Hello guys,

I have the following SA rule which is supposed to block base64 encoded mails:

body EN_BASE64_B /(Content-Transfer-Encoding: base64\sContent-Type: text\/(plain|html); charset="?utf-8"?)|(Content-Type: text\/(plain|html); charset="?utf-8"?\sContent-Transfer-Encoding: base64)/i
describe             EN_BASE64_B        TEXT OR HTML B64 ENCODED
score                 EN_BASE64_B        5

this is the mail that i want to stop:

(... header header...)
X-Scanned-By: MIMEDefang 2.79 # last header line here

Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64



the rule don't match for this mail, but it match when i had an empty line like this:

   #empty line here
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

How can i do to match the both, with the empty line and without it? THANK'S

Signature Academique

Reply via email to