I got a false Positive and dont know why:

It is a booking-Conformation from Ryanair.
Here the Log-Entry (I masked the mailadresses):

[logstart]
Aug-27-07 15:58:36 id-3116c6352 195.27.14.155 <itinerary**ryanair.com>
accepting triplet:
(195.27.14.0,itinerary**ryanair.com,xxx**recipient-doma.in) waited: 15m
Aug-27-07 15:58:36 id-3116c6352 195.27.14.155 <itinerary**ryanair.com>
to: xxx**recipient-doma.in recipient accepted unchecked:
xxx**recipient-doma.in Aug-27-07 15:58:38 [SPF] id-3116c6352
195.27.14.155 <itinerary**ryanair.com> to: xxx**recipient-doma.in
Received-SPF: pass (ASSP.nospam: local policy) client-ip=195.27.14.155;
envelope-from=itinerary**ryanair.com; helo=mail2.ryanair.com; Aug-27-07
15:58:38 Commencing DNSBL checks on 195.27.14.155 Aug-27-07 15:58:39
Completed DNSBL checks on 195.27.14.155 Aug-27-07 15:58:39 [DNSBL]
id-3116c6352 195.27.14.155 <itinerary**ryanair.com> to:
xxx**recipient-doma.in DNSBL Received-DNSBL: pass Aug-27-07 15:58:39
[BombData] id-3116c6352 195.27.14.155 <itinerary**ryanair.com> to:
xxx**recipient-doma.in deleting spamming whitelisted tuplet:
(195.27.14.0,ryanair.com) age: 3s Aug-27-07 15:58:39 [BombData]
id-3116c6352 195.27.14.155 <itinerary**ryanair.com> to:
xxx**recipient-doma.in PB: 195.27.14.155 score: 0+50 => 50
reason:BombData Aug-27-07 15:58:39 [BombData] id-3116c6352 195.27.14.155
<itinerary**ryanair.com> to: xxx**recipient-doma.in BombRe: ' Casino '
Travel_Itinerary_  -> c:\assp/spam/Travel_Itinerary_--434.eml
Aug-27-07 15:58:39 id-3116c6352 195.27.14.155 <itinerary**ryanair.com>
to: xxx**recipient-doma.in is disconnected
[logend]

The word "Casino" is not in the mail (can a single word activate the
BombRe? I have an Urologe within my customers, and he might have real
mails containing information about V * * * * a ).

(btw, I had a couple of problems to send this mail caused by using the
name of the product I filled with stars now)



So why is that trapped?

Christian


-------------------------------------------------------------------------
This SF.net email is sponsored by: Splunk Inc.
Still grepping through log files to find problems?  Stop.
Now Search log events and configuration files using AJAX and a browser.
Download your FREE copy of Splunk now >>  http://get.splunk.com/
_______________________________________________
Assp-user mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/assp-user

Reply via email to