spamassassin-commits mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From hst...@apache.org
Subject svn commit: r556893 - /spamassassin/trunk/rules/20_dynrdns.cf
Date Tue, 17 Jul 2007 11:55:56 GMT
Author: hstern
Date: Tue Jul 17 04:55:51 2007
New Revision: 556893

URL: http://svn.apache.org/viewvc?view=rev&rev=556893
Log:
Fixed broken regexes requiring auth= to immediately proceed rdns= fields.
Wrong as per unwritten spec. ;)

Closes bug 5563.


Modified:
    spamassassin/trunk/rules/20_dynrdns.cf

Modified: spamassassin/trunk/rules/20_dynrdns.cf
URL: http://svn.apache.org/viewvc/spamassassin/trunk/rules/20_dynrdns.cf?view=diff&rev=556893&r1=556892&r2=556893
==============================================================================
--- spamassassin/trunk/rules/20_dynrdns.cf (original)
+++ spamassassin/trunk/rules/20_dynrdns.cf Tue Jul 17 04:55:51 2007
@@ -33,6 +33,11 @@
 # connecting to a trusted relay; if a mail came from a dynamic addr but
 # was relayed through their smarthost, that's fine.
 
+# All of the RDNS_DYNAMIC rules require that the last untrusted relay
+# did not use SMTP authentication.  These rules should not be firing on
+# friendlies!
+header __LAST_UNTRUSTED_RELAY_NO_AUTH X-Spam-Relays-Untrusted =~ /^[^\]]+ auth= /
+
 # dhcp024-210-034-053.columbus.rr.com [24.210.34.53]
 # c-66-176-16-108.se.client2.attbi.com [66.176.16.108]
 # c-67-168-174-61.client.comcast.net [67.168.174.61]
@@ -52,8 +57,9 @@
 # d53-64-35-171.nap.wideopenwest.com [64.53.171.35]
 # 74.67-201-80.adsl.skynet.be [80.201.67.74]
 # 12-218-225-223.client.mchsi.com [12.218.225.223]
+# pptp-81-30-186-139.ufanet.ru [81.30.186.139]
 # (require an alpha first, as legit HELO'ing-as-IP-address is hit otherwise)
-header __RDNS_DYNAMIC_IPADDR X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=[a-z]\S*\d+[^\d\s]\d+[^\d\s]\d+[^\d\s]\d+[^\d\s][^\.]*\.\S+\.\S+[^\]]+
auth= /i
+header __RDNS_DYNAMIC_IPADDR X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=[a-z]\S*\d+[^\d\s]\d+[^\d\s]\d+[^\d\s]\d+[^\d\s][^\.]*\.\S+\.\S+/i
 describe __RDNS_DYNAMIC_IPADDR Relay HELO'd using suspicious hostname (IP addr 1)
 
 # dhcp024-210-034-053.columbus.rr.com [24.210.34.53]
@@ -61,21 +67,21 @@
 # node-c-8b22.a2000.nl
 # cm89.omega139.maxonline.com.sg
 # cm114.gamma208.maxonline.com.sg
-header __RDNS_DYNAMIC_DHCP X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=\S*(?:cm|catv|docsis|cable|dsl|dhcp|cpe|node)\S*\d+[^\d\s]+\d+[^\]]+
auth= /i
+header __RDNS_DYNAMIC_DHCP X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=\S*(?:cm|catv|docsis|cable|dsl|dhcp|cpe|node)\S*\d+[^\d\s]+\d+/i
 describe __RDNS_DYNAMIC_DHCP Relay HELO'd using suspicious hostname (DHCP)
 
 # fia83-8.dsl.hccnet.nl [62.251.8.83]
 # fia160-115-100.dsl.hccnet.nl [80.100.115.160]
-header __RDNS_DYNAMIC_HCC   X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=\S*\d+[^\d\s]+\d+\S*\.(?:docsis|cable|dsl|adsl|dhcp|cpe)\.[^\]]+
auth= /i
+header __RDNS_DYNAMIC_HCC   X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=\S*\d+[^\d\s]+\d+\S*\.(?:docsis|cable|dsl|adsl|dhcp|cpe)\./i
 describe __RDNS_DYNAMIC_HCC Relay HELO'd using suspicious hostname (HCC)
 
 # h0002a5d76857.ne.client2.attbi.com [65.96.12.59]
-header __RDNS_DYNAMIC_ATTBI  X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=\S+\d+\S+\.client2\.attbi\.com[^\]]+
auth= /i
+header __RDNS_DYNAMIC_ATTBI  X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=\S+\d+\S+\.client2\.attbi\.com/i
 describe __RDNS_DYNAMIC_ATTBI Relay HELO'd using suspicious hostname (ATTBI.com)
 
 # CPE0004e2372711-CM000a73666706.cpe.net.cable.rogers.com
 # CPE00e0184f0eba-CM014490118324.cpe.net.cable.rogers.com [24.43.109.140]
-header __RDNS_DYNAMIC_ROGERS X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=CPE\d+\S+\.rogers\.com[^\]]+
auth= /i
+header __RDNS_DYNAMIC_ROGERS X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=CPE\d+\S+\.rogers\.com/i
 describe __RDNS_DYNAMIC_ROGERS Relay HELO'd using suspicious hostname (Rogers)
 
 # ca-morpark-cuda1-zone7-b-159.vnnyca.adelphia.net[67.23.129.159]
@@ -83,7 +89,7 @@
 # ky-richmond2a-123.rhmdky.adelphia.net [68.71.36.123]
 # ny-lackawannacadent4-chtwga3a-b-117.buf.adelphia.net [68.71.205.117]
 # fl-edel-u2-c3c-233.pbc.adelphia.net [68.64.89.233]
-header __RDNS_DYNAMIC_ADELPHIA X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=[a-z]{2}-\S+-\d{1,3}\.[a-z]{3,8}\.adelphia\.net[^\]]+
auth= /i
+header __RDNS_DYNAMIC_ADELPHIA X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=[a-z]{2}-\S+-\d{1,3}\.[a-z]{3,8}\.adelphia\.net/i
 describe __RDNS_DYNAMIC_ADELPHIA Relay HELO'd using suspicious hostname (Adelphia)
 
 # pD9E4F89F.dip.t-dialin.net [217.228.248.159]
@@ -100,62 +106,62 @@
 describe __RDNS_DYNAMIC_SPLIT_IP Relay HELO'd using suspicious hostname (Split IP)
 
 # YahooBB219173000034.bbtec.net [219.173.0.34]
-header __RDNS_DYNAMIC_YAHOOBB X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=YahooBB[^\]]+ auth=
/i
+header __RDNS_DYNAMIC_YAHOOBB X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=YahooBB/i
 describe __RDNS_DYNAMIC_YAHOOBB Relay HELO'd using suspicious hostname (YahooBB)
 
 # ool-18be1aaf.dyn.optonline.net [24.190.26.175]
 header __RDNS_DYNAMIC_OOL X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=\S+\.dyn\.optonline\.net/
 describe __RDNS_DYNAMIC_OOL Relay HELO'd using suspicious hostname (OptOnline)
 
-header __RDNS_DYNAMIC_IPADDR2 X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=\d+[^\d\s]\d+[^\d\s]\d+[^\d\s]\d+[^\d\s][^\.]*\.\S+\.\S+[^\]]+
auth= /i
+header __RDNS_DYNAMIC_IPADDR2 X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=\d+[^\d\s]\d+[^\d\s]\d+[^\d\s]\d+[^\d\s][^\.]*\.\S+\.\S+/i
 describe __RDNS_DYNAMIC_IPADDR2 Relay HELO'd using suspicious hostname (IP addr 2)
 
 # wiley-170-10231.roadrunner.nf.net [205.251.210.249]
-header __RDNS_DYNAMIC_RR2   X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=[a-z]+-\d{1,3}-\d{1,5}\.roadrunner[^\]]+
auth= /i
+header __RDNS_DYNAMIC_RR2   X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=[a-z]+-\d{1,3}-\d{1,5}\.roadrunner/i
 describe __RDNS_DYNAMIC_RR2 Relay HELO'd using suspicious hostname (RR 2)
 
 # pcp04024417pcs.toresd01.pa.comcast.net [68.86.206.126]
 # bgp542174bgs.ewndsr01.nj.comcast.net[68.38.144.91]
 # Computer-udp135632uds.union01.nj.comcast.net [68.39.99.32]
-header __RDNS_DYNAMIC_COMCAST X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=[a-z-]+\d+[a-z]{3}\.[a-z0-9]+\...\.comcast[^\]]+
auth= /i
+header __RDNS_DYNAMIC_COMCAST X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=[a-z-]+\d+[a-z]{3}\.[a-z0-9]+\...\.comcast/i
 describe __RDNS_DYNAMIC_COMCAST Relay HELO'd using suspicious hostname (Comcast)
 
 # h234n2fls32o895.telia.com [217.208.73.234]
 # h53n2fls32o828.telia.com
 # h116n2fls32o1111.telia.com
 # h29n1fls306o1003.telia.com
-header __RDNS_DYNAMIC_TELIA X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=h\d+n\d+fls\S+\.telia\.com[^\]]+
auth= /i
+header __RDNS_DYNAMIC_TELIA X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=h\d+n\d+fls\S+\.telia\.com/i
 describe __RDNS_DYNAMIC_TELIA Relay HELO'd using suspicious hostname (Telia)
 
 # CM-vina5-168-207.cm.vtr.net [200.104.168.207]
 # CM-anto1-98-153.cm.vtr.net [200.104.98.153]
-header __RDNS_DYNAMIC_VTR X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=cm-[a-z]+\d+-\d+-\d+\.cm\.vtr[^\]]+
auth= /i
+header __RDNS_DYNAMIC_VTR X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=cm-[a-z]+\d+-\d+-\d+\.cm\.vtr/i
 describe __RDNS_DYNAMIC_VTR Relay HELO'd using suspicious hostname (VTR)
 
 # ec9z5l.cm.chello.no
-header __RDNS_DYNAMIC_CHELLO_NO  X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=\S+\.cm\.chello\.no[^\]]+
auth= /i
+header __RDNS_DYNAMIC_CHELLO_NO  X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=\S+\.cm\.chello\.no/i
 describe __RDNS_DYNAMIC_CHELLO_NO Relay HELO'd using suspicious hostname (Chello.no)
 
 # g225174.upc-g.chello.nl
 # a151145.upc-a.chello.nl
 # a96134.upc-a.chello.nl
-header __RDNS_DYNAMIC_CHELLO_NL  X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=[a-z]\d+\.upc-[a-z]\.chello\.nl[^\]]+
auth= /i
+header __RDNS_DYNAMIC_CHELLO_NL  X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=[a-z]\d+\.upc-[a-z]\.chello\.nl/i
 describe __RDNS_DYNAMIC_CHELLO_NL Relay HELO'd using suspicious hostname (Chello.nl)
 
 # MG001182.user.veloxzone.com.br
 # ba199058073.user.veloxzone.com.br
-header __RDNS_DYNAMIC_VELOX  X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=[a-z]{2}\d+\.user\.veloxzone\.[^\]]+
auth= /i
+header __RDNS_DYNAMIC_VELOX  X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=[a-z]{2}\d+\.user\.veloxzone\./i
 describe __RDNS_DYNAMIC_VELOX Relay HELO'd using suspicious hostname (Veloxzone)
 
 # public4-seve6-5-cust173.lond.broadband.ntl.com
 # spr1-bolt5-5-0-cust9.manc.broadband.ntl.com
 # spc1-lewi4-6-0-cust190.lond.broadband.ntl.com
-header __RDNS_DYNAMIC_NTL  X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=\S+\d+-\d+-cust\d+\.[a-z]{4,6}\.broadband\.ntl\.com[^\]]+
auth= /i
+header __RDNS_DYNAMIC_NTL  X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=\S+\d+-\d+-cust\d+\.[a-z]{4,6}\.broadband\.ntl\.com/i
 describe __RDNS_DYNAMIC_NTL Relay HELO'd using suspicious hostname (NTL)
 
 # cp160000-a.mill1.nb.home.nl
 # cp341468-b.venra1.lb.home.nl
-header __RDNS_DYNAMIC_HOME_NL  X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=[a-z]{2}\d+-\S\.\S+\d\.[a-z]{2}\.home\.nl[^]]+
auth= /i
+header __RDNS_DYNAMIC_HOME_NL  X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns=[a-z]{2}\d+-\S\.\S+\d\.[a-z]{2}\.home\.nl/i
 describe __RDNS_DYNAMIC_HOME_NL Relay HELO'd using suspicious hostname (Home.nl)
 
 # (I'm quite sure these may be a good spamsign in future)
@@ -191,7 +197,7 @@
 
 ###########################################################################
 
-meta RDNS_DYNAMIC   (__RDNS_DYNAMIC_IPADDR || __RDNS_DYNAMIC_DHCP || __RDNS_DYNAMIC_HCC ||
__RDNS_DYNAMIC_ATTBI || __RDNS_DYNAMIC_ROGERS || __RDNS_DYNAMIC_ADELPHIA || __RDNS_DYNAMIC_DIALIN
|| __RDNS_DYNAMIC_HEXIP || __RDNS_DYNAMIC_SPLIT_IP || __RDNS_DYNAMIC_YAHOOBB || __RDNS_DYNAMIC_OOL
|| __RDNS_DYNAMIC_IPADDR2 || __RDNS_DYNAMIC_RR2   || __RDNS_DYNAMIC_COMCAST || __RDNS_DYNAMIC_TELIA
|| __RDNS_DYNAMIC_VTR || __RDNS_DYNAMIC_CHELLO_NO  || __RDNS_DYNAMIC_CHELLO_NL  || __RDNS_DYNAMIC_VELOX
 || __RDNS_DYNAMIC_NTL  || __RDNS_DYNAMIC_HOME_NL  || __RDNS_DYNAMIC_TDS || __RDNS_DYNAMIC_VIRTUA
|| __RDNS_DYNAMIC_SPACELAN || __RDNS_INDICATOR_DYN || __RDNS_INDICATOR_RES || __RDNS_INDICATOR_TYPE2
|| __RDNS_DYNAMIC_TTNET || __RDNS_DYNAMIC_ASAHI)
+meta RDNS_DYNAMIC   (__LAST_UNTRUSTED_RELAY_NO_AUTH && (__RDNS_DYNAMIC_IPADDR ||
__RDNS_DYNAMIC_DHCP || __RDNS_DYNAMIC_HCC || __RDNS_DYNAMIC_ATTBI || __RDNS_DYNAMIC_ROGERS
|| __RDNS_DYNAMIC_ADELPHIA || __RDNS_DYNAMIC_DIALIN || __RDNS_DYNAMIC_HEXIP || __RDNS_DYNAMIC_SPLIT_IP
|| __RDNS_DYNAMIC_YAHOOBB || __RDNS_DYNAMIC_OOL || __RDNS_DYNAMIC_IPADDR2 || __RDNS_DYNAMIC_RR2
  || __RDNS_DYNAMIC_COMCAST || __RDNS_DYNAMIC_TELIA || __RDNS_DYNAMIC_VTR || __RDNS_DYNAMIC_CHELLO_NO
 || __RDNS_DYNAMIC_CHELLO_NL  || __RDNS_DYNAMIC_VELOX  || __RDNS_DYNAMIC_NTL  || __RDNS_DYNAMIC_HOME_NL
 || __RDNS_DYNAMIC_TDS || __RDNS_DYNAMIC_VIRTUA || __RDNS_DYNAMIC_SPACELAN || __RDNS_INDICATOR_DYN
|| __RDNS_INDICATOR_RES || __RDNS_INDICATOR_TYPE2 || __RDNS_DYNAMIC_TTNET || __RDNS_DYNAMIC_ASAHI))
 describe RDNS_DYNAMIC Delivered to trusted network by host with dynamic-looking rDNS
 
 header RDNS_NONE    X-Spam-Relays-Untrusted =~ /^[^\]]+ rdns= /



Mime
View raw message