I noticed ASSP blocks emails from microsoft because of the default bombRe 
filter.
It was a password reset email from microsoft:


Jul-17-16 17:26:50 m1-69207-08649 [Worker_3] [TLS-in] [bombRe] 65.54.190.96 
<[email protected]> to: <snip> [spam found] 
(Regex: bombRe 'PB 20: for dRUg$'  bombRe: 'dRUg$') [Microsoft account password 
reset] -> /var/db/assp/discarded/Microsoft_account_password_reset--3138.eml;

I checked the eml file and it contains the words "drug%" inside a pretty long 
hashed link like this:

 ... href="https://accounts.live.com/......9aQVwkungdRUg%24%24";>

------------------------------------------------------------------------------
What NetFlow Analyzer can do for you? Monitors network bandwidth and traffic
patterns at an interface-level. Reveals which users, apps, and protocols are 
consuming the most bandwidth. Provides multi-vendor support for NetFlow, 
J-Flow, sFlow and other flows. Make informed decisions using capacity planning
reports.http://sdm.link/zohodev2dev
_______________________________________________
Assp-user mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/assp-user

Reply via email to