{"id":441,"date":"2022-01-09T15:28:55","date_gmt":"2022-01-09T14:28:55","guid":{"rendered":"https:\/\/nissel.it\/?p=441"},"modified":"2022-01-09T15:51:54","modified_gmt":"2022-01-09T14:51:54","slug":"phishing-mails-mit-spamassassin-erkennen","status":"publish","type":"post","link":"https:\/\/nissel.it\/index.php\/2022\/01\/09\/phishing-mails-mit-spamassassin-erkennen\/","title":{"rendered":"Phishing Mails mit spamassassin erkennen"},"content":{"rendered":"\n<p>Mit Spamassassin 3.4.2 gibt es mit dem Plugin &#8222;Phishing&#8220; die M\u00f6glichkeit Mails nach Phishing-URLs zu durchsuchen.<\/p>\n\n\n\n<!--more-->\n\n\n\n<p>Die Listen mit Phishing URL m\u00fcssen \u00fcber einen cronjob herunter geladen werden. Ich habe dazu ein Skript in \/etc\/cron.daily\/update-mail-phishing erstellt.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>#!\/bin\/bash\n\/usr\/bin\/curl -L https:\/\/openphish.com\/feed.txt -z \/etc\/mail\/spamassassin\/openphish-feed.txt -o \/etc\/mail\/spamassassin\/openphish-feed.txt &amp;&gt; \/dev\/null\n\/usr\/bin\/curl -L https:\/\/raw.githubusercontent.com\/mitchellkrogza\/Phishing.Database\/master\/phishing-links-ACTIVE.txt -z \/etc\/mail\/spamassassin\/phishing-links-ACTIVE.txt -o \/etc\/mail\/spamassassin\/phishing-links-ACTIVE.txt  &amp;&gt; \/dev\/null\n\/usr\/bin\/curl -L http:\/\/data.phishtank.com\/data\/online-valid.csv -z \/etc\/mail\/spamassassin\/phishtank-feed.csv -o \/etc\/mail\/spamassassin\/phishtank-feed.csv &amp;&gt; \/dev\/null<\/code><\/pre>\n\n\n\n<p>Das Skript muss nat\u00fcrlich ausf\u00fchrbar sein.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>chmod 700 \/etc\/cron.daily\/update-mail-phishing<\/code><\/pre>\n\n\n\n<p>In Spamassassin kann nun die Konfiguration hinzugef\u00fcgt werden.<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>loadplugin Mail::SpamAssassin::Plugin::Phishing\nifplugin Mail::SpamAssassin::Plugin::Phishing\n  phishing_openphish_feed \/etc\/mail\/spamassassin\/openphish-feed.txt\n  phishing_openphish_feed \/etc\/mail\/spamassassin\/phishing-links-ACTIVE.txt\n  phishing_phishtank_feed \/etc\/mail\/spamassassin\/phishtank-feed.csv\n  body     URI_PHISHING      eval:check_phishing()\n  describe URI_PHISHING      Url match phishing in feed\n  score    URI_PHISHING      5.0\nendif<\/code><\/pre>\n\n\n\n<p>Nach dem Neustart vom Spamassassin kann diese Regel einfach getestet werden, indem man sich eine Mail mit einer URL, aus den Konfigurierten Listen, schickt. <\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Quellen <\/h2>\n\n\n\n<p><a href=\"https:\/\/git.ispconfig.org\/ispconfig\/ispconfig3\/-\/issues\/5596\">https:\/\/git.ispconfig.org\/ispconfig\/ispconfig3\/-\/issues\/5596<\/a><\/p>\n\n\n\n<p><a href=\"https:\/\/github.com\/mitchellkrogza\/Phishing.Database\">https:\/\/github.com\/mitchellkrogza\/Phishing.Database<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Mit Spamassassin 3.4.2 gibt es mit dem Plugin &#8222;Phishing&#8220; die M\u00f6glichkeit Mails nach Phishing-URLs zu durchsuchen.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[5,28],"class_list":["post-441","post","type-post","status-publish","format-standard","hentry","category-webserver","tag-mail","tag-spamassassin"],"_links":{"self":[{"href":"https:\/\/nissel.it\/index.php\/wp-json\/wp\/v2\/posts\/441","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nissel.it\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nissel.it\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nissel.it\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nissel.it\/index.php\/wp-json\/wp\/v2\/comments?post=441"}],"version-history":[{"count":2,"href":"https:\/\/nissel.it\/index.php\/wp-json\/wp\/v2\/posts\/441\/revisions"}],"predecessor-version":[{"id":443,"href":"https:\/\/nissel.it\/index.php\/wp-json\/wp\/v2\/posts\/441\/revisions\/443"}],"wp:attachment":[{"href":"https:\/\/nissel.it\/index.php\/wp-json\/wp\/v2\/media?parent=441"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nissel.it\/index.php\/wp-json\/wp\/v2\/categories?post=441"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nissel.it\/index.php\/wp-json\/wp\/v2\/tags?post=441"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}