On 2016-08-03 14:13, Robert Boyl wrote:
I have a very nice regex a friend passed me that catches those emails
that have an HTML attached with a redirect html command to some
malefic website.
bravo
He has some tool in Exim that scans text in attachments. But I wanted
to use a spamassassin rule.
clamav ?
google foxhole 3dr party signature, tell clamav-milter to accept virus,
and then in mta stage REJECT official virus, what is left is unofficiel
sigs to be spam handled later
Is there some plugin/way in Spamassassin to scan text of an html
attachment?
yes clamav plugin, its just ram hungry, so take the clamav-milter way
in spamassassin then create rules based on clamav-milter headers
just remember to in mta stage reject virus