Can be done with brute-force rule creation, EG:

  # ISKIMARO 66.55.160.0/19  (12/8/05) SBL11507
header L_RCVD_SPAMMER161 Received =~ /\[66\.55\.1[678]\d\.\d {1,3}\]/
  describe L_RCVD_SPAMMER161   ISKIMARO Spamhaus
  score L_RCVD_SPAMMER161      1.5

Bit of a pain to maintain but does work.

I see what you mean David. And your example reminds me of one of my professional spammer techniques: score Spamhaus entries and then manually block those spam producing IP entries I agree with.

I just need to let go of my text file 'unified system' mind set and adopt the modular approach SA prefers. Once configured, several private dnsbl's will probably be pretty sweet. Its just a whole other layer of things to learn and configure.

Dan

Reply via email to