Odd message header blocking from NATed gm |
Post Reply
|
| Author | |
MartinC
Newbie
Joined: 29 July 2005 Status: Offline Points: 25 |
Post Options
Thanks(0)
Quote Reply
Topic: Odd message header blocking from NATed gmPosted: 16 June 2006 at 11:48am |
|
had an odd one today... a user from gmail was blocked due to the filter [(href="http://+[\d])] in the body. the odd thing is that this isn't in the body, its in the message headers, and is the person's nat-ed ip address & private firewall passing off to gmail. I didn't think that Spamfilter was able to check the message headers, only the body or subject? I tried doing an reverse Allowedkeywords on this, but that didn't work... (unless I got my syntax wrong). 06/16/06 16:21:15:162 -- (10280) Found Keywords: [(href="http://+[\d])] the content of the header is something like this:- gRdjsMDa+gmJ2s84+QJYShLArqnR9DxQPLyJeaM= it doesn't appear to even match what I thought was in the regex expression either ... http://numeric address of some sort. Anyone? |
|
![]() |
|
Desperado
Senior Member
Joined: 27 January 2005 Location: United States Status: Offline Points: 1143 |
Post Options
Thanks(0)
Quote Reply
Posted: 16 June 2006 at 11:40pm |
|
Martin, Are you running the latest version? Note the release notes: |
|
|
The Desperado
Dan Seligmann. Work: http://www.mags.net Personal: http://www.desperado.com |
|
![]() |
|
LogSat
Admin Group
Joined: 25 January 2005 Location: United States Status: Offline Points: 4106 |
Post Options
Thanks(0)
Quote Reply
Posted: 17 June 2006 at 11:52am |
|
MartinC,
Please note that SpamFilter does scan the "Received:" headers in an email (an option to turn this feature off is in the SpamFilter.ini file). Also, as Dan mentions, in the latest builds SpamFilter is checking the "whitelist" keywords thru the complete headers as well. This is done as some admins may have specific headers in emails by trusted servers that they wish to whitelist. Scanning for whitelisted keyword throughtout the full headers allows them to do that. This is done only for whitelists however, as experience has taught s in the past that scanning for blacklist keywords in the headers resulted in a very large number of false positives. |
|
![]() |
|
MartinC
Newbie
Joined: 29 July 2005 Status: Offline Points: 25 |
Post Options
Thanks(0)
Quote Reply
Posted: 19 June 2006 at 5:12am |
|
thanks, we'll just switch the option off for now. can't see us catching that much on scanning the headers, especially if its causing false positives like this. |
|
![]() |
|
Post Reply
|
|
|
Tweet
|
| Forum Jump | Forum Permissions ![]() You cannot post new topics in this forum You cannot reply to topics in this forum You cannot delete your posts in this forum You cannot edit your posts in this forum You cannot create polls in this forum You cannot vote in polls in this forum |
This page was generated in 0.262 seconds.


Topic Options
Post Options
Thanks(0)


