You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@spamassassin.apache.org by bu...@bugzilla.spamassassin.org on 2014/06/06 13:55:40 UTC

[Bug 7049] New: HTTPS_IP_MISMATCH false negative on quoted-printable body

https://issues.apache.org/SpamAssassin/show_bug.cgi?id=7049

            Bug ID: 7049
           Summary: HTTPS_IP_MISMATCH false negative on quoted-printable
                    body
           Product: Spamassassin
           Version: 3.3.2
          Hardware: PC
                OS: Linux
            Status: NEW
          Severity: normal
          Priority: P2
         Component: Rules
          Assignee: dev@spamassassin.apache.org
          Reporter: jh@excello.cz

Created attachment 5202
  --> https://issues.apache.org/SpamAssassin/attachment.cgi?id=5202&action=edit
HTTPS_IP_MISMATCH false negative example

Atteched EML file hits HTTPS_IP_MISMATCH rule. Links are the same, can you
please check if it's thrown because of quoted printable formatting?

-- 
You are receiving this mail because:
You are the assignee for the bug.

[Bug 7049] HTTPS_IP_MISMATCH false negative on quoted-printable body

Posted by bu...@bugzilla.spamassassin.org.
https://issues.apache.org/SpamAssassin/show_bug.cgi?id=7049

--- Comment #3 from Karsten Bräckelmann <gu...@rudersport.de> ---
(In reply to Jan Hejl from comment #2)
> Thanks for the explanation. So you say that the message raw body is
> formatted badly? It was created by "Lotus Domino Web Server Release
> 9.0.1HF195". Do I have to post it to Lotus support as a bug?

Yes, the text/html part is formatted badly.

> I'm using version 3.3.2 with last sa-update (actually it was long time ago
> it worked), but HTTPS_IP_MISMATCH rule has its own score.

No, the score is 0, effectively disabling that rule.

$ grep HTTPS_IP_MISMATCH 3.003002/updates_spamassassin_org/50_scores.cf 
score HTTPS_IP_MISMATCH 0 # n=0 n=1 n=2 n=3

-- 
You are receiving this mail because:
You are the assignee for the bug.

[Bug 7049] HTTPS_IP_MISMATCH false negative on quoted-printable body

Posted by bu...@bugzilla.spamassassin.org.
https://issues.apache.org/SpamAssassin/show_bug.cgi?id=7049

Jan Hejl <jh...@excello.cz> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |jh@excello.cz

--- Comment #2 from Jan Hejl <jh...@excello.cz> ---
Thanks for the explanation. So you say that the message raw body is formatted
badly? It was created by "Lotus Domino Web Server Release 9.0.1HF195". Do I
have to post it to Lotus support as a bug?

I'm using version 3.3.2 with last sa-update (actually it was long time ago it
worked), but HTTPS_IP_MISMATCH rule has its own score.

-- 
You are receiving this mail because:
You are the assignee for the bug.

[Bug 7049] HTTPS_IP_MISMATCH false negative on quoted-printable body

Posted by bu...@bugzilla.spamassassin.org.
https://issues.apache.org/SpamAssassin/show_bug.cgi?id=7049

Karsten Bräckelmann <gu...@rudersport.de> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
             Status|NEW                         |RESOLVED
         Resolution|---                         |INVALID

--- Comment #1 from Karsten Bräckelmann <gu...@rudersport.de> ---
(In reply to Jan Hejl from comment #0)
> Atteched EML file hits HTTPS_IP_MISMATCH rule. Links are the same, can you
> please check if it's thrown because of quoted printable formatting?

The "links" (HTML anchor href and link text) do match and appear identical to
the recipient when rendered. However, the anchor text actually does differ from
the href. This is not caused by the content encoding.

Stripped down HTML from your sample with removed paths:

  <a href=3D"https://10.4.45.34:3435/">=0Dhttps://10.4.45.34:3435/</a>

The anchor text has an embedded carriage return character, internally
substituted by an underscore. Regardless which char, the text does not match
the href.

The solution is easy: Drop that unnecessary embedded carriage return. In both
cases in your message.

Closing RESOLVED INVALID, aka "not a bug".


The rule HTTPS_IP_MISMATCH has a score of 0 assigned for SA 3.3, effectively
disabling that rule altogether. You appear to either run 3.2.x (despite setting
version to 3.3.2 in the report), or missed to run sa-update in quite a while
and get the latest rules.

-- 
You are receiving this mail because:
You are the assignee for the bug.