Public bug reported:

Antispam check was return false positives for domains that are not on
spam list

To test:

Create a site and then
1) Edit the Configuration -> Security settings
and set Anti-spam to 'Advanced'
Turn on Spamhaus and SURBL URL blacklists
And save the settings

2) Create a group and create a forum post
In your forum post add a url in the TinyMCE Editor, eg http://aaeebl.org
And save the post

You should be alerted that the url is blacklisted (you may not be
alerted - it all depends on the third party response)

You can check via terminal what is happening as well, eg for aaeebl.org
you can do

dig aaeebl.org.black.uribl.com

dig aaeebl.org.spamhaus.org

dig aaeebl.org.multi.surbl.com


If any of the results have an A record in the answer section then the domain 
name is on a blacklist
Except if the A record is 127.0.0.1 - this means the request has been rejected 
before testing

also try
dig aaeebl.org.multi.surbl.org

This should pass where the .com version is failing

** Affects: mahara
     Importance: Medium
     Assignee: Robert Lyon (robertl-9)
         Status: In Progress

** Affects: mahara/15.04
     Importance: Medium
         Status: In Progress

** Affects: mahara/15.10
     Importance: Medium
         Status: In Progress

** Affects: mahara/16.04
     Importance: Medium
         Status: In Progress

** Affects: mahara/16.10
     Importance: Medium
         Status: In Progress

** Affects: mahara/17.04
     Importance: Medium
     Assignee: Robert Lyon (robertl-9)
         Status: In Progress

** Also affects: mahara/15.10
   Importance: Undecided
       Status: New

** Also affects: mahara/17.04
   Importance: Medium
     Assignee: Robert Lyon (robertl-9)
       Status: In Progress

** Also affects: mahara/16.10
   Importance: Undecided
       Status: New

** Also affects: mahara/15.04
   Importance: Undecided
       Status: New

** Also affects: mahara/16.04
   Importance: Undecided
       Status: New

** Changed in: mahara/16.10
       Status: New => In Progress

** Changed in: mahara/16.04
       Status: New => In Progress

** Changed in: mahara/15.10
       Status: New => In Progress

** Changed in: mahara/15.04
       Status: New => In Progress

** Changed in: mahara/15.04
   Importance: Undecided => Medium

** Changed in: mahara/15.10
   Importance: Undecided => Medium

** Changed in: mahara/16.04
   Importance: Undecided => Medium

** Changed in: mahara/16.10
   Importance: Undecided => Medium

** Changed in: mahara/16.10
    Milestone: None => 16.10.3

** Changed in: mahara/16.04
    Milestone: None => 16.04.6

** Changed in: mahara/15.10
    Milestone: None => 15.10.8

** Changed in: mahara/15.04
    Milestone: None => 15.04.12

-- 
You received this bug notification because you are a member of Mahara
Contributors, which is subscribed to Mahara.
Matching subscriptions: Subscription for all Mahara Contributors -- please ask 
on #mahara-dev or mahara.org forum before editing or unsubscribing it!
https://bugs.launchpad.net/bugs/1662367

Title:
  False positives in antispam checking

Status in Mahara:
  In Progress
Status in Mahara 15.04 series:
  In Progress
Status in Mahara 15.10 series:
  In Progress
Status in Mahara 16.04 series:
  In Progress
Status in Mahara 16.10 series:
  In Progress
Status in Mahara 17.04 series:
  In Progress

Bug description:
  Antispam check was return false positives for domains that are not on
  spam list

  To test:

  Create a site and then
  1) Edit the Configuration -> Security settings
  and set Anti-spam to 'Advanced'
  Turn on Spamhaus and SURBL URL blacklists
  And save the settings

  2) Create a group and create a forum post
  In your forum post add a url in the TinyMCE Editor, eg http://aaeebl.org
  And save the post

  You should be alerted that the url is blacklisted (you may not be
  alerted - it all depends on the third party response)

  You can check via terminal what is happening as well, eg for
  aaeebl.org you can do

  dig aaeebl.org.black.uribl.com

  dig aaeebl.org.spamhaus.org

  dig aaeebl.org.multi.surbl.com

  
  If any of the results have an A record in the answer section then the domain 
name is on a blacklist
  Except if the A record is 127.0.0.1 - this means the request has been 
rejected before testing

  also try
  dig aaeebl.org.multi.surbl.org

  This should pass where the .com version is failing

To manage notifications about this bug go to:
https://bugs.launchpad.net/mahara/+bug/1662367/+subscriptions

_______________________________________________
Mailing list: https://launchpad.net/~mahara-contributors
Post to     : mahara-contributors@lists.launchpad.net
Unsubscribe : https://launchpad.net/~mahara-contributors
More help   : https://help.launchpad.net/ListHelp

Reply via email to