Nestor Burma wrote:
Look in the recent archives for a thread with the subject "New(?) URL obfuscation technique". There are some rules in there that should help you.Strange thing is that no URIBL rules are triggered. But if we change HTTP to http, or WWW to www (or both), those rules are properly triggered.
Since we are not (yet) SA-rules hackers, where should we look to upgrade locally our rules to detect this simple scheme ?