NAME
Mail::SpamAssassin::Handler::SVG - A MIME-part handler for image/svg+xml parts
SYNOPSIS
loadhandler Mail::SpamAssassin::Handler::SVG
svgtext RULE_NAME /pattern/modifiers
body SVG_TEXT_HEAVY eval:check_svg_text_ratio('5')
DESCRIPTION
SVG is increasingly used as a phishing vector: an image file that is really a text/link canvas, often carrying embedded JavaScript. This handler parses each SVG part and exposes its text content to svgtext rules -- kept separate from HTML body text so the same word (e.g. "docusign") can be scored differently in an SVG than in ordinary HTML.
Links found in the SVG are added to the URI detail list (type svg), and any embedded JavaScript is surfaced for the JavaScript handler -- see "RETURNS". An SVG whose ratio of text words to graphics elements is high -- a mostly-text "image" -- is flagged via the check_svg_text_ratio() eval rule (see "EVAL RULES").
RETURNS
The handler returns any embedded JavaScript found in the SVG as a single { type => 'text/javascript', data => $bytes } sub-part, which the handler framework dispatches to the JavaScript handler (Mail::SpamAssassin::Handler::JavaScript). The script bodies of <script> elements, javascript: URIs, and on* event-handler attributes are joined into that one part. When the SVG contains no script, the handler returns an empty list.
SVG TEXT RULES
svgtext RULENAME /regex/modifiers
score RULENAME 1.0
describe RULENAME SVG contains text matching /regex/
These rules behave like rawbody rules and support the multiple and maxhits=N tflags.
EVAL RULES
check_svg_text_ratio(MIN_RATIO)
Fires if any SVG part's ratio of text words to graphics elements
(image/path/rect/circle/ellipse/line/polyline/polygon/use) is greater than
or equal to MIN_RATIO. An SVG that contains text words but no graphics
element at all is treated as having an infinite ratio and always fires.
MIN_RATIO defaults to 1.