CASG Beta 1, Feedback!

Come on Kirill, release the dragon now! ;D :smiley:
Please!

If its ready, dont you think that the documentation update could be updated after the release?
Just a suggestion. :wink:

Believe me, I completely understand your point :slight_smile:
But as we are serious company ;), the release has strict procedures - confirmation by management, QA and Doc teams, update procedure for Comodo administrators (developers does not have access to live servers due to security reasons) and etc.

So losing in speed we gain in security and stability.

We’ll surely let you know as soon as it is installed.

You are completely right. Sorry. I will keep waiting.

Hello,

CASG its really working with most of the spam.
However, there are only a few messages that are bypassed.

The thing is that almost ALL of these bypassed messages have this headers:

X-Qasd-Class: ham
X-Qasd-Evidence: dnswl
X-Recommended-Action: accept

Im not sure about DNS Whitelisting. Spammers seems to be using DNS that are whitelisted.
Is it possible to turn off this feature. I think the Administrator should have the opportunity in the console to user or not, this DNS Whitelisting.

Hello w-e-v,

As the first step please use report spam feature, this will increase score for that servers and we will work on it.

Thanks for the suggestion, we’ll think about it.

We have been doing it with every SPAM received with DNS whitelisting.
However, even with reporting the email as SPAM, messages are still bypassed.

For example, there is 1 particular organization that keeps sending and ALL the messages are by passed.
I am sending you the HEADER through PM so you can check it out.

DNSWhitelisting is still a problem with CASG.

Take a look at this headers:

Received: from www3.sprit.org ([81.223.238.243] helo=foxyline.net)
	by mxsrv1.spamgateway.comodo.com with esmtp (Exim 4.76)
	(envelope-from <cialis-soft.pills3@xtendnetworks.com>)
	id 1Rr0GX-0000zC-Cn
From: "Cialis-Soft Pills" <cialis-soft.pills3@xtendnetworks.com>
Subject: Hi, get 60% better prices, viz venite
Message-ID: <004b01c4e47f$d4dfce9c$f0205e34@cialis-soft.pills3@xtendnetworks.com>
X-Priority: 3
X-Mailer: ZuckMail [version 1.00]
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="UTF-8"
X-Filter-ID: XtLePq6GTMn8G68F0EmQvZAj7tqJ0ej0C1JWJai+lY4ppluN15d4TOtfR6Z3QhgOCqR44+oZ8bSc
 5uJscc/yMPdjzQ6YC7Heg3Xf7O1TOd7DqXNGcJ5XfHGYbZA9M2aYuwR/UWMu5wKXM6GGn3Svu55Z
 y8/4VEX61TSN7kr9mXViEuOCYulIfmBfDbLxZBKJgPEjmkbQpSGEzqxulF2axE3XBBNcugilHYun
 3t2JQWYJ54DivSe/fN7q8LcX9aVY9R/2gMGq0KWAzmMf+ibVDt8fxbyR70vBesA9RyIUrVTt6JtT
 TglxNZAq/da6Ra+kKR7gDfrbDXBC2L/XEc78USGwv8Y7bD2jWZH7EbL5U/xmSFz9niS3cpwwAzD5
 fQg53LqqfPTsdLzspmKYpVq2QhqRYRKBUIjHUMDP4un6fNYr1HYYVME/IlBa+rD/Odlh214cGr2q
 1ReIj+2hnCQb/d2DF2/nvxSegHUEtQscFkU=
X-Qasd-Class: ham
X-Qasd-Evidence: dnswl
X-Recommended-Action: accept
Return-Path: <cialis-soft.pills3@xtendnetworks.com>
Received: from www3.sprit.org ([81.223.238.243] helo=foxyline.net)
	by mxsrv1.spamgateway.comodo.com with esmtp (Exim 4.76)
	(envelope-from <viagra-pro.store@bmwnbb.com>)
	id 1RrE7o-0002RM-78
From: "Viagra-Pro Store" <viagra-pro.store@bmwnbb.com>
Subject: Notification, Discount 75% on Pfizer, constant grub than
Message-ID: <006e01c43dd0$2cc63045$fedad9c8@viagra-pro.store@bmwnbb.com>
X-Priority: 3
X-Mailer: ZuckMail [version 1.00]
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="UTF-8"
X-Filter-ID: XtLePq6GTMn8G68F0EmQvdokK1GpKSV/8qR1uHKVl52cEh07XnQB841XWa8HA0uyS7X5R1anTuIn
 Gq7k6TFebbt3pV3HuwBRHpSJGJXSOSF42BqosLNlGtqwcNnA2IDFileQqR9q2QUTqb8GuHepIoHV
 9p0QGXxTMA0SC+4EugfGXc/ZdFdb5MTMoZoDebLAZuM7jUXIESohoO51xWmU8Xuj8c1Fd43MQo9h
 nmsjtIoEbE4g7dAvJw216gehW0S9kRQX7tjJgRQR1Ii4cipsda9zUwQ5sM86J2yiG2gvipuCSz4p
 nwdptGEMJaiwpzkz2uWQp9+5DM2dIK0KIzCKRX0QZhC6BArnjKT/72/S3nABIkUL/j1Y48GvmeUR
 QjjEg1KqQirrRmrGcZZzeb1nRyz9VqijfvPCZ4o4AYrZfAFXoNz/OUeAhA0G9nxvmY3RDX69RC0t
 gT0cq+mZhGJ3jIFEtw5YHlwJIsPhsH6IO0g=
X-Qasd-Class: ham
X-Qasd-Evidence: dnswl
X-Recommended-Action: accept
Return-Path: <viagra-pro.store@bmwnbb.com>
Received: from server.creocommunico.com ([72.34.45.194] helo=bearthbaskets.com)
	by mxsrv1.spamgateway.comodo.com with esmtp (Exim 4.76)
	(envelope-from <cialis.store24@ferrotor.com>)
	id 1RrSYJ-0004eU-SP
From: "Cialis Store" <cialis.store24@ferrotor.com>
Subject: Notification, Discount 71% on Pfizer, deux rushlights
Message-ID: <000901c45309$8ed845c9$aa4a7d66@cialis.store24@ferrotor.com>
X-Priority: 3
X-Mailer: ZuckMail [version 1.00]
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="UTF-8"
X-Filter-ID: XtLePq6GTMn8G68F0EmQvX4qN9Els2ZeLZ9WCo+SbeWIORavYFEVhd7VG5im04xjS7X5R1anTuIn
 Gq7k6TFebR8OupqW0VOlIGvQVni4FV+8pwP2ErKAYcc1CFJUXw1B4VyyIUdOUGaLi02dtuRjVBNz
 xCKEbUxov7Y0OBYclesdFyTG2zXb7ZeFrlbUMBRX+hvHtVRnCTrIPuCqFexsjw867shrUGxttOQf
 END4tuoYqG794Ue4w8A9mweVyk7cfqb5R4VemuUI6bcEARsm0L/bTqaDraKzKGkgwW58N3OdIffH
 rne3hlOCMNF7fbxhiKJqPkuG9mdf9NNpos+p87aF9i+jWyMC/dHmnBDm6uqCxurmH7PTykqwsmFJ
 bXSEt1tDxU7fh2+4n1Sek/ppBBt9Oh+de8tXZoGTlofJVcyUCJkkJcqCvjatKrfuvg7B2xqeIWOL
 +jpqvt69Ky0HATXYXYBx6T9gEq71G50CYlLQai5Fxms57gn2kNcPyaTh
X-Qasd-Class: ham
X-Qasd-Evidence: dnswl
X-Recommended-Action: accept
Return-Path: <cialis.store24@ferrotor.com>

The three of them have the header lines:
X-Qasd-Class: ham
X-Qasd-Evidence: dnswl
X-Recommended-Action: accept

The problem is that they are comming from different servers (IPs).
If I report these messages as Spam, it would probably be useless because definitely the next spams to be received are not comming from same servers (IPs). They will come from different IPs.

I definitely consider the best solution is to improve/review the DNS whitelist CASG has.
Or at least allow the administrator to disable this function. I know you said you would consider it, but seeing this case, it makes me think now is an urgency for this new feature/option to be added into CASG console.

DNSWhitelisting is still a problem with CASG.

Some filtering changes where made this week, was the problem resolved?

Also please keep reporting SPAM using UI, it will help us to solve the problems.

Unfortunately, my 120 days trial service for CASG are finished tomorrow.
I removed the MX records and now I am using the usual service.

If you could extend my trial service to keep posting feedback, I would be more than glad to help.

As a last feedback I can give, due to my trial license expiration, I found a serious bug.

I deleted ALL the domains at once, from the AntiSpam Gateway console.
After that, I went to the dashboard again and the console was redirecting me awfully in a loop-less way, to the very first domain installed in the console. Of course that domain didnt exist anymore.

So I would only get an error saying that the domain didnt exist. But I went to the GENERAL DASHBOARD.
The only way to fix it, was to logout and login back again.

Regards,

Hi!
I have some questions for this bug:

  • what browser was used?
  • how many domains were deleted?
  • please, clarify the url you went to when said “After that, I went to the dashboard again”
    As I understand it was Secure Email Gateway Login Page/admin_dashboard/
    am I right?

Hello Anna! :slight_smile:

Mozilla Firefox latest version on a Mac.

All of them at once. They were only 2 domains, as I was using the trial.

You are right, that shouldve been the right URL to be taken to.
But right after the confirmation of deletion, and click on the DASHBOARD BUTTON, I was taken to:
Secure Email Gateway Login Page<customer_name>//admin_domain_desktop

Yesterday we have the CASG v1.2 update, I’ve checked this issue on it and everything is ok.
1.2 version has some navigation fixes, so I think this bug was fixed.

Nevertheless thanks for your reporting!