NAME

Mail::SpamAssassin::Handler::SVG - A MIME-part handler for image/svg+xml parts

SYNOPSIS

loadhandler  Mail::SpamAssassin::Handler::SVG

svgtext  RULE_NAME  /pattern/modifiers

body  SVG_TEXT_HEAVY  eval:check_svg_text_ratio('5')

DESCRIPTION

SVG is increasingly used as a phishing vector: an image file that is really a text/link canvas, often carrying embedded JavaScript. This handler parses each SVG part and exposes its text content to svgtext rules -- kept separate from HTML body text so the same word (e.g. "docusign") can be scored differently in an SVG than in ordinary HTML.

Links found in the SVG are added to the URI detail list (type svg), and any embedded JavaScript is surfaced for the JavaScript handler -- see "RETURNS". An SVG whose ratio of text words to graphics elements is high -- a mostly-text "image" -- is flagged via the check_svg_text_ratio() eval rule (see "EVAL RULES").

RETURNS

The handler returns any embedded JavaScript found in the SVG as a single { type => 'text/javascript', data => $bytes } sub-part, which the handler framework dispatches to the JavaScript handler (Mail::SpamAssassin::Handler::JavaScript). The script bodies of <script> elements, javascript: URIs, and on* event-handler attributes are joined into that one part. When the SVG contains no script, the handler returns an empty list.

SVG TEXT RULES

svgtext  RULENAME  /regex/modifiers
score    RULENAME  1.0
describe RULENAME  SVG contains text matching /regex/

These rules behave like rawbody rules and support the multiple and maxhits=N tflags.

EVAL RULES

check_svg_text_ratio(MIN_RATIO)

  Fires if any SVG part's ratio of text words to graphics elements
  (image/path/rect/circle/ellipse/line/polyline/polygon/use) is greater than
  or equal to MIN_RATIO.  An SVG that contains text words but no graphics
  element at all is treated as having an infinite ratio and always fires.
  MIN_RATIO defaults to 1.