Re: [Exim] Regex for catching RAR flavour of Bagle/beagle

Top Page
Delete this message
Reply to this message
Author: Bruce Richardson
Date:  
To: Exim users mailing list
Subject: Re: [Exim] Regex for catching RAR flavour of Bagle/beagle
--
On Fri, Mar 19, 2004 at 01:40:46PM +0100, Marcin Owsiany wrote:
> Might be useful for someone...
>
> condition = ${if and{\
>               {eq{${lookup{$h_subject:}lsearch{CONFDIR/lists/virus-subjects-beagle}{$value}}}{yes}}\
>               {match{$message_body:}{  UmFyIRoHA[A-P]..c[wxyz0-9\+/]...............[HXn3][Q-T][EMUcks08]}}\
>             }{yes}{no}}

>
> My current list of subjects is:


The exiscan patch plus a decent av scanner (e.g. clamav) are both more
reliable and considerably less work than this method, imho. Less likely
to give false positives, also.

--
Bruce

Hummingbirds are the only birds that can fly backwards, apart from
ostriches if you punch them hard enough.
--
Content-Description: Digital signature

[ signature.asc of type application/pgp-signature deleted ]
--