSGID_NO_HOST,NO_REAL_NAME,
RCVD_NUMERIC_HELO,SUBJ_ALL_CAPS autolearn=no version=2.63
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----------=_41186603.847BCC58"


"



And the message subject is "
FFICE 2003 $8O! XP PR0 $5O; AD0BE PH0TOSH0P $8O; NORT0N 2004 $15; 0FFICE XP $100
"
 
That looks like the default SpamAssassin behavior when DirectAdmin is first installed.

So the first question is:

What did you do to change the behavior so it would write "spam" into the subject?

And the second question is"

What did you do to change the behavior back?

Both the "old" default exim.conf and the SpamBlocker exim.conf file I wrote configure SpamAssassin for the behavior your system is exhibiting.

Jeff
 
Hi,

I've been following instructions on the how to's.
All incoming emails aren't modified with subject "scanned or spam"

I found that in the /etc/exim.conf file, the lines that were suggested to added

"spool_directory = /var/spool/exim.in
queue_only = true
queue_only_override = false
log_file_path = /var/spool/exim/msglog/%slog
"

However, if we comment out the 2nd line, we will not be able to receive mail, however, once the 2nd line is uncomment, restart server, we can receive mail will subject "spam or scanned".

Can someone please help.

Thanks.

Here's the email when 2nd line is un-comment "
Return-path: <[email protected]>
Envelope-to: [email protected]
Delivery-date: Tue, 10 Aug 2004 22:38:43 +0800
Received: from mail by host.hkimac.com with spam-scanned (Exim 4.34)
id 1BuXly-0000xN-VX
for [email protected]; Tue, 10 Aug 2004 22:38:43 +0800
Received: from [218.254.20.21] (helo=[192.168.1.80])
by host.hkimac.com with asmtp (Exim 4.34)
id 1BuXly-0000xK-Ph
for [email protected]; Tue, 10 Aug 2004 22:38:42 +0800
User-Agent: Microsoft-Entourage/11.0.0.040405
Date: Tue, 10 Aug 2004 22:35:46 +0800
Subject: <no subject>
From: "[email protected]" <[email protected]>
To: "[email protected]" <[email protected]>
Message-ID: <BD3EFE42.D520%[email protected]>
Mime-version: 1.0
Content-type: multipart/alternative;
boundary="B_3175022147_220653"
X-Spam-Checker-Version: SpamAssassin 2.63 (2004-01-11) on host.hkimac.com
X-Spam-Level:
X-Spam-Status: No, hits=0.5 required=5.0 tests=AWL,HTML_40_50,HTML_MESSAGE,
TO_ADDRESS_EQ_REAL autolearn=no version=2.63


Here is the email when 2nd line comment out,
received after 2nd line un-comment.




"Return-path: <[email protected]>
Envelope-to: [email protected]
Delivery-date: Tue, 10 Aug 2004 22:37:17 +0800
Received: from mail by host.hkimac.com with spam-scanned (Exim 4.34)
id 1BuXfk-0000sf-1h
for [email protected]; Tue, 10 Aug 2004 22:32:19 +0800
Received: from [218.254.20.21] (helo=[192.168.1.80])
by host.hkimac.com with asmtp (Exim 4.34)
id 1BuXcj-0000xb-Hd
for [email protected]; Tue, 10 Aug 2004 22:29:09 +0800
User-Agent: Microsoft-Entourage/11.0.0.040405
Date: Tue, 10 Aug 2004 22:26:14 +0800
Subject: {Scanned} <no subject>
From: "[email protected]" <[email protected]>
To: "[email protected]" <[email protected]>
Message-ID: <BD3EFC06.D51D%[email protected]>
Mime-version: 1.0
Content-type: multipart/alternative;
boundary="B_3175021575_171562"
X-hkimac-MailScanner: Found to be clean, Found to be clean
X-hkimac-MailScanner-SpamCheck: not spam, SpamAssassin (score=0.486,
required 6, HTML_40_50 0.47, HTML_MESSAGE 0.00,
TO_ADDRESS_EQ_REAL 0.01), not spam, SpamAssassin (score=0.486,
required 6, HTML_40_50 0.47, HTML_MESSAGE 0.00,
TO_ADDRESS_EQ_REAL 0.01)
X-hkimac-MailScanner-Information: Please contact the ISP for more information
X-MailScanner-From: [email protected]
"
 
I can't; I just don't have time for "probono" work right now on non-standard installs.

Perhaps (hoperfully) someone else can.

Jeff
 
Back
Top