aboutsummaryrefslogtreecommitdiffstats
path: root/rules
Commit message (Collapse)AuthorAgeFilesLines
...
| * | Merge pull request #4401 from twesterhever/temp-google-firebaseVsevolod Stakhov2023-02-171-0/+7
| |\ \ | | | | | | | | [Enhancement] Add rule to detect Google Firebase URLs
| | * | [Enhancement] Add rule to detect Google Firebase URLstwesterhever2023-02-171-0/+7
| | |/
| * / [Enhancement] Make Google URL redirection rules productivetwesterhever2023-02-171-5/+5
| |/
| * Fix pcall() argument in rspamd.luadpetrov672023-02-141-1/+1
| |
| * [Fix] received: filtering of artificial headerKako, Chang2023-01-121-1/+1
| |
| * [Rules] Mid: Add MID_END_EQ_FROM_USER_PART ruleVsevolod Stakhov2022-12-231-0/+21
| | | | | | | | Issue: #4299
| * [Minor] Use unicode property for currency detectionVsevolod Stakhov2022-10-291-1/+1
| | | | | | | | Issue: #4320
| * [Rules] Reduce score of HTTP_TO_HTTPS - subject to remove completelyVsevolod Stakhov2022-10-181-1/+1
| |
* | [Minor] Regexp is case-insensitive, omit redundant characterstwesterhever2022-11-061-1/+1
| |
* | [Minor] Fix rule commenttwesterhever2022-11-061-1/+1
| |
* | [Minor] Limit CIDv1 detection to 128 bytestwesterhever2022-11-061-1/+1
| | | | | | As requested by @vstakhov in https://github.com/rspamd/rspamd/pull/4310#pullrequestreview-1148226107, try to limit the performance impact of this regular expression. However, given that there does not seem to be a hard limit for CIDv1s in IPFS itself, using an hashing algorithm with large output my permit miscreants to get around this rule.
* | [Minor] Implement multibase prefixes for IPFS gateway URL ruletwesterhever2022-11-061-2/+2
| |
* | [Minor] Clarify that IPFS *gateway* URLs are likely considered malicioustwesterhever2022-11-061-2/+2
| |
* | [Enhancement] Add IPFS URL heuristictwesterhever2022-10-151-1/+16
|/
* [Rework] Reiterate on prioritiesVsevolod Stakhov2022-09-101-16/+16
|
* [Minor] Update more copyright years/emailVsevolod Stakhov2022-03-275-5/+5
|
* [Minor] Update my email and the copyright yearVsevolod Stakhov2022-03-259-9/+9
|
* [Rules] Slightly reduce MULTIPLE_FROM scoreVsevolod Stakhov2022-03-231-1/+1
|
* Spelling (#4086)Josh Soref2022-02-223-7/+7
| | | [Rework] Massive spelling fix from @jsoref
* [Minor] Oops, fix foldl callVsevolod Stakhov2022-01-111-1/+1
|
* [Minor] Fix some issues in URI_COUNT_ODD ruleVsevolod Stakhov2022-01-111-4/+2
| | | | Issue: #4037
* [Minor] Fix ruleVsevolod Stakhov2021-11-301-1/+1
|
* [Rules] Remove ancient and inefficient rulesVsevolod Stakhov2021-11-291-43/+0
|
* [Rules] Fix old rules to stop global functions usageVsevolod Stakhov2021-11-291-46/+72
|
* [Feature] JSON endpoint for querying mapsAndrew Lewis2021-11-171-1/+65
|
* [Minor] Skip bitcoin address check for very long wordsAnton Yuzhaninov2021-09-171-2/+4
| | | | | | Exclude very long words (which can be extracted e. g. from some text attachments) from bitcoin address check to avoid excessive resource usage.
* [Rules] Improve zero font ruleVsevolod Stakhov2021-09-071-2/+2
|
* [Minor] Regexp: Extend upstream spam filter regexpSebastian Lipponer2021-08-211-1/+3
|
* [Rules] Micro-optimize X_PHP_EVALAnton Yuzhaninov2021-08-051-1/+1
| | | | | Remove /i flag from regexp string "eval()'d code" is always in lower case. While here use long string format for readability.
* [Minor] Fix checks safetyVsevolod Stakhov2021-07-191-2/+4
|
* [Minor] Add safety guardsVsevolod Stakhov2021-07-081-2/+2
|
* [Fix] Fix an edge case in BITCOIN_ADDR ruleAndrew Lewis2021-06-231-2/+3
| | | | | - when using PCRE - and different address types are present
* [Minor] Pet luacheckVsevolod Stakhov2021-06-141-2/+0
|
* [Project] Rework html visibility ruleVsevolod Stakhov2021-06-141-34/+14
|
* [Rules] Fix zerofont rule (partially)Vsevolod Stakhov2021-06-121-1/+3
|
* [Rules] Extend OLD_X_MAILERAnton Yuzhaninov2021-05-221-3/+4
| | | | Add more old iPhone/iPad Mail versions to the regexp.
* [Rules] Extend FORGED_X_MAILERAnton Yuzhaninov2021-05-221-3/+10
| | | | | Match in FORGED_X_MAILER fake iPhone Mail header with a random string in place of iOS build number, e. g. iPhone Mail (WKN0M)
* [Rules] Fix CTYPE_MIXED_BOGUS for text attachmentsVsevolod Stakhov2021-05-191-1/+1
| | | | Issue: #3748
* [Minor] Fix bit operations logicVsevolod Stakhov2021-05-131-5/+6
|
* [Minor] Filter urls for R_SUSPICIOUS_URL checkVsevolod Stakhov2021-05-111-3/+3
| | | | Suggested by: @citrin
* [Minor] Use numeric bit and for checking flagsVsevolod Stakhov2021-05-111-3/+8
|
* [Minor] Fix REPLYTO_ADDR_EQ_FROM for normalised addressesAndrew Lewis2021-04-291-1/+1
|
* [Rules] Add raw addresses to MULTIPLE_FROM optionsAnton Yuzhaninov2021-04-271-9/+2
| | | | | | It is confusing to have MULTIPLE_FROM with a single address in options, which happens if one of addresses is empty - usually because of misplaces <>. While here simplify condition.
* [Minor] Make HAS_PHPMAILER_SIG regexps more specificAnton Yuzhaninov2021-04-271-1/+7
| | | | Use stricter regexp to avoid false matches.
* [Rules] Fix FPs for CTYPE_MIXED_BOGUSVsevolod Stakhov2021-04-111-6/+11
|
* [Rules] Fix HTTP_TO_HTTPS ruleVsevolod Stakhov2021-04-091-1/+1
|
* [Rules] Do not trigger HTML_SHORT_LINK_IMG on external imagesVsevolod Stakhov2021-04-081-1/+1
|
* Fix typos in code commentsKako, Chang2021-04-071-3/+3
|
* [Minor] Bitcoin: Another fix for bleach32 regexpVsevolod Stakhov2021-03-301-1/+1
|
* [Minor] fix typo: obfusicated -> obfuscatedRichard Schwab2021-03-241-1/+1
|