John Rudd wrote:

It would be great if Botnet could do something similar, like:

2.0 BOTNET The submitting mail server looks like part of a Botnet
                            [ip=12.34.56.789 rdns=dhcp12.34.example.org]


Any tips on how to do that? :-}


Well, I had a look, and the good news: it's rather simple to add such a line: just use something like:

    $pms->test_log("ip=$ip, rdns=$rdns");

The bad news, of course, is that BOTNET is a meta rule, so you can't do this for that rule. You can still do so for the individual rules, but as those are going away, that won't help much...

 - Michael

Reply via email to