Журнал лабораторных работ

Содержание

Журнал

Суббота (11/04/06)

/dev/ttyv2
15:19:42
#tail /var/log/maillog
Oct 18 02:51:17 fbsd1 mimedefang-multiplexor[78705]: Starting slave 1 (pid 78727) (2 running): Bringing slaves up to minSlaves (2)
Nov  4 15:14:13 fbsd1 sendmail[78771]: kA4DEDpM078771: from=devi, size=1104, class=0, nrcpts=1, msgid=<20061104131413.GD72946@fbsd1.xgu.ru>, relay=devi@localhost
Nov  4 15:14:13 fbsd1 sm-mta[78772]: kA4DED6b078772: from=<devi@fbsd1.xgu.ru>, size=1277, class=0, nrcpts=1, msgid=<20061104131413.GD72946@fbsd1.xgu.ru>, proto=ESMTP, daemon=IPv4, relay=localhost [127.0.0.1]
Nov  4 15:14:14 fbsd1 mimedefang.pl[78707]: kA4DED6b078772: Could not connect to clamd daemon at /var/run/clamav/clamd
Nov  4 15:14:14 fbsd1 mimedefang.pl[78707]: Problem running virus scanner: code=999, category=cannot-execute, action=tempfail
Nov  4 15:14:14 fbsd1 sm-mta[78772]: kA4DED6b078772: Milter: data, reject=451 4.3.0 Problem running virus-scanner
Nov  4 15:14:14 fbsd1 sm-mta[78772]: kA4DED6b078772: to=<devi@fbsd1.xgu.ru>, delay=00:00:01, pri=31277, stat=Problem running virus-scanner
Nov  4 15:14:14 fbsd1 sendmail[78771]: kA4DEDpM078771: to=devi@fbsd1.xgu.ru, ctladdr=devi (1002/0), delay=00:00:01, xdelay=00:00:01, mailer=relay, pri=31104, relay=[127.0.0.1] [127.0.0.1], dsn=4.0.0, stat=Deferred: 451 4.3.0 Problem running virus-scanner
Nov  4 15:17:54 fbsd1 sendmail[78906]: gethostbyaddr(192.168.1.199) failed: 1
Nov  4 15:18:47 fbsd1 sendmail[78962]: gethostbyaddr(192.168.1.199) failed: 1
15:19:44
#tail /var/log/maillog
Oct 18 02:51:17 fbsd1 mimedefang-multiplexor[78705]: Starting slave 1 (pid 78727) (2 running): Bringing slaves up to minSlaves (2)
Nov  4 15:14:13 fbsd1 sendmail[78771]: kA4DEDpM078771: from=devi, size=1104, class=0, nrcpts=1, msgid=<20061104131413.GD72946@fbsd1.xgu.ru>, relay=devi@localhost
Nov  4 15:14:13 fbsd1 sm-mta[78772]: kA4DED6b078772: from=<devi@fbsd1.xgu.ru>, size=1277, class=0, nrcpts=1, msgid=<20061104131413.GD72946@fbsd1.xgu.ru>, proto=ESMTP, daemon=IPv4, relay=localhost [127.0.0.1]
Nov  4 15:14:14 fbsd1 mimedefang.pl[78707]: kA4DED6b078772: Could not connect to clamd daemon at /var/run/clamav/clamd
Nov  4 15:14:14 fbsd1 mimedefang.pl[78707]: Problem running virus scanner: code=999, category=cannot-execute, action=tempfail
Nov  4 15:14:14 fbsd1 sm-mta[78772]: kA4DED6b078772: Milter: data, reject=451 4.3.0 Problem running virus-scanner
Nov  4 15:14:14 fbsd1 sm-mta[78772]: kA4DED6b078772: to=<devi@fbsd1.xgu.ru>, delay=00:00:01, pri=31277, stat=Problem running virus-scanner
Nov  4 15:14:14 fbsd1 sendmail[78771]: kA4DEDpM078771: to=devi@fbsd1.xgu.ru, ctladdr=devi (1002/0), delay=00:00:01, xdelay=00:00:01, mailer=relay, pri=31104, relay=[127.0.0.1] [127.0.0.1], dsn=4.0.0, stat=Deferred: 451 4.3.0 Problem running virus-scanner
Nov  4 15:17:54 fbsd1 sendmail[78906]: gethostbyaddr(192.168.1.199) failed: 1
Nov  4 15:18:47 fbsd1 sendmail[78962]: gethostbyaddr(192.168.1.199) failed: 1
15:19:45
#tail /var/log/maillog
Oct 18 02:51:17 fbsd1 mimedefang-multiplexor[78705]: Starting slave 1 (pid 78727) (2 running): Bringing slaves up to minSlaves (2)
Nov  4 15:14:13 fbsd1 sendmail[78771]: kA4DEDpM078771: from=devi, size=1104, class=0, nrcpts=1, msgid=<20061104131413.GD72946@fbsd1.xgu.ru>, relay=devi@localhost
Nov  4 15:14:13 fbsd1 sm-mta[78772]: kA4DED6b078772: from=<devi@fbsd1.xgu.ru>, size=1277, class=0, nrcpts=1, msgid=<20061104131413.GD72946@fbsd1.xgu.ru>, proto=ESMTP, daemon=IPv4, relay=localhost [127.0.0.1]
Nov  4 15:14:14 fbsd1 mimedefang.pl[78707]: kA4DED6b078772: Could not connect to clamd daemon at /var/run/clamav/clamd
Nov  4 15:14:14 fbsd1 mimedefang.pl[78707]: Problem running virus scanner: code=999, category=cannot-execute, action=tempfail
Nov  4 15:14:14 fbsd1 sm-mta[78772]: kA4DED6b078772: Milter: data, reject=451 4.3.0 Problem running virus-scanner
Nov  4 15:14:14 fbsd1 sm-mta[78772]: kA4DED6b078772: to=<devi@fbsd1.xgu.ru>, delay=00:00:01, pri=31277, stat=Problem running virus-scanner
Nov  4 15:14:14 fbsd1 sendmail[78771]: kA4DEDpM078771: to=devi@fbsd1.xgu.ru, ctladdr=devi (1002/0), delay=00:00:01, xdelay=00:00:01, mailer=relay, pri=31104, relay=[127.0.0.1] [127.0.0.1], dsn=4.0.0, stat=Deferred: 451 4.3.0 Problem running virus-scanner
Nov  4 15:17:54 fbsd1 sendmail[78906]: gethostbyaddr(192.168.1.199) failed: 1
Nov  4 15:18:47 fbsd1 sendmail[78962]: gethostbyaddr(192.168.1.199) failed: 1
15:19:51
#mailq
/var/spool/mqueue is empty
                Total requests: 0
15:19:56
#tail -f /var/log/maillog
Oct 18 02:51:17 fbsd1 mimedefang-multiplexor[78705]: Starting slave 1 (pid 78727) (2 running): Bringing slaves up to minSlaves (2)
Nov  4 15:14:13 fbsd1 sendmail[78771]: kA4DEDpM078771: from=devi, size=1104, class=0, nrcpts=1, msgid=<20061104131413.GD72946@fbsd1.xgu.ru>, relay=devi@localhost
Nov  4 15:14:13 fbsd1 sm-mta[78772]: kA4DED6b078772: from=<devi@fbsd1.xgu.ru>, size=1277, class=0, nrcpts=1, msgid=<20061104131413.GD72946@fbsd1.xgu.ru>, proto=ESMTP, daemon=IPv4, relay=localhost [127.0.0.1]
Nov  4 15:14:14 fbsd1 mimedefang.pl[78707]: kA4DED6b078772: Could not connect to clamd daemon at /var/run/clamav/clamd
Nov  4 15:14:14 fbsd1 mimedefang.pl[78707]: Problem running virus scanner: code=999, category=cannot-execute, action=tempfail
Nov  4 15:14:14 fbsd1 sm-mta[78772]: kA4DED6b078772: Milter: data, reject=451 4.3.0 Problem running virus-scanner
Nov  4 15:14:14 fbsd1 sm-mta[78772]: kA4DED6b078772: to=<devi@fbsd1.xgu.ru>, delay=00:00:01, pri=31277, stat=Problem running virus-scanner
Nov  4 15:14:14 fbsd1 sendmail[78771]: kA4DEDpM078771: to=devi@fbsd1.xgu.ru, ctladdr=devi (1002/0), delay=00:00:01, xdelay=00:00:01, mailer=relay, pri=31104, relay=[127.0.0.1] [127.0.0.1], dsn=4.0.0, stat=Deferred: 451 4.3.0 Problem running virus-scanner
Nov  4 15:17:54 fbsd1 sendmail[78906]: gethostbyaddr(192.168.1.199) failed: 1
Nov  4 15:18:47 fbsd1 sendmail[78962]: gethostbyaddr(192.168.1.199) failed: 1
...
Nov  4 15:21:46 fbsd1 sendmail[79168]: kA4DLfKt079168: to=devi@fbsd1.xgu.ru, ctladdr=devi (1002/0), delay=00:00:05, xdelay=00:00:05, mailer=relay, pri=30272, relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (kA4DLfq2079169 Message accepted for delivery)
Nov  4 15:21:47 fbsd1 sm-mta[79170]: kA4DLfq2079169: to=<devi@fbsd1.xgu.ru>, ctladdr=<devi@fbsd1.xgu.ru> (1002/0), delay=00:00:06, xdelay=00:00:00, mailer=local, pri=30735, relay=local, dsn=2.0.0, stat=Sent
Nov  4 15:23:48 fbsd1 sendmail[79247]: kA4DNmSH079247: from=devi, size=1294, class=0, nrcpts=1, msgid=<20061104132348.GA79239@fbsd1.xgu.ru>, relay=devi@localhost
Nov  4 15:23:48 fbsd1 sm-mta[79248]: kA4DNmHU079248: from=<devi@fbsd1.xgu.ru>, size=1467, class=0, nrcpts=1, msgid=<20061104132348.GA79239@fbsd1.xgu.ru>, proto=ESMTP, daemon=IPv4, relay=localhost [127.0.0.1]
Nov  4 15:23:49 fbsd1 mimedefang.pl[78707]: MDLOG,kA4DNmHU079248,virus,ClamAV-Test-File,127.0.0.1,<devi@fbsd1.xgu.ru>,<devi@fbsd1.xgu.ru>,Re: your mail
Nov  4 15:23:49 fbsd1 mimedefang.pl[78707]: Discarding because of virus ClamAV-Test-File
Nov  4 15:23:49 fbsd1 sm-mta[79248]: kA4DNmHU079248: Milter: data, discard
Nov  4 15:23:49 fbsd1 sm-mta[79248]: kA4DNmHU079248: discarded
Nov  4 15:23:49 fbsd1 sendmail[79247]: kA4DNmSH079247: to=devi@fbsd1.xgu.ru, ctladdr=devi (1002/0), delay=00:00:01, xdelay=00:00:01, mailer=relay, pri=31294, relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (kA4DNmHU079248 Message accepted for delivery)
^C
/dev/ttyv1
15:20:43
$mutt
                                                                                                                                                                                                                                               =1S
                                                                                                                                                                ---Mutt: /var/mail/devi [Msgs:6 8,7K]---(date/date)---------------------(all)---
ðÏÞÔÏ×ÙÊ ÑÝÉË ÎÅ ÉÚÍÅÎÉÌÓÑ.     (   1) test2ÉÔØ  u:÷ÏÓÓÔÁÎÏ×ÉÔØ  s:óÏÈÒÁÎÉÔØ  m:óÏÚÄÁÔØ  r:ïÔ×ÅÔÉÔØ  g:÷ÓÅÍ
   2   + Sep 28 Igor Chubin     (   1) test2
   3   + Sep 28 Igor Chubin     (   1) test3
   4   + Sep 28 Igor Chubin     (  27)
   5   + Oct 18 Mail Delivery S (  80) Returned mail: see transcript for details   6   F Oct 18 To devi@fbsd1.x (  21) test
15:20:48
$mail
Mail version 8.1 6/6/93.  Type ? for help.
"/var/mail/devi": 6 messages
>   1 devi@chub.in          Thu Sep 28 21:56  22/709   "test2"
    2 devi@chub.in          Thu Sep 28 21:59  22/709   "test2"
    3 devi@chub.in          Thu Sep 28 22:03  22/709   "test3"
    4 igor@chub.in          Thu Sep 28 22:05  52/1780
    5 MAILER-DAEMON         Wed Oct 18 02:12 100/3384  "Returned mail: see tr"
    6 devi@fbsd1.xgu.ru     Wed Oct 18 02:15  46/1657  "test"
& t 5
&
...
--yNb1oOkm5a9FJOVX
Content-Type: application/zipses had permanent fatal errors -----
Content-Disposition: attachment; filename="clam.zip"
Content-Transfer-Encoding: base64: virus (ClamAV-Test-File) found. I don't need virus :-).)
UEsDBBQAAAAIALwMJjH9PAfvAAEAACACAAAIABUAY2xhbS5leGVVVAkAA1SjO0El6E1BVXgE
AOgD6APzjQpgYGJgYGBh4Gf4/5+BYQeQrQjEDgxSDAQBIwPD7kIBBwbjAwEB3Z+DgwM2aDoY
sKStqfy5y5ChgndtwP+0Aj75fYYML5/+38J5VnGLz1nFJB4uRqaCMnEmOT8eFv1bZwRQjTwA
5Degid0C8r+gicGAt2uQn6uPsZGei48PA4NrRWZJQFF+cmpxMUNosGsQVNzZx9EXKJSYnuqUirus :-).
X+HI8Axqlj0QBLgyMPgwMjIkOic6wcx8wNDXyM3IJAkMFAYGNoiYA0iPAChcwDwwGxRwjFA9
zAxcEIYCODDBgAlMCkDEQDTUXmSvtID8izeQaQOiQWHiGBbLAPUXsl+QwAEAUEsBAhcDFAAA
15:21:08
$mutt
   1  D+ Sep 28 Igor Chubin     (   1) test2
   2  D+ Sep 28 Igor Chubin     (   1) test2
   3  D+ Sep 28 Igor Chubin     (   1) test3
                                Del:4 3,8K]---(date/date)                       -*-Mutt: /var/mail/devi [Msgs:4 3,8K]---(date/date)---------------------(all)---
ïÓÔÁ×ÌÅÎÏ: 0, ÕÄÁÌÅÎÏ: 4.in     (   1) test2ÉÔØ  u:÷ÏÓÓÔÁÎÏ×ÉÔØ  s:óÏÈÒÁÎÉÔØ  m:óÏÚÄÁÔØ  r:ïÔ×ÅÔÉÔØ  g:÷ÓÅÍ
   2   + Sep 28 Igor Chubin     (   1) test2
   3   + Sep 28 Igor Chubin     (   1) test3
   4   + Sep 28 Igor Chubin     (  27)
15:21:35
$echo Hello | mutt devi@fbsd1.xgu.ru

15:21:53
$mutt
q        d:õÄÁÌÉÔØ  u:÷ÏÓÓÔÁÎÏ×ÉÔØ  s:óÏÈÒÁÎÉÔØ  m:óÏÚÄÁÔØ  r:ïÔ×ÅÔÉÔØ  g:÷ÓÅÍ
Return-Path: <devi@fbsd1.xgu.ru>
Received: from fbsd1.xgu.ru (localhost [127.0.0.1])
        by fbsd1.xgu.ru (8.13.6/8.13.6) with ESMTP id kA4DLfq2079169
        for <devi@fbsd1.xgu.ru>; Sat, 4 Nov 2006 15:21:41 +0200 (EET)
        (envelope-from devi@fbsd1.xgu.ru)
Received: (from devi@localhost)
        by fbsd1.xgu.ru (8.13.6/8.13.6/Submit) id kA4DLfKt079168
        for devi@fbsd1.xgu.ru; Sat, 4 Nov 2006 15:21:41 +0200 (EET)
        (envelope-from devi)
...
To: devi@fbsd1.xgu.ru
Message-ID: <20061104132141.GA79166@fbsd1.xgu.ru>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/1.4.2.2i
X-Scanned-By: MIMEDefang 2.57 on 217.27.159.219
Hello
 *-Mutt: /var/mail/devi [Msgs:1 0,8K]---(date/date)---------------------(all)---1S=1S
ïÓÔÁ×ÌÅÎÏ: 1, ÕÄÁÌÅÎÏ: 0....Hq:÷ÙÈÏÄ  d:õÄÁÌÉÔØ  u:÷ÏÓÓÔÁÎÏ×ÉÔØ  s:óÏÈÒÁÎÉÔØ  m:óÏÚÄÁÔØ  r:ïÔ×ÅÔÉÔØ  g:÷ÓÅÍ     1 N F Nov 04 To devi@fbsd1.x (   1)
15:22:45
$mutt

/dev/ttyv2
15:23:56
#tail -f /var/log/clamav/
clamd.log      freshclam.log
15:23:56
#tail -f /var/log/clamav/clamd.log
Archive: Compression ratio limit set to 250.
Archive support enabled.
Archive: RAR support disabled.
Portable Executable support enabled.
Mail files support enabled.
OLE2 support enabled.
HTML support enabled.
Self checking every 1800 seconds.
/var/spool/MIMEDefang/mdefang-kA4DKGeD079063/Work/msg-78707-4.zip: ClamAV-Test-File FOUND
/var/spool/MIMEDefang/mdefang-kA4DNmHU079248/Work/msg-78707-7.zip: ClamAV-Test-File FOUND
^C
15:24:09
#less /usr/local/etc/mime
15:24:09
#less /usr/local/etc/mimedefang/
15:24:09
#less /usr/local/etc/mimedefang/mimedefang-filter
15:24:32
#mutt
q        d:õÄÁÌÉÔØ  u:÷ÏÓÓÔÁÎÏ×ÉÔØ  s:óÏÈÒÁÎÉÔØ  m:óÏÚÄÁÔØ  r:ïÔ×ÅÔÉÔØ  g:÷ÓÅÍ
   1     Jul 26 Charlie Root    (  28) fbsd1.xgu.ru security run output
   2     Jul 26 Charlie Root    (  57) fbsd1.xgu.ru daily run output
   3     Jul 27 Charlie Root    (  36) fbsd1.xgu.ru security run output
   4     Jul 27 Charlie Root    (  55) fbsd1.xgu.ru dailrity run output
   5   F Jul 28 To root@fbsd1.x (  76) fbsd1.xgu.ru security run output
   6   F Jul 28 To root@fbsd1.x (  62) fbsd1.xgu.ru daily run output
úÁÐÉÓØ... 20 (64%)
   9 O F Jul 29 To root@fbsd1.x (   8) fbsd1.xgu.ru weekly run output
  10 O F Jul 30 To root@fbsd1.x (  35) fbsd1.xgu.ru security run output
...
  14 O F Aug 01 To root@fbsd1.x (3016) fbsd1.xgu.ru security run output
  15 O F Aug 01 To root@fbsd1.x (  64) fbsd1.xgu.ru daily run output
  16 O F Aug 01 To root@fbsd1.x (   8) fbsd1.xgu.ru monthly run output
  17 O F Aug 04 To root@fbsd1.x ( 189) fbsd1.xgu.ru security run output
  18 O F Aug 04 To root@fbsd1.x (  65) fbsd1.xgu.ru daily run output
  19 O F Aug 05 To root@fbsd1.x (  61) fbsd1.xgu.ru security run output
  20 O F Aug 05 To root@fbsd1.x (  54) fbsd1.xgu.ru daily run output
  21 O F Aug 05 To root@fbsd1.x (   8) fbsd1.xgu.ru weekly run output
  22 O F Sep 29 To root@fbsd1.x ( 212) fbsd1.xgu.ru security run output
---Mutt: /var/mail/root [Msgs:63 Old:63 475K]---(date/date)-------------(34%)---
15:24:53
#less /usr/local/etc/mimedefang/mimedefang-filter
15:25:56
#tail /var/log/maillog
maillog        maillog.1.bz2  maillog.3.bz2  maillog.5.bz2  maillog.7.bz2
maillog.0.bz2  maillog.2.bz2  maillog.4.bz2  maillog.6.bz2
15:25:56
#tail /var/log/maillog
Nov  4 15:21:46 fbsd1 sm-mta[79169]: kA4DLfq2079169: Milter add: header: X-Scanned-By: MIMEDefang 2.57 on 217.27.159.219
Nov  4 15:21:46 fbsd1 sendmail[79168]: kA4DLfKt079168: to=devi@fbsd1.xgu.ru, ctladdr=devi (1002/0), delay=00:00:05, xdelay=00:00:05, mailer=relay, pri=30272, relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (kA4DLfq2079169 Message accepted for delivery)
Nov  4 15:21:47 fbsd1 sm-mta[79170]: kA4DLfq2079169: to=<devi@fbsd1.xgu.ru>, ctladdr=<devi@fbsd1.xgu.ru> (1002/0), delay=00:00:06, xdelay=00:00:00, mailer=local, pri=30735, relay=local, dsn=2.0.0, stat=Sent
Nov  4 15:23:48 fbsd1 sendmail[79247]: kA4DNmSH079247: from=devi, size=1294, class=0, nrcpts=1, msgid=<20061104132348.GA79239@fbsd1.xgu.ru>, relay=devi@localhost
Nov  4 15:23:48 fbsd1 sm-mta[79248]: kA4DNmHU079248: from=<devi@fbsd1.xgu.ru>, size=1467, class=0, nrcpts=1, msgid=<20061104132348.GA79239@fbsd1.xgu.ru>, proto=ESMTP, daemon=IPv4, relay=localhost [127.0.0.1]
Nov  4 15:23:49 fbsd1 mimedefang.pl[78707]: MDLOG,kA4DNmHU079248,virus,ClamAV-Test-File,127.0.0.1,<devi@fbsd1.xgu.ru>,<devi@fbsd1.xgu.ru>,Re: your mail
Nov  4 15:23:49 fbsd1 mimedefang.pl[78707]: Discarding because of virus ClamAV-Test-File
Nov  4 15:23:49 fbsd1 sm-mta[79248]: kA4DNmHU079248: Milter: data, discard
Nov  4 15:23:49 fbsd1 sm-mta[79248]: kA4DNmHU079248: discarded
Nov  4 15:23:49 fbsd1 sendmail[79247]: kA4DNmSH079247: to=devi@fbsd1.xgu.ru, ctladdr=devi (1002/0), delay=00:00:01, xdelay=00:00:01, mailer=relay, pri=31294, relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (kA4DNmHU079248 Message accepted for delivery)
15:26:03
#tail /var/log/messages
Oct 17 16:02:35 fbsd1 kernel: lnc0: Missed packet -- no receive buffer
Oct 17 18:12:19 fbsd1 kernel: lnc0: Missed packet -- no receive buffer
Oct 17 21:27:08 fbsd1 kernel: lnc0: Missed packet -- no receive buffer
Oct 17 23:27:45 fbsd1 kernel: lnc0: Missed packet -- no receive buffer
Oct 18 00:20:30 fbsd1 kernel: lnc0: Missed packet -- no receive buffer
Oct 18 00:31:47 fbsd1 kernel: lnc0: Missed packet -- no receive buffer
Oct 18 01:59:32 fbsd1 kernel: lnc0: Missed packet -- no receive buffer
Oct 18 01:59:33 fbsd1 kernel: lnc0: Missed packet -- no receive buffer
Oct 18 02:21:36 fbsd1 kernel: lnc0: Missed packet -- no receive buffer
Oct 18 02:37:32 fbsd1 kernel: lnc0: Missed packet -- no receive buffer
15:26:14
#less /usr/local/etc/mimedefang/mimedefang-filter
15:26:31
#grep -r 'Discarding because' /var/log/*
/var/log/debug.log:Nov  4 15:20:16 fbsd1 mimedefang[78721]: kA4DKGeD079063: Discarding because filter instructed us to
/var/log/debug.log:Nov  4 15:23:49 fbsd1 mimedefang[78721]: kA4DNmHU079248: Discarding because filter instructed us to
/var/log/maillog:Nov  4 15:20:16 fbsd1 mimedefang.pl[78707]: Discarding because of virus ClamAV-Test-File
/var/log/maillog:Nov  4 15:23:49 fbsd1 mimedefang.pl[78707]: Discarding because of virus ClamAV-Test-File
15:26:41
#cd /usr/ports/security/

прошло 65 минут
16:32:19
#cd /usr/ports/security/clamav
clamav/       clamav-devel/
16:32:19
#cd /usr/ports/security/clamav
clamav/       clamav-devel/
16:32:19
#cd /usr/ports/security/clamav
clamav/       clamav-devel/
16:32:19
#cd /usr/ports/security/clamav/
Makefile   distinfo   files/     pkg-descr  pkg-plist  work/
16:32:19
#cd /usr/ports/security/clamav/

16:32:29
#cd /usr/ports/security/clamav/work/

16:32:32
#cd /usr/ports/security/clamav/work/
.PLIST.flattened                   .patch_done.clamav._usr_local
.PLIST.mktmp                       clamav-0.88.3/
.PLIST.objdump                     clamav-clamd
.PLIST.setuid                      clamav-freshclam
.PLIST.writable                    clamav-milter
.build_done.clamav._usr_local      pkg-deinstall
.configure_done.clamav._usr_local  pkg-install
.extract_done.clamav._usr_local    testoutput.txt
.install_done.clamav._usr_local
16:32:32
#cd /usr/ports/security/clamav/work/clamav-*

16:32:39
#cd /usr/ports/security/clamav/work/clamav-*

16:32:42
#ls
AUTHORS                 clamav-config.h.in      docs
BUGS                    clamav-config.in        etc
COPYING                 clamav-milter           examples
ChangeLog               clamd                   freshclam
FAQ                     clamdscan               install-sh
INSTALL                 clamscan                libclamav
Makefile                config.guess            libclamav.pc
Makefile.am             config.log              libclamav.pc.in
Makefile.in             config.status           libtool
Makefile.in.orig        config.sub              ltmain.sh
NEWS                    configure               missing
README                  configure.bak           mkinstalldirs
TODO                    configure.in            shared
UPGRADE                 configure.lineno        sigtool
acinclude.m4            configure.orig          stamp-h1
aclocal.m4              contrib                 target.h
clamav-config           database                test
clamav-config.h         depcomp
16:32:45
#cd /usr/ports/security/clamav/work/clamav-*

16:32:49
#ls test/
README          clam.cab        clam.exe.bz2    clam.zip
clam-error.rar  clam.exe        clam.rar        mbox
16:41:31
#tail /var/log/maillog
q        d:õÄÁÌÉÔØ  u:÷ÏÓÓÔÁÎÏ×ÉÔØ  s:óÏÈÒÁÎÉÔØ  m:óÏÚÄÁÔØ  r:ïÔ×ÅÔÉÔØ  g:÷ÓÅÍ
   1 r F Nov 04 To devi@2d25;25H2d25;25H2d                                     25d÷Ù ÕÖÅ ÎÁ ÐÏÓÌÅÄÎÅÊ ÓÔÒÁÎÉÃÅ.2d25düÔÏ ÐÅÒ×ÏÅ ÓÏÏÂÝÅÎÉÅ.2d25;6HÏÓÌÅÄÎÅ
From: "Igor Chub.in" <devi@fbsd1.xgu.ru>  Nov  4 15:23:49 fbsd1 sm-mta[79248]: kA4DNmHU079248: Milter: data, discard
To: devi@fbsd1.xgu.ru
Nov  4 15:23:49 fbsd1 sm-mta[79248]: kA4DNmHU079248: discarded
X-Scanned-By: MIMEDefang 2.57 on 217.27.159.219
Nov  4 15:23:49 fbsd1 sendmail[79247]: kA4DNmSH079247: to=devi@fbsd1.xgu.ru, ctladdr=devi (1002/0), delay=00:00:01, xdelay=00:00:01, mailer=relay, pri=31294, relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (kA4DNmHU079248 Message accepted for delivery)
Hello
Nov  4 15:48:54 fbsd1 sm-mta[79363]: kA4DmrRO079363: from=<devi@fbsd1.xgu.ru>, size=1277, class=0, nrcpts=1, msgid=<20061104131413.GD72946@fbsd1.xgu.ru>, proto=ESMTP, daemon=IPv4, relay=localhost [127.0.0.1]
Nov  4 15:49:10 fbsd1 mimedefang.pl[78707]: MDLOG,kA4DmrRO079363,virus,ClamAV-Test-File,127.0.0.1,<devi@fbsd1.xgu.ru>,<devi@fbsd1.xgu.ru>,TEST2
Nov  4 15:49:10 fbsd1 mimedefang.pl[78707]: Discarding because of virus ClamAV-Test-File
Nov  4 15:49:10 fbsd1 sm-mta[79363]: kA4DmrRO079363: Milter: data, discard
Nov  4 15:49:10 fbsd1 sm-mta[79363]: kA4DmrRO079363: discarded
Nov  4 15:49:10 fbsd1 sm-msp-queue[79362]: kA4DEDpM078771: to=devi@fbsd1.xgu.ru, ctladdr=devi (1002/0), delay=00:34:57, xdelay=00:00:17, mailer=relay, pri=211104, relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (kA4DmrRO079363 Message accepted for delivery)
Nov  4 16:08:47 fbsd1 sm-mta[79405]: kA4E8lJn079405: [82.148.186.243] did not issue MAIL/EXPN/VRFY/ETRN during connection to IPv4
 --Mutt: /var/mail/devi [Msgs:1 0,8K]---(date/date)---------------------(all)---1S=1S
ðÏÞÔÏ×ÙÊ ÑÝÉË ÓÏÒÔÉÒÕÅÔÓÑ...Hq:÷ÙÈÏÄ  d:õÄÁÌÉÔØ  u:÷ÏÓÓÔÁÎÏ×ÉÔØ  s:óÏÈÒÁÎÉÔØ  m:óÏÚÄÁÔØ  r:ïÔ×ÅÔÉÔØ  g:÷ÓÅÍ     1 r F Nov 04 To devi@fbsd1.x (   1)
/dev/ttyv1
16:42:26
$mutt
q        d:õÄÁÌÉÔØ  u:÷ÏÓÓÔÁÎÏ×ÉÔØ  s:óÏÈÒÁÎÉÔØ  m:óÏÚÄÁÔØ  r:ïÔ×ÅÔÉÔØ  g:÷ÓÅÍ
From: "Igor Chub.in" <devi@fbsd1.xgu.ru>
To: devi@fbsd1.xgu.ru
User-Agent: Mutt/1.4.2.2i
X-Scanned-By: MIMEDefang 2.57 on 217.27.159.219
Hello
 --Mutt: /var/mail/devi [Msgs:1 0,8K]---(date/date)---------------------(all)---1S=1S
ðÏÞÔÏ×ÙÊ ÑÝÉË ÎÅ ÉÚÍÅÎÉÌÓÑ..Hq:÷ÙÈÏÄ  d:õÄÁÌÉÔØ  u:÷ÏÓÓÔÁÎÏ×ÉÔØ  s:óÏÈÒÁÎÉÔØ  m:óÏÚÄÁÔØ  r:ïÔ×ÅÔÉÔØ  g:÷ÓÅÍ     1 r F Nov 04 To devi@fbsd1.x (   1)
/dev/ttyv2
16:43:19
#tail -f /var/log/maillog
Nov  4 15:23:49 fbsd1 sm-mta[79248]: kA4DNmHU079248: Milter: data, discard
Nov  4 15:23:49 fbsd1 sm-mta[79248]: kA4DNmHU079248: discarded
Nov  4 15:23:49 fbsd1 sendmail[79247]: kA4DNmSH079247: to=devi@fbsd1.xgu.ru, ctladdr=devi (1002/0), delay=00:00:01, xdelay=00:00:01, mailer=relay, pri=31294, relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (kA4DNmHU079248 Message accepted for delivery)
Nov  4 15:48:54 fbsd1 sm-mta[79363]: kA4DmrRO079363: from=<devi@fbsd1.xgu.ru>, size=1277, class=0, nrcpts=1, msgid=<20061104131413.GD72946@fbsd1.xgu.ru>, proto=ESMTP, daemon=IPv4, relay=localhost [127.0.0.1]
Nov  4 15:49:10 fbsd1 mimedefang.pl[78707]: MDLOG,kA4DmrRO079363,virus,ClamAV-Test-File,127.0.0.1,<devi@fbsd1.xgu.ru>,<devi@fbsd1.xgu.ru>,TEST2
Nov  4 15:49:10 fbsd1 mimedefang.pl[78707]: Discarding because of virus ClamAV-Test-File
Nov  4 15:49:10 fbsd1 sm-mta[79363]: kA4DmrRO079363: Milter: data, discard
Nov  4 15:49:10 fbsd1 sm-mta[79363]: kA4DmrRO079363: discarded
Nov  4 15:49:10 fbsd1 sm-msp-queue[79362]: kA4DEDpM078771: to=devi@fbsd1.xgu.ru, ctladdr=devi (1002/0), delay=00:34:57, xdelay=00:00:17, mailer=relay, pri=211104, relay=[127.0.0.1] [127.0.0.1], dsn=2.0.0, stat=Sent (kA4DmrRO079363 Message accepted for delivery)
Nov  4 16:08:47 fbsd1 sm-mta[79405]: kA4E8lJn079405: [82.148.186.243] did not issue MAIL/EXPN/VRFY/ETRN during connection to IPv4
...
Nov  4 16:54:43 fbsd1 sm-mta[79622]: kA4EseIC079622: Milter delete (noop): header: X-Spam-Score
Nov  4 16:54:43 fbsd1 sm-mta[79622]: kA4EseIC079622: Milter add: header: X-Scanned-By: MIMEDefang 2.57 on 217.27.159.219
Nov  4 16:54:44 fbsd1 sm-mta[79623]: kA4EseIC079622: to=<devi@fbsd1.xgu.ru>, delay=00:00:02, xdelay=00:00:01, mailer=local, pri=31179, relay=local, dsn=2.0.0, stat=Sent
Nov  4 16:55:43 fbsd1 sm-mta[79721]: kA4EthIh079721: from=<devi@kievnet.kiev.ua>, size=873, class=0, nrcpts=1, msgid=<20061104150505.GA14749@kievnet.kiev.ua>, proto=ESMTP, daemon=IPv4, relay=postfix@217.27.159.222.sitel.com.ua [217.27.159.222] (may be forged)
Nov  4 16:55:44 fbsd1 mimedefang-multiplexor[78705]: Slave 0 stderr: auto-whitelist: open of auto-whitelist file failed: locker: safe_lock: cannot create tmp lockfile /root/.spamassassin/auto-whitelist.lock.fbsd1.xgu.ru.78707 for /root/.spamassassin/auto-whitelist.lock: No such file or directory
Nov  4 16:55:44 fbsd1 mimedefang.pl[78707]: MDLOG,kA4EthIh079721,mail_in,,,<devi@kievnet.kiev.ua>,<devi@fbsd1.xgu.ru>,VIAGRA
Nov  4 16:55:44 fbsd1 sm-mta[79721]: kA4EthIh079721: Milter delete (noop): header: X-Spam-Score
Nov  4 16:55:44 fbsd1 sm-mta[79721]: kA4EthIh079721: Milter add: header: X-Scanned-By: MIMEDefang 2.57 on 217.27.159.219
Nov  4 16:55:44 fbsd1 sm-mta[79722]: kA4EthIh079721: to=<devi@fbsd1.xgu.ru>, delay=00:00:01, xdelay=00:00:00, mailer=local, pri=31194, relay=local, dsn=2.0.0, stat=Sent
^C
/dev/ttyv1
16:52:47
$ping ya.ru
^C
16:52:54
$exit
exit
16:52:56
#ping ya.ry
PING ya.ry.xgu.ru (217.27.159.217): 56 data bytes
^C
--- ya.ry.xgu.ru ping statistics ---
1 packets transmitted, 0 packets received, 100% packet loss
16:52:58
#ping ya.ru
PING ya.ru (213.180.204.8): 56 data bytes
64 bytes from 213.180.204.8: icmp_seq=0 ttl=55 time=158.321 ms
^C
--- ya.ru ping statistics ---
1 packets transmitted, 1 packets received, 0% packet loss
round-trip min/avg/max/stddev = 158.321/158.321/158.321/0.000 ms
16:53:01
#ifconfig
lnc0: flags=108843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,NEEDSGIANT> mtu 1500
        inet6 fe80::20c:29ff:fec1:7c41%lnc0 prefixlen 64 scopeid 0x1
        inet 217.27.159.219 netmask 0xfffffff8 broadcast 217.27.159.223
        inet 192.168.1.199 netmask 0xffffff00 broadcast 192.168.1.255
        ether 00:0c:29:c1:7c:41
plip0: flags=108810<POINTOPOINT,SIMPLEX,MULTICAST,NEEDSGIANT> mtu 1500
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
        inet6 ::1 prefixlen 128
        inet6 fe80::1%lo0 prefixlen 64 scopeid 0x3
        inet 127.0.0.1 netmask 0xff000000
16:53:04
#ping 217.27.159.222
PING 217.27.159.222 (217.27.159.222): 56 data bytes
64 bytes from 217.27.159.222: icmp_seq=0 ttl=64 time=2.012 ms
^C
--- 217.27.159.222 ping statistics ---
1 packets transmitted, 1 packets received, 0% packet loss
round-trip min/avg/max/stddev = 2.012/2.012/2.012/0.000 ms
16:53:49
#ping 217.27.159.217
PING 217.27.159.217 (217.27.159.217): 56 data bytes
^C
--- 217.27.159.217 ping statistics ---
10 packets transmitted, 0 packets received, 100% packet loss
16:54:02
#su - devi
mutl3-agent is already running: pid=6110; pidfile=/home/devi/.lilalo/l3-agent.pid
t
16:54:50
$mutt
i        d:õÄÁÌÉÔØ  u:÷ÏÓÓÔÁÎÏ×ÉÔØ  s:óÏÈÒÁÎÉÔØ  m:óÏÚÄÁÔØ  r:ïÔ×ÅÔÉÔØ  g:÷ÓÅÍ
   1 r F Nov 04 To devi@fbsd1.x (   1)
   2   + Nov 04 devi@kievnet.ki (   1) XXXX
        with ESMTP id JFe6ceu2TQ6e for <devi@fbsd1.xgu.ru>;
        Sat,  4 Nov 2006 17:05:05 +0200 (EET)
Received: by alien.kievnet.kiev.ua (Postfix, from userid 5074)
        id 740F08561E; Sat,  4 Nov 2006 17:05:05 +0200 (EET)
Date: Sat, 4 Nov 2006 17:05:05 +0200
To: devi@fbsd1.xgu.ru
Subject: VIAGRA
...
User-Agent: Mutt/1.5.6+20040907i
From: devi@kievnet.kiev.ua
X-Scanned-By: MIMEDefang 2.57 on 217.27.159.219
BUY
BUY
VIAGRA
=1S+- 3/3: devi@kievnet.kiev.ua   VIAGRA                               -- (end)Bð*-Mutt: /var/mail/devi [Msgs:3 3,3K]---(date/date)---------------------(all)---
ïÓÔÁ×ÌÅÎÏ: 3, ÕÄÁÌÅÎÏ: 0.                =S=SHq
Received: from alien.kievnet.kiev.ua (postfix@217.27.159.222.sitel.com.ua
You have mail in /var/mail/devid))
16:58:08
$mutt

/dev/ttyv2
16:58:15
#vi /usr/local/etc/mime
16:58:15
#vi /usr/local/etc/mimedefang/
16:58:15
#vi /usr/local/etc/mimedefang/sa-mimedefang.cf
16:58:36
#vi /usr/local/etc/mimedefang/
16:58:36
#vi /usr/local/etc/mimedefang/mimedefang-filter
17:00:21
#pkg_info -Lx defang | while read file; do grep /var

17:00:21
#pkg_info -Lx defang | while read file; do grep /va

17:00:21
#pkg_info -Lx defang | while read file; do grep /va

17:00:21
#pkg_info -Lx defang | while read file; do grep /v $

17:00:21
#pkg_info -Lx defang | while read file; do grep / $f

17:00:21
#pkg_info -Lx defang | while read file; do grep $fi

17:00:21
#pkg_info -Lx defang | while read file; do grep $fil

17:00:21
#pkg_info -Lx defang | while read file; do grep $fi

17:00:21
#pkg_info -Lx defang | while read file; do grep s $f

17:00:21
#pkg_info -Lx defang | while read file; do grep sp $

17:00:21
#pkg_info -Lx defang | while read file; do grep spa

17:00:21
#pkg_info -Lx defang | while read file; do grep spam
_assassin_check
grep: Information: No such file or directory
grep: for: No such file or directory
grep: mimedefang-2.57:: No such file or directory
grep: Files:: No such file or directory
/usr/local/bin/mimedefang.pl:    my($hits, $req, $tests, $report) = spam_assassin_check(@_);
/usr/local/bin/mimedefang.pl:# %PROCEDURE: spam_assassin_check
/usr/local/bin/mimedefang.pl:sub spam_assassin_check (;$) {
/usr/local/etc/mimedefang/mimedefang-filter.example:        my($hits, $req, $names, $report) = spam_assassin_check();
/usr/local/share/doc/mimedefang/README.SPAMASSASSIN:   spam_assassin_check in filter_end().  See the sample filter in
/usr/local/share/examples/mimedefang/suggested-minimum-filter-for-windows-clients:          my($hits, $req, $names, $report) = spam_assassin_check();
17:00:47
#vi /usr/local/bin/mimedefang.pl
17:02:21
#pkg_info -Lx defang | while read file; do grep spam
_assassin_check $file /dev/null; done
17:02:21
#vi /usr/local/etc/mimedefang/sa-mimedefang.cf
26c26
< required_hits		5
---
> required_hits		0
17:05:08
#tail /var/log/maillog
Nov  4 17:02:22 fbsd1 mimedefang.pl[78707]: MDLOG,kA4F2K6L079880,mail_in,,,<igor@chub.in>,<devi@fbsd1.xgu.ru>,XLXLXLX
Nov  4 17:02:22 fbsd1 sm-mta[79880]: kA4F2K6L079880: Milter delete (noop): header: X-Spam-Score
Nov  4 17:02:22 fbsd1 sm-mta[79880]: kA4F2K6L079880: Milter add: header: X-Scanned-By: MIMEDefang 2.57 on 217.27.159.219
Nov  4 17:02:23 fbsd1 sm-mta[79885]: kA4F2K6L079880: to=<devi@fbsd1.xgu.ru>, delay=00:00:02, xdelay=00:00:00, mailer=local, pri=30753, relay=local, dsn=2.0.0, stat=Sent
Nov  4 17:04:13 fbsd1 sm-mta[79903]: kA4F4DbO079903: from=<devi@kievnet.kiev.ua>, size=866, class=0, nrcpts=1, msgid=<20061104151343.GB14749@kievnet.kiev.ua>, proto=ESMTP, daemon=IPv4, relay=postfix@217.27.159.222.sitel.com.ua [217.27.159.222] (may be forged)
Nov  4 17:04:13 fbsd1 mimedefang-multiplexor[78705]: Slave 0 stderr: auto-whitelist: open of auto-whitelist file failed: locker: safe_lock: cannot create tmp lockfile /root/.spamassassin/auto-whitelist.lock.fbsd1.xgu.ru.78707 for /root/.spamassassin/auto-whitelist.lock: No such file or directory
Nov  4 17:04:13 fbsd1 mimedefang.pl[78707]: MDLOG,kA4F4DbO079903,mail_in,,,<devi@kievnet.kiev.ua>,<devi@fbsd1.xgu.ru>,VIAGRA
Nov  4 17:04:13 fbsd1 sm-mta[79903]: kA4F4DbO079903: Milter delete (noop): header: X-Spam-Score
Nov  4 17:04:13 fbsd1 sm-mta[79903]: kA4F4DbO079903: Milter add: header: X-Scanned-By: MIMEDefang 2.57 on 217.27.159.219
Nov  4 17:04:14 fbsd1 sm-mta[79904]: kA4F4DbO079903: to=<devi@fbsd1.xgu.ru>, delay=00:00:01, xdelay=00:00:00, mailer=local, pri=31187, relay=local, dsn=2.0.0, stat=Sent
17:05:23
#vi /usr/local/etc/mimedefang/sa-mimedefang.cf
50c50
< rewrite_subject 0
---
> rewrite_subject 1
17:06:45
#tail -f /var/log/maillog
Nov  4 17:02:22 fbsd1 mimedefang.pl[78707]: MDLOG,kA4F2K6L079880,mail_in,,,<igor@chub.in>,<devi@fbsd1.xgu.ru>,XLXLXLX
Nov  4 17:02:22 fbsd1 sm-mta[79880]: kA4F2K6L079880: Milter delete (noop): header: X-Spam-Score
Nov  4 17:02:22 fbsd1 sm-mta[79880]: kA4F2K6L079880: Milter add: header: X-Scanned-By: MIMEDefang 2.57 on 217.27.159.219
Nov  4 17:02:23 fbsd1 sm-mta[79885]: kA4F2K6L079880: to=<devi@fbsd1.xgu.ru>, delay=00:00:02, xdelay=00:00:00, mailer=local, pri=30753, relay=local, dsn=2.0.0, stat=Sent
Nov  4 17:04:13 fbsd1 sm-mta[79903]: kA4F4DbO079903: from=<devi@kievnet.kiev.ua>, size=866, class=0, nrcpts=1, msgid=<20061104151343.GB14749@kievnet.kiev.ua>, proto=ESMTP, daemon=IPv4, relay=postfix@217.27.159.222.sitel.com.ua [217.27.159.222] (may be forged)
Nov  4 17:04:13 fbsd1 mimedefang-multiplexor[78705]: Slave 0 stderr: auto-whitelist: open of auto-whitelist file failed: locker: safe_lock: cannot create tmp lockfile /root/.spamassassin/auto-whitelist.lock.fbsd1.xgu.ru.78707 for /root/.spamassassin/auto-whitelist.lock: No such file or directory
Nov  4 17:04:13 fbsd1 mimedefang.pl[78707]: MDLOG,kA4F4DbO079903,mail_in,,,<devi@kievnet.kiev.ua>,<devi@fbsd1.xgu.ru>,VIAGRA
Nov  4 17:04:13 fbsd1 sm-mta[79903]: kA4F4DbO079903: Milter delete (noop): header: X-Spam-Score
Nov  4 17:04:13 fbsd1 sm-mta[79903]: kA4F4DbO079903: Milter add: header: X-Scanned-By: MIMEDefang 2.57 on 217.27.159.219
Nov  4 17:04:14 fbsd1 sm-mta[79904]: kA4F4DbO079903: to=<devi@fbsd1.xgu.ru>, delay=00:00:01, xdelay=00:00:00, mailer=local, pri=31187, relay=local, dsn=2.0.0, stat=Sent
Nov  4 17:07:15 fbsd1 sm-mta[79945]: kA4F7Fbl079945: from=<devi@kievnet.kiev.ua>, size=860, class=0, nrcpts=1, msgid=<20061104151637.GC14749@kievnet.kiev.ua>, proto=ESMTP, daemon=IPv4, relay=postfix@217.27.159.222.sitel.com.ua [217.27.159.222] (may be forged)
Nov  4 17:07:16 fbsd1 mimedefang-multiplexor[78705]: Slave 0 stderr: auto-whitelist: open of auto-whitelist file failed: locker: safe_lock: cannot create tmp lockfile /root/.spamassassin/auto-whitelist.lock.fbsd1.xgu.ru.78707 for /root/.spamassassin/auto-whitelist.lock: No such file or directory
Nov  4 17:07:16 fbsd1 mimedefang.pl[78707]: MDLOG,kA4F7Fbl079945,mail_in,,,<devi@kievnet.kiev.ua>,<devi@fbsd1.xgu.ru>,TEST
Nov  4 17:07:16 fbsd1 sm-mta[79945]: kA4F7Fbl079945: Milter delete (noop): header: X-Spam-Score
Nov  4 17:07:16 fbsd1 sm-mta[79945]: kA4F7Fbl079945: Milter add: header: X-Scanned-By: MIMEDefang 2.57 on 217.27.159.219
Nov  4 17:07:16 fbsd1 sm-mta[79946]: kA4F7Fbl079945: to=<devi@fbsd1.xgu.ru>, delay=00:00:01, xdelay=00:00:00, mailer=local, pri=31181, relay=local, dsn=2.0.0, stat=Sent
^C
17:07:28
#vi /usr/local/bin/mimedefang.pl
17:09:35
#vi /usr/local/etc/mimedefang/
17:09:35
#vi /usr/local/etc/mimedefang/mimedefang-filter
304c304
< 	    if ($hits >= $req) {
---
> 	    if (1 || $hits >= $req) {
17:10:27
#tail -f /var/log/maillog
Nov  4 17:04:13 fbsd1 mimedefang.pl[78707]: MDLOG,kA4F4DbO079903,mail_in,,,<devi@kievnet.kiev.ua>,<devi@fbsd1.xgu.ru>,VIAGRA
Nov  4 17:04:13 fbsd1 sm-mta[79903]: kA4F4DbO079903: Milter delete (noop): header: X-Spam-Score
Nov  4 17:04:13 fbsd1 sm-mta[79903]: kA4F4DbO079903: Milter add: header: X-Scanned-By: MIMEDefang 2.57 on 217.27.159.219
Nov  4 17:04:14 fbsd1 sm-mta[79904]: kA4F4DbO079903: to=<devi@fbsd1.xgu.ru>, delay=00:00:01, xdelay=00:00:00, mailer=local, pri=31187, relay=local, dsn=2.0.0, stat=Sent
Nov  4 17:07:15 fbsd1 sm-mta[79945]: kA4F7Fbl079945: from=<devi@kievnet.kiev.ua>, size=860, class=0, nrcpts=1, msgid=<20061104151637.GC14749@kievnet.kiev.ua>, proto=ESMTP, daemon=IPv4, relay=postfix@217.27.159.222.sitel.com.ua [217.27.159.222] (may be forged)
Nov  4 17:07:16 fbsd1 mimedefang-multiplexor[78705]: Slave 0 stderr: auto-whitelist: open of auto-whitelist file failed: locker: safe_lock: cannot create tmp lockfile /root/.spamassassin/auto-whitelist.lock.fbsd1.xgu.ru.78707 for /root/.spamassassin/auto-whitelist.lock: No such file or directory
Nov  4 17:07:16 fbsd1 mimedefang.pl[78707]: MDLOG,kA4F7Fbl079945,mail_in,,,<devi@kievnet.kiev.ua>,<devi@fbsd1.xgu.ru>,TEST
Nov  4 17:07:16 fbsd1 sm-mta[79945]: kA4F7Fbl079945: Milter delete (noop): header: X-Spam-Score
Nov  4 17:07:16 fbsd1 sm-mta[79945]: kA4F7Fbl079945: Milter add: header: X-Scanned-By: MIMEDefang 2.57 on 217.27.159.219
Nov  4 17:07:16 fbsd1 sm-mta[79946]: kA4F7Fbl079945: to=<devi@fbsd1.xgu.ru>, delay=00:00:01, xdelay=00:00:00, mailer=local, pri=31181, relay=local, dsn=2.0.0, stat=Sent
Nov  4 17:10:47 fbsd1 sm-mta[79988]: kA4FAkOW079988: from=<devi@kievnet.kiev.ua>, size=860, class=0, nrcpts=1, msgid=<20061104151956.GA15163@kievnet.kiev.ua>, proto=ESMTP, daemon=IPv4, relay=postfix@217.27.159.222.sitel.com.ua [217.27.159.222] (may be forged)
Nov  4 17:10:47 fbsd1 mimedefang-multiplexor[78705]: Slave 0 stderr: auto-whitelist: open of auto-whitelist file failed: locker: safe_lock: cannot create tmp lockfile /root/.spamassassin/auto-whitelist.lock.fbsd1.xgu.ru.78707 for /root/.spamassassin/auto-whitelist.lock: No such file or directory
Nov  4 17:10:47 fbsd1 mimedefang.pl[78707]: MDLOG,kA4FAkOW079988,mail_in,,,<devi@kievnet.kiev.ua>,<devi@fbsd1.xgu.ru>,XXXX
Nov  4 17:10:47 fbsd1 sm-mta[79988]: kA4FAkOW079988: Milter delete (noop): header: X-Spam-Score
Nov  4 17:10:47 fbsd1 sm-mta[79988]: kA4FAkOW079988: Milter add: header: X-Scanned-By: MIMEDefang 2.57 on 217.27.159.219
Nov  4 17:10:47 fbsd1 sm-mta[79990]: kA4FAkOW079988: to=<devi@fbsd1.xgu.ru>, delay=00:00:00, xdelay=00:00:00, mailer=local, pri=31181, relay=local, dsn=2.0.0, stat=Sent
^C
17:11:24
#vi /usr/local/etc/mimedefang/mimedefang-filter
17:11:34
#vi /etc/mail
17:11:34
#vi /etc/mail
17:11:34
#vi /etc/mail/
17:11:34
#vi /etc/mail/fbsd1.xgu.ru.mc
17:16:43
#tail -f /var/log/maillog
Nov  4 17:07:16 fbsd1 mimedefang.pl[78707]: MDLOG,kA4F7Fbl079945,mail_in,,,<devi@kievnet.kiev.ua>,<devi@fbsd1.xgu.ru>,TEST
Nov  4 17:07:16 fbsd1 sm-mta[79945]: kA4F7Fbl079945: Milter delete (noop): header: X-Spam-Score
Nov  4 17:07:16 fbsd1 sm-mta[79945]: kA4F7Fbl079945: Milter add: header: X-Scanned-By: MIMEDefang 2.57 on 217.27.159.219
Nov  4 17:07:16 fbsd1 sm-mta[79946]: kA4F7Fbl079945: to=<devi@fbsd1.xgu.ru>, delay=00:00:01, xdelay=00:00:00, mailer=local, pri=31181, relay=local, dsn=2.0.0, stat=Sent
Nov  4 17:10:47 fbsd1 sm-mta[79988]: kA4FAkOW079988: from=<devi@kievnet.kiev.ua>, size=860, class=0, nrcpts=1, msgid=<20061104151956.GA15163@kievnet.kiev.ua>, proto=ESMTP, daemon=IPv4, relay=postfix@217.27.159.222.sitel.com.ua [217.27.159.222] (may be forged)
Nov  4 17:10:47 fbsd1 mimedefang-multiplexor[78705]: Slave 0 stderr: auto-whitelist: open of auto-whitelist file failed: locker: safe_lock: cannot create tmp lockfile /root/.spamassassin/auto-whitelist.lock.fbsd1.xgu.ru.78707 for /root/.spamassassin/auto-whitelist.lock: No such file or directory
Nov  4 17:10:47 fbsd1 mimedefang.pl[78707]: MDLOG,kA4FAkOW079988,mail_in,,,<devi@kievnet.kiev.ua>,<devi@fbsd1.xgu.ru>,XXXX
Nov  4 17:10:47 fbsd1 sm-mta[79988]: kA4FAkOW079988: Milter delete (noop): header: X-Spam-Score
Nov  4 17:10:47 fbsd1 sm-mta[79988]: kA4FAkOW079988: Milter add: header: X-Scanned-By: MIMEDefang 2.57 on 217.27.159.219
Nov  4 17:10:47 fbsd1 sm-mta[79990]: kA4FAkOW079988: to=<devi@fbsd1.xgu.ru>, delay=00:00:00, xdelay=00:00:00, mailer=local, pri=31181, relay=local, dsn=2.0.0, stat=Sent
Nov  5 00:00:03 fbsd1 newsyslog[81022]: logfile turned over
^C
You have new mail in /var/mail/root

Воскресенье (11/05/06)

/dev/ttyv1
11:18:25
$mutt
   4   + Nov 04 Igor Chubin     (   9) TEST
=1S6   + Nov 04 devi@kievnet.ki (   1) XXXX                                        7   + Nov 04 devi@kievnet.ki (   5) VIAGRA
=1S7   + Nov 04 devi@kievnet.ki (   5) VIAGRA                                      8   + Nov 04 devi@kievnet.ki (   1) VIAGRA
=1S8   + Nov 04 devi@kievnet.ki (   1) VIAGRA                                      9   + Nov 04 devi@kievnet.ki (   1) TEST
=1S9   + Nov 04 devi@kievnet.ki (   1) TEST                                       10   + Nov 04 devi@kievnet.ki (   1) XXXX
                                                                                                                                                               =1S
                                                                                ---Mutt: /var/mail/devi [Msgs:10 10K]---(date/date)---------------------(all)---
ðÏÞÔÏ×ÙÊ ÑÝÉË ÎÅ ÉÚÍÅÎÉÌÓÑ.d1.x (   1)d:õÄÁÌÉÔØ  u:÷ÏÓÓÔÁÎÏ×ÉÔØ  s:óÏÈÒÁÎÉÔØ  m:óÏÚÄÁÔØ  r:ïÔ×ÅÔÉÔØ  g:÷ÓÅÍ
   2   + Nov 04 Igor Chubin     (  16) VIAGRA
   3   + Nov 04 Igor Chubin     (   9) TEST
   4   + Nov 04 Igor Chubin     (   9) TEST
   5   + Nov 04 Igor Chubin     (   1) XLXLXLX
   6   + Nov 04 devi@kievnet.ki (   1) XXXX
   7   + Nov 04 devi@kievnet.ki (   5) VIAGRA
   8   + Nov 04 devi@kievnet.ki (   1) VIAGRA
   9   + Nov 04 devi@kievnet.ki (   1) TEST
  10   + Nov 04 devi@kievnet.ki (   1) XXXX
11:18:29
$mutt
i        d:õÄÁÌÉÔØ  u:÷ÏÓÓÔÁÎÏ×ÉÔØ  s:óÏÈÒÁÎÉÔØ  m:óÏÚÄÁÔØ  r:ïÔ×ÅÔÉÔØ  g:÷ÓÅÍ
   1 r F Nov 04 To devi@fbsd1.x (   1)
   2   + Nov 04 Igor Chubin     (  16) VIAGRA
   3   + Nov 04 Igor Chubin     (   9) TEST
   4   + Nov 04 Igor Chubin     (   9) TEST
   5   + Nov 04 Igor Chubin     (   1) XLXLXLX
   6   + Nov 04 devi@kievnet.ki (   1) XXXX
   7   + Nov 04 devi@kievnet.ki (   5) VIAGRA
   8   + Nov 04 devi@kievnet.ki (   1) VIAGRA
   9   + Nov 04 devi@kievnet.ki (   1) TEST
...
   5   + Nov 04 Igor Chubin     (   1) XLXLXLX
   6   + Nov 04 devi@kievnet.ki (   1) XXXX
   7   + Nov 04 devi@kievnet.ki (   5) VIAGRA
   8   + Nov 04 devi@kievnet.ki (   1) VIAGRA
   9   + Nov 04 devi@kievnet.ki (   1) TEST
  10   + Nov 04 devi@kievnet.ki (   1) XXXX
  12 N + Nov 05 devi@kievnet.ki (   1) XXXX
  13 N + Nov 05 devi@kievnet.ki (   1) YYYYY
  14 N + Nov 05 devi@kievnet.ki (   1) YYDDDDdYYY
  15 N + Nov 05 devi@kievnet.ki (  33) YYDDDDdYYY
/dev/ttyv2
11:18:35
#pkg_info -Lx defang | while read file; do grep spam
                     g': pkg_info -Lx defang | while read file; do grep spam_a
assin_check $file /dev/null; done
11:18:35
#pkg_info -Lx defang | while read file; do grep spa

11:18:35
#pkg_info -Lx defang | while read file; do grep spa

11:18:35
#pkg_info -Lx defang | while read file; do grep sp $

11:18:35
#pkg_info -Lx defang | while read file; do grep s $f

11:18:35
#pkg_info -Lx defang | while read file; do grep $fi

11:18:35
#pkg_info -Lx defang | while read file; do grep h $f

11:18:35
#pkg_info -Lx defang | while read file; do grep hr $

11:18:35
#pkg_info -Lx defang | while read file; do grep hre

11:18:35
#pkg_info -Lx defang | while read file; do grep hrem
ove
grep: Information: No such file or directory
grep: for: No such file or directory
grep: mimedefang-2.57:: No such file or directory
grep: Files:: No such file or directory
11:19:10
#pkg_info -Lx defang | while read file; do grep hrem

11:19:10
#pkg_info -Lx defang | while read file; do grep remo

11:19:10
#pkg_info -Lx defang | while read file; do grep
grep: Information: No such file or directory
grep: for: No such file or directory
grep: mimedefang-2.57:: No such file or directory
grep: Files:: No such file or directory
Binary file /usr/local/bin/mimedefang-multiplexor matches
Binary file /usr/local/bin/mimedefang matches
/usr/local/bin/mimedefang.pl:# Perl scanner which parses MIME messages and filters or removes
/usr/local/bin/mimedefang.pl:       $sel->remove($sock);
/usr/local/bin/mimedefang.pl:    # At least one virus removed - Should not happen as we aren't
/usr/local/bin/mimedefang.pl:# %PROCEDURE: remove_redundant_html_parts
...
/usr/local/etc/mimedefang/mimedefang-filter.example:    return action_drop_with_warning("An attachment named $fname was removed from this document as it\nconstituted a security hazard.  If you require this document, please contact\nthe sender and arrange an alternate means of receiving it.\n");
/usr/local/etc/mimedefang/mimedefang-filter.example:    return action_drop_with_warning("A non-multipart attachment named $fname was removed from this document as it\nconstituted a security hazard.  If you require this document, please contact\nthe sender and arrange an alternate means of receiving it.\n");
/usr/local/etc/mimedefang/mimedefang-filter.example:    return action_drop_with_warning("An attachment of type $type, named $fname was removed from this document as it\nconstituted a security hazard.  If you require this document, please contact\nthe sender and arrange an alternate means of receiving it.\n");
/usr/local/etc/mimedefang/mimedefang-filter.example:    return action_drop_with_warning("A non-message/rfc822 attachment named $fname was removed from this document as it\nconstituted a security hazard.  If you require this document, please contact\nthe sender and arrange an alternate means of receiving it.\n");
/usr/local/etc/mimedefang/mimedefang-filter.example:    # remove_redundant_html_parts($entity);
/usr/local/share/examples/mimedefang/suggested-minimum-filter-for-windows-clients:      return action_drop_with_warning("An attachment named $fname was removed from this document as it\nconstituted a security hazard.  If you require this document, please contact\nthe sender and arrange an alternate means of receiving it.\n");
/usr/local/share/examples/mimedefang/suggested-minimum-filter-for-windows-clients:      return action_drop_with_warning("A non-multipart attachment named $fname was removed from this document as it\nconstituted a security hazard.  If you require this document, please contact\nthe sender and arrange an alternate means of receiving it.\n");
/usr/local/share/examples/mimedefang/suggested-minimum-filter-for-windows-clients:      return action_drop_with_warning("An attachment of type $type, named $fname was removed from this document as it\nconstituted a security hazard.  If you require this document, please contact\nthe sender and arrange an alternate means of receiving it.\n");
/usr/local/share/examples/mimedefang/suggested-minimum-filter-for-windows-clients:      return action_drop_with_warning("A non-message/rfc822 attachment named $fname was removed from this document as it\nconstituted a security hazard.  If you require this document, please contact\nthe sender and arrange an alternate means of receiving it.\n");
/usr/local/share/examples/mimedefang/suggested-minimum-filter-for-windows-clients:    # remove_redundant_html_parts($entity);
11:19:19
#pkg_info -Lx defang | while read file; do grep remo
ve  $file /dev/null; done | less
grep: Information: No such file or directory
grep: for: No such file or directory
grep: mimedefang-2.57:: No such file or directory
grep: Files:: No such file or directory
^[[B^[[B^[[B
/usr/local/etc/mimedefang/mimedefang-filter.example:    # remove_redundant_html_parts($entity);
/usr/local/share/examples/mimedefang/suggested-minimum-filter-for-windows-clients:      return action_drop_with_warning("An attachment named $fname was removed from this document as it\nconstituted a security hazard.  If you require this document, please contact\nthe sender and arrange an alternate means of receiving it.\n");
/usr/local/share/examples/mimedefang/suggested-minimum-filter-for-windows-clients:      return action_drop_with_warning("A non-multipart attachment named $fname was removed from this document as it\nconstituted a security hazard.  If you require this document, please contact\nthe sender and arrange an alternate means of receiving it.\n");
/usr/local/share/examples/mimedefang/suggested-minimum-filter-for-windows-clients:      return action_drop_with_warning("An attachment of type $type, named $fname was removed from this document as it\nconstituted a security hazard.  If you require this document, please contact\nthe sender and arrange an alternate means of receiving it.\n");
/usr/local/share/examples/mimedefang/suggested-minimum-filter-for-windows-clients:      return action_drop_with_warning("A non-message/rfc822 attachment named $fname was removed from this document as it\nconstituted a security hazard.  If you require this document, please contact\nthe sender and arrange an alternate means of receiving it.\n");
/usr/local/share/examples/mimedefang/suggested-minimum-filter-for-windows-clients:    # remove_redundant_html_parts($entity);
/usr/local/bin/mimedefang.pl:sub remove_redundant_html_parts ($); # Prototype
/usr/local/bin/mimedefang.pl:sub remove_redundant_html_parts ($) {
/usr/local/bin/mimedefang.pl:    return 0 unless in_filter_end("remove_redundant_html_parts");
/usr/local/bin/mimedefang.pl:       $didsomething = 1 if (remove_redundant_html_parts($part));
/usr/local/etc/mimedefang/mimedefang-filter.example:    return action_drop_with_warning("An attachment named $fname was removed from this document as it\nconstituted a security hazard.  If you require this document, please contact\nthe sender and arrange an alternate means of receiving it.\n");
/usr/local/etc/mimedefang/mimedefang-filter.example:    return action_drop_with_warning("A non-multipart attachment named $fname was removed from this document as it\nconstituted a security hazard.  If you require this document, please contact\nthe sender and arrange an alternate means of receiving it.\n");
/usr/local/etc/mimedefang/mimedefang-filter.example:    return action_drop_with_warning("An attachment of type $type, named $fname was removed from this documen
11:19:40
#pkg_info -Lx defang | while read file; do grep remo

11:19:40
#pkg_info -Lx defang | while read file; do grep hrem

11:19:40
#tail -f /var/log/maillog

Статистика

Время первой команды журнала15:19:42 2006-11- 4
Время последней команды журнала11:19:40 2006-11- 5
Количество командных строк в журнале101
Процент команд с ненулевым кодом завершения, % 6.93
Процент синтаксически неверно набранных команд, % 0.00
Суммарное время работы с терминалом *, час 0.88
Количество командных строк в единицу времени, команда/мин 1.92
Частота использования команд
while29|==================| 18.12%
pkg_info29|==================| 18.12%
do29|==================| 18.12%
tail16|==========| 10.00%
vi16|==========| 10.00%
mutt11|======| 6.88%
cd11|======| 6.88%
ping5|===| 3.12%
less5|===| 3.12%
ls2|=| 1.25%
ifconfig1|| 0.62%
mailq1|| 0.62%
echo1|| 0.62%
mail1|| 0.62%
grep1|| 0.62%
exit1|| 0.62%
su1|| 0.62%
____
*) Интервалы неактивности длительностью 30 минут и более не учитываются

Справка

Для того чтобы использовать LiLaLo, не нужно знать ничего особенного: всё происходит само собой. Однако, чтобы ведение и последующее использование журналов было как можно более эффективным, желательно иметь в виду следующее:
  1. В журнал автоматически попадают все команды, данные в любом терминале системы.

  2. Для того чтобы убедиться, что журнал на текущем терминале ведётся, и команды записываются, дайте команду w. В поле WHAT, соответствующем текущему терминалу, должна быть указана программа script.

  3. Команды, при наборе которых были допущены синтаксические ошибки, выводятся перечёркнутым текстом:
    $ l s-l
    bash: l: command not found
    

  4. Если код завершения команды равен нулю, команда была выполнена без ошибок. Команды, код завершения которых отличен от нуля, выделяются цветом.
    $ test 5 -lt 4
    Обратите внимание на то, что код завершения команды может быть отличен от нуля не только в тех случаях, когда команда была выполнена с ошибкой. Многие команды используют код завершения, например, для того чтобы показать результаты проверки

  5. Команды, ход выполнения которых был прерван пользователем, выделяются цветом.
    $ find / -name abc
    find: /home/devi-orig/.gnome2: Keine Berechtigung
    find: /home/devi-orig/.gnome2_private: Keine Berechtigung
    find: /home/devi-orig/.nautilus/metafiles: Keine Berechtigung
    find: /home/devi-orig/.metacity: Keine Berechtigung
    find: /home/devi-orig/.inkscape: Keine Berechtigung
    ^C
    

  6. Команды, выполненные с привилегиями суперпользователя, выделяются слева красной чертой.
    # id
    uid=0(root) gid=0(root) Gruppen=0(root)
    

  7. Изменения, внесённые в текстовый файл с помощью редактора, запоминаются и показываются в журнале в формате ed. Строки, начинающиеся символом "<", удалены, а строки, начинающиеся символом ">" -- добавлены.
    $ vi ~/.bashrc
    2a3,5
    >    if [ -f /usr/local/etc/bash_completion ]; then
    >         . /usr/local/etc/bash_completion
    >        fi
    

  8. Для того чтобы изменить файл в соответствии с показанными в диффшоте изменениями, можно воспользоваться командой patch. Нужно скопировать изменения, запустить программу patch, указав в качестве её аргумента файл, к которому применяются изменения, и всавить скопированный текст:
    $ patch ~/.bashrc
    В данном случае изменения применяются к файлу ~/.bashrc

  9. Для того чтобы получить краткую справочную информацию о команде, нужно подвести к ней мышь. Во всплывающей подсказке появится краткое описание команды.

    Если справочная информация о команде есть, команда выделяется голубым фоном, например: vi. Если справочная информация отсутствует, команда выделяется розовым фоном, например: notepad.exe. Справочная информация может отсутствовать в том случае, если (1) команда введена неверно; (2) если распознавание команды LiLaLo выполнено неверно; (3) если информация о команде неизвестна LiLaLo. Последнее возможно для редких команд.

  10. Большие, в особенности многострочные, всплывающие подсказки лучше всего показываются браузерами KDE Konqueror, Apple Safari и Microsoft Internet Explorer. В браузерах Mozilla и Firefox они отображаются не полностью, а вместо перевода строки выводится специальный символ.

  11. Время ввода команды, показанное в журнале, соответствует времени начала ввода командной строки, которое равно тому моменту, когда на терминале появилось приглашение интерпретатора

  12. Имя терминала, на котором была введена команда, показано в специальном блоке. Этот блок показывается только в том случае, если терминал текущей команды отличается от терминала предыдущей.

  13. Вывод не интересующих вас в настоящий момент элементов журнала, таких как время, имя терминала и других, можно отключить. Для этого нужно воспользоваться формой управления журналом вверху страницы.

  14. Небольшие комментарии к командам можно вставлять прямо из командной строки. Комментарий вводится прямо в командную строку, после символов #^ или #v. Символы ^ и v показывают направление выбора команды, к которой относится комментарий: ^ - к предыдущей, v - к следующей. Например, если в командной строке было введено:

    $ whoami
    
    user
    
    $ #^ Интересно, кто я?
    
    в журнале это будет выглядеть так:
    $ whoami
    
    user
    
    Интересно, кто я?

  15. Если комментарий содержит несколько строк, его можно вставить в журнал следующим образом:

    $ whoami
    
    user
    
    $ cat > /dev/null #^ Интересно, кто я?
    
    Программа whoami выводит имя пользователя, под которым 
    мы зарегистрировались в системе.
    -
    Она не может ответить на вопрос о нашем назначении 
    в этом мире.
    
    В журнале это будет выглядеть так:
    $ whoami
    user
    
    Интересно, кто я?
    Программа whoami выводит имя пользователя, под которым
    мы зарегистрировались в системе.

    Она не может ответить на вопрос о нашем назначении
    в этом мире.
    Для разделения нескольких абзацев между собой используйте символ "-", один в строке.

  16. Комментарии, не относящиеся непосредственно ни к какой из команд, добавляются точно таким же способом, только вместо симолов #^ или #v нужно использовать символы #=

  17. Содержимое файла может быть показано в журнале. Для этого его нужно вывести с помощью программы cat. Если вывод команды отметить симоволами #!, содержимое файла будет показано в журнале в специально отведённой для этого секции.
  18. Для того чтобы вставить скриншот интересующего вас окна в журнал, нужно воспользоваться командой l3shot. После того как команда вызвана, нужно с помощью мыши выбрать окно, которое должно быть в журнале.
  19. Команды в журнале расположены в хронологическом порядке. Если две команды давались одна за другой, но на разных терминалах, в журнале они будут рядом, даже если они не имеют друг к другу никакого отношения.
    1
        2
    3   
        4
    
    Группы команд, выполненных на разных терминалах, разделяются специальной линией. Под этой линией в правом углу показано имя терминала, на котором выполнялись команды. Для того чтобы посмотреть команды только одного сенса, нужно щёкнуть по этому названию.

О программе

LiLaLo (L3) расшифровывается как Live Lab Log.
Программа разработана для повышения эффективности обучения Unix/Linux-системам.
(c) Игорь Чубин, 2004-2008

$Id$