Re: Empty message apparently not tokenized

John Chandler <jpc-WwYSd80vZ+3bI6/[email protected]> Mon, 13 Feb 2006 23:14:56 -0600
Newsgroups gmane.mail.spam.spamprobe.general
Message-ID <[email protected]>
Date: Mon, 13 Feb 2006 09:51:08 +0100
From: tBB <tbb-MQwlIdhhGh0tX/[email protected]>
To: John Chandler <jpc-WwYSd80vZ+3bI6/[email protected]>
Subject: Re: [Spamprobe-users] Empty message apparently not tokenized

> (I think) I would like spamprobe 
> to tokenize the header and create a decision matrix.
> 
> What do you think?

If SpamProbe is called with the "-H all" option all headers will be 
tokenized.

Regards, Nico


Thanks for the hint,
but I don't think this would be a good way 
to handle the problem, even if it works.

The man page (see below) refers to 
"headers from the email message"
when discussing the -H option,
but it seems clear that this means
what many people would call
"fields in the header of the e-mail message."

There is no reason to think it would be smart
to tokenize all of the fields in _every_ header,
which is what would be required to avoid 
having all messages with no body become false negatives,
assuming that that even does the job.
Presumably Brian Burton avoided tokenizing some header fields
for good reason.

I guess I could try to list all of the header fields
that spamprobe ordinarily tokenizes,
and then try to request through the -H option
that these fields always be tokenized,
but would this actually solve the problem?
I see no reason to think it would.

Appending a blank line to the spam message below
causes the header to be tokenized.
Therefore it seems to me that the failure
to tokenize the header when there is no blank line present
could be considered to be a design problem.

Apparently I could solve the problem by modifying
our copy of spamprobe, or my .procmailrc file,
to append a blank line to every message 
before it is subjected to tokenizing.
If necessary I _will_ do this,
but it sounds to me like a pretty kludgy way 
of solving the problem.

Again I ask, 

   What is a sensible way to avoid
   having all messages with no body
   come through as false negatives?

-----------
John Chandler


+-------------------------------------------+
- Mailto: tbb-MQwlIdhhGh0tX/[email protected]
- No pure HTML mails please
+-------------------------------------------+
Brian Burton:

In the past week or so 
I have received perhaps ten messages 
similar to the one below.
Most of them, although not all,
claim, like this one, to be from optonline.

Running with -T as I always do, I can see that
spamprobe never created a decision matrix or,
apparently, even tokenized the header.
All of these messages have come through 
as false negatives with a spam score of 0.5, 
which I take to be a default value 
for "No tokens found."

(I think) I would like spamprobe 
to tokenize the header and create a decision matrix.

What do you think?


Return-Path: [email protected]
Delivery-Date: Sun Feb 12 17:14:33 2006
Return-Path: <[email protected]>
X-Original-To: [email protected]
Delivered-To: [email protected]
Received: from lh (201-221-207-53.bk11-dsl.surnet.cl [201.221.207.53])
	by a.cs.okstate.edu (Postfix) with SMTP id 9AA4BA0633;
	Sun, 12 Feb 2006 17:13:59 -0600 (CST)
Received: from congruent2 ([127.0.0.1]) by writely.com with Microsoft SMTPSVC(6.0.3790.1830);
	 Sun, 12 Feb 2006 17:15:43 -0600
Message-Id: <7.9.1.5.4.7[14
Date: Sun, 12 Feb 2006 17:13:59 -0600 (CST)
From: [email protected]
To: undisclosed-recipients:;
X-SpamProbe: GOOD 0.5000000 44e527864b85d781d1ba7de482ab0a38
-----
John Chandler



Version 1.4        Last change: December 2005                  10


      -H option

By default SpamProbe only scans a meaningful  subset  of headers
from the email  message  when  searching  for  words  to score.  The -H
option allows the user to specify additional headers  to scan.
Legal values are  "all",  "nox",  "none",  or  "normal".  "all" scans
all headers, "nox" scans all headers except those start- ing with
X-, "none" does not scan headers, and "normal" scans the normal
set of headers.

In addition to those values you can also explicitly  add a header
to the list of headers to process by adding  the  header name in
lower case preceded by a plus  sign.   Multiple  headers can be
specified by using multiple -H options.  For example, to include
only the From and Received headers in your train command you could
run spamprobe as follows:

   spamprobe -Hnone -H+from -H+received train

To process the normal set of headers but  also  add  the SpamAssassin
header X-SpamStatus you could run spamprobe as follows:

   spamprobe -H+x-spam-status train



-------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc. Do you grep through log files
for problems?  Stop!  Download the new AJAX search engine that makes
searching your log files as easy as surfing the  web.  DOWNLOAD SPLUNK!
http://sel.as-us.falkag.net/sel?cmd=lnk&kid=103432&bid=230486&dat=121642