<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for Random thoughts of an overloaded mind</title>
	<atom:link href="http://blog.amarkulo.com/comments/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.amarkulo.com</link>
	<description>Yet another technical blog about iOS, Windows, Linux, Arduino and everything else</description>
	<lastBuildDate>Wed, 28 Dec 2011 15:05:07 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by Juan</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-753</link>
		<dc:creator>Juan</dc:creator>
		<pubDate>Wed, 28 Dec 2011 15:05:07 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-753</guid>
		<description>amar, 

I am attaching the tail-f capture. Because the /^Received:/ HOLD sends them to the queue, but as the spamassassins and MailScanner takes to scan and there are accumulating mail in the queue of postfix and not forwarded to the exchange.

Dec 28 12:00:38 xxx MailScanner[22438]: Enabling SpamAssassin auto-whitelist functionality...
Dec 28 12:00:39 xxx MailScanner[22438]: Connected to Processing Attempts Database
Dec 28 12:00:39 xxx MailScanner[22438]: Found 108 messages in the Processing Attempts Database
Dec 28 12:00:39 xxx MailScanner[22438]: Using locktype = flock
Dec 28 12:00:39 xxx MailScanner[22438]: Warning: skipping message 83DBA8D460.AF3C0 as it has been attempted too many times
Dec 28 12:00:39 xxx MailScanner[22438]: Quarantined message 83DBA8D460.AF3C0 as it caused MailScanner to crash several times
Dec 28 12:00:43 xxx MailScanner[22439]: MailScanner E-Mail Virus Scanner version 4.84.3 starting...
Dec 28 12:00:43 xxx MailScanner[22439]: Reading configuration file /opt/MailScanner/etc/MailScanner.conf
Dec 28 12:00:43 xxx MailScanner[22439]: Reading configuration file /opt/MailScanner/etc/conf.d/README
Dec 28 12:00:43 xxx MailScanner[22439]: Read 869 hostnames from the phishing whitelist
Dec 28 12:00:43 xxx MailScanner[22439]: Read 3544 hostnames from the phishing blacklists

&quot;83DBA8D460 mail is safe&quot;</description>
		<content:encoded><![CDATA[<p>amar, </p>
<p>I am attaching the tail-f capture. Because the /^Received:/ HOLD sends them to the queue, but as the spamassassins and MailScanner takes to scan and there are accumulating mail in the queue of postfix and not forwarded to the exchange.</p>
<p>Dec 28 12:00:38 xxx MailScanner[22438]: Enabling SpamAssassin auto-whitelist functionality&#8230;<br />
Dec 28 12:00:39 xxx MailScanner[22438]: Connected to Processing Attempts Database<br />
Dec 28 12:00:39 xxx MailScanner[22438]: Found 108 messages in the Processing Attempts Database<br />
Dec 28 12:00:39 xxx MailScanner[22438]: Using locktype = flock<br />
Dec 28 12:00:39 xxx MailScanner[22438]: Warning: skipping message 83DBA8D460.AF3C0 as it has been attempted too many times<br />
Dec 28 12:00:39 xxx MailScanner[22438]: Quarantined message 83DBA8D460.AF3C0 as it caused MailScanner to crash several times<br />
Dec 28 12:00:43 xxx MailScanner[22439]: MailScanner E-Mail Virus Scanner version 4.84.3 starting&#8230;<br />
Dec 28 12:00:43 xxx MailScanner[22439]: Reading configuration file /opt/MailScanner/etc/MailScanner.conf<br />
Dec 28 12:00:43 xxx MailScanner[22439]: Reading configuration file /opt/MailScanner/etc/conf.d/README<br />
Dec 28 12:00:43 xxx MailScanner[22439]: Read 869 hostnames from the phishing whitelist<br />
Dec 28 12:00:43 xxx MailScanner[22439]: Read 3544 hostnames from the phishing blacklists</p>
<p>&#8220;83DBA8D460 mail is safe&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by Juan</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-750</link>
		<dc:creator>Juan</dc:creator>
		<pubDate>Wed, 28 Dec 2011 14:11:44 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-750</guid>
		<description>Hi Amar,
thanks for the help earlier, and fix those 2 problems.Ahora me I have the following are all queued mail (some are reliable and some not). I attached the result of tail-f /var/log/syslog

Dec 28 11:00:29 XXX postfix/pickup[21244]: 8DF748D8B6: uid=103 from= orig_id=076D48D885
Dec 28 11:00:29 XXX postfix/cleanup[21305]: 8DF748D8B6: message-id=
Dec 28 11:00:29 XXX postfix/qmgr[21245]: 8DF748D8B6: from=, size=1576, nrcpt=1 (queue active)

I have created in the directory /etc/postfix file &quot;header_checks&quot; with the single line: /^Received: / HOLD
if the comment before I left with # the mail in the queue, the problem you grow doubtful or spam mail.Thanks again</description>
		<content:encoded><![CDATA[<p>Hi Amar,<br />
thanks for the help earlier, and fix those 2 problems.Ahora me I have the following are all queued mail (some are reliable and some not). I attached the result of tail-f /var/log/syslog</p>
<p>Dec 28 11:00:29 XXX postfix/pickup[21244]: 8DF748D8B6: uid=103 from= orig_id=076D48D885<br />
Dec 28 11:00:29 XXX postfix/cleanup[21305]: 8DF748D8B6: message-id=<br />
Dec 28 11:00:29 XXX postfix/qmgr[21245]: 8DF748D8B6: from=, size=1576, nrcpt=1 (queue active)</p>
<p>I have created in the directory /etc/postfix file &#8220;header_checks&#8221; with the single line: /^Received: / HOLD<br />
if the comment before I left with # the mail in the queue, the problem you grow doubtful or spam mail.Thanks again</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by amar</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-746</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Tue, 27 Dec 2011 14:00:15 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-746</guid>
		<description>Hi Juan,

1. I think this is default behavior with notifying sender, but sending the whole content to admin I don&#039;t know how to do it, try with activating notifications and chech this link http://www.mailscanner.info/man/MailScanner.conf.5.html#Notifications%20back%20to%20the%20senders%20of%20blocked%20messages

2. If you check http://www.mailscanner.info/man/MailScanner.conf.5.html you will find that you have 2 possible settings, Maximum Message Size and Maximum Attachment Size where you can specify size in bytes to limit message</description>
		<content:encoded><![CDATA[<p>Hi Juan,</p>
<p>1. I think this is default behavior with notifying sender, but sending the whole content to admin I don&#8217;t know how to do it, try with activating notifications and chech this link <a href="http://www.mailscanner.info/man/MailScanner.conf.5.html#Notifications%20back%20to%20the%20senders%20of%20blocked%20messages" rel="nofollow">http://www.mailscanner.info/man/MailScanner.conf.5.html#Notifications%20back%20to%20the%20senders%20of%20blocked%20messages</a></p>
<p>2. If you check <a href="http://www.mailscanner.info/man/MailScanner.conf.5.html" rel="nofollow">http://www.mailscanner.info/man/MailScanner.conf.5.html</a> you will find that you have 2 possible settings, Maximum Message Size and Maximum Attachment Size where you can specify size in bytes to limit message</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by Juan</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-745</link>
		<dc:creator>Juan</dc:creator>
		<pubDate>Tue, 27 Dec 2011 13:52:54 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-745</guid>
		<description>Hi amar,

I was able to solve the above problems, but now I have the following:
1) I want to send copies of the emails in quarantine and also a notice of rejection (at least who is the sender and the receiver?) To an admin account or log to check.
2) I want to limit the size of attachments, but can not find in mailscanner.conf or rules for editing. Thanks

Regards</description>
		<content:encoded><![CDATA[<p>Hi amar,</p>
<p>I was able to solve the above problems, but now I have the following:<br />
1) I want to send copies of the emails in quarantine and also a notice of rejection (at least who is the sender and the receiver?) To an admin account or log to check.<br />
2) I want to limit the size of attachments, but can not find in mailscanner.conf or rules for editing. Thanks</p>
<p>Regards</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Display CGRect frame values in NSLog by amar</title>
		<link>http://blog.amarkulo.com/display-cgrect-frame-values-in-nslog-iphonedev#comment-714</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Thu, 22 Dec 2011 07:58:42 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=398#comment-714</guid>
		<description>You are welcome :-)</description>
		<content:encoded><![CDATA[<p>You are welcome <img src='http://blog.amarkulo.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Display CGRect frame values in NSLog by Ryan McLeod</title>
		<link>http://blog.amarkulo.com/display-cgrect-frame-values-in-nslog-iphonedev#comment-713</link>
		<dc:creator>Ryan McLeod</dc:creator>
		<pubDate>Thu, 22 Dec 2011 00:24:41 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=398#comment-713</guid>
		<description>Thanks!</description>
		<content:encoded><![CDATA[<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by Juan</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-666</link>
		<dc:creator>Juan</dc:creator>
		<pubDate>Thu, 15 Dec 2011 17:18:44 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-666</guid>
		<description>The line&gt; / dev / null 2​​&gt; &amp; 1 copy it and paste it in the crontab file, it may be that here is the error, now remove that line and ran this command: root @ xxxx: ~ # crontab-e&gt; / dev / null 2​​&gt; &amp; 1, did not return to # the peer&#039;m thinking (I ran the command correctly?). This command resolves that does not reach either of the 2 mail?. I am attaching the lines / opt / MailScanner / lib / MailScanner / Config.pm .El file is by default I did not do any modification
  
line 2213--MailScanner::Log::WarnLog(&quot;Syntax error(s) in configuration file:&quot;);
    #print STDERR &quot;Syntax error(s) in configuration file:\n&quot;;
    foreach $leftover (sort @leftovers) {
      MailScanner::Log::WarnLog(&quot;Unrecognised keyword \&quot;%s\&quot; at line %d&quot;,
                                ItoE($leftover), $LineNos{$leftover});
      #print STDERR &quot;Unrecognised keyword \&quot;&quot; . ItoE($leftover) .
      #             &quot;\&quot; at line &quot; . $LineNos{$leftover} . &quot;\n&quot;;
    }
    MailScanner::Log::WarnLog(&quot;Warning: syntax errors in %s.&quot;,
line  2222              $filename);
line 3132   #print STDERR &quot;Config: $keyword has a ruleset $isrules\n&quot;;
    if (!$RulesAllowed) {
      MailScanner::Log::WarnLog(&quot;Value of %s cannot be a ruleset, only a &quot; .
                                &quot;simple value&quot;, $keyword);
line 3136    }

Thanks for your time and sorry for my lack of knowledge of the subject and errors to the problem as well talk to you about my bad ingles.</description>
		<content:encoded><![CDATA[<p>The line&gt; / dev / null 2​​&gt; &amp; 1 copy it and paste it in the crontab file, it may be that here is the error, now remove that line and ran this command: root @ xxxx: ~ # crontab-e&gt; / dev / null 2​​&gt; &amp; 1, did not return to # the peer&#8217;m thinking (I ran the command correctly?). This command resolves that does not reach either of the 2 mail?. I am attaching the lines / opt / MailScanner / lib / MailScanner / Config.pm .El file is by default I did not do any modification</p>
<p>line 2213&#8211;MailScanner::Log::WarnLog(&#8220;Syntax error(s) in configuration file:&#8221;);<br />
    #print STDERR &#8220;Syntax error(s) in configuration file:\n&#8221;;<br />
    foreach $leftover (sort @leftovers) {<br />
      MailScanner::Log::WarnLog(&#8220;Unrecognised keyword \&#8221;%s\&#8221; at line %d&#8221;,<br />
                                ItoE($leftover), $LineNos{$leftover});<br />
      #print STDERR &#8220;Unrecognised keyword \&#8221;" . ItoE($leftover) .<br />
      #             &#8220;\&#8221; at line &#8221; . $LineNos{$leftover} . &#8220;\n&#8221;;<br />
    }<br />
    MailScanner::Log::WarnLog(&#8220;Warning: syntax errors in %s.&#8221;,<br />
line  2222              $filename);<br />
line 3132   #print STDERR &#8220;Config: $keyword has a ruleset $isrules\n&#8221;;<br />
    if (!$RulesAllowed) {<br />
      MailScanner::Log::WarnLog(&#8220;Value of %s cannot be a ruleset, only a &#8221; .<br />
                                &#8220;simple value&#8221;, $keyword);<br />
line 3136    }</p>
<p>Thanks for your time and sorry for my lack of knowledge of the subject and errors to the problem as well talk to you about my bad ingles.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by amar</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-664</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Thu, 15 Dec 2011 15:49:34 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-664</guid>
		<description>Hmm I don&#039;t understand why crontab part is not working, you maybe did something wrong because you should add it to crontab line with crontab -e command, not to any config file so it shouldn&#039;t interfere with those files and create errors that you get. Check those 2 lines 2216 and 2221 for errors.

Logs should be available in /opt/Mailscanner and eventual bounce messages should return to senders.</description>
		<content:encoded><![CDATA[<p>Hmm I don&#8217;t understand why crontab part is not working, you maybe did something wrong because you should add it to crontab line with crontab -e command, not to any config file so it shouldn&#8217;t interfere with those files and create errors that you get. Check those 2 lines 2216 and 2221 for errors.</p>
<p>Logs should be available in /opt/Mailscanner and eventual bounce messages should return to senders.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by Juan</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-662</link>
		<dc:creator>Juan</dc:creator>
		<pubDate>Thu, 15 Dec 2011 15:40:50 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-662</guid>
		<description>thank amar,

I commented that add the line &quot;&gt; / dev / null 2​​&gt; &amp; 1&quot; at the end of the crontab file and mail Mailscanner.conf and I keep coming, but in the case of modification of MailScanner gives me an error when I restart the service :

root@xxxx:~# root@xxx:~# service mailscanner restart
 * Restarting mail spam/virus scanner MailScanner
Syntax error(s) in configuration file: at /opt/MailScanner/lib/MailScanner/Config.pm line 2213
Unrecognised keyword &quot;optmailscannerbin&quot; at line 3132 at /opt/MailScanner/lib/MailScanner/Config.pm line 2216
Warning: syntax errors in /opt/MailScanner/etc/MailScanner.conf. at /opt/MailScanner/lib/MailScanner/Config.pm line 2221

So I had to undo the last change to service MailScanner start.
Finally the last question I want to add the following, where seconfigura mail notifications to the administrator&#039;s mail in quarantine or are bounced by spam or where you can view these log (would need the commands) Thanks again and sorry for my bad English</description>
		<content:encoded><![CDATA[<p>thank amar,</p>
<p>I commented that add the line &#8220;&gt; / dev / null 2​​&gt; &amp; 1&#8243; at the end of the crontab file and mail Mailscanner.conf and I keep coming, but in the case of modification of MailScanner gives me an error when I restart the service :</p>
<p>root@xxxx:~# root@xxx:~# service mailscanner restart<br />
 * Restarting mail spam/virus scanner MailScanner<br />
Syntax error(s) in configuration file: at /opt/MailScanner/lib/MailScanner/Config.pm line 2213<br />
Unrecognised keyword &#8220;optmailscannerbin&#8221; at line 3132 at /opt/MailScanner/lib/MailScanner/Config.pm line 2216<br />
Warning: syntax errors in /opt/MailScanner/etc/MailScanner.conf. at /opt/MailScanner/lib/MailScanner/Config.pm line 2221</p>
<p>So I had to undo the last change to service MailScanner start.<br />
Finally the last question I want to add the following, where seconfigura mail notifications to the administrator&#8217;s mail in quarantine or are bounced by spam or where you can view these log (would need the commands) Thanks again and sorry for my bad English</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by Juan</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-660</link>
		<dc:creator>Juan</dc:creator>
		<pubDate>Thu, 15 Dec 2011 13:59:30 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-660</guid>
		<description>thank amar,

I commented that add the line &quot;&gt; / dev / null 2​​&gt; &amp; 1&quot; at the end of the crontab file and mail Mailscanner.conf and I keep coming, but in the case of modification of MailScanner gives me an error when I restart the service :

root@PMCSpam:~# root@xxx:~# service mailscanner restart
 * Restarting mail spam/virus scanner MailScanner
Syntax error(s) in configuration file: at /opt/MailScanner/lib/MailScanner/Config.pm line 2213
Unrecognised keyword &quot;optmailscannerbin&quot; at line 3132 at /opt/MailScanner/lib/MailScanner/Config.pm line 2216
Warning: syntax errors in /opt/MailScanner/etc/MailScanner.conf. at /opt/MailScanner/lib/MailScanner/Config.pm line 2221

So I had to undo the last change to service MailScanner start.
Finally the last question I want to add the following, where seconfigura mail notifications to the administrator&#039;s mail in quarantine or are bounced by spam or where you can view these log (would need the commands) Thanks again and sorry for my bad English</description>
		<content:encoded><![CDATA[<p>thank amar,</p>
<p>I commented that add the line &#8220;&gt; / dev / null 2​​&gt; &amp; 1&#8243; at the end of the crontab file and mail Mailscanner.conf and I keep coming, but in the case of modification of MailScanner gives me an error when I restart the service :</p>
<p>root@PMCSpam:~# root@xxx:~# service mailscanner restart<br />
 * Restarting mail spam/virus scanner MailScanner<br />
Syntax error(s) in configuration file: at /opt/MailScanner/lib/MailScanner/Config.pm line 2213<br />
Unrecognised keyword &#8220;optmailscannerbin&#8221; at line 3132 at /opt/MailScanner/lib/MailScanner/Config.pm line 2216<br />
Warning: syntax errors in /opt/MailScanner/etc/MailScanner.conf. at /opt/MailScanner/lib/MailScanner/Config.pm line 2221</p>
<p>So I had to undo the last change to service MailScanner start.<br />
Finally the last question I want to add the following, where seconfigura mail notifications to the administrator&#8217;s mail in quarantine or are bounced by spam or where you can view these log (would need the commands) Thanks again and sorry for my bad English</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by amar</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-654</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Wed, 14 Dec 2011 20:40:15 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-654</guid>
		<description>Yes you are correct, you nat or forward port 25 to postfix which filters it and then forward further.

Now regarding cron you have set it to update itself from cron, so you can edit crontab and add &gt;/dev/null 2&gt;&amp;1 at the end of the mailscanner line so it won&#039;t send you e-mail and it will update itself.

Answer to the second question is pretty simple, try to send yourself copy of some spam mail, or mail that contains .exe file, spamassasing should put it to quarantine and you would receive mail that attachment has been removed.

Also when you check mail headers you should see spamasassin score in the header.</description>
		<content:encoded><![CDATA[<p>Yes you are correct, you nat or forward port 25 to postfix which filters it and then forward further.</p>
<p>Now regarding cron you have set it to update itself from cron, so you can edit crontab and add >/dev/null 2>&#038;1 at the end of the mailscanner line so it won&#8217;t send you e-mail and it will update itself.</p>
<p>Answer to the second question is pretty simple, try to send yourself copy of some spam mail, or mail that contains .exe file, spamassasing should put it to quarantine and you would receive mail that attachment has been removed.</p>
<p>Also when you check mail headers you should see spamasassin score in the header.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by Juan</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-653</link>
		<dc:creator>Juan</dc:creator>
		<pubDate>Wed, 14 Dec 2011 19:29:27 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-653</guid>
		<description>Hi,

All very good first scenario is the tutorial.mi the firewall nat all that comes to port 25 to an X port you configure in the postfix (Intal from your tutorial), he analyzes the mail and forwards it to me to exchange 2010 up here ok.Mi question is this: first I get mail sent by the cron (attached) and the other is how to update and how do I verify the basis of MailScanner, ClamAV and SpamAssassin?

Attached:
from:From: Cron Daemon 
To: 
Subject: Cron  /opt/MailScanner/bin/check_mailscanner
Message:MailScanner running with pid 1261 1262 1431 1432 1433 1434 
Message:Failed to retrieve valid current details Reading status from /var/spool/MailScanner/quarantine/phishingupdate/status
Checking that /var/spool/MailScanner/quarantine/phishingupdate/cache/2011-493 exists... ok Checking that /var/spool/MailScanner/quarantine/phishingupdate/cache/2011-493.32 exists... ok</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>All very good first scenario is the tutorial.mi the firewall nat all that comes to port 25 to an X port you configure in the postfix (Intal from your tutorial), he analyzes the mail and forwards it to me to exchange 2010 up here ok.Mi question is this: first I get mail sent by the cron (attached) and the other is how to update and how do I verify the basis of MailScanner, ClamAV and SpamAssassin?</p>
<p>Attached:<br />
from:From: Cron Daemon<br />
To:<br />
Subject: Cron  /opt/MailScanner/bin/check_mailscanner<br />
Message:MailScanner running with pid 1261 1262 1431 1432 1433 1434<br />
Message:Failed to retrieve valid current details Reading status from /var/spool/MailScanner/quarantine/phishingupdate/status<br />
Checking that /var/spool/MailScanner/quarantine/phishingupdate/cache/2011-493 exists&#8230; ok Checking that /var/spool/MailScanner/quarantine/phishingupdate/cache/2011-493.32 exists&#8230; ok</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-651</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Wed, 14 Dec 2011 14:34:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-651</guid>
		<description>Glad that I could help.

Cheers</description>
		<content:encoded><![CDATA[<p>Glad that I could help.</p>
<p>Cheers</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by Hans</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-650</link>
		<dc:creator>Hans</dc:creator>
		<pubDate>Wed, 14 Dec 2011 14:33:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-650</guid>
		<description>Excellent, I will try to finish up my install today. Thanks again!</description>
		<content:encoded><![CDATA[<p>Excellent, I will try to finish up my install today. Thanks again!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-645</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Wed, 14 Dec 2011 07:23:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-645</guid>
		<description>I think they should without any problem, the only thing changed are new ruleset and eventually some new config options in snort.conf but as we are using default one with removed ssh preprocessor it should work.</description>
		<content:encoded><![CDATA[<p>I think they should without any problem, the only thing changed are new ruleset and eventually some new config options in snort.conf but as we are using default one with removed ssh preprocessor it should work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by Hans</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-639</link>
		<dc:creator>Hans</dc:creator>
		<pubDate>Tue, 13 Dec 2011 19:39:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-639</guid>
		<description>Another quick question for you Amar. The newest version of Snort is currently at 2.9 something, will these directions work with the newest version too?

I&#039;m looking through the snort.conf now and things seem to be a bit different.  Once again thanks for your time and patience..</description>
		<content:encoded><![CDATA[<p>Another quick question for you Amar. The newest version of Snort is currently at 2.9 something, will these directions work with the newest version too?</p>
<p>I&#8217;m looking through the snort.conf now and things seem to be a bit different.  Once again thanks for your time and patience..</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-635</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Tue, 13 Dec 2011 18:05:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-635</guid>
		<description>No hard feelings here ;-)

Reason for moderation is that akismet spam filter is down sometimes and then I got loads of spam idiots with replicas of watches, viagra, you name it which I block manually, but all comments from real people are approved directly, good and bad ones.

Glad that you find blog helpful.

Regards
Amar</description>
		<content:encoded><![CDATA[<p>No hard feelings here <img src='http://blog.amarkulo.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>Reason for moderation is that akismet spam filter is down sometimes and then I got loads of spam idiots with replicas of watches, viagra, you name it which I block manually, but all comments from real people are approved directly, good and bad ones.</p>
<p>Glad that you find blog helpful.</p>
<p>Regards<br />
Amar</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by Hans</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-634</link>
		<dc:creator>Hans</dc:creator>
		<pubDate>Tue, 13 Dec 2011 18:03:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-634</guid>
		<description>I want to apologize for being so hasty with my words. I do understand the spam and wanted to be a man and apologize for being rude. You don&#039;t have to post this, I just wanted you to know i feel like a complete a-hole about it! Have a great day and great blog, best of luck!</description>
		<content:encoded><![CDATA[<p>I want to apologize for being so hasty with my words. I do understand the spam and wanted to be a man and apologize for being rude. You don&#8217;t have to post this, I just wanted you to know i feel like a complete a-hole about it! Have a great day and great blog, best of luck!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-633</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Tue, 13 Dec 2011 16:55:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-633</guid>
		<description>Tnx, will do.

Regarding your comments about moderation it&#039;s not moderation that&#039;s issue, it&#039;s spam.</description>
		<content:encoded><![CDATA[<p>Tnx, will do.</p>
<p>Regarding your comments about moderation it&#8217;s not moderation that&#8217;s issue, it&#8217;s spam.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by Hans</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-630</link>
		<dc:creator>Hans</dc:creator>
		<pubDate>Tue, 13 Dec 2011 16:52:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-630</guid>
		<description>Your link to download snort is dead.. Please update it so people can continue to use your directions and get the correct version of snort.. Thank you..</description>
		<content:encoded><![CDATA[<p>Your link to download snort is dead.. Please update it so people can continue to use your directions and get the correct version of snort.. Thank you..</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by amar</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-627</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Mon, 12 Dec 2011 16:53:46 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-627</guid>
		<description>You can set list of domains that are accepted for relaying and it will allow sending only for them.

http://www.postfix.org/SMTPD_ACCESS_README.html

Tnx for highlighting type error, I will fix it in the post.</description>
		<content:encoded><![CDATA[<p>You can set list of domains that are accepted for relaying and it will allow sending only for them.</p>
<p><a href="http://www.postfix.org/SMTPD_ACCESS_README.html" rel="nofollow">http://www.postfix.org/SMTPD_ACCESS_README.html</a></p>
<p>Tnx for highlighting type error, I will fix it in the post.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by Adam</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-626</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Mon, 12 Dec 2011 16:43:04 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-626</guid>
		<description>I got working, there was two things:
1- The first problem was on master.cf I had to uncomment one line.
2- I copy/paste your main.cf and there was a mistype in: myorigin = $mydomain
(it was: myorgin = $mydomain).

Thanks a lot man.

I want to use it on production, so can we harden it for more spams filtering ?
I tried to send using aaaa@aaaa.com and it works, and don&#039;t want it to work for this kind of emails.
Can you help on this please.

Thanks again.</description>
		<content:encoded><![CDATA[<p>I got working, there was two things:<br />
1- The first problem was on master.cf I had to uncomment one line.<br />
2- I copy/paste your main.cf and there was a mistype in: myorigin = $mydomain<br />
(it was: myorgin = $mydomain).</p>
<p>Thanks a lot man.</p>
<p>I want to use it on production, so can we harden it for more spams filtering ?<br />
I tried to send using <a href="mailto:aaaa@aaaa.com">aaaa@aaaa.com</a> and it works, and don&#8217;t want it to work for this kind of emails.<br />
Can you help on this please.</p>
<p>Thanks again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by amar</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-625</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Mon, 12 Dec 2011 14:57:06 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-625</guid>
		<description>Hello Adam,

This configuration seems ok, but I would say that you have problem with transport file or master.cf so check them if they are correct.

Master.cf can be pain in the ass, spaces and dashes matters there.</description>
		<content:encoded><![CDATA[<p>Hello Adam,</p>
<p>This configuration seems ok, but I would say that you have problem with transport file or master.cf so check them if they are correct.</p>
<p>Master.cf can be pain in the ass, spaces and dashes matters there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by Adam</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-622</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Wed, 07 Dec 2011 22:23:15 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-622</guid>
		<description>Amar, just to understand, we are trying to configure a MTA (SMTP relay) for Exchange.
For my part: MX record is set up on the DNS, relayhost is empty (relayhost = )
my main.cf look like this:
myhostname = smtp1.office.com
mydomain = office.com
myorgin = $mydomain
inet_interfaces = all
mydestination = $myhostname, localhost.$mydomain $mydomain
mynetwork_style = host
relay_domains = office.com
transport_maps = hash:/etc/postfix/transport
append_at_myorigin = no
local_recipient_maps =
header_checks = regexp:/etc/postfix/header_checks
alias_maps = hash:/etc/aliases
alias_database = hash:/etc/aliases
relayhost = 
mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128
mailbox_size_limit = 0
recipient_delimiter = +

Kindly, could you review it please.
Thanks.</description>
		<content:encoded><![CDATA[<p>Amar, just to understand, we are trying to configure a MTA (SMTP relay) for Exchange.<br />
For my part: MX record is set up on the DNS, relayhost is empty (relayhost = )<br />
my main.cf look like this:<br />
myhostname = smtp1.office.com<br />
mydomain = office.com<br />
myorgin = $mydomain<br />
inet_interfaces = all<br />
mydestination = $myhostname, localhost.$mydomain $mydomain<br />
mynetwork_style = host<br />
relay_domains = office.com<br />
transport_maps = hash:/etc/postfix/transport<br />
append_at_myorigin = no<br />
local_recipient_maps =<br />
header_checks = regexp:/etc/postfix/header_checks<br />
alias_maps = hash:/etc/aliases<br />
alias_database = hash:/etc/aliases<br />
relayhost =<br />
mynetworks = 127.0.0.0/8 [::ffff:127.0.0.0]/104 [::1]/128<br />
mailbox_size_limit = 0<br />
recipient_delimiter = +</p>
<p>Kindly, could you review it please.<br />
Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by amar</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-619</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Tue, 06 Dec 2011 06:37:40 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-619</guid>
		<description>Hello Adam,

Actually there isn&#039;t any configuration for exchange, because linux is acting as a gateway so it intercepts mail and deliver it to next hop, which is exchange.

Check which ip addresses you have for test domain, and it&#039;s mx records, it could be a dns problem, because as I can see it from your logs postfix is not sending it further, it&#039;s stopping them because it&#039;s not able to reach domain.</description>
		<content:encoded><![CDATA[<p>Hello Adam,</p>
<p>Actually there isn&#8217;t any configuration for exchange, because linux is acting as a gateway so it intercepts mail and deliver it to next hop, which is exchange.</p>
<p>Check which ip addresses you have for test domain, and it&#8217;s mx records, it could be a dns problem, because as I can see it from your logs postfix is not sending it further, it&#8217;s stopping them because it&#8217;s not able to reach domain.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by Adam</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-618</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Mon, 05 Dec 2011 23:04:06 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-618</guid>
		<description>Thanks Amar for this How-To,
Is there any configuration we need to do on the Exchange Server ?

I am asking this question because I am getting these logs:

Dec  5 17:41:19 smtp1 postfix/smtpd[4234]: connect from test-host[192.168.1.10]
Dec  5 17:41:19 smtp1 postfix/smtpd[4234]: 8316424600C7: client=test-host[192.168.1.10]
Dec  5 17:41:19 smtp1 postfix/cleanup[4238]: 8316424600C7: hold: header Received: from monitor-test.office.com (test-host [192.168.1.10])??by smtp1.office.com (Postfix) with ESMTPS id 8316424600C7??for ; Mon,  5 Dec from test-host[192.168.1.10]; from= to= proto=ESMTP helo=
Dec  5 17:41:19 smtp1 postfix/cleanup[4238]: 8316424600C7: message-id=
Dec  5 17:41:19 smtp1 postfix/smtpd[4234]: disconnect from test-host[192.168.1.10]
Dec  5 17:41:39 smtp1 postfix/qmgr[3725]: 34D0B24600A2: from=, size=908, nrcpt=1 (queue active)
Dec  5 17:41:39 smtp1 postfix/qmgr[3725]: warning: connect to transport private/smtp [192.168.2.20]: No such file or directory
Dec  5 17:41:39 smtp1 postfix/qmgr[3725]: 4BBBB24600A8: from=, size=908, nrcpt=1 (queue active)
Dec  5 17:41:39 smtp1 postfix/error[4240]: 34D0B24600A2: to=, relay=none, delay=8826, delays=8826/0/0/0, dsn=4.3.0, status=deferred (mail transport unavailable)
Dec  5 17:41:39 smtp1 postfix/error[4241]: 4BBBB24600A8: to=, relay=none, delay=8798, delays=8798/0.01/0/0, dsn=4.3.0, status=deferred (mail transport unavailable)
Dec  5 17:42:01 smtp1 update.virus.scanners: Found clamav installed
Dec  5 17:42:01 smtp1 update.virus.scanners: Running autoupdate for clamav
Dec  5 17:42:01 smtp1 ClamAV-autoupdate[4305]: ClamAV updater /usr/local/bin/freshclam cannot be run
Dec  5 17:42:01 smtp1 update.virus.scanners: Found generic installed
Dec  5 17:42:01 smtp1 update.virus.scanners: Running autoupdate for generic

Client sending email is 192.168.1.10 (root@monitor-test.office.com) and destination email address is test-user@office.com and exchange server is 192.168.2.20

Thanks for your help.</description>
		<content:encoded><![CDATA[<p>Thanks Amar for this How-To,<br />
Is there any configuration we need to do on the Exchange Server ?</p>
<p>I am asking this question because I am getting these logs:</p>
<p>Dec  5 17:41:19 smtp1 postfix/smtpd[4234]: connect from test-host[192.168.1.10]<br />
Dec  5 17:41:19 smtp1 postfix/smtpd[4234]: 8316424600C7: client=test-host[192.168.1.10]<br />
Dec  5 17:41:19 smtp1 postfix/cleanup[4238]: 8316424600C7: hold: header Received: from monitor-test.office.com (test-host [192.168.1.10])??by smtp1.office.com (Postfix) with ESMTPS id 8316424600C7??for ; Mon,  5 Dec from test-host[192.168.1.10]; from= to= proto=ESMTP helo=<br />
Dec  5 17:41:19 smtp1 postfix/cleanup[4238]: 8316424600C7: message-id=<br />
Dec  5 17:41:19 smtp1 postfix/smtpd[4234]: disconnect from test-host[192.168.1.10]<br />
Dec  5 17:41:39 smtp1 postfix/qmgr[3725]: 34D0B24600A2: from=, size=908, nrcpt=1 (queue active)<br />
Dec  5 17:41:39 smtp1 postfix/qmgr[3725]: warning: connect to transport private/smtp [192.168.2.20]: No such file or directory<br />
Dec  5 17:41:39 smtp1 postfix/qmgr[3725]: 4BBBB24600A8: from=, size=908, nrcpt=1 (queue active)<br />
Dec  5 17:41:39 smtp1 postfix/error[4240]: 34D0B24600A2: to=, relay=none, delay=8826, delays=8826/0/0/0, dsn=4.3.0, status=deferred (mail transport unavailable)<br />
Dec  5 17:41:39 smtp1 postfix/error[4241]: 4BBBB24600A8: to=, relay=none, delay=8798, delays=8798/0.01/0/0, dsn=4.3.0, status=deferred (mail transport unavailable)<br />
Dec  5 17:42:01 smtp1 update.virus.scanners: Found clamav installed<br />
Dec  5 17:42:01 smtp1 update.virus.scanners: Running autoupdate for clamav<br />
Dec  5 17:42:01 smtp1 ClamAV-autoupdate[4305]: ClamAV updater /usr/local/bin/freshclam cannot be run<br />
Dec  5 17:42:01 smtp1 update.virus.scanners: Found generic installed<br />
Dec  5 17:42:01 smtp1 update.virus.scanners: Running autoupdate for generic</p>
<p>Client sending email is 192.168.1.10 (root@monitor-test.office.com) and destination email address is <a href="mailto:test-user@office.com">test-user@office.com</a> and exchange server is 192.168.2.20</p>
<p>Thanks for your help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on CANON PowerShot and Ixus service manual and part list by budi</title>
		<link>http://blog.amarkulo.com/canon-powershot-and-ixus-service-manual-and-part-list#comment-615</link>
		<dc:creator>budi</dc:creator>
		<pubDate>Fri, 25 Nov 2011 13:51:20 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=278#comment-615</guid>
		<description>very generous, thanks a million:)</description>
		<content:encoded><![CDATA[<p>very generous, thanks a million:)</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on &quot;Setup failed to start on the remote machine. Check the Task scheduler event log on the remote machine.&quot; error while installing Microsoft Sql Server 2005 in failover cluster by amar</title>
		<link>http://blog.amarkulo.com/setup-failed-to-start-on-the-remote-machine-check-the-task-scheduler-event-log-on-the-remote-machine-error-while-installing-microsoft-sql-server-2005-in-failover-cluster#comment-608</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Thu, 17 Nov 2011 07:19:53 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=165#comment-608</guid>
		<description>Hmm, this worked for me, but also I have a two node cluster.</description>
		<content:encoded><![CDATA[<p>Hmm, this worked for me, but also I have a two node cluster.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on &quot;Setup failed to start on the remote machine. Check the Task scheduler event log on the remote machine.&quot; error while installing Microsoft Sql Server 2005 in failover cluster by Matt</title>
		<link>http://blog.amarkulo.com/setup-failed-to-start-on-the-remote-machine-check-the-task-scheduler-event-log-on-the-remote-machine-error-while-installing-microsoft-sql-server-2005-in-failover-cluster#comment-607</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Thu, 17 Nov 2011 01:45:20 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=165#comment-607</guid>
		<description>Yes - a simple solution - if only were the solution....

I am consistently receiving this error even though I am the only person logged onto the machine and have checked &amp; stop/started the Task Scheduler services on all nodes.

This is not made easier by having an existing 2n cluster (A/P) to which a third node (A) is being added to run a second instance (because the business wants to piggyback an application on an existing cluster rather than set up its own).</description>
		<content:encoded><![CDATA[<p>Yes &#8211; a simple solution &#8211; if only were the solution&#8230;.</p>
<p>I am consistently receiving this error even though I am the only person logged onto the machine and have checked &amp; stop/started the Task Scheduler services on all nodes.</p>
<p>This is not made easier by having an existing 2n cluster (A/P) to which a third node (A) is being added to run a second instance (because the business wants to piggyback an application on an existing cluster rather than set up its own).</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by Kashif</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-606</link>
		<dc:creator>Kashif</dc:creator>
		<pubDate>Tue, 15 Nov 2011 17:54:35 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-606</guid>
		<description>Hi amar,
I want to have SNORT send realtime alerts to my remote syslog server and also send alerts to my email address.
I am using IDS center and it seems like alerts are getting wrtitten on alerts.ids log file but it is neither sending to sysslog nor via email.
Below is config for syslog:

output alert_syslog: host=10.1.1.254:514, LOG_AUTH LOG_ALERT
output alert_fast : alerts.ids

I am using AlertMail and interneting thing is Test Messge works but it doesnt send realtime so something needs to be activated.
Below is the service paramerters I am running:


Snort is currently configured to run as a Windows service using the following
command-line parameters:

     -c C:\Snort\etc\snort.conf -l C:\Snort\log -s -k all -i3

Please advice if I am missing anything.
Many thanks</description>
		<content:encoded><![CDATA[<p>Hi amar,<br />
I want to have SNORT send realtime alerts to my remote syslog server and also send alerts to my email address.<br />
I am using IDS center and it seems like alerts are getting wrtitten on alerts.ids log file but it is neither sending to sysslog nor via email.<br />
Below is config for syslog:</p>
<p>output alert_syslog: host=10.1.1.254:514, LOG_AUTH LOG_ALERT<br />
output alert_fast : alerts.ids</p>
<p>I am using AlertMail and interneting thing is Test Messge works but it doesnt send realtime so something needs to be activated.<br />
Below is the service paramerters I am running:</p>
<p>Snort is currently configured to run as a Windows service using the following<br />
command-line parameters:</p>
<p>     -c C:\Snort\etc\snort.conf -l C:\Snort\log -s -k all -i3</p>
<p>Please advice if I am missing anything.<br />
Many thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by amar</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-603</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Tue, 01 Nov 2011 07:33:14 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-603</guid>
		<description>Hi Arek,

You have enabled client authentication for relaying somewhere. You need to add internal ip addresses to config as permitted ones which are not requiring client authentication.</description>
		<content:encoded><![CDATA[<p>Hi Arek,</p>
<p>You have enabled client authentication for relaying somewhere. You need to add internal ip addresses to config as permitted ones which are not requiring client authentication.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to build antispam SMTP gateway for Exchange on Ubuntu 8.04 by Arek</title>
		<link>http://blog.amarkulo.com/how-to-build-spam-free-smtp-gateway-for-exchange-on-ubuntu-804#comment-598</link>
		<dc:creator>Arek</dc:creator>
		<pubDate>Mon, 31 Oct 2011 17:27:57 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=141#comment-598</guid>
		<description>Hi guys,
I have some issues i guess on Exchange side, i have ubuntu box with Mailscanner + spamassassin + clam + postfix and it works as a Gateway for exchange, but unfortunately when it relay email exchange 2010 bounce relayed email, and i cant figure out why is so.
if you could help me solve this issue i would appreciate.

to=, relay=192.168.105.31[192.168.105.31]:25, delay=11, delays=5.9/0/0/5, dsn=5.7.1, status=bounced (host 192.168.105.31[192.168.105.31] said: 530 5.7.1 Client was not authenticated (in reply to MAIL FROM command)
why is so ?</description>
		<content:encoded><![CDATA[<p>Hi guys,<br />
I have some issues i guess on Exchange side, i have ubuntu box with Mailscanner + spamassassin + clam + postfix and it works as a Gateway for exchange, but unfortunately when it relay email exchange 2010 bounce relayed email, and i cant figure out why is so.<br />
if you could help me solve this issue i would appreciate.</p>
<p>to=, relay=192.168.105.31[192.168.105.31]:25, delay=11, delays=5.9/0/0/5, dsn=5.7.1, status=bounced (host 192.168.105.31[192.168.105.31] said: 530 5.7.1 Client was not authenticated (in reply to MAIL FROM command)<br />
why is so ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Defending Exchange server against spam with SpamAssassin by amar</title>
		<link>http://blog.amarkulo.com/defending-exchange-server-against-spam-with-spamassassin#comment-595</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Sun, 16 Oct 2011 17:33:20 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=139#comment-595</guid>
		<description>Hi John,

I didn&#039;t try to set it up on Windows so I&#039;m not of big help there but I would try to run it with -v (verbose) to see what does it say and on what part of system is it complaining.

Also check if you can set it somehow to create debug log, usually there are several types of logging, informational, warn, debug, etc. where debug is the one that gives the most informations about everything.

Try something like this and let me know if I can &quot;help&quot; you more.

Kind regards
Amar</description>
		<content:encoded><![CDATA[<p>Hi John,</p>
<p>I didn&#8217;t try to set it up on Windows so I&#8217;m not of big help there but I would try to run it with -v (verbose) to see what does it say and on what part of system is it complaining.</p>
<p>Also check if you can set it somehow to create debug log, usually there are several types of logging, informational, warn, debug, etc. where debug is the one that gives the most informations about everything.</p>
<p>Try something like this and let me know if I can &#8220;help&#8221; you more.</p>
<p>Kind regards<br />
Amar</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Defending Exchange server against spam with SpamAssassin by John</title>
		<link>http://blog.amarkulo.com/defending-exchange-server-against-spam-with-spamassassin#comment-594</link>
		<dc:creator>John</dc:creator>
		<pubDate>Sun, 16 Oct 2011 17:27:06 +0000</pubDate>
		<guid isPermaLink="false">http://dzo.blogsite.org/?p=139#comment-594</guid>
		<description>Hi Amar,

Thanks for the *very* comprehensive write-up on SpamAssassin for Windows.

I am trying to get SpamAssassin working on an SBS2003 server.

I have followed the instructions of David Stephens at:

http://www.davidstephens.co.uk/category/windows/

However, he makes no mention of installing ActivePerl, or compilation.

My SpamAssassin does appear to be partly working, but I am getting errors in the logs such as:


10/16/2011 12:01:35 AM:   SpamAssassin: C:\ESA\SPAMC-SPAMD.BAT -d 127.0.0.1 -u spamd  &quot;C:\ESA\NEW\msg111016000135_95EEA.out&quot;
10/16/2011 12:01:35 AM:   SpamAssassin result: 64
10/16/2011 12:01:35 AM:   Checking for PERL in Path...
10/16/2011 12:01:35 AM:   *** ERROR - OUT File is blank: C:\ESA\NEW\msg111016000135_95EEA.out
10/16/2011 12:01:35 AM:   *** ERROR - Logging Major Error: &#039;32&#039;. Err: 53 - OUT File is blank

However,  I note that there is at least one spam message in C:\ESA\Spam:

msg111016164107_D7C10.out

Inspection shows it to be spam.

Where am I going wrong?  I apologise for bothering you, as you must be very busy.

Any help greatfully received.

Yours sincerely,

John Langley.</description>
		<content:encoded><![CDATA[<p>Hi Amar,</p>
<p>Thanks for the *very* comprehensive write-up on SpamAssassin for Windows.</p>
<p>I am trying to get SpamAssassin working on an SBS2003 server.</p>
<p>I have followed the instructions of David Stephens at:</p>
<p><a href="http://www.davidstephens.co.uk/category/windows/" rel="nofollow">http://www.davidstephens.co.uk/category/windows/</a></p>
<p>However, he makes no mention of installing ActivePerl, or compilation.</p>
<p>My SpamAssassin does appear to be partly working, but I am getting errors in the logs such as:</p>
<p>10/16/2011 12:01:35 AM:   SpamAssassin: C:\ESA\SPAMC-SPAMD.BAT -d 127.0.0.1 -u spamd  &#8220;C:\ESA\NEW\msg111016000135_95EEA.out&#8221;<br />
10/16/2011 12:01:35 AM:   SpamAssassin result: 64<br />
10/16/2011 12:01:35 AM:   Checking for PERL in Path&#8230;<br />
10/16/2011 12:01:35 AM:   *** ERROR &#8211; OUT File is blank: C:\ESA\NEW\msg111016000135_95EEA.out<br />
10/16/2011 12:01:35 AM:   *** ERROR &#8211; Logging Major Error: &#8217;32&#8242;. Err: 53 &#8211; OUT File is blank</p>
<p>However,  I note that there is at least one spam message in C:\ESA\Spam:</p>
<p>msg111016164107_D7C10.out</p>
<p>Inspection shows it to be spam.</p>
<p>Where am I going wrong?  I apologise for bothering you, as you must be very busy.</p>
<p>Any help greatfully received.</p>
<p>Yours sincerely,</p>
<p>John Langley.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-589</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Thu, 29 Sep 2011 18:29:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-589</guid>
		<description>There isn&#039;t any difference in functionality, linux version has ssh modules as well, but principle is the same.</description>
		<content:encoded><![CDATA[<p>There isn&#8217;t any difference in functionality, linux version has ssh modules as well, but principle is the same.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by Ali Raza</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-588</link>
		<dc:creator>Ali Raza</dc:creator>
		<pubDate>Thu, 29 Sep 2011 17:12:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-588</guid>
		<description>Is there any difference, feature wise, installing Snort in Windows or Linux?
Thanks</description>
		<content:encoded><![CDATA[<p>Is there any difference, feature wise, installing Snort in Windows or Linux?<br />
Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-585</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Wed, 14 Sep 2011 19:00:05 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-585</guid>
		<description>I&#039;m writing article about it, will publish it soon.</description>
		<content:encoded><![CDATA[<p>I&#8217;m writing article about it, will publish it soon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by Bhavin Satashiya</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-584</link>
		<dc:creator>Bhavin Satashiya</dc:creator>
		<pubDate>Wed, 14 Sep 2011 17:49:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-584</guid>
		<description>sir, how the snort are work..will you give information about it.please..</description>
		<content:encoded><![CDATA[<p>sir, how the snort are work..will you give information about it.please..</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on CANON PowerShot and Ixus service manual and part list by morrisrocks</title>
		<link>http://blog.amarkulo.com/canon-powershot-and-ixus-service-manual-and-part-list#comment-583</link>
		<dc:creator>morrisrocks</dc:creator>
		<pubDate>Sat, 10 Sep 2011 11:45:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=278#comment-583</guid>
		<description>How generous - many thanks</description>
		<content:encoded><![CDATA[<p>How generous &#8211; many thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on #Arduino -&gt; Flash trigger via laser for watterdrops by amar</title>
		<link>http://blog.amarkulo.com/arduino-nikon-trigger-via-laser-for-watterdrops#comment-582</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Fri, 09 Sep 2011 05:27:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=291#comment-582</guid>
		<description>I took cheapest laser and photo resistor  that I could find, so any should do</description>
		<content:encoded><![CDATA[<p>I took cheapest laser and photo resistor  that I could find, so any should do</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on #Arduino -&gt; Flash trigger via laser for watterdrops by david</title>
		<link>http://blog.amarkulo.com/arduino-nikon-trigger-via-laser-for-watterdrops#comment-581</link>
		<dc:creator>david</dc:creator>
		<pubDate>Fri, 09 Sep 2011 01:22:31 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=291#comment-581</guid>
		<description>can you tell me more about the laser and the detector ?
part numbers focusing ?

anything please

David</description>
		<content:encoded><![CDATA[<p>can you tell me more about the laser and the detector ?<br />
part numbers focusing ?</p>
<p>anything please</p>
<p>David</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-579</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Wed, 07 Sep 2011 12:23:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-579</guid>
		<description>Hello.

Try to start command prompt as administrator, then you will have more privileges.</description>
		<content:encoded><![CDATA[<p>Hello.</p>
<p>Try to start command prompt as administrator, then you will have more privileges.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by GAKURU</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-578</link>
		<dc:creator>GAKURU</dc:creator>
		<pubDate>Sat, 03 Sep 2011 07:47:04 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-578</guid>
		<description>how &#039;re you?
please help me,i try to run snort by this command:&quot;snort -c c:\snort\etc\snort.conf -l c:\Snort\log -i3&quot; on windows 7 ultimate 32bits, then an errors: Unknown preprocessor:&quot;normalize _ipv4&quot; could not create registry key. what can i do to fix this error?
thanks!</description>
		<content:encoded><![CDATA[<p>how &#8216;re you?<br />
please help me,i try to run snort by this command:&#8221;snort -c c:\snort\etc\snort.conf -l c:\Snort\log -i3&#8243; on windows 7 ultimate 32bits, then an errors: Unknown preprocessor:&#8221;normalize _ipv4&#8243; could not create registry key. what can i do to fix this error?<br />
thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-568</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Mon, 15 Aug 2011 06:25:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-568</guid>
		<description>I have it installed with Manage Engine Log Analyzer which is free up to 5 hosts. On the same machine snort is installed with -E flag which tells him to log everything in eventlog, then EventLog Analyzer is parsing those logs and I have created special kind of alerts that alerts me in case that some suspicious snort log has been found. You don&#039;t need to know any programming language to implement this. I will write a new blog post how to have everything configured and setup properly.</description>
		<content:encoded><![CDATA[<p>I have it installed with Manage Engine Log Analyzer which is free up to 5 hosts. On the same machine snort is installed with -E flag which tells him to log everything in eventlog, then EventLog Analyzer is parsing those logs and I have created special kind of alerts that alerts me in case that some suspicious snort log has been found. You don&#8217;t need to know any programming language to implement this. I will write a new blog post how to have everything configured and setup properly.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-567</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Mon, 15 Aug 2011 06:23:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-567</guid>
		<description>Hi!

You can try to start snort from command prompt just to see if it is capturing anything with command snort  -v. In case of error with winpcap you will see directly which error you have. Also you can try running snort -W if you have more than one network interface and then if that is the case run snort with snort -v -i number_of_interface_that_you_got_with_command_before.</description>
		<content:encoded><![CDATA[<p>Hi!</p>
<p>You can try to start snort from command prompt just to see if it is capturing anything with command snort  -v. In case of error with winpcap you will see directly which error you have. Also you can try running snort -W if you have more than one network interface and then if that is the case run snort with snort -v -i number_of_interface_that_you_got_with_command_before.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by jonh gape</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-563</link>
		<dc:creator>jonh gape</dc:creator>
		<pubDate>Sat, 13 Aug 2011 16:39:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-563</guid>
		<description>hi! after  installation of winpcap i didn&#039;t  saw anything from network driver, then what can i do?</description>
		<content:encoded><![CDATA[<p>hi! after  installation of winpcap i didn&#8217;t  saw anything from network driver, then what can i do?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by GATERA J.Peter</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-559</link>
		<dc:creator>GATERA J.Peter</dc:creator>
		<pubDate>Mon, 25 Jul 2011 18:36:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-559</guid>
		<description>hello!i need to know how i can use snort to detect network intrusion,because i&#039;ve read that it requires the following softwares: Snort, WinPCap, Mysql......, but i do not get how i can implement that system to detect intrusion. i use windows 7 , ultimate 32bits, and i would like to ask if it requires to know at least one of the programming languages?which one is the best?
can i get source code to be used?
thanks!</description>
		<content:encoded><![CDATA[<p>hello!i need to know how i can use snort to detect network intrusion,because i&#8217;ve read that it requires the following softwares: Snort, WinPCap, Mysql&#8230;&#8230;, but i do not get how i can implement that system to detect intrusion. i use windows 7 , ultimate 32bits, and i would like to ask if it requires to know at least one of the programming languages?which one is the best?<br />
can i get source code to be used?<br />
thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-558</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Fri, 22 Jul 2011 20:27:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-558</guid>
		<description>You can try to create it with some network scanning tool like Retina or Nessus which is free and see what&#039;s happening.

There are also command switches to start snort from command prompt and to display everything on console so you can check if it is working in real time.</description>
		<content:encoded><![CDATA[<p>You can try to create it with some network scanning tool like Retina or Nessus which is free and see what&#8217;s happening.</p>
<p>There are also command switches to start snort from command prompt and to display everything on console so you can check if it is working in real time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by amar</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-557</link>
		<dc:creator>amar</dc:creator>
		<pubDate>Fri, 22 Jul 2011 20:26:12 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-557</guid>
		<description>Well first is to run snort as service and to log something, then you need to parse logs and do actions based on log entries.

For example you will have different kind of entries but with priority 1, 2 or 3, where that mean high, moderate or informational priority.

When you detect something with high priority then you can with that software do actions based on alert, I&#039;m using Manage Engine Log Analyzer (which is free up to 5 servers) to manage actions based on log entries.

P.S. After installation you will need to download the latest ruleset for Snort and to apply them as well.</description>
		<content:encoded><![CDATA[<p>Well first is to run snort as service and to log something, then you need to parse logs and do actions based on log entries.</p>
<p>For example you will have different kind of entries but with priority 1, 2 or 3, where that mean high, moderate or informational priority.</p>
<p>When you detect something with high priority then you can with that software do actions based on alert, I&#8217;m using Manage Engine Log Analyzer (which is free up to 5 servers) to manage actions based on log entries.</p>
<p>P.S. After installation you will need to download the latest ruleset for Snort and to apply them as well.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to install Snort Intrusion Detection System on Windows by GATERA J.Peter</title>
		<link>http://blog.amarkulo.com/how-to-install-snort-ids-on-windows#comment-556</link>
		<dc:creator>GATERA J.Peter</dc:creator>
		<pubDate>Fri, 22 Jul 2011 19:59:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.amarkulo.com/?p=267#comment-556</guid>
		<description>just i need to detect network intrusion</description>
		<content:encoded><![CDATA[<p>just i need to detect network intrusion</p>
]]></content:encoded>
	</item>
</channel>
</rss>

