Re: catching corrupt base64 emails

2013-03-12 Thread Benny Pedersen
Jason Haar skrev den 2013-03-11 23:19: http://pastebin.com/673Lbh4a its a phish, both have http and https, on my opensuse it try to let me have some exe file for windows xp :) i wonder if we in spamassassin terms should make a tidy test ? ripmime -i spammsg -d . tidy -m textfile0 see the

Re: catching corrupt base64 emails

2013-03-11 Thread Martin Gregorie
On Tue, 2013-03-12 at 11:19 +1300, Jason Haar wrote: > We're seeing a run on our MTAs at the moment. Scores are very low > because the email claims to be base64 encoded HTML, whereas the content > is actually not in base64. So the end user receives this "binary blob" > email that has no value to an

catching corrupt base64 emails

2013-03-11 Thread Jason Haar
We're seeing a run on our MTAs at the moment. Scores are very low because the email claims to be base64 encoded HTML, whereas the content is actually not in base64. So the end user receives this "binary blob" email that has no value to anyone - including the spammer. However, it's cr*p and it's sit