Maybe try these:

describe SILLYLONGDOMAINURI  Includes a very long domain name gt 8 levels
uri SILLYLONGDOMAINURI  /^http?\:\/\/([a-z0-9_\-A-Z]+\.){8,}/
score SILLYLONGDOMAINURI  1.8

describe SILLYDOTSDOMAINURI  Includes a multiple dots domain name
body SILLYDOTSDOMAINURI   /^http?\:\/\/([a-z0-9_\-A-Z]+\.)+\./
score SILLYDOTSDOMAINURI 1.8

jp


Quoting Bookworm <[EMAIL PROTECTED]>:

I'm starting to see some new phishing/scam attempts.

What I was thinking was that it might be worthwhile to add a rule to not so much check links, but count periods. Here's the example that just came in my email -

(removing http:// ) - connect.colonialbank.webbizcompany.c6b5r64whf623lx426xq.secureserv.onlineupdatemirror81105.colonial.certificate.update.65tw.com/logon.htm

Notice that there are ten periods. That makes it be an eleventh level domain name? :)

In general, you see fewer than four periods in a domain name - but I've seen this sort of behavior in spams before. Thoughts?

(I'm just a general administrator. I use other people's rules, I haven't had time to learn to make my own)

BW



--
Framework?  I don't need no steenking framework!

----------------------------------------------------------------
@fferent Security Labs: Isolate/Insulate/Innovate http://www.afferentsecurity.com

Reply via email to