match rules to base64 encoded body

2018-04-11 Thread saqariden
Hi all, lately i see more and more mails using base64 encoding for the body of the mails. example: --- Date: Thu, 05 Apr 2018 16:22:08 +0200 From: ca...@blaha.net Subject: Marth X-Originating-IP: 179.96.142.37 X-Sender: ca...@blaha.net To: xxx...@xx.com Message-id: <90905a

bypass milter but not the test.

2018-04-04 Thread saqariden
Hello everybody, I'm using spamassassin with mimedefang, i have some custom rulesets, one of those match when i test the positifs mail through "spamassassin -t", but the mail still bypassing the milter. the rule: header FR_SHORT_SPAM_H Subject =~ /((\(|\[)\d{

Re: Custom rule don't match without empty line before the string!

2018-02-23 Thread saqariden
On 22/02/2018 17:48, RW wrote: On Thu, 22 Feb 2018 10:35:48 -0600 (CST) David B Funk wrote: On Thu, 22 Feb 2018, RW wrote: On Thu, 22 Feb 2018 15:54:45 +0100 saqariden wrote: Hello guys, I have the following SA rule which is supposed to block base64 encoded mails: This may be

Custom rule don't match without empty line before the string!

2018-02-22 Thread saqariden
Hello guys, I have the following SA rule which is supposed to block base64 encoded mails: bodyEN_BASE64_B/(Content-Transfer-Encoding: base64\sContent-Type: text\/(plain|html); charset="?utf-8"?)|(Content-Type: text\/(plain|html); charset="?utf-8"?\sContent-Transfer-

spamasssassin vs mimedefang scores

2018-02-22 Thread saqariden
Hello guys, i'm using mimedefang with spamassasin, when I test an email with the command "spamassain -t file.eml", I got results like this: Dails de l'analyse du message: (-5.8 points, 3.0 requis) -5.0 RCVD_IN_DNSWL_HI RBL: Sender listed at http://www.dnswl.org/, high

action_drop_with_warning called outside of filter context

2018-02-21 Thread saqariden
Hello, We are running mimedefang with Spamassassin and Clamav to secure our mailling server. but actually, i have a probleme with mimedefang-filter. the following error appear when a virus is detected: mimedefang.pl[10245]: w1K87JOB027594: Detected virus PUA.Win.Trojan.EmbeddedPDF-1 mimedefang.