#
#   Vispan - VIrus and SPam ANalyser
#	This program analyses the mail log file entries created by the 
#	MailScanner program written by Julian Field. It is available at
#	http://www.mailscanner.info
#
#   Copyright (C) 2002  David While
#
#   $Id: README,v 1.5 2004/09/28 12:07:52 dwhile Exp $
#
#   This program is free software; you can redistribute it and/or modify
#   it under the terms of the GNU General Public License as published by
#   the Free Software Foundation; either version 2 of the License, or
#   (at your option) any later version.
#
#   This program is distributed in the hope that it will be useful,
#   but WITHOUT ANY WARRANTY; without even the implied warranty of
#   MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
#   GNU General Public License for more details.
#
#   You should have received a copy of the GNU General Public License
#   along with this program; if not, write to the Free Software
#   Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA  02111-1307  USA
#
#   The author, David While, can be contacted by email at
#      david.while@uce.ac.uk
#   or by paper mail at
#      David While
#      School of Computing
#      University of Central England
#      Birmingham
#      B42 2SU
#      United Kingdom
#


Description

Vispan is a PERL script which analyses the mail log file to produce useful statistics. It requires MailScanner to provide the necessary log file entries. At the moment the virus list is dependent on the virus scanner you have installed.

In order to detect the spam correctly it is strongly recommended to use SpamAssassin with MailScanner

The script can also use heuristics in the senders of the spam emails and can then automatically add them to the sendmail access file which will cause further mails to be rejected. After a definable period of time they will be removed from the access file and once again allowed to send mail to you.

I believe that this is superior to the RBLs that are maintained since you have control over them and it is specific to the behaviour of your particular mail server

To INSTALL:

	tar xvzf Vispan-X.tar.gz   (X = release number)
	cd Vispan-1.X
	perl Makefile.PL
	make install


The /etc/Vispan.conf file contains configuration information which you should change to suite your requirements as follows:

UseAccess
	Set to 1 to use the access file in sendmail set to 0 to avoid it
UseHeuristics
	Set to 1 to use the heuristics system. Set to 0 to just produce a list of IP addresses that have sent spam - this might get pretty large!
HighScore
	Set this to the value you use for your High Spam Score in MailScanner.conf
AccessList
	Path to the access file - only used if UseAccess is set to 1
MakeMap
	The location of the makemap command - needed to rebuild the access file for sendmail
LogFile
	The location of your mail log file
tmpfile
	The location of the temporary file that is created
WorkDir
	The directory that you want to use to keep the working files in.
HTMLDir
	The directory to hold the output HTML code (and MRTG code if you are using it
header
	The location of a header file that can be used to provide HTML to be added before the generated HTML
Logo
	A logo to be included on the output page.
footer
	Similar to the header but added after the generated HTML.
StyleSheet
	If you use a style sheet you can specify it here - it should be relative
PageTitle
	The title to appear on the page
BlockTime
	The amount of time that the sender should stay in the access block list. Specified in hours
Scanner
	The virus scanning software you are using. Currently can be one of inoculan , clamav, sophos, sophosSAVI, command, f-prot, mcafee, f-secure, rav, mailscanner, filename, filetype.
WhiteList
	An array containing the IP addresses of servers that should not be added to the access file.
Queue_Dirs
	A space separated list of the full paths of any extra mail queue dirs. 
Spam_Reject_Text
	The text placed after the IP address in the access file. This is sent to the sending MTA when mail is rejected.
Virus_Reject_Text
	The text paced after the IP address in the access file.
DisplayTop
	A number to indicate that the program should only display the top n in the country list and the SpamAssassin trap report.
ServersToLookAt
	A list of servers to report for - useful if you log to one central server
AccessNotify
	Do you want an email each time an IP address is added to the access file.
NotifyToAddress
	The address to send the email to
NotifyFromAddress
	The address the email comes from
NotifySubject
	The subject of the email
SMTPServer
	The SMTP server to use to send the email
NumSpams
	The number of spam emails to allow from a host in a 24 hour period
NumViruses
	The number of virus emails to allow from a host in a 24 hour period.
Debug
	Set to 1 to print Debugging messages
