Change Log
The page below describes the changes in ORF Enterprise Edition since its first release.
| version |
4.3 |
| Release date: 15/06/2009 09:25 CET |
-
ADDED: DHA Protection Test
A new test in ORF that can help to detect and stop Directory Harvest Attacks (DHAs).
-
ADDED: Honeypot test
Allows setting up honeypot (spamtrap) addresses and ban senders that attempt to send to these addresses.
-
ADDED: Restartless configuration changes
ORF can now reinitialize with the new configuration without restarting the ORF Service, so you can enjoy uninterrupted email filtering.
-
IMPROVED: Remote control
The Remote Control feature which allows sending IP and email addresses from the ORF Log Viewer to various ORF lists has been improved. It no longer requires a running ORF Administration Tool, more target lists are supported and multiple items can be sent at once.
-
ADDED: Whitelist Test Exception for the SPF Test
The SPF Test was added to the Whitelist Test Exceptions (disabled by default) so now you can validate the authenticity of the sender email address before the Auto Sender Whitelist or Sender Whitelist would run. This prevents forged emails from getting whitelisted.
-
IMPROVED: Live Statistics
The live statistics of ORF was redesigned to include a stopwatch functionality and got a few new counters.
-
ADDED: Blacklisting on SPF Neutral
For specific (user-configurable) domains, blacklisting on SPF Neutral result is now available.
-
ADDED: Option to Skip Greylisting on SPF Pass
Allows skipping the Greylisting test if the SPF Test says the sender is explicitly authorized to send in the name of a domain (enabled by default).
-
ADDED: DNS Blacklist definition updates
- ADDED: Barracuda Reputation Block List
- ADDED: UCEPROTECT-Network Level 1
- ADDED: Unsubscribe Blacklist (UBL) Resources
- ADDED: SpamRats! Dyna List
- ADDED: SpamRats! NoPtr List
- ADDED: SpamRats! Spam List
- ADDED: SpamRats! Combined List
- REMOVED: All Spamhaus lists but Spamhaus ZEN
- REMOVED: Blackholes.us lists
- REMOVED: Spambag.org
- REMOVED: Distributed Sender Boycott List (DSBL)
-
ADDED: Minor improvements and minor bugfixes
|
| version |
4.2 |
| Release date: 08/07/2008 07:32 CET |
-
ADDED: "Real" Reverse DNS Test
This new subtest of the Reverse DNS Test checks if the sending IP has reverse name (DNS PTR record).
Blacklisting the resolved host names is also supported.
-
ADDED: Keyword Whitelist
A new On Arrival-only test for whitelisting emails with specific keywords or patterns
in the email body, subject or header.
-
ADDED: Charset Blacklist
Another On Arrival-only test, for blacklisting emails written in specific languages/scripts.
-
ADDED: Compatible with Microsoft® Exchange 2007 on Windows Server 2008
Version 4.2 now supports the Windows Server 2008 platform, when running with
Microsoft® Exchange 2007. Note that the IIS SMTP-only mode is not supported on this
platform, Exchange 2007 is required.
-
ADDED: SPF Exceptions
Allows excluding specific senders from the SPF test by the sender email address or the
source IP address.
-
ADDED: Auto Sender Whitelist Sender Exceptions
This feature can be used to quickly un-whitelist accidentally whitelisted senders, without editing
the Auto Sender Whitelist database.
-
ADDED: ORF Text Log Retention Control
Allows automatic deletion of the ORF Text Log files after a user-defined number of days. This
feature is disabled by default.
-
ADDED: Optional HELO/EHLO Logging
When this option is enabled, the SMTP HELO/EHLO argument domain is added to the ORF logs as a
separate column, helping the creation of HELO Blacklist expressions. This feature is disabled by default.
-
ADDED: Minor improvements
- Integrated Configuration Export/Import Guide: Instructions on exporting and importing the entire ORF configuration are now available from the ORF Administration Tool menu.
- The ORF Administration Tool now remembers the last open page.
- The ORF Log Viewer can start the ORF Administration Tool when sending to blacklists/whitelists.
- The Uninstaller now asks if data and configuration files should be left on the system.
- Minor bugfixes.
|
| version |
4.1 |
| Release date: 27/03/2008 11:05 CET |
- ADDED: Microsoft® Exchange 2007 Support
ORF 4.1 now can be installed on Exchange 2007 Servers (Edge Transport or Hub Transport).
- ADDED: Email Header Filtering
The Keyword Filtering feature was extended with the ability to filter for keywords in the email header.
- BUGFIX: ORF Does Not Filter Mails with Blank HELO
ORF logged a warning message and did not filter emails that arrived with a blank HELO/EHLO domain argument.
- BUGFIX: Connection Is Not Tarpitted At Before Arrival Under Specific Conditions
Tarpit Delay was not triggered (irrespectively of the mode it was switched to) at the Before Arrival
filtering point in case the Recipient Validation Test was excluded from the whitelists' scope (Whitelist
Test Exceptions).
|
| version |
4.0.4 |
| Release date: 11/09/2007 10:12 CET |
- ADDED: Recipient Validation Test
This new test takes over the role of the Active Directory test and allows
you to validate recipients using the Active Directory and two new sources:
SQL databases and text files.
- IMPROVED: ORF Log Viewer Log File Handling
The Log Viewer now supports viewing user-selected log files in addition
to the automatic log file loading.
- BUGFIX: Memory Leak in the ORF SMTP Module
The ORF SMTP Module was leaking a specific amount of memory on every email
that reached the On Arrival filtering point. The potential impacts of the
leak were IIS crashes and out of memory errors. This bug primarly affected
servers with very high email load.
- REMOVED: Active Directory test "Synchronization Mode"
|
| version |
4.0.3 |
| Release date: 16/08/2007 13:20 CET |
- BUGFIX: Before Arrival Delivery Problems Under Specific Circumstances
Valid recipients did not get the email when all of the following
conditions were satisfied at once:
- The email had multiple recipients
- At least one recipient was rejected at Before Arrival
- BUGFIX: Log Viewer Time Filter Problems
The "Time" filter could not be set higher than 12:59:59 (after(...date/time),
before(...date/time), between(...date/time) modes). Events that occurred after
12:59:59 could not be filtered by the "Time" filter.
- BUGFIX: Log Viewer IP Address Filter May Return an Error
Under Windows 2003 Server, the Log Viewer returned a "List index out of bounds"
error when an IP filter with either CIDR notation (e.g. 1.2.3.0/24) or text range
notation (e.g. 1.2.3.4-1.2.3.255) was applied to the "Related IP address" field.
|
| version |
4.0.2 |
| Release date: 08/08/2007 12:42 CET |
- BUGFIX: Delivery Problems Under Specific Conditions
Valid recipients did not get the email when all of the following
conditions were satisfied at once:
- Active Directory Test was enabled at the On Arrival filtering point
- The email had multiple recipients (valid and invalid ones)
- The recipient list of the mail began with an invalid address (which is not listed in the Active Directory)
- BUGFIX: Log Viewer: Saved Email Subject Filtering Expression Changes Randomly
Previously saved Log Viewer email subject filtering expressions
could have changed unexpectedly when modified.
- BUGFIX: Saved Log Viewer Filter Cannot Be Deleted Under Specific Conditions
Previously saved filter in the Log Viewer could not be deleted if the view
was switched to "All" mode.
|
| version |
4.0.1 |
| Release date: 18/07/2007 13:15 CET |
- BUGFIX: Incorrect SMTP Module Status Displayed
A bug in the ORF SMTP Module caused the SMTP Module status displayed
for one or more of the SMTP Virtual Server as "not loaded/inactive"
when multiple SMTP Virtual Servers were present, even when the SMTP
Module was loaded and active.
- BUGFIX: IP List CSV Export is Broken
The ORF Administration Tool IP list (IP Blacklist, IP Whitelist)
CSV format exports were broken in version 4.0 and thus could not
be imported. Exporting/importing in TXT format and importing from
earlier version CSV exports worked, however.
- BUGFIX: Email Loss When Whitelisting Under Specific Circumstances
Whitelisted recipients did not get the email when all of the following
conditions were satisfied at once:
- The email had multiple recipients at the On Arrival filtering point
- Some, but not all of the email recipients were whitelisted
- The email was not blacklisted
- BUGFIX: Some External Agents Do Not Run Under Specific Conditions
When External Agents whitelist test exceptions were enabled and
there were enabled External Agents with both Anti-Virus and Spam
Filter role, agents with Spam Filter role were not ran by ORF.
|
| version |
4.0 |
| Release date: 10/07/2007 10:35 CET |
- IMPROVED: Combined Actions
The new version can tag and redirect the email at
the same time at the On Arrival filtering point.
- ADDED: Whitelist Test Exceptions
This feature allows some blacklist tests to take precedence
over whitelists (Attachment Filtering, External Agents,
Active Directory Integration and the Recipient Blacklist),
which provides better email security.
- ADDED: External Databases
Allows using Microsoft® SQL Server® databases
for storing the Auto Sender Whitelist and Greylisting data.
- ADDED: Email Subject Logging
The subject of the incoming email is now logged at
the On Arrival filtering point.
- ADDED: 64-bit Windows Support
ORF 4.0 can be used on 64-bit Windows Server editions.
- ADDED: Auto Sender Whitelist Automatic Response Detection
This new feature prevents automatic responses (e.g. Out of Office autoresponses)
from polluting your Auto Sender Whitelist.
- ADDED: Greylisting /24 Support
Now Greylisting can be configured to accept delivery re-attempts
from the same /24 network block. This reduces the email delay
from senders with a pool of outgoing email servers.
- ADDED: Automatic Update Check
This feature periodically checks for a new ORF
version and tells you if there is any available.
- IMPROVED: Log Filtering and Search
The filtering feature of the ORF Log Viewer was completely
redesigned to allow creating more flexible filters. The Search
functionality is no longer column-specific (free text search).
- IMPROVED: More flexible IP Address Definitions
In the new version, IP network definitions can be entered in various formats,
including text range and CIDR notation.
- IMPROVED: PowerLog Preprocessing Speed
ORF 4.0 preprocesses the PowerLog files about 75 times faster
than the previous 3.0 version.
- BUGFIX: PowerLog Files May Get Deleted
A bug in ORF caused the ORF PowerLog file under preprocessing
to be deleted on the specific conditions (affected versions:
3.0 and 3.0.1).
- BUGFIX: Legitimate Emails Tarpitted on Specific Conditions
ORF applied the tarpit delay on any non-whitelisted email
on specific conditions (affected versions: 3.0 and 3.0.1).
- BUGFIX: External Agent Exit Code Enabled State Cannot Be Changed
A bug in ORF prevented persisting the changes made to the enabled
state of the External Agent exit codes (affected versions:
2.1, 3.0 and 3.0.1).
|
| version |
3.0.2 |
| Release date: 08/08/2007 14:18 CET |
|
|
| version |
3.0.1 |
| Release date: 18/07/2006 11:15 CET |
|
|
| version |
3.0 |
| Release date: 11/07/2006 08:15 CET |
|
|
| version |
2.1 |
| Release date: 05/09/2005 10:13 CET |
- ADDED: SPF support
The new version supports using the Sender Policy Framework (SPF),
which is an email authentication protocol for recognizing email
address forgery. As most of the spam arrives with forged sender
address, SPF can do a great job in reducing spam.
- ADDED: External Agents
Allows attaching various external software, such as anti-virus
or anti-spam products to ORF. Depending on the agents used, it
can boost ORF's spam filtering performance significantly or act
as another layer of defense against viruses. You can download
agent definitions for a few software from our website or define
your own.
- ADDED: HELO domain blacklist
A new feature which helps to detect poorly written spammer
software and malicious content based on the HELO/EHLO domain.
- Minor improvements
- URL Domain Blacklist: Version 2.1 allows defining domain
exceptions which are not checked by the URL Domain Blacklist.
- Tarpit Delay: ORF delays maximum 10 connections
concurrently to avoid eating up IIS resources.
|
| version |
2.0.2 |
| Release date: 26/05/2005. 12:30 CET |
- BUGFIX: Database problems
This version is shipped with an updated version of the database
engine used by ORF. The update fixes the problems which may lead
to corruption of the Greylisting or the Automatic Sender Whitelist
databases. The symptoms of the database corruption were occasional
database error messages logged by ORF and, in rare cases, 100%
processor use for a long period (more than a minute) on a large
number of outgoing emails (e.g. newsletters).
- BUGFIX: IP Whitelist ignored in Short log mode
A bug in ORF caused the IP Whitelist to be ignored at the
Before Arrival filtering point when the ORF log was in
"Short Log Messages" mode.
- IMPROVED: Automatic Sender Whitelist performance
We improved the performance of the Automatic Sender Whitelist
performance, the new version processes outgoing email significantly
faster and uses less resources than the previous version.
|
| version |
2.0.1 |
| Release date: 12/04/2005. 16:30 CET |
|
|
| version |
2.0 |
| Release date: 29/03/2005 11:32 CET |
- ADDED: Support for SURBL's (URL Blacklist Support)
SURBL's are very similar to DNS blacklist, except that they list
domain names instead of spam IP sources. ORF 2.0 can collect links
to "spamvertized" sites from the scanned email and check the
linked domains in the SURBL's.
- ADDED: Greylisting
Anti-spam feature based on temporary rejection of emails from
unknown senders. While greylisting provides outstanding spam stop
rate, it causes about 15 minutes delay of emails from unknown senders
as well. Moreover, it works at the Before Arrival filtering point only.
- ADDED: Automatic Sender Whitelist
A self-learning whitelist which monitors your outgoing emails and
builds a sender email address whitelist from the recipients of the
outgoing emails. In other words, the recipients of the emails that
you send become whitelisted senders.
- ADDED: Tarpit Delay
Delays your server's response to blacklisted mails. Can be used
to slow down/stop Directory Harvest Attacks or to fight back to spammers.
- Several minor improvements
- Completely rewritten DNS cache with persistent cache data store
- DNS TCP fallback option
- Updated DNS client in ORF
- Improved email wildcard mask support, now both the * and the ? wildcards are supported
- Attachment filter wildcard support (* and ? wildcards are now supported)
- Configurable SMTP response for the On Arrival email drop action
- Configurable SMTP response for the attachment filter drop action
- ORF Log Viewer: "Remote Control"—add addresses to the ORF sender and IP lists by one click
- ORF Log Viewer: "Quick Filters"—easier filter selection
- ORF Log Viewer: "Preview Panel"—easier viewing of long log column data
- ORF Log Viewer: Customizable color-coding of event records based on the event severity
- ORF Log Viewer: Filters are now listed in alphabetical order
- ORF Admin Tool: Sorting improvements, now you can sort virtually every list of ORF by any column
- ORF Admin Tool: SMA expiration reminder
- ORF Admin Tool: DNS Test to check the health of your DNS servers
|
| version |
1.5.2 |
| Release date: 01/12/2004 11:24 CET |
|
|
| version |
1.5.1 |
| Release date: 16/07/2004 12:10 CET |
- ADDED: Active Directory integration "Live Mode"
The new AD integration mode allows validating the recipient
"live", without extracting all addresses from the Active
Directory (synchronization). The Live Mode is more
resource-friendly and faster than the previous Synchronization
mode when working with large directories. The performance of
the Synchronization mode (pre-1.5.1 AD integration) was also improved.
- BUGFIX: Memory leak in the ORF SMTP Module
A bug in the ORF 1.5 SMTP Module resulted in a 20-byte memory
leak per email at the On Arrival filtering point. This has caused
out of memory errors in ORF and IIS crashes.
This bug has been fixed by version 1.5.1.
|
| version |
1.5 |
| Release date: 11/06/2004 10:55 CET |
- ADDED: Dual filtering points model
Previous ORF versions filtered the emails before email arrival.
Now with 1.5 you can filter emails on arrival, which allows
delivery path analysis, keyword and attachment filtering, etc.
- ADDED: Attachment and keyword filtering
Using the attachment filter you can drop emails with malicious
attachments or replace the attachments with a customisable
warning text. Both the keyword and the attachment filtering
support using Perl-compatible regular expressions, which makes
the filtering extremely flexible. Both features are Unicode-aware.
- ADDED: Reviewing emails caught by the filter
Emails blacklisted at the On Arrival filtering point can be dropped,
redirected or tagged (header or subject).
- ADDED: ORF Log Viewer
ORF is now shipped with a built-in log viewer which allows easy
browsing, searching and filtering the logs.
- ADDED: DNS blacklist updates
The default DNS blacklist definition set (blacklists.xml)
has been updated.
|
| version |
1.4 |
| Release date: 19/09/2003 13:10 CET |
|
|
| version |
1.3 |
| Release date: 21/08/2003 13:15 CET |
- ADDED: Exception list for the Active Directory integration
Using the new exception list, you can exclude specific email
addresses or domains from the Active Directory-based recipient
filtering. This comes handy if you provide filtered mail
services for domains that are not listed in your directory.
- ADDED: AD integration user authentication support
User authentication may be required for the AD integration
if ORF is running on a computer which is not a member of
the domain. ORF now supports specifying a user name and
password for LDAP authentication.
- ADDED: Whitelisting authenticated sessions now can be disabled
- ADDED: Authenticated user name in the log
For easier tracking of authenticated sessions, version 1.3
logs the authenticated user name with the whitelist event message.
- ADDED: Customizable RDNS SMTP response
- ADDED: Minor improvements
- BUGFIX: Cannot start syslogd when ORF Service is up
You could not start the syslog daemon on the syslog UDP port
while ORF was running, if you had ORF syslogd logging enabled.
This was caused by an unclosed socket has which allocated the
syslog UDP port so the syslog daemon was unable to start
listening to syslog messages. This issue occurred only when both
ORF and the syslog daemon was running on the same computer.
- ADDED: DNS blacklist updates
- Removed: DORKSZTL and DORKS (dead blacklists)
- Removed: MONKEYFORMMAIL (no hits, seemingly dead)
- Removed: BLITZEDHTTP, BLITZEDWINGATE, BLITZEDSOCKS (these zones are no longer up)
- Added: CBL, LBL, REYNOLDST1, UCEB
- Update: Four new zones added to FIVETEN, BLITZED also updated
- Update: MONKEYPROXIES has been renamed to MONKEYUPL (zone remains the same)
|
| version |
1.2.1 |
| Release date: 18/07/2003 12:30 CET |
|
|
| version |
1.2 |
| Release date: 08/07/2003 14:55 CET |
- ADDED: Seamless update
Until version 1.2, you had to manually stop and restart
Exchange services during an ORF update. The new Update
Setup shipped with ORF version 1.2 can automatically
stop and restart the Exchange services and transfer
your previous ORF settings to the updated version.
- ADDED: Active Directory integration
Unlike other mail servers, Exchange 2000 does not
reject mails coming to mailboxes that does not exist.
Exchange 2000 accepts the mail for delivery and bounces
the email later if the recipient mailbox is unavailable.
Spam is often sent with fake sender email address that
does not exist to recipients that are no longer valid,
which results in tons of NDR's filling up the mail queue.
Using the ORF's Active Directory integration you can reject
all mails that are addressed to mailboxes that are
no longer (or never been) valid and accept mails only
to mailboxes that exists in the Active Directory.
- ADDED: Built-in Bonded Sende™ Program DNS whitelist support
IronPort Systems Inc's
Bonded Sender™ Program provides a public DNS whitelist,
which is now supported by ORF 1.2.
More information about this program is available at
http://www.bondedsender.com.
- ADDED: Better ORF community support
Do you find it confusing to select the best DNS blacklists?
Now ORF can automatically send your ORF statistics anonymously
to our server in email. The server collects these statistics
and displays DNS blacklist popularity and statistics on our website.
- ADDED: Commentable list items
The new version supports commenting IP/sender/recipient
whitelist and blacklist items which makes managing and
exchanging these lists easier.
- ADDED: Regular expressions
Using regular expressions you can create complex email
address masks. ORF 1.2 supports the Perl-compatible
regular expressions (PCRE, for more information, please see
http://www.pcre.org).
This feature is available for the sender whitelist,
sender blacklist, recipient whitelist and recipient blacklists.
- ADDED: Windows Event Log and BSD syslog support
Version 1.2 extends logging capabilities with Windows
Event Log and BSD syslog support.
- ADDED: Automatic whitelisting of authenticated SMTP connections
Authenticated SMTP connections are now recognized
and automatically whitelisted by the new version.
- BUGFIX: Sender email address is not logged under specific conditions
ORF did not log the sender email address when a recipient blacklist
hit occurred and the log was configured to produce short log messages.
- BUGFIX: Cumulative statistics not saved on system reboot/shutdown
ORF failed to save the cumulative statistics to the statistics
storage file (orfestat.dat) on system reboot or shutdown.
Consequently, statistics generated since last ORF Enterprise Service
startup got lost.
|
| version |
1.1.1 |
| Release date: 14/01/2003 16:20 CET |
- BUGFIX: Reverse DNS test fails when MX is missing but A/CNAME exists
The reverse DNS test with "MX or A/CNAME" test mode did not
test A/CNAME records due to a software bug. This bug caused
the software to work as the reverse DNS test running with
"MX" (strict check) mode and to provide wrong information
to the remote SMTP server on the reason for the block.
- BUGFIX: Incorrect reverse DNS statistics
Reverse DNS statistics were displayed incorrectly.
The "Tests" value was equal to the "Blocks" value.
- ADDED: Log level recorded in the log
This feature makes writing log parsers easier.
|
| version |
1.1 |
| Release date: 10/01/2003 15:10 CET |
- ADDED: Support for multiple DNS servers
In version 1.1, you can define multiple
(fail-over) DNS servers with priorities.
- ADDED: Cumulative statistics
Using the new cumulative statistics feature you can view the
statistics of ORF since the installation not just since the
last start up. You can also take a snapshot of the current
run-time statistics and export the snapshot to various file
formats (including CSV, which can be imported by
Microsoft® Excel®). The statistics are resetable.
- ADDED: Reverse DNS test with MX or A/CNAME records
The 1.0 version reverse DNS test was very strict.
Version 1.1 offers you a more lenient check.
This helps in reducing the number of legitimate mails blocked.
- ADDED: Address list export/import
Exporting and importing address lists (IP, sender, recipient
whitelists and blacklists) is now available. Multiple text
formats supported, including CSV which can be imported
by Microsoft® Excel®.
- ADDED: Blocking broken sender domains
ORFEE 1.1 can block mail with broken sender domain
information (i.e. sender domain is not a fully qualified
domain name - FQDN).
- ADDED: Temporary rejection of mail due to DNS errors
You can configure ORF to reject mail temporarily when
it cannot be tested due to DNS errors. Using this
option you can avoid accepting mail when the filtering
is not available due to unavailable DNS data.
- ADDED: Several minor improvements
- All address lists (IP, sender and recipient whitelists
and blacklists) can be sorted in ascending or descending order with one click
- You can set the order of listed items using the drag&drop method (where applicable)
- Sending test notification mail is now available from the Events page
- Default values are automatically assigned to various SMTP responses
- You can configure ORF to add the local server name to the log in a separate column
- {HOUR} field has been added to the available log file name fields
- You can control line wrapping in the notification mail
- The sender address now also occurs in the log when a mail is blocked
due to the fact that they were listed on the recipient blacklist
- CTRL-SPACE displays the directory browser dialog in path edit boxes
- DNS blacklist definitions have been updated
- BUGFIX: RDNS test may fail with specially formatted addresses
The reverse DNS test did not handle some specially
formatted sender addresses correctly such as formats
"mailbox@[1.2.3.4]", "mailbox@1.2.3.4". This syntax is
allowed by RFC standards, but used rarely on the Internet.
ORF did not recognize that the sender domain is actually
an IPv4 address and blocked the mail (because it failed
on RDNS test).
- BUGFIX: Sender blacklist hits are not logged
Mail blocked due to being listed on the sender
blacklist were not logged by ORF Enterprise.
- BUGFIX: Some controls may not appear with Large Fonts setting
If your display was set to Large Fonts mode,
you have experienced that some controls in
the ORF Administration Tool were not visible on the screen.
|