]> source.dussan.org Git - rspamd.git/commitdiff
[Minor] Make LEAKED_PASSWORD_SCAM rule more strict
authorVsevolod Stakhov <vsevolod@highsecure.ru>
Mon, 12 Nov 2018 14:32:52 +0000 (14:32 +0000)
committerVsevolod Stakhov <vsevolod@highsecure.ru>
Mon, 12 Nov 2018 14:32:52 +0000 (14:32 +0000)
rules/regexp/misc.lua

index 0a399e2adebafac09ffe9a532bdcf3c86052e5de..2332cd6ceb94a3c7153780b1125c3c8e80eb6fa9 100644 (file)
@@ -63,11 +63,12 @@ reconf['HAS_ONION_URI'] = {
 
 local password_in_subject = [[Subject=/\bpassword\b/i]]
 local password_in_body = [[/\bpassword\b/i{sa_body}]]
-local btc_wallet = [[/^[13][0-9a-zA-Z]{25,34}$/{words}]]
+local btc_wallet_address = [[/^[13][0-9a-zA-Z]{25,34}$/{words}]]
+local wallet_word = [[/^wallet$/i{words}]]
 
 reconf['LEAKED_PASSWORD_SCAM'] = {
-  re = string.format('(%s | %s) & %s', password_in_subject,
-      password_in_body, btc_wallet),
+  re = string.format('(%s | %s) & %s & %s', password_in_subject,
+      password_in_body, btc_wallet_address, wallet_word),
   description = 'Contains password word and BTC wallet address',
   score = 7.0,
   group = 'scams'