Karsten Bräckelmann wrote:
On Tue, 2008-09-09 at 22:59 +0200, mouss wrote:
Lars Ebeling wrote:
Got this after sending message earlier to this list. Could someone here
explain it?
explain what?
Oh, come on, mouss, had a bad day? :)
didn't eat enough headers (or too much?) ;-p
sorry.
- stop posting html to the list
- avoid posting spammy content. instead, use your web server and post
the URL here.
What's got HTML to do with that? It's a lousy, braindead bare-word
scanner, run by (or in front of) a subscriber to this list. It's known,
and has been discussed before. (Too lazy to dig out the previous
thread.)
In Lars' case, Antigen triggered on the mere occurrence of the word
'porn'. I bet it recursively triggered on his subsequent forwarding to
this list, too, which effectively resulted in this very thread. :)
Ah! that was that. but he has an SA in the path that fired the
PORN_URL_MISC rule (because of 20_porn.cf??). so the word appears twice.
Just like that Antigen will trigger on this mail, because I mentioned
the bad, bad word 'porn'. It will bounce this messages as well.
let's see.
even your server (apparently) said: PORN_URL_MISC.
Where did you get that from?
The post that supposedly generated the backscatter contains:
X-Old-Spam-Status: No, score=-0.4 required=5.0
tests=ALL_TRUSTED,AWL,BAYES_00,
HTML_MESSAGE,PORN_URL_MISC autolearn=ham version=3.1.0