SA Bugzilla – Bug 2478
Virus appears to be able to hide from SpamAssassin with MIME
Last modified: 2003-09-24 01:11:23 UTC
I have a message (the message is from the SWEN worm going around) and I'm unable to create a SpamAssassin rule for it! SA just won't match on any text, be it body or rawbody. I figure it might hide because of it's weird MIME layering. See attached. I'm trying to use: body OT_FAKE_MS_PATCH /latest version of security update/i describe OT_FAKE_MS_PATCH Fake Microsoft patches score OT_FAKE_MS_PATCH 10.00 but it just won't match.
Created attachment 1403 [details] Message which I can't match body text against
I agree, and I can't match on full, body or rawbody. As this virus is so widespread, I have a horrible feeling that by tommorrow, every spammer int hw world will have realised how to get straight past spamassassin if we can't fx this soon. Ideally, a suggestion for a suitable rule would be great, but failing that, I'm happy to start poking around in the source if necessary!
What version of SA are you using? With the latest CVS, this isn't a problem.
I'm using 2.55, hence why I posted the bug against SA 2.55
Confirmed fixed in 2.60.