New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 24)
· Marcia's (CO8)
· Bill G's (CO12)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 1157
Comments: 21
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin 

Daisy-chaining Mailserver->Benign->MWP

 
Post new topic   Reply to topic       Computer Cops Forum Index -> Mailwasher - Troubleshooting / General
View previous topic :: View next topic  
Author Message
Eisenson

Corporal
Corporal
Premium Member
Premium Member


Joined: May 22, 2004
Posts: 59
Location: USA

PostPosted: Sat Jun 05, 2004 1:04 pm    Post subject: Daisy-chaining Mailserver->Benign->MWP
Reply with quote

Gary Partain (to whom many of us owe a lot!) says in his notes:
"...you can daisy-chain
MailWasher and Benign together. Benign will decode Base64, get rid of
extraneous comments, etc., that spammers try to use to confuse filters."

That might help, but I can't figure out how to do it. Other posts here say the two packages must be operated in parallel, not serial.

Thoughts?
Back to top
View users profile Send private message
rogerw

Major
Major
Premium Member
Premium Member


Joined: May 11, 2003
Posts: 857
Location: USA

PostPosted: Sat Jun 05, 2004 1:47 pm    Post subject:
Reply with quote

It was a good recommendation some time back, but as MW evolved and added new tools of spamcop reporting, First Alert, and Bayesian, it's no longer recommended.

Modifications of the email (except for a minor few specific ones) are disallowed by spamcop (they need to report the raw email).

Bayesian should have the raw emails reported.

First alert does a kind of a signature of the email. In order to match what others submit, the raw email needs to be processed, too.

All the other tools use IP addresses or email addresses....

So - don't bother with B9 in the path for MW. It's fine for your normal email program, though.
Back to top
View users profile Send private message
Eisenson

Corporal
Corporal
Premium Member
Premium Member


Joined: May 22, 2004
Posts: 59
Location: USA

PostPosted: Sat Jun 05, 2004 3:24 pm    Post subject:
Reply with quote

I bought Benign thinking it would reduce spam by helping MWP, via that stripping function mentioned by Partain. If that won't work, I don't mind having thrown a few extra dollars at Firetrust --- MWP has really paid off for me.

On the other hand, I don't use SpamCop, and wonder if there would be a net benefit to me by putting B9 before MWP.... I may try it one of these days.

But thanks to you gurus, my MWP installation is so well tweaked that it doesn't need much attention. I'm starting to miss the satisfaction from winning those battles, and might start all over again. Yeah, right!

_________________
Perfection is sometimes sufficient...
Back to top
View users profile Send private message
rogerw

Major
Major
Premium Member
Premium Member


Joined: May 11, 2003
Posts: 857
Location: USA

PostPosted: Sat Jun 05, 2004 5:34 pm    Post subject:
Reply with quote

Eisenson wrote:
I bought Benign thinking it would reduce spam by helping MWP, via that stripping function mentioned by Partain. If that won't work ....

B9 did do it's part in helping to reduce spam. About two (and more) years ago, almost all SPAM was laced with things like web bugs and other ways of sending the spammers PIA (personal identifying information) which served the purpose of letting spammers know that:
1) the spam was looked at
2) the email address the spam was sent to was a good one

If you looked at the spam your address got added to the next CD of email addresses spammers use.

B9 removed all those types of things - so if spam got into your mailbox, it was just an annoyance - not a means of tell the spammers you received their spam.

Now-a-days, the techniques used by spammers to do the things listed above have been pretty much abandoned for several reasons - the least of which is that programs like B9 have thwarted them.

In general terms, B9 is a privacy tool. It helped to lessen spam by virtue of that fact. I still use B9 in front of my email client so that the commercial mail I let through (like mailings from Real.com, Costco, Roxio, etc. - which still use all the PIA techniques to get feedback for their marketing) are stripped of those things to keep my presence in their marketing databases to a minimum. People who (seemingly) ignore their emails don't get *more* emails!

Gary was correct in pointing out that the filtering/conversion/processing done by B9 would allow one to write filters that didn't have to take into account the raw content of spam. In that respect, B9 would allow the less skilled to make use of the filtering tools in MW.

However, what B9 does is rather at cross-purposes with what MW has evolved to since that time. The filtering/changes that B9 does might, in fact, preclude accurate operation of spam tools.

Last edited by rogerw on Sun Jun 06, 2004 4:20 pm, edited 1 time in total
Back to top
View users profile Send private message
Ikeb

General
General
Premium Member
Premium Member


Joined: Apr 20, 2003
Posts: 3553
Location: Canada

PostPosted: Sun Jun 06, 2004 4:16 pm    Post subject:
Reply with quote

Good summary Roger! Thumbs Up
_________________
I like SPAM ... on my sandwich!
Back to top
View users profile Send private message Send email
rogerw

Major
Major
Premium Member
Premium Member


Joined: May 11, 2003
Posts: 857
Location: USA

PostPosted: Sun Jun 06, 2004 4:47 pm    Post subject:
Reply with quote

Ikeb wrote:
Good summary Roger
Thanks for the kudos....but as I think more on the subject, it would seem that if one is not using FA! OR Spamcop reporting - it might not be too counter-productive to use B9 in front of MW.

The filtering would be simplified from the constructor's POV (but not transportable to other setups).

Bayesian wouldn't be adversely affected (but, again, training files couldn't be portable to other machines).

In the long run, Joe Spamvicim might not be too disserved by the combination - but 'splaining the setup to him might be more trouble than it's worth.

Were one to decide to put B9 in front of MW, he'd need to wipe out his craining files and start anew, as the filtering B9 does would make the old training useless.
Back to top
View users profile Send private message
Ikeb

General
General
Premium Member
Premium Member


Joined: Apr 20, 2003
Posts: 3553
Location: Canada

PostPosted: Sun Jun 06, 2004 6:24 pm    Post subject:
Reply with quote

Dunno about having to wipe out training files. Why would SPAM/HAM word probabilities change?

Also, I don't see how B9 preprocessing would affect SpamCop reporting. Certainly it would affect FA! msg signatures though.

If I understand it correctly, Gary suggested a B9 proxy so as to allow binhex decoding before MWP filtering? I suppose that's a benefit for folks who receive a lot of legit binhexed msgs. I'd like to see MWP decode any encoded msgs (or at least allow the user the option to do so) but given the current choice, IMO I'd sooner have the benefit of FA! (it is improving).

_________________
I like SPAM ... on my sandwich!
Back to top
View users profile Send private message Send email
Display posts from previous:   
Post new topic   Reply to topic       Computer Cops Forum Index -> Mailwasher - Troubleshooting / General All times are GMT - 5 Hours
Page 1 of 1

 
 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB 2.0.8a © 2001 phpBB Group

Version 2.0.6 of PHP-Nuke Port by Tom Nitzschner © 2002 www.toms-home.com
Version 2.2 by Paul Laudanski © 2003-2004 Computer Cops