spfilter-config.xml_0.59_040712 PROJECT="spfilter" VERSION="0.59" DATE="040712" -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
- COMMENT # this file in the current directory . or /usr/local/etc prevents # spfilter from using the cached 'live' copy at all. # its safe to delete this file, spfilter.pl has all the xml embedded # the cleartext-signature will be verified if gpgv available in path. # - section 'preset' describes aliases for sources # - section 'source' describes input-sources (url) # - section 'format' describes output-formats # changes should be done exclusively in ./spfilter-local.xml # which # may be included with argument '-x ./spfilter-local.xml' # the trusted local config allows to override sources, formats # and most config-variables (not complete, work in progress) # use html-entities for this chars: ' < ', ' > ', ' & ' and ' " ' # XML-Viewer at http://spfilter.sourceforge.net/code/xml-view.php
- PRESET
- COMMENT # Aliases listed here will be expanded recursively # the *_ALL variants are not meant for automated blocking # the *_SAFE variants should be safe for most mailservers # more aliases and sources may be added on request
- DEFAULT COMMENT="used if spfilter called without arguments" ALIAS="SPAM_SAFE,DYNAMIC_SAFE"
- SPFILTER COMMENT="EASYNET/PERMBLOCK gone 2003-12-01" ALIAS="DEFAULT"
- COMPLETE COMMENT="expands to 26 sources, 230k records, 20 mb octets" ALIAS="SPAM,DYNAMIC_SAFE,RELAYS_SAFE,ISP_SAFE,COUNTRY_SAFE"
- SPAM ALIAS="SBL,SPEWS,SPAMSITE"
- SPAM_SAFE ALIAS="SBL,SPEWS,SPAMSITE,FLOWGOAWAY"
- SPAM_ALL ALIAS="SBL,SPEWS,SPAMSITE,FLOWGOAWAY,RISKY_NET,BOGO"
- RELAYS ALIAS="DSBL,DSBL_MULTIHOP"
- NJABL ALIAS="NJABL_DATA,NJABL_AUTO"
- NJABL_NODUL ALIAS="NJABL_DATA_NUDUL,NJABL_AUTO" COMMENT="all except DUL"
- DYNAMIC ALIAS="PDL,NJABL_DUL,SORBS_DUL"
- DYNAMIC_SAFE ALIAS="PDL,NJABL_DUL" COMMENT="EASYNET_DYNA gone 2003-12-01"
- DYNAMIC_ALL ALIAS="PDL_DIALUP,EASYNET_DYNA,NJABL_DUL,SORBS_DUL,BADHOST_DYNA"
- COUNTRY ALIAS="KOREA,TAIWAN,HONGKONG,CHINA"
- DSBL_ALL ALIAS="DSBL,DSBL_MULTIHOP,DSBL_UNCONFIRMED" COMMENT="see warnings about unconfirmed"
- SORBS COMMENT="list heavy split up, source not pulic available" ALIAS="SORBS_HTTP,SORBS_SOCKS,SORBS_MISC,SORBS_DUL, SORBS_WEB,SORBS_SPAM,SORBS_ZOMBIE,SORBS_SMTP,SORBS_BLOCK"
- SORBS_SAFE COMMENT="SORBS without SPAM" ALIAS="SORBS,-SORBS_SPAM"
- SORBS_NODUL COMMENT="SORBS_SAFE without DUL and BLOCK" ALIAS="SORBS_SAFE,-SORBS_DUL,-SORBS_BLOCK"
- UCEPROTECT COMMENT="all consolidated" ALIAS="UCEPROT_SINGLE,UCEPROT_NET,UCEPROT_VIRUS"
- ISP_SAFE COMMENT="exclude those which act on complaints" ALIAS="ISP_ABOVE,ISP_AFFINITY,ISP_BELLSOUTH,ISP_BROADWING, ISP_CIBERLYNX,ISP_COGENTCO,ISP_CYBERCON,ISP_HOSTNOC,ISP_INFLOW,ISP_INFOLINK, ISP_INTERNAP,ISP_LAUDERDALE,ISP_LEVEL3,ISP_RACKSPACE,ISP_ROADRUNNER, ISP_TELESP,ISP_VALUENET,ISP_VERIO,ISP_YIPES"
- ISP_ALL COMMENT="all of blackholes.us and a few more" ALIAS="ISP_ABOVE,ISP_AFFINITY,ISP_ATT,ISP_BELLSOUTH, ISP_BROADWING,ISP_CIBERLYNX,ISP_COGENTCO,ISP_CW,ISP_CYBERCON,ISP_ELI, ISP_HE,ISP_HOSTNOC,ISP_INFLOW,ISP_INFOLINK,ISP_INTERBUSINESS,ISP_INTERNAP, ISP_LAUDERDALE,ISP_LEVEL3,ISP_PAJO,ISP_QWEST,ISP_RACKSPACE,ISP_ROADRUNNER, ISP_SPRINT,ISP_TELESP,ISP_UU,ISP_VALUENET,ISP_VERIO,ISP_XO,ISP_YIPES"
- TEST_HTTP COMMENT="deprecated" ALIAS="TEST_LIST"
- LINT_ALL INTERVAL="999" DEBUG="999" ALIAS="SPAM_ALL,RELAYS_ALL,DYNAMIC_ALL,COUNTRY,DSBL_ALL,ISP_ALL"
- BADHOST COMMENT="Spam-sources, usually lists the /24" ALIAS="RISKY_NET,BADHOST_DYNA,BADHOST_IGNORE"
- BADFROM COMMENT="Name-based lists - make shure your app handles FREEMAIL!" ALIAS="RISKY_DOM,BADFROM_FREEMAIL,BADFROM_IGNORE"
- LOCAL_ADDR COMMENT="restrictive, you have been warned" ALIAS="RISKY_NET,BADHOST_IGNORE,KOREA,TAIWAN,ISP_ABOVE, ISP_AFFINITY,ISP_BROADWING,ISP_CIBERLYNX,ISP_COGENTCO,ISP_CYBERCON,ISP_HOSTNOC, ISP_INFLOW,ISP_INFOLINK,ISP_LAUDERDALE,ISP_LEVEL3,ISP_PAJO,ISP_RACKSPACE, ISP_ROADRUNNER,ISP_TELESP,ISP_VALUENET,ISP_YIPES"
- LOCAL_FROM COMMENT="Name-Based list, supported by postfix, SPAMLIST_EXTENDED gone 2003-12-01" ALIAS="RISKY_DOM,BADFROM_IGNORE"
- UPDATE
- COMMENT # update local copy below ./cache, verify gpg-signature # file still must be copied manually to the destination
- SPFILTER-CONFIG.XML TYPE="config" INTERVAL="3" MINSIZE="20" MAXSIZE="100"
- title spfilter xml-configuration
- home http://spfilter.sourceforge.net/code/xml-view.php
- fingerprint 984C 6100 1C0E 5813 4077 6C48 051F C28D 26BD CEF3
- keyserver http://pgp.mit.edu:11371/pks/lookup?search=spfilter & op=index & fingerprint=on
- url http://spfilter.sourceforge.net/code/spfilter-config.xml.bz2
- url http://mirror.bliab.com/spfilter/spfilter-config.xml.bz2
- url http://spfilter.sourceforge.net/code/spfilter-config.xml
- SOURCE
- SBL INTERVAL="1" TYPE="cidr/8" MINSIZE="100" MAXSIZE="1000"
- title SBL Spamhaus Block List
- home http://spamhaus.org/sbl/
- comment may not be redistributed with another name
- url http://mirror.bliab.com/sbl/SBL.cidr.bz2
- url http://spfilter.sourceforge.net/data/sbl/SBL.cidr.bz2
- url http://mirror.bliab.com/sbl/SBL.cidr.bak.bz2
- url http://spfilter.sourceforge.net/data/sbl/SBL.cidr.bak.bz2
- NJABL_AUTO INTERVAL="-1" TYPE="rbldns" MINSIZE="48000" MAXSIZE="128000"
- title NJABL - not just another bogus blocklist
- url rsync://rsync.njabl.org/njabl/rbldnsd/dnsbl.njabl.org.auto
- NJABL_DATA INTERVAL="1" TYPE="rbldns" MINSIZE="1000" MAXSIZE="4000"
- title NJABL - not just another bogus blocklist
- url rsync://rsync.njabl.org/njabl/rbldnsd/dnsbl.njabl.org.data
- NJABL_DUL INTERVAL="3" TYPE="rbldns" ALIAS="NJABL_DATA" OPTION="notext"
- comment extract only DUL from NJABL
- url rsync://rsync.njabl.org/njabl/rbldnsd/dnsbl.njabl.org.data
- regexp_include ^127\.0\.0\.3
- NJABL_DATA_NODUL TYPE="rbldns" ALIAS="NJABL_DATA"
- comment exclude DUL from NJABL
- url rsync://rsync.njabl.org/njabl/rbldnsd/dnsbl.njabl.org.data
- regexp_exclude ^127\.0\.0\.3
- NJABL_SPAM TYPE="rbldns" ALIAS="NJABL_DATA"
- comment extract only spam sources from NJABL
- url rsync://rsync.njabl.org/njabl/rbldnsd/dnsbl.njabl.org.data
- regexp_include :127\.0\.0\.4:$
- SORBS_HTTP INTERVAL="-1" TYPE="addr" MINSIZE="8000" MAXSIZE="32000"
- title SORBS HTTP (Open Proxy)
- zone http.dnsbl.sorbs.net
- url rsync://rsync.bliab.com/sorbs/http.dnsbl.sorbs.net
- SORBS_SOCKS INTERVAL="-1" TYPE="addr" MINSIZE="8000" MAXSIZE="32000"
- title SORBS SOCKS (Open Proxy)
- zone socks.dnsbl.sorbs.net
- url rsync://rsync.bliab.com/sorbs/socks.dnsbl.sorbs.net
- SORBS_MISC INTERVAL="1" TYPE="addr" MINSIZE="100" MAXSIZE="10000"
- title SORBS MISC (Misc Server)
- zone misc.dnsbl.sorbs.net
- url rsync://rsync.bliab.com/sorbs/misc.dnsbl.sorbs.net
- SORBS_DUL INTERVAL="2" TYPE="addr" MINSIZE="100" MAXSIZE="10000"
- title SORBS DUL (Dynamic IP Address)
- url rsync://rsync.bliab.com/sorbs/dul.dnsbl.sorbs.net
- SORBS_WEB INTERVAL="1" TYPE="addr" MINSIZE="10" MAXSIZE="1000"
- title SORBS WEB (Exploitable Server)
- url rsync://rsync.bliab.com/sorbs/web.dnsbl.sorbs.net
- SORBS_SPAM INTERVAL="1" TYPE="addr" MINSIZE="10" MAXSIZE="1000"
- title SORBS SPAM (Spam Received)
- zone spam.dnsbl.sorbs.net
- url rsync://rsync.bliab.com/sorbs/spam.dnsbl.sorbs.net
- SORBS_ZOMBIE INTERVAL="1" TYPE="addr" MINSIZE="1" MAXSIZE="100"
- title SORBS ZOMBIE (Hijacked/Disused Netblock)
- zone zombie.dnsbl.sorbs.net
- url rsync://rsync.bliab.com/sorbs/zombie.dnsbl.sorbs.net
- SORBS_SMTP INTERVAL="1" TYPE="addr" MINSIZE="1" MAXSIZE="100"
- title SORBS SMTP (Open Relay)
- zone smtp.dnsbl.sorbs.net
- url rsync://rsync.bliab.com/sorbs/smtp.dnsbl.sorbs.net
- SORBS_BLOCK INTERVAL="3" TYPE="addr" MINSIZE="1" MAXSIZE="100"
- title SORBS BLOCK (Blocked by Request)
- zone block.dnsbl.sorbs.net
- url rsync://rsync.bliab.com/sorbs/block.dnsbl.sorbs.net
- SPEWS INTERVAL="1" TYPE="cidr/15" MINSIZE="500" MAXSIZE="2000"
- comment also included in relays.osirusoft.com
- url http://mirror.bliab.com/spews/SPEWS.cidr.bz2
- url http://spews.org/spews_list_level1.txt.bz2
- url http://spfilter.sourceforge.net/data/spews/SPEWS.cidr.bz2
- url http://spews.org/spews_list_level1.txt
- SPEWS2 INTERVAL="1" TYPE="cidr/15" MINSIZE="750" MAXSIZE="2500"
- title SPEWS Level 2 (include Level 1)
- comment spews level 2 includes level 1, blocks faster and longer
- url http://mirror.bliab.com/spews/SPEWS2.cidr.bz2
- url http://spews.org/spews_list_level2.txt.bz2
- url http://spfilter.sourceforge.net/data/spews/SPEWS2.cidr.bz2
- url http://spews.org/spews_list_level2.txt
- SPEWS_RELAY INTERVAL="1" TYPE="cidr/15" MINSIZE="500" MAXSIZE="2000"
- title SPEWS Level 1, Proxies Loosers Only
- comment extract only parts referring to dynamic sources
- regexp_include (OpenProxy|Cable|Modem|S456|S586|S1255)
- url http://spews.org/spews_list_level1.txt.bz2
- SPAMSITE INTERVAL="3" TYPE="addr" MINSIZE="20" MAXSIZE="100"
- home http://www.spamsites.org/
- zone spamsites.relays.osirusoft.com
- comment also included in relays.osirusoft.com
- url http://www.spamsites.org/j_ips.txt
- append http://openrbl.org/#
- PDL INTERVAL="2" TYPE="cidr/10" MINSIZE="1" MAXSIZE="4000"
- title PDL - Pan-Am Dynamic Dialup List
- home http://www.pan-am.ca/pdl/
- comment VERBOSE variant of PDL, appends hyperlink
- url http://www.pan-am.ca/pdl/pdl-list.txt.bz2
- url http://spfilter.sourceforge.net/data/input/PDL.bz2
- append http://pan-am.ca/pdl/#
- PDL_DIALUP INTERVAL="3" TYPE="cidr/10" MINSIZE="1" MAXSIZE="4000"
- title PDL - Pan-Am Dynamic Dialup List
- home http://www.pan-am.ca/pdl/
- comment NON-VERBOSE variant of PDL
- url http://www.pan-am.ca/pdl/pdl-list.txt.bz2
- url http://spfilter.sourceforge.net/data/input/PDL.bz2
- RSL INTERVAL="1" TYPE="addr" MAXSIZE="1000"
- title Visi RSL - Verified Open Relays
- home http://relays.visi.com/
- comment update daily due to dynamic nature
- comment RSL is conservative, consider adding DSBL to the set
- url http://relays.visi.com/rsl-list.txt.bz2
- append http://relays.visi.com/nph-l?ip=
- DSBL INTERVAL="1" TYPE="addr" MINSIZE="24000" MAXSIZE="80000"
- title DSBL - Open Singlestage Relays, Proxies and Trojans
- comment update daily due to dynamic nature
- comment zone file in rbldns format
- url rsync://rsync.dsbl.org:873/dsbl/rbldns-list.dsbl.org
- DSBL_MULTIHOP INTERVAL="2" TYPE="addr" MINSIZE="100" MAXSIZE="2000"
- title DSBL - Open Multihop Relays
- comment know the difference between single- and multihop-relays?
- comment zone file in rbldns format
- url rsync://rsync.dsbl.org:873/dsbl/rbldns-multihop.dsbl.org
- tag DSBL Multistage Relay
- DSBL_UNCONFIRMED INTERVAL="2" TYPE="addr" MINSIZE="24000" MAXSIZE="80000"
- title DSBL - Unconfirmed Relay Nominations
- zone unconfirmed.ds bl.org
- comment do not enable this entry unless you know why
- comment zone file in rbldns format
- url rsync://rsync.dsbl.org:873/dsbl/rbldns-unconfirmed.dsbl.org
- PSBL INTERVAL="1" TYPE="addr" MINSIZE="100" MAXSIZE="10000"
- title PSBL - Passive Spam Block List
- url rsync://psbl.surriel.com/psbl/psbl.txt
- CBL INTERVAL="1" TYPE="addr" MINSIZE="16000" MAXSIZE="48000"
- title CBL - composite blocking list - proxies and trojans
- home http://cbl.abuseat.org/
- comment zone file in rbldns format
- url rsync://rsync.cbl.abuseat.org/cbl/list.txt
- PSS INTERVAL="1" TYPE="rbldns" MINSIZE="4000" MAXSIZE="8000" OPTION="notext"
- title PSS - replacment for socks.relays.osirusoft.com
- home http://spambusters.org.ar
- zone pss.spambusters.org.ar
- comment no website/removal yet - please be patient
- comment zone file in rbldns format
- url rsync://rsync.spambusters.org.ar/pss/rbldns.txt
- DRBL INTERVAL="1" TYPE="reverse" MINSIZE="10" MAXSIZE="4000"
- title Distributed Realtime Blocking List
- home http://www.drbl.ofisp.org/eng/
- comment ALL listings imported - do not use for blocking
- url http://mirror.bliab.com/contrib/drbl.all.bz2
- FIVETEN INTERVAL="999" TYPE="axfr/txt" MINSIZE="1000" MAXSIZE="5000"
- home http://www.five-ten-sg.com/blackhole.php
- zone blackholes.five-ten-sg.com
- comment zone not available 2002-10-27, maybe gone
- comment .exception not handled, dont use for blocking
- url http://localhost/fiveten.axfr
- regexp_exclude \.exception$
- FIVETEN_EXPAND INTERVAL="999" TYPE="axfr/txt" OPTION="axfrexpand" MINSIZE="1000" MAXSIZE="5000"
- home http://www.five-ten-sg.com/blackhole.php
- zone blackholes.five-ten-sg.com
- comment zone not available 2002-10-27, maybe gone
- comment .exception handled, may be used for blocking
- comment 120mb ram, 319650 records, 16mb octets
- url http://localhost/fiveten.axfr
- regexp_exclude \.exception$
- FIVETEN_SPAM INTERVAL="999" TYPE="axfr/txt" MINSIZE="1000" MAXSIZE="5000"
- title FIVETEN Blackholes Spam
- home http://www.five-ten-sg.com/blackhole.php
- zone blackholes.five-ten-sg.com
- comment .exception not handled, dont use for blocking
- url http://localhost/fiveten.axfr
- regexp_include \.(spam|webform|bulk|singlestage|multistage|misc)$
- regexp_exclude \.exception$
- FIVETEN_DIAL INTERVAL="999" TYPE="axfr/cname" MINSIZE="1000" MAXSIZE="5000"
- title FIVETEN Blackholes Dialup
- home http://www.five-ten-sg.com/blackhole.php
- zone blackholes.five-ten-sg.com
- comment .exception not handled, dont use for blocking
- url http://localhost/fiveten.axfr
- regexp_exclude \.exception$
- NOMORE INTERVAL="3" TYPE="rbldns" MINSIZE="500" MAXSIZE="10000"
- title no-more-funn - dr. Jorgen Mashs DNSBL
- home http://moensted.dk/spam/no-more-funn/
- zone no-more-funn.moensted.dk
- comment .exception not handled, dont use for blocking
- url http://moensted.dk/spam/no-more-funn/zone/bzip2/no-more-funn.moensted.dk.auto.bz2
- regexp_exclude \.exc?eption$
- NOMORE_DUL INTERVAL="3" TYPE="rbldns" MINSIZE="100" MAXSIZE="8000"
- url http://moensted.dk/spam/no-more-funn/zone/bzip2/no-more-funn.moensted.dk.data.bz2
- UCEPROT_SINGLE INTERVAL="1" MINSIZE="8000" MAXSIZE="24000" OPTION="notext"
- home http://www.uceprotect.net/en/
- url rsync://at-mirror-2.uceprotect.net/UCE-PFSM-1/access
- url rsync://de-mirror-1.uceprotect.net/UCE-PFSM-1/access
- url rsync://at-mirror-1.uceprotect.net/UCE-PFSM-1/access
- tag UCEPROTECT Level #1 - http://www.uceprotect.net/en/index.php?m=3 & s=3
- UCEPROT_NET INTERVAL="1" MINSIZE="300" MAXSIZE="6000" OPTION="notext"
- home http://www.uceprotect.net/en/
- url rsync://at-mirror-1.uceprotect.net/UCE-PFSM-2/access
- url rsync://de-mirror-1.uceprotect.net/UCE-PFSM-2/access
- url rsync://at-mirror-2.uceprotect.net/UCE-PFSM-2/access
- tag UCEPROTECT Level #2 - http://www.uceprotect.net/en/index.php?m=3 & s=4
- UCEPROT_VIRUS INTERVAL="1" MINSIZE="10" MAXSIZE="1000" OPTION="notext"
- home http://www.uceprotect.net/en/
- url rsync://de-mirror-1.uceprotect.net/UCE-PFSM-3/access
- url rsync://at-mirror-2.uceprotect.net/UCE-PFSM-3/access
- url rsync://at-mirror-1.uceprotect.net/UCE-PFSM-3/access
- tag UCEPROTECT Level #3 - http://www.uceprotect.net/en/index.php?m=3 & s=5
- FLOWGOAWAY INTERVAL="7" TYPE="cidr/20" MAXSIZE="20"
- title Flonetwork Netblocks
- home http://us.mirror.menandmice.com/cgi-bin/DoDig?host=ns1.intersil.com & domain=flowgoaway.com & type=AXFR
- zone netlist.flowgoaway.com
- url http://mirror.bliab.com/contrib/flowgoaway.bz2
- url http://spfilter.sourceforge.net/data/contrib/flowgoaway.bz2
- tag Flonetwork Mainsleaze
- PM0NOMORE INTERVAL="7" TYPE="addr" MAXSIZE="20"
- title Postmastergeneral Opt-Out-Spam
- home http://hatcheck.org/google?pm0-no-more.compu.net
- comment maintained source needed
- tag Postmastergeneral Mainsleaze
- TAIWAN INTERVAL="7" TYPE="addr" MINSIZE="20" MAXSIZE="200" OPTION="notext"
- home h ttp://blackholes.us/
- zone taiwan.blackholes.us
- url http://blackholes.us/zones/country/taiwan.classful
- url http://mirror.bliab.com/bus/country/C_TAIWAN.bz2
- HONGKONG INTERVAL="7" TYPE="addr" MINSIZE="20" MAXSIZE="200" OPTION="notext"
- home http://blackholes.us/
- zone hongkong.blackholes.us
- url http://blackholes.us/zones/country/hongkong.classful
- url http://mirror.bliab.com/bus/country/C_HONGKONG.bz2
- CHINA INTERVAL="7" TYPE="addr" MINSIZE="20" MAXSIZE="200" OPTION="notext"
- home http://blackholes.us/
- url http://blackholes.us/zones/country/china.classful
- url http://mirror.bliab.com/bus/country/C_CHINA.bz2
- KOREA INTERVAL="7" TYPE="addr" MAXSIZE="50" OPTION="notext"
- home http://blackholes.us/
- url http://blackholes.us/zones/country/korea.classful
- url http://mirror.bliab.com/bus/country/C_KOREA.bz2
- KRCN INTERVAL="7" TYPE="cidr/10" MAXSIZE="10"
- title Korean and Chinese Country Block Combined
- home http://www.okean.com/asianspamblocks.html
- url http://www.okean.com/sinokoreacidr.txt
- tag KOREA & CHINA Mail Rejected
- append http://www.apnic.net/apnic-bin/whois2.pl?key=
- ISP_ABOVE INTERVAL="7" TYPE="addr" MAXSIZE="20" OPTION="notext"
- title blackholes.us: Above.net (Score 6490)
- home http://blackholes.us/
- url http://blackholes.us/zones/isp/above.classful
- tag ISP ABOVE.NET http://hatcheck.org/google?above.net; http://hatcheck.org/sbl?above
- ISP_AFFINITY INTERVAL="7" TYPE="addr" MAXSIZE="100" OPTION="notext"
- title blackholes.us: Affinity (Skynetweb/Valueweb)
- home http://blackholes.us/
- zone affinity.blackholes.us
- url http://blackholes.us/zones/isp/affinity.classful
- tag ISP AFFINITY http://hatcheck.org/google?affinity/skynetweb/valueweb; http://hatcheck.org/sbl?affinity; http://hatcheck.org/sbl?valueweb
- ISP_ATT INTERVAL="7" TYPE="addr" MAXSIZE="20" OPTION="notext"
- title AT & T WorldNet (Score 77100)
- url http://mirror.bliab.com/contrib/isp_att.bz2
- url http://spfilter.sourceforge.net/data/contrib/isp_att.bz2
- tag ISP ATT.NET http://hatcheck.org/google?att; http://hatcheck.org/sbl?att
- ISP_BELLSOUTH INTERVAL="7" TYPE="addr" MAXSIZE="20" OPTION="notext"
- title blackholes.us: Bellsouth, Home of Eddie Marin, Steve Hardigree and others
- home http://blackholes.us/
- zone bellsouth.blackholes.us
- url http://blackholes.us/zones/isp/bellsouth.classful
- tag ISP BELLSOUTH http://hatcheck.org/google?bellsouth; http://hatcheck.org/sbl?bellsouth
- ISP_BROADWING INTERVAL="7" TYPE="addr" MAXSIZE="20" OPTION="notext"
- title blackholes.us: Broadwing ISP (Score 5180)
- home htt p://blackholes.us/
- zone broadwing.blackholes.us
- url http://blackholes.us/zones/isp/broadwing.classful
- tag ISP BROADWING http://hatcheck.org/google?broadwing; http://hatcheck.org/sbl?broadwing
- ISP_CIBERLYNX INTERVAL="7" TYPE="addr" MAXSIZE="60" OPTION="notext"
- title blackholes.us: Ciberlynx Spamhaven (Score 1180)
- home http://blackholes.us/
- zone ciberlynx.blackholes.us
- url http://blackholes.us/zones/isp/ciberlynx.classful
- tag ISP CYBERLYNX http://hatcheck.org/sbl?ciberlynx
- ISP_COGENTCO INTERVAL="7" TYPE="addr" MAXSIZE="10" OPTION="notext"
- title Cogentco (Score 2650)
- home http://blackholes.us/
- zone cogentco.blackholes.us
- comment reformed? - abuse@cogentco.com now acting on complaints but still too high at spamhaus.org
- url http://blackholes.us/zones/isp/cogentco.classful
- url http://mirror.bliab.com/bus/isp/ISP_COGENTCO.bz2
- tag ISP COGENTCO http://hatcheck.org/sbl?cogentco
- ISP_CW INTERVAL="7" TYPE="addr" MAXSIZE="80" OPTION="notext"
- title blackholes.us: Cable & Wireless Spamhaven (Score 8330)
- home http://blackholes.us/
- url http://blackholes.us/zones/isp/cw.classful
- tag ISP CW.NET http://hatcheck.org/google?cw.net; http://hatcheck.org/sbl?cw
- ISP_CYBERCON INTERVAL="7" TYPE="addr" MAXSIZE="40" OPTION="notext"
- title blackholes.us: Cybercon Spamhaven (Score 889)
- home http://blackholes.us/
- zone cybercon.blackholes.us
- url http://blackholes.us/zones/isp/cybercon.classful
- tag ISP CYBERCON http://hatcheck.org/google?cybercon; http://hatcheck.org/sbl?cybercon
- ISP_ELI INTERVAL="7" TYPE="addr" MAXSIZE="40" OPTION="notext"
- title blackholes.us: ELI (Score 10400)
- home http://blackholes.us/
- comment probation 2002-10-17 - slowly cleaning up the mess
- comment see http://hatcheck.org/google?author:elipdx2002%40hotmail.com
- url http://blackholes.us/zones/isp/eli.classful
- tag ISP ELI.NET http://hatcheck.org/google?eli.net; http://hatcheck.org/sbl?eli.net
- ISP_HE INTERVAL="7" TYPE="addr" MAXSIZE="20" OPTION="notext"
- title blackholes.us: HE Spamhaven (Score 5570)
- comment abuse@ acted on complaint within hours, 2002-11-13
- home http://blackholes.us/
- url http://blackholes.us/zones/isp/he.classful
- tag ISP HE.NET http://hatcheck.org/google?he.net; http://hatcheck.org/sbl?he.net
- ISP_HOSTNOC INTERVAL="7" TYPE="cidr/16" MAXSIZE="20" OPTION="notext"
- title Hostnoc Spamhaven, Hosting Azoogle
- home http://blackholes.us/
- zone hostnoc.blackholes.us
- url http://blackholes.us/zones/isp/hostnoc.classful
- tag ISP HOSTNOC http://hatcheck.org/google?hostnoc; http://hatcheck.org/sbl?hostnoc
- ISP_INFLOW INTERVAL="7" TYPE="addr" MAXSIZE="20" OPTION="notext"
- title blackholes.us: INFLOW Spamhaven (Score 1190)
- home http://blackholes.us/
- zone inflow.blackholes.us
- url http://blackholes.us/zones/isp/inflow.classful
- tag ISP INFLOW http://hatcheck.org/google?inflow; http://hatcheck.org/sbl?inflow
- ISP_INFOLINK INTERVAL="7" TYPE="addr" MAXSIZE="20" OPTION="notext"
- title blackholes.us: INFOLINK Spamhost - Home of Reinertsen and Hispeedmedia
- home http://blackholes.us/
- zone infolink.blackholes.us
- url http://blackholes.us/zones/isp/inflow.classful
- tag ISP INFOLINK http://hatcheck.org/google?infolink; http://hatcheck.org/sbl?infolink
- ISP_INTERBUSINESS INTERVAL="7" TYPE="addr" MAXSIZE="60" OPTION="notext"
- title blackholes.us: Interbusiness.it
- home http://blackholes.us/
- zone interbusiness.blackhol es.us
- url http://blackholes.us/zones/isp/interbusiness.classful
- tag ISP INTERBUSINESS http://hatcheck.org/google?interbusiness; http://hatcheck.org/sbl?interbusiness
- ISP_INTERNAP INTERVAL="7" TYPE="addr" MAXSIZE="20" OPTION="notext"
- title blackholes.us: INTERNAP (Score 1460)
- home http://blackholes.us/
- zone internap.blackholes.us
- url http://blackholes.us/zones/isp/internap.classful
- tag ISP INTERNAP http://hatcheck.org/google?internap; http://hatcheck.org/sbl?internap
- ISP_LAUDERDALE INTERVAL="7" TYPE="addr" MAXSIZE="20" OPTION="notext"
- title blackholes.us: LAUDERDALE Spamhost, Home of Marin, Hardigree, Richter and more
- home http://blackholes.us/
- zone lauderdale.blackholes.us
- url http://blackholes.us/zones/isp/lauderdale.classful
- tag ISP LAUDERDALE Spamhost http://hatcheck.org/google?lauderdale.net; http://hatcheck.org/sbl?lauderdale
- ISP_LEVEL3 INTERVAL="7" TYPE="addr" MAXSIZE="1000" OPTION="notext"
- title blackholes.us: Level3 (Score 13600)
- home http://blackholes.us/
- zone level3.blackholes.us
- url http://blackholes.us/zones/isp/level3.classful
- tag ISP LEVEL3 http://hatcheck.org/google?level3; http://hatcheck.org/sbl?level3
- ISP_PAJO INTERVAL="7" TYPE="addr" MAXSIZE="20" OPTION="notext"
- title blackholes.us: Pajo (cleaning up their network)
- home http://blackholes.us/
- comment seems to actually kick spammers in early 2003
- comment removed from ISP_SAFE 2003-05-17
- url http://blackholes.us/zones/isp/pajo.classful
- tag ISP PAJO http://hatcheck.org/google?pajo; http://hatcheck.org/sbl?pajo
- ISP_QWEST INTERVAL="7" TYPE="addr" MAXSIZE="20" OPTION="notext"
- title Qwest Spamsupport, Home of Richard Burke, Scott Hirsch and others
- home http://blackholes.us/
- url http://blackholes.us/zones/isp/qwest.classful
- tag ISP QWEST http://hatcheck.org/google?qwest; http://hatcheck.org/sbl?qwest
- ISP_RACKSPACE INTERVAL="7" TYPE="addr" MAXSIZE="20" OPTION="notext"
- title blackholes.us: Rackspace, Hosting Haberli, Azoogle
- home http://blackholes.us/
- zone rackspace.blackholes.us
- url http://blackholes.us/zones/isp/rackspace.classful
- tag ISP RACKSPACE http://hatcheck.org/google?rackspace; http://hatcheck.org/sbl?rackspace
- ISP_ROADRUNNER INTERVAL="7" TYPE="addr" MAXSIZE="60" OPTION="notext"
- title blackholes.us: Roadrunner (Score 136000)
- home http://blackholes.us/
- url http://blackholes.us/zones/isp/rr.classful
- tag ISP ROADRUNNER; http://hatcheck.org/google?rr/roadrunner; http://hatcheck.org/sbl?rr
- ISP_SPRINT INTERVAL="7" TYPE="cidr/11" MAXSIZE="100" OPTION="notext"
- title Sprint Spamhaven, Home of Reinertsen, Baer, Docdrugs and others
- home http://blackholes.us/
- zone sprint.blackholes.us
- url http://blackholes.us/zones/isp/sprint.classful
- url http://mirror.bliab.com/bus/isp/ISP_SPRINT.bz2
- tag ISP SPRINT http://hatcheck.org/sbl?sprint
- ISP_TELESP INTERVAL="7" TYPE="cidr/16" MAXSIZE="40" OPTION="notext"
- title Telesp Brasilia, Hosting Spammers, Open Proxies, @abuse MIA
- home http://spamhaus.org/sbl/listings.lasso?isp=telesp
- url http://mirror.bliab.com/contrib/isp_telesp.bz2
- url http://spfilter.sourceforge.net/data/contrib/isp_telesp.bz2
- tag ISP TELESP.BR http://hatcheck.org/google?telesp; http://hatcheck.org/sbl?telesp
- ISP_UU INTERVAL="7" TYPE="addr" MAXSIZE="20" OPTION="notext"
- title UU. NET WorldCom (Score 70800)
- home http://spamhaus.org/sbl/listings.lasso?isp=uu.net
- comment unfortunately not available at blackholes.us
- url http://mirror.bliab.com/contrib/isp_uu.bz2
- url http://spfilter.sourceforge.net/data/contrib/isp_uu.bz2
- tag ISP UU.NET http://hatcheck.org/google?uu.net; http://hatcheck.org/sbl?uu.net
- ISP_VALUENET INTERVAL="7" TYPE="addr" MAXSIZE="20" OPTION="notext"
- title blackholes.us: Valuenet Spamhaus (Score 367)
- home http://blackholes.us/
- zone valuenet.blackholes.us
- url http://blackholes.us/zones/isp/valuenet.classful
- tag ISP VALUENET http://hatcheck.org/google?valuenet; http://hatcheck.org/sbl?valuenet
- ISP_VERIO INTERVAL="7" TYPE="addr" MAXSIZE="150" OPTION="notext"
- title blackholes.us: Verio Spamhaven (Score 51300)
- home http://blackholes.us/
- url http://blackholes.us/zones/isp/verio.classful
- tag ISP VERIO http://hatcheck.org/google?verio; http://hatcheck.org/sbl?verio
- ISP_WANADOO INTERVAL="7" TYPE="addr" MAXSIZE="60" OPTION="notext"
- title blackholes.us: Wanadoo.fr (Score )
- home http://blackholes.us/
- comment classful data not yet available at blackholes.us
- zone wanadoo-fr.blackholes.us
- url http://blackholes.us/zones/isp/wanadoo-fr.classful
- tag ISP WANADOO.FR http://hatcheck.org/google?wanadoo
- ISP_XO INTERVAL="7" TYPE="addr" MAXSIZE="80" OPTION="notext"
- title blackholes.us: XO/Concentric (Score [out of range])
- home http://blackholes.us/
- url http://blackholes.us/zones/isp/xo.classful
- tag ISP XO/CONCENTRIC http://hatcheck.org/google?concentric; http://hatcheck.org/sbl?xo
- ISP_YIPES INTERVAL="7" TYPE="addr" MAXSIZE="60" OPTION="notext"
- title blackholes.us: Yipes (Score 1340)
- home http://blackholes.us/
- url http://blackholes.us/zones/isp/yipes.classful
- tag ISP YIPES http://hatcheck.org/google?yipes; http://hatcheck.org/sbl?yipes
- BOGO INTERVAL="7" TYPE="cidr/3" MAZSIZE="2" OPTION="notext"
- home http://www.cymru.com/Documents/bogon-list.html
- url http://mirror.bliab.com/bogo/BOGO.cidr.aggreg.gz
- url http://www.cymru.com/Documents/bogon-bn-agg.txt
- url http://www.cymru.com/Documents/bogon-bn-nonagg.txt
- append - http://openrbl.org/whois?i=
- RISKY_NET INTERVAL="1" TYPE="cidr/16" MINSIZE="4000" MAXSIZE="16000"
- title Spamsources, Proxies, multiple aggregated as /24
- comment experimental, entries expire only after few months
- comment expects PERMBLOCK, SPEWS and Relay/Proxylist
- url http://mirror.bliab.com/contrib/risky_net.bz2
- url http://spfilter.sourceforge.net/data/contrib/risky_net.bz2
- BADHOST_DYNA INTERVAL="2" TYPE="cidr/16" MINSIZE="20" MAXSIZE="200"
- title dialups, cable and adsl, usually added after spam
- comment incomplete, includes dsl-ranges, usually added after spam
- comment warning: braeks a couple of legit mailservers on static dsl
- url http://mirror.bliab.com/contrib/badhost_dyna.bz2
- url http://spfilter.sourceforge.net/data/contrib/badhost_dyna.bz2
- BADHOST_IGNORE INTERVAL="3" TYPE="addr" MAXSIZE="10"
- title entries to be ignored (overwrite)
- comment neutralize entries in other lists
- url http://mirror.bliab.com/contrib/bad host_ignore.bz2
- url http://spfilter.sourceforge.net/data/contrib/badhost_ignore.bz2
- COMMENT # WARNING: sources below contain hostnames and email-addresses # not all application can handle (mixed) addr and host
- RISKY_DOM INTERVAL="1" TYPE="host" MINSIZE="500" MAXSIZE="4000"
- title Spamming/Unwanted Hosts, Domains and Localparts
- comment applied to both email and reverse-dns
- url http://mirror.bliab.com/contrib/risky_dom.bz2
- url http://spfilter.sourceforge.net/data/contrib/risky_dom.bz2
- BADFROM_FREEMAIL INTERVAL="2" TYPE="host" MINSIZE="50" MAXSIZE="200"
- title Freemail and other often forged Domains (MX-Check)
- comment use only if your filter handles the tag 'FREEMAIL'
- url http://mirror.bliab.com/contrib/badfrom_freemail.bz2
- url http://spfilter.sourceforge.net/data/contrib/badfrom_freemail.bz2
- BADFROM_IGNORE INTERVAL="3" TYPE="host" MINSIZE="1" MAXSIZE="20"
- title Neutralize Entries from other Sources
- comment use only if your filter handles the tag 'IGNORE'
- url http://mirror.bliab.com/contrib/badfrom_ignore.bz2
- url http://spfilter.sourceforge.net/data/contrib/badfrom_ignore.bz2
- COMMENT # entries used for testing and quality control (soon...)
- TEST_LIST TYPE="cidr/16" MAXSIZE="50"
- title small list for testing via http
- home http://spfilter.sourceforge.net/
- comment used with the spfilter Makefile: 'make test'
- comment manual usage: 'perl ./spfilter.pl -v -d TEST_LIST'
- url http://mirror.bliab.com/contrib/test_list.bz2
- TEST_AXFR TYPE="axfr/txt" MINSIZE="1" MAXSIZE="20"
- title small list for debugging axfr $GENERATE and .exception
- home http://spfilter.sourceforge.net/
- comment manual usage: 'perl ./spfilter.pl -v -d TEST_AXFR'
- regexp_exclude \.exception$
- url http://mirror.bliab.com/contrib/test_axfr.bz2
- FORMAT
- COMMENT # output format options, all keys optional # notation (notation): use 'reverse' for dns (default 'octet') # option=[bindhack|tinydnshack|tcpserverhack]: special processing # head (string): prepended on each line, usually empty # separator (string): between $addr and $text (default "\t") # tail (string): appended after $text (default none) # magic_update (boolean): preserve lines not inserted by spfilter # keys listed below may not work: (run spfilter with argument -o) # outdir (string) write generated list into this directory # outfile (string): specify individual filename of generated list # macros: {AGENT}, {YYMMDD}; for dnsbl: {ZONE}, {ADDR}, {TTL} # todo: macros {OUTFILE}, {SOURCES}, {HOSTNAME}
- OCTETS TYPE="txt" PUBLISH="1" COMMENT="default format, tab delimited"
- REVERSE TYPE="txt" PUBLISH="1" COMMENT="reversed for dns" NOTATION="reverse"
- CIDR TYPE="txt" NOTATION="cidr" OPTION="notext" COMMENT="hack: output with /8,/16,/24 or /23, no text"
- CDB TYPE="cdb" COMMENT="djbs cdb, requires CDB_File"
- DB TYPE="db" COMMENT="buggy old dbm, requires DB_File"
- GDBM TYPE="gdbm" COMMENT="gnu dbm, requires GDBM_File"
- BADFROM.TAB MAGIC_UPDATE="0"
- title generic tab-delimited badfrom, safe for scripting
- comment same as octets.tab, but for use with hostnames and badfrom
- comment legacy, will be removed soon
- include # experimental extensions by {AGENT}: # EXCEPTION, IGNORE or DUNNNO: do not include any matching records in output # WHITELIST, OK or 250: pass entry, sendmail will whitelist on this keyword # FREEMAIL or MXCHECK: pass entry, rcptfilter will deny if not from mx
- SENDMAIL PUBLISH="1" MAGIC_UPDATE="1" MAXLENGTH="1023"
- title stock sendmail with SPAMFRIEND
- home http://www.sendmail.org/m4/anti-spam.html
- include # reference see http://www.sendmail.org/m4/anti-spam.html Connect:10 RELAY Connect:127.0.0 RELAY Connect:192.168 RELAY To:abuse@ SPAMFRIEND To:postmaster@ SPAMFRIEND To:nofilter@ SPAMFRIEND 127.0.0.2 553 Test sendmail_access {AGENT} (20{YYMMDD}) # run 'makemap hash /etc/mail/access < SPFILTER.sendmail'
- POSTFIX PUBLISH="1" MAGIC_UPDATE="0"
- title postfix (without quotes)
- home http://www.postfix.org/
- include # reference see http://www.postfix.org/access.5.html 10 OK 127.0.0 OK 192.168 OK 127.0.0.2 553 Test postfix {AGENT} (20{YYMMDD}) # needs: smtpd_client_restrictions = check_client_access hash:/usr/local/etc/postfix/spfilter_access, ...
- QMAIL_UCE PUBLISH="1" MAGIC_UPDATE="1" OPTION="tcpserverhack"
- title qmail with anti-uce-patches (set variable DENYMAIL)
- home http://www.qmail.org/
- comment tcprules also takes notation 'ranges' (not implemented)
- include # qmail with consolidated anti-uce patches # run tcprules tcprules.dat tcprules.tmp < ./outdir/SPFILTER.qmail_uce 10.:allow,DENYMAIL="" 127.0.0.:allow,DENYMAIL="",RELAYCLIENT="" 192.168.:allow,DENYMAIL="" 127.0.0.2:allow,DENYMAIL="553 Test qmail_uce {AGENT} (20{YYMMDD})"
- separator :allow,DENYMAIL="
- RBLSMTPD PUBLISH="1" MAGIC_UPDATE="1" OPTION="tcpserverhack"
- title qmail with rblsmtpd (set variable RBLSMTPD)
- home http://cr.yp.to/ucspi-tcp/rblsmtpd.html
- include # rblsmtpd only returns temporary error (451) by default # use 'rblsmtpd -b -C' for permanent and failsafe rejection (553) # run 'tcprules tcprules.dat tcprules.tmp < ./outdir/SPFILTER.rblsmtpd' 10.:allow,RBLSMTPD="" 127.0.0.:allow,RBLSMTPD="",RELAYCLIENT="" 192.168.:allow,RBLSMTPD="" 127.0.0.2:allow,RBLSMTPD="Test rblsmtpd {AGENT} (20{YYMMDD})"
- separator :allow,RBLSMTPD="
- TCPSERVER_DENY OPTION="tcpserverhack"
- title tcpserver (reject connection right away, text unused)
- home http://cr.yp.to/ucspi-tcp/tcpserver.html
- comment just to keep them out of the maillog...
- comment drop connection on sight, insane clients may dos you for that
- comment tcpserver requires 'option="tcpserverhack"', append dot to partial octets
- separator :deny,DENYMAIL="
- COURIER PUBLISH="1" MAGIC_UPDATE="0"
- title courier-mta (set variable BLOCK)
- home http://courier-mta.org/
- comment makedat also takes 'cidr' and 'ranges' if Net::CIDR installed
- include # courier-mta etc/smtpaccess 10 allow,BLOCK="",RELAYCLIENT,REQUIRECERT="NO",BOFHBADMIME="accept" 127.0.0 allow,BLOCK="",RELAYCLIENT,REQUIRECERT="NO",BOFHBADMIME="accept" 192.168 allow,BLOCK="",RELAYCLIENT,REQUIRECERT="NO",BOFHBADMIME="accept" 127.0.0.2 allow,BLOCK="Test courier {AGENT} (20{YYMMDD})" # run '/usr/libexec/courier/bin/makesmtpaccess'
- separator allow,BLOCK="553
- COURIERTCPD_DENY
- title couriertcpd (reject connection right away, text unused)
- comment just to keep them out of the maillog...
- EXIM PUBLISH="1" MAGIC_UPDATE="1"
- home http://www.exim.org/
- comment working config examples needed!
- include # exim needs: host_reject_recipients = net-lsearch;/etc/mail/host_reject # note: exim also supports cdb as generated by spfilter 127.0.0.2:Test exim {AGENT} (20{YYMMDD})
- DB_DUMP
- title BerkeleyDB v3+ Btree
- home http://www.sleepycat.com/docs/utility/
- comment null-terminated, compatible with postfix and C
- comment compile: db_load -f SPFILTER.db_dump -T -t btree SPFILTER.db
- comment ATTN: dont mess up format definition below
- include VERSION=3 format=print type=btree HEADER=END
- REVERSE.CSV NOTATION="reverse" MAGIC_UPDATE="0"
- title reverse octets, common csv format (quoted)
- RBLDNSD NOTATION="octets" MAGIC_UPDATE="0"
- title Michael Tokarev lightweight dnsbl-server
- comment http://www.corpit.ru/mjt/rbldnsd/
- comment no options needed at all
- include :127.0.0.2:http://openrbl.org/$
- QUERYPERF NOTATION="reverse" OPTION="notext"
- comment dnsbl performance test
- include ; #server {ADDR} ; #port 53 ; #maxwait 1
- BIND PUBLISH="1" NOTATION="reverse" OPTION="bindhack" MAXLENGTH="255"
- title dnsbl-in-a-box with bind
- comment specify name and ip with -z {ZONE},{ADDR},{TTL}
- comment bind requires option=bindhack, limits txt to 255 chars and changes commentchar to ;
- comment delegate zone {ZONE} to nameserver at {ADDR}
- include ; bind zone {ZONE}., nameserver on [{ADDR}] ; in named.conf specify: zone "{ZONE}" { type master; file "SPFILTER.bind"; }; $TTL {TTL} ; {default ttl for positive answers} $ORIGIN {ZONE}. @ SOA {ZONE}. root.{ZONE}. ( 20{YYMMDD}00 ; serial no. 10800 ; refresh {interval for syncing slaves} 3600 ; retry {retry per hour on failures} 604800 ; expire {remove dead slave zone after 7 days} 21600) ; minimum {ttl for negative answers} ; authoritative nameserver @ 86400 NS {ZONE}. @ 86400 MX 100 {ZONE}. ; {mailserver assumed on same address} @ 86400 A {ADDR} ; {website assumed on same address} www 86400 A {ADDR} ; {website assumed on same address} ; test-entries about TXT "zone built by {AGENT} (20{YYMMDD})" 2.0.0.127 TXT "Test bind {ZONE} [{ADDR}] (20{YYMMDD})" 2.0.0.127 A 127.0.0.2 ; {every dnsbl should have that}
- TINYDNS PUBLISH="1" NOTATION="reverse" OPTION="tinydnshack"
- title dnsbl-in-a-box with djb's tinydns
- comment specify name and ip with -z {ZONE},{ADDR},{TTL}
- comment tinydns requires option="tinydnshack", expand macro {ZONE} and transform :
- comment delegate zone {ZONE} to nameserver at {ADDR}
- include # statically define zone '{ZONE}' at address {ADDR} for tinydns Z.{ZONE}:{ZONE}:root.{ZONE}.:20{YYMMDD}00:14400:3600:604800:28800:{TTL}: & {ZONE}::{ZONE}:86400: ^{ADDR}:{ZONE}:86400: @{ZONE}::{ZONE}:100:86400: +{ZONE}:{ADDR}:86400: +www.{ZONE} :{ADDR}:86400: '2.0.0.127.{ZONE}:Test {ZONE} {AGENT} {YYMMDD} http\072//spfilter.sourceforge.net/: +2.0.0.127.{ZONE}:127.0.0.2:{TTL} # run 'cp ./outdir/SPFILTER.tinydns ./data; tinydns-data' # test1: dig @{ADDR} 2.0.0.127.{ZONE} any # test2: dig 2.0.0.127.{ZONE} any
- secondline .{ZONE}:127.0.0.2:{TTL}
- SQLDUMP NOTATION="octets" MAGIC_UPDATE="0"
- comment parse sources into mysql
- include # created by {AGENT} on 20{YYMMDD} DROP TABLE IF EXISTS spfilter; CREATE TABLE spfilter ( addr varchar(16) NOT NULL default '', text varchar(127) NOT NULL default '', KEY addr (addr) ); # query: SELECT * from spfilter WHERE addr='$a.$b.$c.$d' OR addr='$a.$b.$c'; # tip: insert into non-indexed db and create the index later will be faster # note: sould really use LOAD DATA INFILE and read from csv above
- linestart INSERT INTO spfilter VALUES ('
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFA8w6FBR/CjSa9zvMRAtC6AJ4+d6YainnolQntvwHNJQgAc47BrgCePN8T AyxOLE4z2ITZwjcHPM8zbrs= =0tha -----END PGP SIGNATURE-----