<?xml version="1.0" encoding="utf-8" ?>
<?xml-stylesheet type="text/xsl" href="RSS_xslt_style.asp" version="1.0" ?>
<rss version="2.0" xmlns:WebWizForums="http://syndication.webwizguide.com/rss_namespace/">
 <channel>
  <title>Spam Filter ISP Forums</title>
  <link>http://www.logsat.com/spamfilter/forums/</link>
  <description>This is an XML content feed of; Spam Filter ISP Forums : Last 10 Posts</description>
  <pubDate>Thu, 11 Mar 2010 01:39:48 +0000</pubDate>
  <lastBuildDate>Wed, 10 Mar 2010 23:33:55 +0000</lastBuildDate>
  <docs>http://blogs.law.harvard.edu/tech/rss</docs>
  <generator>Web Wiz Forums 9.61</generator>
  <ttl>30</ttl>
  <WebWizForums:feedURL>www.logsat.com/spamfilter/forums/RSS_topic_feed.asp</WebWizForums:feedURL>
  <item>
   <title>Spam Filter ISP Support : DNS Error: Timedout</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6808&amp;PID=13477#13477</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8" rel="nofollow">LogSat</a><br /><strong>Subject:</strong> DNS Error: Timedout<br /><strong>Posted:</strong> 10 March 2010 at 11:33pm<br /><br />That timeout error usually does indicate just that - there was a timeout when querying the DNS. If you see 2-3 failures every 200-300 DNS queries, that's an acceptable amount of timeouts. If they are higher, it likely indicates other issues, which yes, would negatively impact the spam detection rate.<div><br></div><div><span ="Apple-style-span" style="font-family: Verdana; font-size: medium; line-height: normal; "><div><span ="Apple-style-span" style="font-size: small;">To see if there is an issue with the DNS servers specified in SpamFilter, you can try opening an MSDOS prompt on the server running SpamFilter, and issuing the following commands in bold, repeating the sequence 2-3 times, each time using a different DNS server, and ensuring you receive the 127.0.0.2 result and not a timeout:</span></div><div><br></div><div><div><font ="Apple-style-span" size="3"><span ="Apple-style-span" style="font-size: 11px; ">c:\&gt;<b>nslookup</b></span></font></div><div><font ="Apple-style-span" size="3"><span ="Apple-style-span" style="font-size: 11px; ">&gt;&nbsp;<b>server&nbsp;</b></span></font><font ="Apple-style-span" color="#008000"><font ="Apple-style-span" size="3"><span ="Apple-style-span" style="font-size: 11px; "><b>192.168.1.1 <font ="Apple-style-span" color="#0000CC"><span ="Apple-style-span" style="font-weight: normal;">&nbsp;(replace this IP with your DNS server)</span></font></b></span></font></font></div><div><font ="Apple-style-span" size="3"><span ="Apple-style-span" style="font-size: 11px; ">Default server: 192.168.1.1</span></font></div><div><font ="Apple-style-span" size="3"><span ="Apple-style-span" style="font-size: 11px; ">Address:&nbsp;192.168.1.1#53</span></font></div><div><font ="Apple-style-span" size="3"><span ="Apple-style-span" style="font-size: 11px; ">&gt;&nbsp;<b>247.47.246.41.bl.spamcop.net</b></span></font></div><div><font ="Apple-style-span" size="3"><span ="Apple-style-span" style="font-size: 11px; ">Server: &nbsp; &nbsp; &nbsp; &nbsp;&nbsp;192.168.1.1</span></font></div><div><font ="Apple-style-span" size="3"><span ="Apple-style-span" style="font-size: 11px; ">Address: &nbsp; &nbsp; &nbsp; &nbsp;192.168.1.1#53</span></font></div><div><font ="Apple-style-span" size="3"><span ="Apple-style-span" style="font-size: 11px; "><br></span></font></div><div><font ="Apple-style-span" size="3"><span ="Apple-style-span" style="font-size: 11px; ">Non-authoritative answer:</span></font></div><div><font ="Apple-style-span" size="3"><span ="Apple-style-span" style="font-size: 11px; ">Name: &nbsp; 49.201.79.189.bl.spamcop.net</span></font></div><div><font ="Apple-style-span" size="3"><span ="Apple-style-span" style="font-size: 11px; ">Address:&nbsp;</span></font><font ="Apple-style-span" color="#FF0000"><font ="Apple-style-span" size="3"><span ="Apple-style-span" style="font-size: 11px; "><b>127.0.0.2</b></span></font></font></div><div><font ="Apple-style-span" size="3"><span ="Apple-style-span" style="font-size: 11px; ">&gt;&nbsp;</span></font></div><div><br></div></div></span></div>]]>
   </description>
   <pubDate>Wed, 10 Mar 2010 23:33:55 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6808&amp;PID=13477#13477</guid>
  </item> 
  <item>
   <title>Spam Filter ISP Support : DNS Error: Timedout</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6808&amp;PID=13476#13476</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=199" rel="nofollow">lyndonje</a><br /><strong>Subject:</strong> DNS Error: Timedout<br /><strong>Posted:</strong> 10 March 2010 at 7:01am<br /><br />Hey,<div><br></div><div>I'm seeing this a lot in my logs:</div><div><br></div><div><div>03/10/10 11:51:53:671 -- (3128) DNS Error:TimedOut</div><div>03/10/10 11:51:53:671 -- (3128) DNS Server will rotate after query. New server will be x.x.x.x</div><div><br></div><div>I've also tried using a few different DNS servers but doing so makes no difference.&nbsp;</div><div><br></div><div>Is there any reason (other that delayed DNS response times) that may cause this?</div><div><br></div><div>What are the effects of this error on spam detection?&nbsp;</div><div><br></div><div>Is there anything I could do other than maybe find more responsive DNS servers?</div><div><br></div><div>Thanks.</div></div>]]>
   </description>
   <pubDate>Wed, 10 Mar 2010 07:01:50 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6808&amp;PID=13476#13476</guid>
  </item> 
  <item>
   <title>Spam Filter ISP Support : Time out causing duplication of email?</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6807&amp;PID=13475#13475</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8" rel="nofollow">LogSat</a><br /><strong>Subject:</strong> Time out causing duplication of email?<br /><strong>Posted:</strong> 09 March 2010 at 11:24pm<br /><br />lyndonje,<div><br></div><div>The behavior you describe is very odd. An incoming email is not complete until the &lt;CR&gt;.&lt;CR&gt; end-of-transmission sequence is received. SpamFilter cannot process an incoming email unless that sequence is received. If the remote server is dropping the connection (or timing out) <i>before </i>sending that sequence, it *should* be impossible to process the email (the should is because in IT you've never ever seen it all....)</div><div><br></div><div>What <i>could</i>&nbsp;happen in theory is that the remote server does send the &lt;CR&gt;.&lt;CR&gt; sequence (which will cause SpamFilter to accept the email), but then for some reason does not receive the "250 OK" acceptance SMTP code from SpamFilter, which tells the remote server that the email was received correctly. Without seeing this 250 return code, it would be likely that the remote server will retry. It's however rather strange that there could be a timeout that prevents SpamFilter from successfully sending the 250 return code while at the same time allowing the incoming email to make it thru.</div><div><br></div><div>If you can zip us to support @ logsat.com any logs you have (even the remote server's logs - we'll try to use those as well), we'll try to see what is happening. If you have the ability to also configure a full 2-way network capture (with Wireshark or similar) of the SMTP traffic to/from the remote server in question, this would greatly help in identifying the problem.</div>]]>
   </description>
   <pubDate>Tue, 09 Mar 2010 23:24:29 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6807&amp;PID=13475#13475</guid>
  </item> 
  <item>
   <title>Spam Filter ISP Support : Time out causing duplication of email?</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6807&amp;PID=13474#13474</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=199" rel="nofollow">lyndonje</a><br /><strong>Subject:</strong> Time out causing duplication of email?<br /><strong>Posted:</strong> 09 March 2010 at 5:13am<br /><br />Hi guys,<div><br></div><div>On a number of occasions we have been informed by a few different clients that emails from particular (but varied) senders are being received multiple times - like 100's!</div><div><br></div><div>Looking at the logs our end, we don't see a problem - to us we just see the sending server make a connection, send an email which we forward onto the destination server. I've now been able to get hold of some sort of log file from one of the senders which are experiencing this 'duplication' of emails. From what I can gather, there system connects and sends SF the email, SF does whatever checks it does, but before SF accepts/confirms delivery, the senders end hits a time out, drops the connection and&nbsp;re-queues&nbsp;the email for another delivery attempt later. Despite the senders end timing out before our server has confirmed receipt or acceptance, our server still forwards the email - presumably because our server knows its received the email in its entirety having receiving the &lt;CR&gt;.&lt;CR&gt; instruction? So assuming the email passed spam checks, the email is sent on.&nbsp;</div><div><br></div><div>The above course of events cause a loop, whereby our server receives and delivers the email, the senders continually times out before our server has confirmed acceptance, causing the sending server to re-queue, and re-deliver the email - and then the loop begins again.</div><div><br></div><div>If this is what's happening, I think either one of the following is wrong:</div><div><br></div><div>1) The senders end's time out is too short?</div><div>2) SF should not deliver an email if the connection is dropped/times out - just like it wouldn't if the connection was dropped part way through the DATA stage.</div><div><br></div><div>If number 2 is changed, so that SF does not deliver emails from which the connection is dropped even after a &lt;CR&gt;.&lt;CR&gt; is received, this will not prevent the senders end from timing out, so instead of receiving duplicates, our server would not forward any, meaning the email would never be received, and eventually a bounce back would be generated. What are your thoughts on this? And what do people thing the fix might be?&nbsp;</div><div><br></div>]]>
   </description>
   <pubDate>Tue, 09 Mar 2010 05:13:46 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6807&amp;PID=13474#13474</guid>
  </item> 
  <item>
   <title>Spam Filter ISP Support : V3.1.3.615 on Linux/MySQL &quot;update tblquarantine..&quot;</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6806&amp;PID=13473#13473</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=8" rel="nofollow">LogSat</a><br /><strong>Subject:</strong> V3.1.3.615 on Linux/MySQL &quot;update tblquarantine..&quot;<br /><strong>Posted:</strong> 06 March 2010 at 10:53pm<br /><br />Markus,<div><br></div><div>The version of SpamFilter you're running is <i>very</i>&nbsp;old :-) That was a known issue and was solved a long time ago starting with SpamFilter v3.5.3.657. The partial release notes for that build are as follows:</div><div><br></div><div><span ="Apple-style-span" style="font-family: Helvetica, Arial, sans-serif; line-height: 20px; "><div style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; ">// New to VersionNumber = '3.5.3.657';</div><div style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; ">{TODO -cFix : SpamFilter could send duplicate emails when executing the process that runs every 60 minutes that reprocesses emails in the queue, as it could re-send emails that were being delivered at that exact moment}</div><div style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; ">{TODO -cNew : Added support for AUTH PLAIN in addition to AUTH LOGIN}</div><div style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; ">{TODO -cFix : Solved issues with the quarantine grid display that prevented the quarantine list form being displayed with MS Access and Access Violations with MySQL }</div><div style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; ">{TODO -cNew : Added "ScanAllHeaders" option in SpamFilter.ini file to also scan all headers for keywords}</div><div style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; ">{TODO -cFix : Emails with multiple recipients on multiple domains - if different domains have different destination SMTP servers, the email is split and delivered to each server correctly}</div><div style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; "><b>{TODO -cFix : Converted all queries in lowercase to fix issues with Unix-based MySQL databases}</b></div></span></div>]]>
   </description>
   <pubDate>Sat, 06 Mar 2010 22:53:42 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6806&amp;PID=13473#13473</guid>
  </item> 
  <item>
   <title>Spam Filter ISP Support : V3.1.3.615 on Linux/MySQL &quot;update tblquarantine..&quot;</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6806&amp;PID=13472#13472</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=1287" rel="nofollow">Markus</a><br /><strong>Subject:</strong> V3.1.3.615 on Linux/MySQL &quot;update tblquarantine..&quot;<br /><strong>Posted:</strong> 06 March 2010 at 4:24pm<br /><br /><font face="Courier New, Courier, mono">Sorry for a Question about a old version of SpamFilter.<br>When I changed from Windows to Linux, there was a Error in the Activity Log telling me that a table does not exist:<br><br>Exception occurred during TDeleteExpiredQuarantineThread.Execute: &#091;MySQL&#093;&#091;ODBC 3.51 Driver&#093;&#091;mysqld-5.1.41-community&#093;Table 'spamdb.tblquarantine' doesn't exist<br><br>ODBC Logging showed me that SQL statements normally come with upper and lower case mixed. Example:<br><br>SELECT tblQuarantine.QuarID, tblQuarantine.EmailTo, tblQuarantine.EmailFrom, tblQuarantine.Deliver, tblQuarantine.Expire, tblMsgs.MsgID, tblMsgs.Msg FROM tblQuarantine INNER JOIN tblMsgs ON tblQuarantine.MsgID = tblMsgs.MsgID WHERE Deliver &lt;&gt; 0 AND Expire = 0 AND ( (ServerID = 1) OR (ServerID = 0) OR (ServerID IS NULL) );<br><br>Only one SQL statement that does the cleanup at the quarantine table is all in lower case:<br><br>update tblquarantine set expire = 1 where msgdate &lt;= _latin1'2010-02-04' and ( (serverid = 1) or (serverid = 0) or (serverid is null) );;<br><br>When I open the SpamFilter Application in a HEX Editor, I can find this SQL statement perfectely right:<br><br>UPDATE tblQuarantine SET Expire = 1 WHERE MsgDate &lt;= :MsgDate AND ( (ServerID = ...<br><br>Somewhere in the code, the whole SQL statement gets converted to lowercase?<br><br>What can I do to make the quarantine cleanup work?<br>(Do I have to install a stored procedure instead to do the job or can you fix it that the "</font><font face="Courier New, Courier, mono">UPDATE tblQuarantine SET Expire...</font><font face="Courier New, Courier, mono">" SQL statement doesen't get converted into lower case?)<img src="http://www.logsat.com/spamfilter/forums/smileys/smiley19.gif" border="0" alt="Cry" title="Cry" /><br><br></font><br>]]>
   </description>
   <pubDate>Sat, 06 Mar 2010 16:24:15 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6806&amp;PID=13472#13472</guid>
  </item> 
  <item>
   <title>Spam Filter ISP Support : New feature request - counters in database</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6805&amp;PID=13471#13471</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=104" rel="nofollow">yapadu</a><br /><strong>Subject:</strong> New feature request - counters in database<br /><strong>Posted:</strong> 06 March 2010 at 3:36am<br /><br />I don't know how much additional load it would place on the spamfilter server to have the software do it, but under heavy loads (hundreds of connections) I would imagine the overhead of the stats would be quite a bit.<br><br>Even my servers, which usually only have a few connections (maybe 10) I have had to setup two servers for sawmill to process the data.&nbsp; One for sawmill and one for mysql database to store the stats.&nbsp; Crunching data on a table with 50 million rows takes some serious power so there is no way I could do it on the spamfilter server itself.<br><br>I am actually trying to figure out a way to compress the data and store it in the amazon cloud or something.&nbsp; There when the users want it but not taking up massive amounts of space on the production servers.<br>]]>
   </description>
   <pubDate>Sat, 06 Mar 2010 03:36:41 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6805&amp;PID=13471#13471</guid>
  </item> 
  <item>
   <title>Spam Filter ISP Support : New feature request - counters in database</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6805&amp;PID=13470#13470</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=763" rel="nofollow">peet</a><br /><strong>Subject:</strong> New feature request - counters in database<br /><strong>Posted:</strong> 06 March 2010 at 1:50am<br /><br />Wow, processing the entire raw log. I didn't think about that, but on the other hand I didn't want the server processing so much data, just a simple counter.<div><br></div><div>My current storedprocedure utilizes MS SQL's temporary hold of records being added and based on the event, such as INSERT, it then triggers the storedprocedure and grabs the e-mail address, subtracts the domain and for that day it makes a count.</div><div>It is really easy and fast, and also fast to generate a bar-chart from that.</div><div>So for example a user can see the daily fluctuation of quarantined e-mails for their domain around 50,000 emails daily, and compare it to a graph next to that to their personal mailbox's quarantine with is around 50 for that particular e-mail account daily.</div><div><br></div><div>So if possible I'd like to avoid using raw logs. Server is busy enough already blocking junk e-mails based on the many filters.</div><span style="font-size:10px"><br /><br />Edited by peet - 06 March 2010 at 1:51am</span>]]>
   </description>
   <pubDate>Sat, 06 Mar 2010 01:50:32 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6805&amp;PID=13470#13470</guid>
  </item> 
  <item>
   <title>Spam Filter ISP Support : New feature request - counters in database</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6805&amp;PID=13469#13469</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=104" rel="nofollow">yapadu</a><br /><strong>Subject:</strong> New feature request - counters in database<br /><strong>Posted:</strong> 06 March 2010 at 1:23am<br /><br />I have actually been working on a stats system for our users, it has been several weeks already that I have been working on it.<br><br>I am using sawmill to process the raw logs, then I extract the data I want from the database that sawmill makes and put that data into my own tables.<br><br>We generate about 1 gig of logs per day, so the major issue has been the volume of data to deal with.<br><br>I am tracking messages received, quarantined, virus, forwarded as good.&nbsp; This data is broken down by email address (as well as email addresses that are invalid), by domain and by day.&nbsp; So users can see what is going on.<br><br>I would like to also capture country data and inbound email senders... but that is just too much data.<br>]]>
   </description>
   <pubDate>Sat, 06 Mar 2010 01:23:21 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6805&amp;PID=13469#13469</guid>
  </item> 
  <item>
   <title>Spam Filter ISP Support : New feature request - counters in database</title>
   <link>http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6805&amp;PID=13468#13468</link>
   <description>
    <![CDATA[<strong>Author:</strong> <a href="http://www.logsat.com/spamfilter/forums/member_profile.asp?PF=763" rel="nofollow">peet</a><br /><strong>Subject:</strong> New feature request - counters in database<br /><strong>Posted:</strong> 05 March 2010 at 11:58pm<br /><br />Hi,<div>I've written an enhanced web GUI(still working on it), using SQL DB from where I pickup the quarantined e-mail data.</div><div>As each new e-mail is added by the filter app, I trigger a counter that adds a new e-mail address to a separate table and a counter per day to count how many e-mails come in per day for that e-mail address.</div><div>Also do same for a domain name of that e-mail address to get totals.</div><div>SQL does all the work using a stored procedure.</div><div><br></div><div>But, I can only capture what the filter quarantines.</div><div><br></div><div>I'd love to see a more comprehensive counter per e-mail account and domain name.</div><div>- incoming e-mail count</div><div>- blocked e-mail count</div><div>- forwarded on good e-mail count</div><div>- quarantined e-mail count (this is all I have)</div><div><br></div><div>I build a chart based on the daily count so the user can see how traffic fluctuated over time. It is amazing how an account with average 30-50 quarantined spam per day can all of a sudden for a week drop to under 10 spams, and in another month all of a sudden jump for just one day into the hundreds.</div><div><br></div><div>But I'm only seeing quarantined.</div><div><br></div><div>So would it be possible, and would others also benefit from this?&nbsp;</div><div><br></div><div>Basically the filter would do a one-way communication to the quarantine DB or a local file or cache and later written to file.</div><div>Per email address, per day one record in a counter table for each of the counters.</div><div>Perhaps call a storedprocedure and just let that do the updating and counting freeing up the Filter's process of it.</div><div><br></div><div>It would be great to know the total of good vs. bad e-mails per e-mail account.</div><div><b><br></b></div><div><b>Please, others add your comment/support for this feature if you'd like to see it!</b>)</div>]]>
   </description>
   <pubDate>Fri, 05 Mar 2010 23:58:24 +0000</pubDate>
   <guid isPermaLink="true">http://www.logsat.com/spamfilter/forums/forum_posts.asp?TID=6805&amp;PID=13468#13468</guid>
  </item> 
 </channel>
</rss>