On 26.04.18 18:00, Nick Edwards wrote:
We've been using a separate product to do this, but it struck me, maybe
spamassassin can do this easier (or without having to call yet another
binary to run as can over mails)

Rules that look at URLs in a html message  href and src tags, check the "A"
tag to see if there is a URL there, and if they do not match,  consider it
a phis so apply said phis score to the message.

Has anyone done this? module even?

On 26/04/2018 18:12, Matus UHLAR - fantomas wrote:
the main problem: may non-spam senders do that, see:

https://wiki.apache.org/spamassassin/AntiPhishFakeUrlRule

and further the discussion in linked bug:

https://bz.apache.org/SpamAssassin/show_bug.cgi?id=4255

On 27.04.18 06:51, Noel Butler wrote:
I suspect Nick is still using and referring to mailscanner (which is/was
written in perl), it has/had this ability, I (like a good few of the
names around here) used it back in the day as well, until it became
clear it was abandonware, and did not like certain newer versions of
perl causing exits after each scan, mind you, I did dump it for amavisd
back around 2008/9/10, that said I liked that function, and rarely
noticed any FP's, my memorys hazy, but IIRC, it disarmed the links,
rather than take any scoring action... I might be wrong though, like I
said, its been along time.

I believe that the same arguments (need for hugt whitelist) could apply for
mailscanner too.

I have noticed discussion about this request/issue many times in this
mailing list, still the same conclusions, so I wanted to point out to
problems rather than telling the OP "go search list archives".

Note that I don't like this kind of mismatches too and I would invite having
such plugin in SA

I would maybe even avoid initial whitelist to force organizations stop using
such mismatched URLs (should be safe with not too high scores).

--
Matus UHLAR - fantomas, uh...@fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
REALITY.SYS corrupted. Press any key to reboot Universe.

Reply via email to