Re: New plugin: DecodeShortURLs

2011-01-01 Thread Jason Haar
On 01/02/2011 07:52 AM, Michael Scheidell wrote: >> Currently the default used by the LWP module. Could easily set it to >> use an identical string to Firefox or IE. > > and, on occasion, our IPS will tarpit, or delay, or totally block > anything that hits the web servers more than a couple of tim

Re: New plugin: DecodeShortURLs

2011-01-01 Thread Warren Togami Jr.
On Sat, Jan 1, 2011 at 7:19 AM, Steve Freegard wrote: > 7) How fast are typical URL shortening responses? What is the timeout? We > want to avoid degrading the scan time and delivery performance of > spamassassin, but in a way that cannot be abused by the spammer to evade > detection. > > > This

Re: New plugin: DecodeShortURLs

2011-01-01 Thread Michael Scheidell
On 1/1/11 12:19 PM, Steve Freegard wrote: 8) What UserAgent is used in the HTTP request? If they can easily detect that the request is not a real browser, then they can avoid detection by using a safe looking fake response, while browser-based redirects go to the intended spam target. Curren

Re: New plugin: DecodeShortURLs

2011-01-01 Thread Steve Freegard
On 01/01/11 11:51, Warren Togami Jr. wrote: I'll help you start the process with a Bugzilla ticket. I also hope you could get it into some sort of public source control mechanism soon so we can see the changes that go into it before inclusion in upstream. I feel uncomfortable using something

Re: New plugin: DecodeShortURLs

2011-01-01 Thread Steve Freegard
On 01/01/11 12:02, Warren Togami Jr. wrote: http://www.surbl.org/faqs#redirect BTW, this page mentions SpamCopURI and urirhdbl as existing tools that handle redirection to some degree. Have you confirmed that you are not needlessly reinventing the wheel? It is entirely possible that your de

Re: New plugin: DecodeShortURLs

2011-01-01 Thread Warren Togami Jr.
http://www.surbl.org/faqs#redirect BTW, this page mentions SpamCopURI and urirhdbl as existing tools that handle redirection to some degree. Have you confirmed that you are not needlessly reinventing the wheel? It is entirely possible that your design with suggestions here could be better than th

Re: New plugin: DecodeShortURLs

2011-01-01 Thread Warren Togami Jr.
On Fri, Dec 31, 2010 at 11:46 PM, Steve Freegard wrote: > > I notice that there is no Bugzilla ticket for this plugin. Do you intend >> on submitting it for inclusion in future spamassassin upstream? >> >> > > I hadn't really thought about it TBH and wasn't sure what the procedure was > for this

Re: New plugin: DecodeShortURLs

2011-01-01 Thread Steve Freegard
Hi Warren, On 01/01/11 09:17, Warren Togami Jr. wrote: What is the status of this plugin? As far as I'm concerned - I'm actively maintaining it and have been using it in production on several sites; I've been planning to push out an update as I've recently been contributed a massive list o

Re: New plugin: DecodeShortURLs

2011-01-01 Thread Warren Togami Jr.
What is the status of this plugin? I notice that there is no Bugzilla ticket for this plugin. Do you intend on submitting it for inclusion in future spamassassin upstream? Would a DoS happen if the scanned e-mail contains 10,000 short URL's, and your mail server is hit by many such mail? (Eithe