spamassassin-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From John Hardin <jhar...@impsec.org>
Subject Re: Meta for bogus MIME with DKIM valid?
Date Thu, 13 Jun 2019 00:34:43 GMT
On Wed, 12 Jun 2019, Amir Caspi wrote:

> On Jun 4, 2019, at 2:11 PM, Amir Caspi <Cepheid@3phase.com> wrote:
>>
>> Locally, I've got the score at 4.0, and will be increasing it to 4.5 shortly.  At
least with my spamset (per the spamples I posted), a score of 4.5 seems to be the "magic"
value that should catch almost all the FNs (at least the ones that hit BAYES_50 ... the ones
that hit BAYES_00 might require more aggression).
>
> I'm getting a ton of zero-hour snowshoe spam today that's scoring BAYES_50 and hitting
no other rules besides BOGUS_MIME_VERSION.  These all score 4.6 with BOGUS_MIME_VERSION =
4.0.  I'm going to increase locally to 4.5, and that should get rid of these for me... but
I think we should really expedite deployment of this rule for production, I expect I'm not
the only one this affects...

Looks like it's suddenly worthwhile in masscheck as well:

https://ruleqa.spamassassin.org/20190612-r1861099-n/__BOGUS_MIME_VER_01/detail
https://ruleqa.spamassassin.org/20190612-r1861099-n/__BOGUS_MIME_VER_02/detail

I'll add a scored rule.


-- 
  John Hardin KA7OHZ                    http://www.impsec.org/~jhardin/
  jhardin@impsec.org    FALaholic #11174     pgpk -a jhardin@impsec.org
  key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
-----------------------------------------------------------------------
   Are you a mildly tech-literate politico horrified by the level of
   ignorance demonstrated by lawmakers gearing up to regulate online
   technology they don't even begin to grasp? Cool. Now you have a
   tiny glimpse into a day in the life of a gun owner.   -- Sean Davis
-----------------------------------------------------------------------
  804 days since the first commercial re-flight of an orbital booster (SpaceX)

Mime
View raw message