testing Malware Patrol rules?

2009-07-24 Thread Justin Mason
hi Andre -- A SpamAssassin user mentioned this ruleset today: http://malware.hiperlinks.com.br/cgi/submit?action=list_sa it looks good! Would you mind if I added a copy of that to our rule-QA system (http://ruleqa.spamassassin.org/), primarily to determine false positive rate? If that goes

Re: testing Malware Patrol rules?

2009-07-24 Thread Henrik Krohns
On Fri, Jul 24, 2009 at 09:45:42AM +, Justin Mason wrote: hi Andre -- A SpamAssassin user mentioned this ruleset today: http://malware.hiperlinks.com.br/cgi/submit?action=list_sa it looks good! Would you mind if I added a copy of that to our rule-QA system

Re: testing Malware Patrol rules?

2009-07-24 Thread Matt Sergeant
On Fri, 24 Jul 2009 16:09:46 +0300, Henrik Krohns wrote: On Fri, Jul 24, 2009 at 09:45:42AM +, Justin Mason wrote: hi Andre -- A SpamAssassin user mentioned this ruleset today: http://malware.hiperlinks.com.br/cgi/submit?action=list_sa it looks good! Would you mind if I added a

Re: testing Malware Patrol rules?

2009-07-24 Thread Karsten Bräckelmann
On Fri, 2009-07-24 at 10:05 -0400, Matt Sergeant wrote: On Fri, 24 Jul 2009 16:09:46 +0300, Henrik Krohns wrote: I would add \b or so in front of the sigs.. For example, /zief\.pl\//i should be /\bzief\.pl\//i. Unbounded short domains like that have chances of FPs. Plus they should