Can be done with brute-force rule creation, EG:
# ISKIMARO 66.55.160.0/19 (12/8/05) SBL11507
header L_RCVD_SPAMMER161 Received =~ /\[66\.55\.1[678]\d\.\d
{1,3}\]/
describe L_RCVD_SPAMMER161 ISKIMARO Spamhaus
score L_RCVD_SPAMMER161 1.5
Bit of a pain to maintain but does work.
I see what you mean David. And your example reminds me of one of my
professional spammer techniques: score Spamhaus entries and then
manually block those spam producing IP entries I agree with.
I just need to let go of my text file 'unified system' mind set and
adopt the modular approach SA prefers. Once configured, several
private dnsbl's will probably be pretty sweet. Its just a whole
other layer of things to learn and configure.
Dan