Am 2009-07-16 17:23:41, schrieb McDonald, Dan:
> Have you tried my rule?

Installed for some minutes...  will see how many it catch.

>  I've caught 401 of them since I updated it this
> morning.  It's also got a little surprise for the next logical
> variant...
> 
> body  __MED_OB        
> /\bw{2,3}(?:[[:punct:][:space:]]{1,5}|[[:space:][:punct:]]{1,3}dot[[:space:][:punct:]]{1,3})[[:alpha:]]{2,6}\d{2,6}(?:[[:punct:][:space:]]{1,5}|[[:space:][:punct:]]{1,3}dot[[:space:][:punct:]]{1,3})(?:c\s?o\s?m|n\s?e\s?t|o\s?r\s?g)\b/i
> body  __MED_NOT_OB    /\bw{2,3}\.[[:alpha:]]{2,6}\d{2,6}\.(?:com|net|
> org)\b/i
> meta  AE_MED44        (__MED_OB && ! __MED_NOT_OB)
> describe      AE_MED44        Shorter rule to catch spam obfuscation
> score AE_MED44        2.0


Thanks, Greetings and nice Day/Evening
    Michelle Konzack
    Systemadministrator
    Tamay Dogan Network
    Debian GNU/Linux Consultant


-- 
Linux-User #280138 with the Linux Counter, http://counter.li.org/
##################### Debian GNU/Linux Consultant #####################
Michelle Konzack   c/o Shared Office KabelBW  ICQ #328449886
+49/177/9351947    Blumenstasse 2             MSN LinuxMichi
+33/6/61925193     77694 Kehl/Germany         IRC #Debian (irc.icq.com)

Attachment: signature.pgp
Description: Digital signature

Reply via email to