You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@spamassassin.apache.org by Herold Heiko <He...@previnet.it> on 2005/05/30 11:04:10 UTC

[Newby] attachment rules ?

Spamassassin newby warning. Did read ::Conf manual and
http://wiki.apache.org/spamassassin/WritingRules

How do you check for an attachment name or file type (excel in this case) ?
I resorted by using a rawbody meta rule, but that doesn't seem too right.
I didn't find the documentation for EvalTests.pm, but skimming through it
there didn't seem to be a relevant sub.

If I should want to write a specific test do I need to change EvalTests.pm
(directly or in order to include my module) or is there a standard interface
available I didn't find in the manual ?

Thanks everybody
Heiko

-- 
-- PREVINET S.p.A. www.previnet.it
-- Heiko Herold Heiko.Herold@previnet.it Sistemisti@previnet.it
-- +39-041-5907073 ph
-- +39-041-5907472 fax

Re: [Newby] attachment rules ?

Posted by Loren Wilton <lw...@earthlink.net>.
You don't say what version you are using.

In 2.6x, you can't do this without changing core code - non-text attachments
are stripped before the rules can see them.  One exception is the
"MICROSOFT_EXECUTABLE" rule that can detect some attachment types.  This
rule was deleted in 3.0.

In 3.0 there are plugins that can do this sort of thing, if you really want
to.  If you dig in the wiki, you will find a page with plugin contributions,
and one of them does much like the old ms_executable rule.  You could
probably rework this to do whatever it is you want.

Now, many people will point out that SA is a spam filter, not a virus
filter, and you should be using something like ClamAV for that purpose.

        Loren