https://issues.apache.org/SpamAssassin/show_bug.cgi?id=6169

           Summary: whitelist_from_rcvd is fooled by forged rdns
           Product: Spamassassin
           Version: 3.2.5
          Platform: Other
        OS/Version: All
            Status: NEW
          Severity: enhancement
          Priority: P5
         Component: Libraries
        AssignedTo: [email protected]
        ReportedBy: [email protected]


Hi,

whitelist_from_rcvd fails to recognize a forged rnds entry. More precisely the
following entry:

whitelist_from_rcvd *[email protected] localhost

Is matched by this mail:

>From [email protected]  Thu Jul 30 13:49:11 2009
Return-Path: <[email protected]>
X-Spam-Checker-Version: SpamAssassin 3.2.5 (2008-06-10) on alita.karotte.org
X-Spam-Level:
X-Spam-Status: No, score=-77.7 required=5.0 tests=BAYES_60=1,
       
HTML_IMAGE_ONLY_04=2.041,HTML_MESSAGE=0.001,HTML_SHORT_LINK_IMG_1=0.001,
       
MIME_HTML_ONLY=1.457,RAZOR2_CF_RANGE_51_100=0.5,RAZOR2_CF_RANGE_E8_51_100=1.5,
        RAZOR2_CHECK=0.5,RCVD_IN_BL_SPAMCOP_NET=1.96,RCVD_IN_PBL=0.905,
        RCVD_IN_SORBS_WEB=0.619,RCVD_IN_XBL=3.033,SARE_HTML_A_BODY=0.742,
        SARE_HTML_IMG_ONLY=1.666,SPF_FAIL=0.693,TVD_SPACE_RATIO=2.219,
        URIBL_BLACK=1.955,URIBL_JP_SURBL=1.501,USER_IN_WHITELIST=-100
autolearn=no
        bayes=0.7770 version=3.2.5
Received: from alside.com (localhost [220.231.127.15] (may be forged))
        by alita.karotte.org (8.14.3/8.14.3/Debian-5) with SMTP id
n6UBn1BJ021997
        for <[email protected]>; Thu, 30 Jul 2009 13:49:05 +0200
X-DKIM: Sendmail DKIM Filter v2.8.2 alita.karotte.org n6UBn1BJ021997
Date: Thu, 30 Jul 2009 13:49:01 +0200
Message-Id: <[email protected]>
To: <[email protected]>
Subject: Delivery Status Notification
From: <[email protected]>
MIME-Version: 1.0
Importance: High
Content-Type: text/html
Status: RO
Content-Length: 324
Lines: 6

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">

-- 
Configure bugmail: 
https://issues.apache.org/SpamAssassin/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.

Reply via email to