Nestor Burma wrote:

Strange thing is that no URIBL rules are triggered.
But if we change HTTP to http, or WWW to www (or
both), those rules are properly triggered.

Since we are not (yet) SA-rules hackers, where should
we look to upgrade locally our rules to detect this
simple scheme ?



Look in the recent archives for a thread with the subject "New(?) URL obfuscation technique". There are some rules in there that should help you.



Reply via email to