: From: Jeff Chan [mailto:jeffc@surbl.org]
: Hi Martin,
: On behalf of everyone contributing to the SURBL poject,
: thanks for your kind words. Glad you're finding SURBLs useful.
Hi!
We can't thank you guys enough. What should we do without SA and these
services? :)
: 1. Get rid of bigevil.cf, it's mostly in be.surbl.org 2. Get
: rid of be.surbl.org, it's in ws.surbl.org
Bigevil.cf and be.surbl.org removed.
Thanks for your help!
/ Martin
Ok guys, sorry there have been little updates to BE for a while. I have been
working closely with SURBL project. We have got to the point where BE is now
generated from ws.surbl.org which is what I have been contributing domains
to instead of BE. Awaiting for this day. :)
So we now have BE auto generated from WS.surbl.org...however this is a LOT
more data! HUGE increase. There are now 2369 rules!
TOP reports SIZE going from 22 megs to now 36 megs for spamd, however RSS
only went from 21 megs to 22 megs.
I have no idea how this will effect systems under heavy load. Those systems
should definitely stay with SURBL as this is just a local regex copy of it.
But for those systems that can't/won't use SURBL and want a local copy of
this larger bigevil here is the link: (~600k)
www.rulesemporium.com/rules/bigevil2.cf
PLEASE report any findings to this list. It lints fine and I'm running it
today. Part of me is wondering if this is even worthwhile when SA 3.0 will
support SURBL direct. So these tests may be just to see the effect of such a
ruleset on SA right now. We may just do away with it and have everyone use
SURBL.
The only updates I've been doing to the regular BE is removing a few FPs. I
will not officially make this new large file the regular Bigevil for at
least a week.
Again, please give feedback. Thanks!
Chris Santerre
System Admin and SARE Ninja
http://www.rulesemporium.comhttp://www.surbl.org
'It is not the strongest of the species that survives,
not the most intelligent, but the one most responsive to change.'
Charles Darwin
Hi!
I'm been using the SURBL-lists for some month now, and i'm very satisfied
with the results.
This is the lists i use at the moment:
# sc.surbl.org - SpamCop message-body URI domains
# ws.surbl.org - sa-blacklist domains as a SURBL
# be.surbl.org - BigEvil and MidEvil domains
# ob.surbl.org - OutBlaze spamvertised sites
# ab.surbl.org - AbuseButler spamvertised sites
I wonder if any of my following rulesets is overlapping the SURBL-lists and
should be removed?
I have the following rulesets:
70_sare_adult.cf
70_sare_random.cf
70_sare_specific.cf
72_sare_bml_post25x.cf
antidrug.cf
backhair.cf
bigevil.cf
chickenpox.cf
evilnumbers.cf
tripwire.cf
weeds.cf
Thanks alot for this great service, and keep up the good work guys!
/ Martin
>-----Original Message-----
>From: Jeff Chan [mailto:jeffc@surbl.org]
>Sent: Monday, June 28, 2004 10:41 PM
>To: SURBL Discuss
>Subject: [SURBL-Discuss] Pleaae beta test ds.surbl.org - 6dos data
>
>
>Please beta test ds.surbl.org which is the 6dos data turned into
>a SURBL. In particular, please check the false positive rate and
>let us know what you find.
>
>Please do not use ds.surbl.org for production mail servers as it
>is hosted only on my name server.
>
>(Chris, the list has about 120,000 entries. Were there some .c
>files which we should exclude?)
"So, drop: Misc.c Registrars.c Mainsleaze.c and that oughta put a pretty
big dent in complaints." - A friend. ;)
--Chris
Good day, all,
The physical host that hosts www.stearns.org, spamgate, and around
25 other virtual machines has experienced some massive drive problems over
the last 36 exhausing hours. I have the systems mostly up, but there's a
lot of cleanup work that needs to be done.
I don't expect to be able to restore the automatic update
functionality until this weekend.
To the best of my knowledge, ws.surbl.org (hosted on another
physical system) is working just fine. It'll keep providing the latest
list until I can get the automatic updates working again.
Cheers,
- Bill
---------------------------------------------------------------------------
"Absence is to love what wind is to fire. It extinguishes the
small, it enkindles the great."
(Courtesy of Arnaud Installe <ainstalle(a)filepool.com>)
--------------------------------------------------------------------------
William Stearns (wstearns(a)pobox.com). Mason, Buildkernel, freedups, p0f,
rsync-backup, ssh-keyinstall, dns-check, more at: http://www.stearns.org
--------------------------------------------------------------------------
>-----Original Message-----
>From: Jeff Chan [mailto:jeffc@surbl.org]
>Sent: Tuesday, June 29, 2004 10:24 AM
>To: SURBL Discussion list (E-mail)
>Subject: Re: [SURBL-Discuss] Whitelist entry needed
>
>
>On Tuesday, June 29, 2004, 7:18:15 AM, Chris Santerre wrote:
>> I can't get to Stearns site just yet to fix this. (server is
>up, but not
>> back to where we can change things yet.) We need to
>whitelist search.com
>
>I've whitelisted it in SURBLs.
>
Many thanks.
--chris
>-----Original Message-----
>From: Jeff Chan [mailto:jeffc@surbl.org]
>Sent: Tuesday, June 29, 2004 10:23 AM
>To: Chris Santerre
>Cc: 'Jeff Chan'; 'SURBL Discussion list'
>Subject: Re: [SURBL-Discuss] Pleaae beta test ds.surbl.org - 6dos data
>
>
>On Tuesday, June 29, 2004, 7:12:38 AM, Chris Santerre wrote:
>
>>>From: Jeff Chan [mailto:jeffc@surbl.org]
>
>>>As a data point, 6dos hit 300 whitelist entries out of 120,000
>>>records, which is about a ten times greater whitelist hit *rate*
>>>than ob.surbl.org.
>>>
>
>> 0.25% fp rate, so it has an S/O rating of 99.75 :)
>
>No, that's not an FP rate since my whitelist does not include
>every possible FP. In fact, it's rather limited. More like
>the 1000 most common web domains plus many more obscure
>geographic tlds that will probably never be used in spams.
LOL, you missed the joke there! ;)
>
>The whitelist hits might give a hint at relative FP rates between
>lists, but only actual testing against real messages will give
>meaningful FP rates.
Believe me, I know!
>
>> Actually that is great info. Can we get the whitelist hits?
>This might be a
>> great way to tweak the 6dos list. I'm also very interested
>in who hit the
>> whitelist. I'd like to see the xref in 6dos to see who these
>people are
>> dealing with. I think RSK would be interested as well.
>
>I've saved a copy of the 6dos hits against my whitelist at:
>
> http://spamcheck.freeapp.net/6dos.domains.whitelist-hits
>
Sweeeeet!
>The entire whitelist, including many geographic domains is at:
>
> http://spamcheck.freeapp.net/whitelist-domains.sort
>
>> Even if we have to clean up 1-2% of these listed, look how
>many evil domains
>> we get. But I fully understand your philosophy on this Jeff.
>Some of these
>> evil domains may not have spammed.....yet. ;)
>
>I don't mind pre-emptively listing every domain of every known
>spam operation. What we don't want are FPs on legitimate domains.
>
10-4 good buddy.
--Chris
I can't get to Stearns site just yet to fix this. (server is up, but not
back to where we can change things yet.) We need to whitelist search.com
Anyway you can fix that Jeff?
Chris Santerre
System Admin and SARE Ninja
http://www.rulesemporium.comhttp://www.surbl.org
'It is not the strongest of the species that survives,
not the most intelligent, but the one most responsive to change.'
Charles Darwin
>-----Original Message-----
>From: Jeff Chan [mailto:jeffc@surbl.org]
>Sent: Tuesday, June 29, 2004 1:21 AM
>To: SURBL Discuss
>Subject: Re: [SURBL-Discuss] Pleaae beta test ds.surbl.org - 6dos data
>
>
>On Monday, June 28, 2004, 7:46:16 PM, David Coulson wrote:
>> Jeff Chan wrote:
>>> Please do not use ds.surbl.org for production mail servers as it
>>> is hosted only on my name server.
>
>> Even though it took a day to load (almost), I've got it
>running on ns10
>> if you want to add that to the NS glue.
>
>Thanks David. I'd like to see what kind of false positive rates
>we see before committing to running it for real.
>
>As a data point, 6dos hit 300 whitelist entries out of 120,000
>records, which is about a ten times greater whitelist hit *rate*
>than ob.surbl.org.
>
0.25% fp rate, so it has an S/O rating of 99.75 :)
Actually that is great info. Can we get the whitelist hits? This might be a
great way to tweak the 6dos list. I'm also very interested in who hit the
whitelist. I'd like to see the xref in 6dos to see who these people are
dealing with. I think RSK would be interested as well.
Even if we have to clean up 1-2% of these listed, look how many evil domains
we get. But I fully understand your philosophy on this Jeff. Some of these
evil domains may not have spammed.....yet. ;)
--Chris
We are using the spamcop_uri with the 3 main feeds, ws, ob, ab and the main
man and we are seeing a reduction of 4-5 in our mail box in the mornings to
1, of course all the other junk is nailed with SA.
Great idea and a great addition to fighting the ads for pills, my small
p*nis and my girlfriends undersized headlight notifications as well as the
fact that I am approved for high interest loans. I am so gullible that I now
can rest easy knowing I won't be taken ;)
Thanks to the SURLB team...
--
David Thurman
The Web Presence Group
http://www.the-presence.com
Web Development/E-Commerce/CMS/Hosting/Dedicated Servers
800-399-6441/309-679-0774