Re: [bitfolk] The perils of opening tcp/22 to the Internet

Top Page

Reply to this message
Author: Paul Tansom
Date:  
Subject: Re: [bitfolk] The perils of opening tcp/22 to the Internet
set=us-ascii
Content-Disposition: inline

I've just had an interesting problem turn up: I replied to an email
on a kernel.org mailing list. There were Chinese characters near the
top of the original mail. On its way out through my mail hub, the mail
was run through the Bitfolk spamassassin, which added its usual two
headers: one with the spam score in it, and one with a horribly
mangled extract of the original mail. This mail got rejected by
vger.kernel.org on the grounds that it doesn't accept UTF-8 in mail
headers.

Is there any way I can get the X-frost.carfax.org.uk-Spam-Report:
header either suppressed completely, or (in preference) without the
content of the original message in it?

I'm guessing the answer is "not without running your own
spamassassin", since this is a shared service, but I thought I'd ask
anyway, just in case...

Hugo.

-- 
=== Hugo Mills: hugo@... carfax.org.uk | darksatanic.net | lug.org.uk ===
  PGP key: 515C238D from wwwkeys.eu.pgp.net or http://www.carfax.org.uk
                 --- This year,  I'm giving up Lent. ---                 


--uc35eWnScqDcQrv5
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iD8DBQFOY8PPIKyzvlFcI40RAu6eAJ0cNkzPmlZeX/JmNmKCSvko6KmOKgCfTnSz
KMaGSK0cFLhcC5XsR0H1a1g=
=+4oB
-----END PGP SIGNATURE-----

--uc35eWnScqDcQrv5--


From dgl@??? Sun Sep 04 18:52:40 2011
Received: from [2a01:348:11:20::1] (helo=sirius.otherwize.co.uk
    ident=Debian-exim)
    by bitfolk.com with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32)
    (Exim 4.72) (envelope-from <dgl@???>) id 1R0Ho7-0000hl-Kc
    for users@???; Sun, 04 Sep 2011 18:52:40 +0000
Received: from babylon.otherwize.co.uk ([212.13.194.119]:52132
    helo=[127.0.0.1])
    by sirius.otherwize.co.uk with esmtpsa (TLS1.0:RSA_AES_128_CBC_SHA1:16)
    (Exim 4.71) (envelope-from <dgl@???>)
    id 1R0Hnn-0000E6-UN; Sun, 04 Sep 2011 18:52:19 +0000
Mime-Version: 1.0 (Apple Message framework v1244.3)
Content-Type: text/plain; charset=windows-1252
From: David Leadbeater <dgl@???>
In-Reply-To: <20110904183039.GG9907@???>
Date: Sun, 4 Sep 2011 19:52:17 +0100
Content-Transfer-Encoding: quoted-printable
Message-Id: <824754D3-AEDC-4D06-8F46-3942D897B9E1@???>
References: <20110904183039.GG9907@???>
To: Hugo Mills <hugo-bf@???>
X-Mailer: Apple Mail (2.1244.3)
X-bitfolk.com-Metrics-Host-Lookup-Failed: Reverse DNS lookup failed for
    2a01:348:11:20::1 (deferred)
X-Virus-Scanner: Scanned by ClamAV on bitfolk.com at Sun,
    04 Sep 2011 18:52:39 +0000
X-SA-Exim-Connect-IP: 2a01:348:11:20::1
X-SA-Exim-Mail-From: dgl@???
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on
    spamd3.lon.bitfolk.com
X-Spam-Level: *
X-Spam-ASN: 
X-Spam-Status: No, score=1.3 required=5.0 tests=RDNS_NONE shortcircuit=no
    autolearn=disabled version=3.3.1
X-Spam-Report: *  1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
X-SA-Exim-Version: 4.2.1 (built Wed, 25 Jun 2008 17:14:11 +0000)
X-SA-Exim-Scanned: Yes (on bitfolk.com)
Cc: BitFolk Users List <users@???>
Subject: Re: [bitfolk] Custom Spamassassin config
X-BeenThere: users@???
X-Mailman-Version: 2.1.11
Precedence: list
List-Id: Users of BitFolk hosting <users.lists.bitfolk.com>
List-Unsubscribe: <https://lists.bitfolk.com/mailman/options/users>,
    <mailto:users-request@lists.bitfolk.com?subject=unsubscribe>
List-Archive: <http://lists.bitfolk.com/lurker/list/users.html>
List-Post: <mailto:users@lists.bitfolk.com>
List-Help: <mailto:users-request@lists.bitfolk.com?subject=help>
List-Subscribe: <https://lists.bitfolk.com/mailman/listinfo/users>,
    <mailto:users-request@lists.bitfolk.com?subject=subscribe>
X-List-Received-Date: Sun, 04 Sep 2011 18:52:41 -0000


On 4 Sep 2011, at 19:30, Hugo Mills wrote:
[=85]
> Is there any way I can get the X-frost.carfax.org.uk-Spam-Report:
> header either suppressed completely, or (in preference) without the
> content of the original message in it?


The header is actually added on the MTA side rather than in spamd so it =
is configurable. An easier approach might be to avoid spam scanning mail =
you send outbound though.

David=


From hrm@??? Sun Sep 04 19:24:08 2011
Received: from [2001:ba8:1f1:f1d9:216:3eff:fe14:aef9]
    (helo=frost.carfax.org.uk)
    by bitfolk.com with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32)
    (Exim 4.72) (envelope-from <hrm@???>) id 1R0IIY-0001nR-TZ
    for users@???; Sun, 04 Sep 2011 19:24:08 +0000
Received: from ruthven.local ([10.73.18.16] helo=ruthven.carfax.org.uk)
    by frost.carfax.org.uk with esmtp (Exim 4.72)
    (envelope-from <hrm@???>)
    id 1R0IIW-000795-Oo; Sun, 04 Sep 2011 19:24:06 +0000
Received: from hrm by ruthven.carfax.org.uk with local (Exim 4.72)
    (envelope-from <hrm@???>)
    id 1R0IIV-0006Oe-TF; Sun, 04 Sep 2011 20:24:03 +0100
Date: Sun, 4 Sep 2011 20:24:03 +0100
From: Hugo Mills <hugo-bf@???>
To: David Leadbeater <dgl@???>
Message-ID: <20110904192403.GI9907@???>
References: <20110904183039.GG9907@???>
    <824754D3-AEDC-4D06-8F46-3942D897B9E1@???>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1;
    protocol="application/pgp-signature"; boundary="byLs0wutDcxFdwtm"
Content-Disposition: inline
In-Reply-To: <824754D3-AEDC-4D06-8F46-3942D897B9E1@???>
X-GPG-Fingerprint: 8C59 86C7 81F3 93FE BB02  DDB1 20AC B3BE 515C 238D
X-GPG-Key: 515C238D
X-Parrot: It is no more. It has joined the choir invisible.
X-IRC-Nicks: darksatanic darkersatanic darkling darkthing
User-Agent: Mutt/1.5.20 (2009-06-14)
X-frost.carfax.org.uk-Spam-Score: 0.0 (/)
X-bitfolk.com-Metrics-Host-Lookup-Failed: Reverse DNS lookup failed for
    2001:ba8:1f1:f1d9:216:3eff:fe14:aef9 (failed)
X-Virus-Scanner: Scanned by ClamAV on bitfolk.com at Sun,
    04 Sep 2011 19:24:07 +0000
X-SA-Exim-Connect-IP: 2001:ba8:1f1:f1d9:216:3eff:fe14:aef9
X-SA-Exim-Mail-From: hrm@???
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on
    spamd3.lon.bitfolk.com
X-Spam-Level: 
X-Spam-ASN: 
X-Spam-Status: No, score=0.0 required=5.0 tests=none shortcircuit=no
    autolearn=disabled version=3.3.1
X-Spam-Report: 
X-SA-Exim-Version: 4.2.1 (built Wed, 25 Jun 2008 17:14:11 +0000)
X-SA-Exim-Scanned: Yes (on bitfolk.com)
Cc: BitFolk Users List <users@???>
Subject: Re: [bitfolk] Custom Spamassassin config
X-BeenThere: users@???
X-Mailman-Version: 2.1.11
Precedence: list
List-Id: Users of BitFolk hosting <users.lists.bitfolk.com>
List-Unsubscribe: <https://lists.bitfolk.com/mailman/options/users>,
    <mailto:users-request@lists.bitfolk.com?subject=unsubscribe>
List-Archive: <http://lists.bitfolk.com/lurker/list/users.html>
List-Post: <mailto:users@lists.bitfolk.com>
List-Help: <mailto:users-request@lists.bitfolk.com?subject=help>
List-Subscribe: <https://lists.bitfolk.com/mailman/listinfo/users>,
    <mailto:users-request@lists.bitfolk.com?subject=subscribe>
X-List-Received-Date: Sun, 04 Sep 2011 19:24:08 -0000



--byLs0wutDcxFdwtm
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Sun, Sep 04, 2011 at 07:52:17PM +0100, David Leadbeater wrote:
> On 4 Sep 2011, at 19:30, Hugo Mills wrote:
> [=E2=80=A6]
> > Is there any way I can get the X-frost.carfax.org.uk-Spam-Report:
> > header either suppressed completely, or (in preference) without the
> > content of the original message in it?
>=20
> The header is actually added on the MTA side rather than in spamd so
> it is configurable. An easier approach might be to avoid spam
> scanning mail you send outbound though.


Aaah, thanks. I grepped for the header in /etc/exim4/conf.d/ but I
didn't do it in /etc/exim4 -- now I see where the relevant bits are
kept.

Anything which requires me to do more than trivial changes to my
mail config is not "easier". :)

Hugo.

--=20
=3D=3D=3D Hugo Mills: hugo@... carfax.org.uk | darksatanic.net | lug.org.uk=
 =3D=3D=3D
  PGP key: 515C238D from wwwkeys.eu.pgp.net or http://www.carfax.org.uk
     --- I don't care about "it works on my machine". We are not ---    =20
                         shipping your machine.                         =20


--byLs0wutDcxFdwtm
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (GNU/Linux)

iD8DBQFOY9BTIKyzvlFcI40RApxHAJ9jsZpbAJCsIuVxYbbysR3UgeGw/ACfd0jg
DfOI5JC2Zxef+OXNztlQD3c=
=6DGK
-----END PGP SIGNATURE-----

--byLs0wutDcxFdwtm--


From bitfolk-users@??? Sun Sep 04 20:58:53 2011
Received: from xvm-23-214.ghst.net ([92.243.23.214]
    helo=dogfood3.lampservers.net) by bitfolk.com with esmtp