Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Merge pull request #5209 from twesterhever/temp-auth-origin-helo-user | Vsevolod Stakhov | 2024-11-05 | 1 | -1/+1 |
|\ | | | | | [Minor] Add "User" HELO in Received headers to ABUSE_FROM_INJECTOR | ||||
| * | [Minor] Add "User" HELO in Received headers to ABUSE_FROM_INJECTOR | twesterhever | 2024-11-04 | 1 | -1/+1 |
| | | | | | | | | | | | | This pattern often surfaces in spam (frequently advance fee fraud) disseminated via compromised accounts, adding it to ABUSE_FROM_INJECTOR to increase the likelihood of such spam getting rejected. | ||||
* | | [Minor] Improve FREEMAIL_AFF catch rate | twesterhever | 2024-11-04 | 1 | -1/+1 |
|/ | | | | | This "Mail message body" Content-Description header appears to be a common quirk of advance fee fraud e-mails leveraging freemail services. | ||||
* | Exclude MIME_BAD_UNICODE false positive (#5030) | Dmitriy Alekseev | 2024-06-26 | 1 | -0/+12 |
| | | | | | | | | | | | | | | | * Update composites.conf * Update composites.conf * Update composites.conf * Update composites.conf * Update mime_types_group.conf * Update mime_types_group.conf * Update composites.conf | ||||
* | Merge pull request #4915 from twesterhever/temp-freemail-mdn | Vsevolod Stakhov | 2024-04-30 | 1 | -1/+8 |
|\ | | | | | Add detection for freemail and disposable e-mail usage for message delivery notification | ||||
| * | [Minor] Fix typo in rule name | twesterhever | 2024-04-09 | 1 | -1/+1 |
| | | |||||
| * | [Minor] Add composite for suspicios free/disposamail MDN usage | twesterhever | 2024-04-09 | 1 | -0/+7 |
| | | |||||
| * | [Minor] Improve FREEMAIL_AFF detection | twesterhever | 2024-04-09 | 1 | -1/+1 |
| | | |||||
* | | [Minor] Also respect HAS_XOIP for authenticated messages | twesterhever | 2024-04-09 | 1 | -1/+1 |
| | | |||||
* | | [Minor] Add some missing groups to existing composite rules | twesterhever | 2024-04-09 | 1 | -0/+3 |
| | | |||||
* | | [Minor] Rework composites for spam injected into compromised accounts | twesterhever | 2024-04-09 | 1 | -3/+9 |
|/ | |||||
* | Merge pull request #4683 from twesterhever/temp-improve-freemail-aff | Vsevolod Stakhov | 2023-11-03 | 1 | -1/+1 |
|\ | | | | | [Minor] Improve FREEMAIL_AFF capture rates | ||||
| * | [Minor] Improve FREEMAIL_AFF capture rates | twesterhever | 2023-11-03 | 1 | -1/+1 |
| | | |||||
* | | [Enhancement] Add composite rule for suspicious URLs in suspicious messages | twesterhever | 2023-11-03 | 1 | -0/+6 |
|/ | |||||
* | [Rules] Blank spam detection | Andrew Lewis | 2023-10-13 | 1 | -0/+6 |
| | |||||
* | Merge pull request #4556 from twesterhever/temp-improve-freemail-aff | Vsevolod Stakhov | 2023-08-02 | 1 | -1/+1 |
|\ | | | | | [Minor] Improve catch rates of FREEMAIL_AFF | ||||
| * | [Minor] Improve catch rates of FREEMAIL_AFF | twesterhever | 2023-08-02 | 1 | -1/+1 |
| | | |||||
* | | Add composites exclusions for known Apple Mail bad symbols | Dmitriy Alekseev | 2023-07-11 | 1 | -0/+8 |
|/ | |||||
* | Merge pull request #4507 from ↵ | Vsevolod Stakhov | 2023-06-03 | 1 | -2/+9 |
|\ | | | | | | | | | twesterhever/temp-composites-thread-hijacking-injector [Rules] Add thread hijacking composite rule | ||||
| * | [Minor] Fix RCVD_UNAUTH_PBL | twesterhever | 2023-06-02 | 1 | -2/+2 |
| | | |||||
| * | [Rules] Add thread hijacking composite rule | twesterhever | 2023-06-02 | 1 | -0/+7 |
| | | |||||
* | | [Minor] Improve HACKED_WP_PHISHING coverage | twesterhever | 2023-06-02 | 1 | -1/+1 |
|/ | |||||
* | [Enhancement] Add composite rule for messages only containing a redirector URL | twesterhever | 2023-05-26 | 1 | -0/+6 |
| | |||||
* | [Conf] Remove outdated composite rules | Vsevolod Stakhov | 2023-05-09 | 1 | -10/+0 |
| | |||||
* | Merge branch 'master' into temp-propose-alternative-solution-to-xbl-any-hack | Vsevolod Stakhov | 2023-02-19 | 1 | -9/+6 |
|\ | |||||
| * | [Minor] Improve readability of composites rule configuration | twesterhever | 2023-02-17 | 1 | -9/+6 |
| | | |||||
* | | [Minor] Replace "Spamhaus XBL any" hack with a more clear solution | twesterhever | 2023-02-17 | 1 | -4/+0 |
|/ | |||||
* | Merge pull request #4308 from frederikbosch/patch-1 | Vsevolod Stakhov | 2022-10-19 | 1 | -1/+11 |
|\ | | | | | [Rules] Penalize bounce spam | ||||
| * | Update composites.conf | Frederik Bosch | 2022-10-17 | 1 | -1/+1 |
| | | |||||
| * | Composites should not be recursive | Frederik Bosch | 2022-10-12 | 1 | -1/+1 |
| | | |||||
| * | Protect against bounce spam | Frederik Bosch | 2022-10-12 | 1 | -1/+11 |
| | | |||||
* | | [Enhancement] Add composite rule against AFF involving freemailers | twesterhever | 2022-10-09 | 1 | -0/+7 |
|/ | |||||
* | [Fix] BAD_REP_POLICIES did not trigger when message was classified as spam ↵ | Player701 | 2022-08-19 | 1 | -1/+1 |
| | | | | by Bayes | ||||
* | [Rules] Fix symbol for DKIM temporary failure | Anton Yuzhaninov | 2022-02-15 | 1 | -1/+1 |
| | | | | There is no R_DKIM_DNSFAIL symbol (in default config), but there is R_DKIM_TEMPFAIL. | ||||
* | [Conf] Clarify documentation in the config files | Vsevolod Stakhov | 2019-10-11 | 1 | -7/+6 |
| | |||||
* | [Conf] Make LEAKED_PASSWORD_SCAM a composite rule again | Vsevolod Stakhov | 2019-09-19 | 1 | -1/+7 |
| | |||||
* | [Rework] Migrate from ip_score to reputation | Vsevolod Stakhov | 2019-07-17 | 1 | -1/+1 |
| | |||||
* | [Conf] Add BROKEN_HEADERS_MAILLIST composite | Vsevolod Stakhov | 2019-07-17 | 1 | -0/+7 |
| | |||||
* | [Rules] Rework LEAKED_PASSWORD_SCAM rule one more time | Vsevolod Stakhov | 2019-06-18 | 1 | -7/+0 |
| | |||||
* | [Conf] Add IP_SCORE_FREEMAIL composite rule | Vsevolod Stakhov | 2019-04-29 | 1 | -0/+7 |
| | |||||
* | Add a reference to the doc of composite rules | Edmond | 2019-04-08 | 1 | -1/+2 |
| | |||||
* | [Feature] Validate BTC addresses in LEAKED_PASSWORD_SCAM | Vsevolod Stakhov | 2019-03-19 | 1 | -0/+7 |
| | |||||
* | fix typo in RCVD_UNAUTH_PBL | heraklit256 | 2019-02-13 | 1 | -1/+1 |
| | |||||
* | [Rules] Add VIOLATED_DIRECT_SPF composite | Vsevolod Stakhov | 2019-01-15 | 1 | -113/+120 |
| | |||||
* | Merge pull request #2566 from heraklit256/composites-leave | Vsevolod Stakhov | 2018-10-18 | 1 | -5/+10 |
|\ | | | | | Minor Composite rule cleanup | ||||
| * | lower score for PHISH_EMOTION to 1.0 | heraklit256 | 2018-10-17 | 1 | -1/+1 |
| | | |||||
| * | lower score for HAS_ANON_DOMAIN to 0.1 | heraklit256 | 2018-10-17 | 1 | -1/+1 |
| | | |||||
| * | Include ARC into AUTH_NA rule | heraklit256 | 2018-10-04 | 1 | -2/+2 |
| | | |||||
| * | Composite rules: Minor cleanups | heraklit256 | 2018-10-04 | 1 | -1/+3 |
| | | | | | | | | Added descriptions to some rules and unified AND operator. | ||||
| * | leave original symbols for composite rules | heraklit256 | 2018-10-04 | 1 | -0/+3 |
| | | | | | | | | | | Removing original symbols if a composite rule triggers is kind of confusing and makes debugging harder. |