Re: Stealth HREF= (missed by SA)

2023-09-14 Thread Pedro David Marco via users
The same happens with other HTML tags... so, with Giovanni permission, i  tighten the nut 1 more turn   (limiting to 100 chars to prevent Regex Self-DOS) rawbody BADHREF /<(a|img|video)[^>]{0,100}\/(src|href)\=/ Pete. On Thursday, September 14, 2023 at 04:37:15 PM GMT+2, wrote:

Re: Stealth HREF= (missed by SA)

2023-09-14 Thread giovanni
On 9/14/23 16:24, Bill Cole wrote: On 2023-09-14 at 04:37:03 UTC-0400 (Thu, 14 Sep 2023 17:37:03 +0900) Joe Wein via users is rumored to have said: I filed a bug for this issue on Bugzilla (#8186) but so far no response from developers. https://bz.apache.org/SpamAssassin/show_bug.cgi?id=8186

Re: Stealth HREF= (missed by SA)

2023-09-14 Thread Bill Cole
On 2023-09-14 at 04:37:03 UTC-0400 (Thu, 14 Sep 2023 17:37:03 +0900) Joe Wein via users is rumored to have said: I filed a bug for this issue on Bugzilla (#8186) but so far no response from developers. https://bz.apache.org/SpamAssassin/show_bug.cgi?id=8186 FWIW, I've thought about it a

Re: Stealth HREF= (missed by SA)

2023-09-14 Thread Benny Pedersen
Joe Wein via users skrev den 2023-09-14 10:37: This means even if the bad site is listed on domain RBLs (SURBL, Spamhaus or URIBL), the mail is not tagged for that. should sa maybe begin using HtmlTidi https://metacpan.org/dist/Perl-Tidy/view/lib/Perl/Tidy.pod i have samples with src=""

Stealth HREF= (missed by SA)

2023-09-14 Thread Joe Wein via users
I filed a bug for this issue on Bugzilla (#8186) but so far no response from developers. https://bz.apache.org/SpamAssassin/show_bug.cgi?id=8186 We're seeing literally millions of phishing spams from Tencent VMs in Singapore targeting mostly Amazon Japan that are getting around SA checks