You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@spamassassin.apache.org by gb...@apache.org on 2021/01/21 07:29:50 UTC

svn commit: r1885744 - /spamassassin/trunk/rulesrc/sandbox/gbechis/20_misc.cf

Author: gbechis
Date: Thu Jan 21 07:29:50 2021
New Revision: 1885744

URL: http://svn.apache.org/viewvc?rev=1885744&view=rev
Log:
better regexp

Modified:
    spamassassin/trunk/rulesrc/sandbox/gbechis/20_misc.cf

Modified: spamassassin/trunk/rulesrc/sandbox/gbechis/20_misc.cf
URL: http://svn.apache.org/viewvc/spamassassin/trunk/rulesrc/sandbox/gbechis/20_misc.cf?rev=1885744&r1=1885743&r2=1885744&view=diff
==============================================================================
--- spamassassin/trunk/rulesrc/sandbox/gbechis/20_misc.cf (original)
+++ spamassassin/trunk/rulesrc/sandbox/gbechis/20_misc.cf Thu Jan 21 07:29:50 2021
@@ -2,7 +2,7 @@
 # meta        GB_MALWARE_DROPBOX_JAR_URI	( __MALWARE_DROPBOX_JAR_URI && (HTML_SHORT_LINK_IMG_1 || HTML_SHORT_LINK_IMG_2 || HTML_SHORT_LINK_IMG_3) )
 # describe    GB_MALWARE_DROPBOX_JAR_URI Dropbox that forces user to download jar file
 
-uri         GB_GOOGLE_OBFUR	/^https:\/\/www\.google\.([a-z]{2,3})\/url\?sa=t\&rct=j\&q=\&esrc=s\&source=web\&cd=([0-9])+\&cad=rja\&uact=([0-9]+)\&ved=.{1,50}\&url=https?:\/\/.{1,50}&usg=.{1,50}/
+uri         GB_GOOGLE_OBFUR	/^https:\/\/www\.google\.([a-z]{2,3})\/url\?sa=t\&rct=j\&q=\&esrc=s\&source=web\&cd=([0-9])*\&cad=rja\&uact=([0-9]+)\&ved=.{1,50}\&url=https?:\/\/.{1,50}&usg=.{1,50}/
 describe    GB_GOOGLE_OBFUR	Obfuscate url through Google redirect
 score       GB_GOOGLE_OBFUR     0.75 # limit
 tflags      GB_GOOGLE_OBFUR     publish