filter evasion

Stefan Mashkevich mash at mashke.org
Fri Nov 7 01:58:54 CET 2003


On Fri, 7 Nov 2003, Matthias Andree wrote:

> > Same here. I also see 'sp<!ham>am' -- didn't even know one could write
> > HTML comments that way -- but that does already tokenize properly
> > ('spam').
> 
> What makes people accept HTML mail today, given all the dangers that
> bogofilter will not detect?

I'm afraid the answer is "the fact that 90% of mail agents out there 
interpret HTML by default, and 80% of users don't know what HTML is, leave 
alone knowing how to disable it in their email".

Clearly, authors of messages like that are targeting people accepting HTML 
-- and they must know what they are doing...

                                                  Stefan





More information about the Bogofilter mailing list