/var/lib/spamassassin/3.004006/updates_spamassassin_org
NameSizeModeActions
10_default_prefs.cf87680644editdlrm
10_hasbase.cf24520644editdlrm
20_advance_fee.cf76120644editdlrm
20_aux_tlds.cf405820644editdlrm
20_body_tests.cf71800644editdlrm
20_compensate.cf19350644editdlrm
20_dnsbl_tests.cf105440644editdlrm
20_drugs.cf155250644editdlrm
20_dynrdns.cf113860644editdlrm
20_fake_helo_tests.cf92860644editdlrm
20_freemail.cf30600644editdlrm
20_freemail_domains.cf413330644editdlrm
20_freemail_mailcom_domains.cf44200644editdlrm
20_head_tests.cf274770644editdlrm
20_html_tests.cf107380644editdlrm
20_imageinfo.cf53020644editdlrm
20_mailspike.cf29310644editdlrm
20_meta_tests.cf35040644editdlrm
20_net_tests.cf18800644editdlrm
20_pdfinfo.cf158990644editdlrm
20_phrases.cf81550644editdlrm
20_porn.cf20620644editdlrm
20_ratware.cf168710644editdlrm
20_uri_tests.cf60390644editdlrm
20_vbounce.cf207660644editdlrm
23_bayes.cf30090644editdlrm
25_accessdb.cf15470644editdlrm
25_antivirus.cf15390644editdlrm
25_asn.cf19750644editdlrm
25_dcc.cf29570644editdlrm
25_dkim.cf57110644editdlrm
25_dmarc.cf20780644editdlrm
25_dnswl.cf30630644editdlrm
25_pyzor.cf15220644editdlrm
25_razor2.cf31640644editdlrm
25_replace.cf214850644editdlrm
25_spf.cf44000644editdlrm
25_textcat.cf17710644editdlrm
25_uribl.cf200030644editdlrm
25_url_redirectors.cf35200644editdlrm
25_url_shortener.cf110210644editdlrm
30_text_de.cf263050644editdlrm
30_text_fr.cf198030644editdlrm
30_text_it.cf18610644editdlrm
30_text_nl.cf206310644editdlrm
30_text_pl.cf172550644editdlrm
30_text_pt_br.cf429340644editdlrm
50_scores.cf380410644editdlrm
60_adsp_override_dkim.cf93400644editdlrm
60_awl.cf15140644editdlrm
60_bayes_stopwords.cf150850644editdlrm
60_shortcircuit.cf24170644editdlrm
60_txrep.cf13420644editdlrm
60_welcomelist.cf116140644editdlrm
60_welcomelist_auth.cf765570644editdlrm
60_welcomelist_dkim.cf110950644editdlrm
60_welcomelist_spf.cf62510644editdlrm
60_welcomelist_subject.cf39130644editdlrm
72_active.cf5374610644editdlrm
72_scores.cf304860644editdlrm
73_sandbox_manual_scores.cf42170644editdlrm
languages1336000644editdlrm
local.cf32180644editdlrm
MIRRORED.BY10800644editdlrm
regression_tests.cf27710644editdlrm
sa-update-pubkey.txt47770644editdlrm
STATISTICS-set0-72_scores.cf.txt14970644editdlrm
STATISTICS-set1-72_scores.cf.txt14990644editdlrm
STATISTICS-set2-72_scores.cf.txt00644editdlrm
STATISTICS-set3-72_scores.cf.txt00644editdlrm
user_prefs.template19120644editdlrm
Edit: /var/lib/spamassassin/3.004006/updates_spamassassin_org/20_html_tests.cf (10738B)
# SpamAssassin rules file: HTML tests # # Please don't modify this file as your changes will be overwritten with # the next update. Use /etc/mail/spamassassin/local.cf instead. # See 'perldoc Mail::SpamAssassin::Conf' for details. # # <@LICENSE> # Licensed to the Apache Software Foundation (ASF) under one or more # contributor license agreements. See the NOTICE file distributed with # this work for additional information regarding copyright ownership. # The ASF licenses this file to you under the Apache License, Version 2.0 # (the "License"); you may not use this file except in compliance with # the License. You may obtain a copy of the License at: # # http://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. # See the License for the specific language governing permissions and # limitations under the License. # # ########################################################################### require_version 3.004006 # HTML parser tests # # please sort these by eval type then name meta HTML_SHORT_LINK_IMG_1 __HTML_LENGTH_0000_1024 && __HTML_LINK_IMAGE meta HTML_SHORT_LINK_IMG_2 __HTML_LENGTH_1024_1536 && __HTML_LINK_IMAGE meta HTML_SHORT_LINK_IMG_3 __HTML_LENGTH_1536_2048 && __HTML_LINK_IMAGE describe HTML_SHORT_LINK_IMG_1 HTML is very short with a linked image describe HTML_SHORT_LINK_IMG_2 HTML is very short with a linked image describe HTML_SHORT_LINK_IMG_3 HTML is very short with a linked image meta HTML_SHORT_CENTER (__HTML_LENGTH_384 && __TAG_EXISTS_CENTER) describe HTML_SHORT_CENTER HTML is very short with CENTER tag meta HTML_TITLE_SUBJ_DIFF __HTML_TITLE_SUBJ_DIFF && !__MIME_ATTACHMENT meta HTML_CHARSET_FARAWAY (__HTML_CHARSET_FARAWAY && __HIGHBITS) describe HTML_CHARSET_FARAWAY A foreign language charset used in HTML markup tflags HTML_CHARSET_FARAWAY userconf meta HTML_MIME_NO_HTML_TAG MIME_HTML_ONLY && !__TAG_EXISTS_HTML describe HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag meta HTML_MISSING_CTYPE (!__MIME_HTML && HTML_MESSAGE) describe HTML_MISSING_CTYPE Message is HTML without HTML Content-Type ########################################################################### # rawbody HTML tests rawbody HIDE_WIN_STATUS /<[^>]{1,1000}onMouseOver=[^>]{1,1000}window\.status=/i describe HIDE_WIN_STATUS Javascript to hide URLs in browser rawbody __OBFUSCATING_COMMENT_A /\w(?:]*>)+\w/ rawbody __OBFUSCATING_COMMENT_B /[^\s>](?:]*>)+[^\s<]/ ifplugin Mail::SpamAssassin::Plugin::HTMLEval ifplugin Mail::SpamAssassin::Plugin::MIMEEval meta OBFUSCATING_COMMENT ((__OBFUSCATING_COMMENT_A && HTML_MESSAGE) || (__OBFUSCATING_COMMENT_B && MIME_HTML_ONLY)) && !__ISO_2022_JP_DELIM describe OBFUSCATING_COMMENT HTML comments which obfuscate text endif endif # spams that are assembled from a Javascript array # look for the XOR op rawbody __JS_FROMCHARCODE /String\.fromCharCode\s*\(\s*\S+\s*\[\s*\S+\s*\]\s*\^/ rawbody __JS_DOCWRITE /document\.write/ meta JS_FROMCHARCODE (__JS_FROMCHARCODE && __JS_DOCWRITE) describe JS_FROMCHARCODE Document is built from a Javascript charcode array # a good possible rule that may resurface # ! $ % ' ( ) , - . / : ; = ? @ _ #rawbody ENTITY_DEC_OTHER /\&\#0*(?:3[3679]|4[014567]|5[89]|6[134]|95)\;/ #describe ENTITY_DEC_OTHER HTML contains needlessly encoded punctuation body __HIGHBITS /(?:[\x80-\xff].?){4}/ # note: __HIGHBITS is used by HTML_CHARSET_FARAWAY ########################################################################### ifplugin Mail::SpamAssassin::Plugin::HTMLEval # HTML control test, HTML spam rules should all have better S/O than this body HTML_MESSAGE eval:html_test('html') describe HTML_MESSAGE HTML included in message # HTML comment tests body HTML_COMMENT_SHORT eval:html_text_match('comment', '') describe HTML_COMMENT_SHORT HTML comment is very short body HTML_COMMENT_SAVED_URL eval:html_text_match('comment', '