1 # ********************************************************************
3 # File : $Source: /cvsroot/ijbswa/current/default.filter,v $
5 # $Id: default.filter,v 1.11.2.7 2002/09/25 15:09:39 oes Exp $
7 # Purpose : Rules to process the content of web pages
9 # Copyright : Written by and Copyright
10 # Privoxy team. http://www.privoxy.org/
12 # We value your feedback. However, to provide you with the best support,
15 # * Use the support forum to get help:
16 # http://sourceforge.net/tracker/?group_id=11118&atid=211118
17 # * Submit bugs only thru our bug forum:
18 # http://sourceforge.net/tracker/?group_id=11118&atid=111118
19 # Make sure that the bug has not already been submitted. Please try
20 # to verify that it is a Privoxy bug, and not a browser or site
21 # bug first. If you are using your own custom configuration, please
22 # try the stock configs to see if the problem is a configuration
23 # related bug. And if not using the latest development snapshot,
24 # please try the latest one. Or even better, CVS sources.
25 # * Submit feature requests only thru our feature request forum:
26 # http://sourceforge.net/tracker/?atid=361118&group_id=11118&func=browse
28 # For any other issues, feel free to use the mailing lists:
29 # http://sourceforge.net/mail/?group_id=11118
31 # Anyone interested in actively participating in development and related
32 # discussions can join the appropriate mailing list here:
33 # http://sourceforge.net/mail/?group_id=11118. Archives are available
36 #################################################################################
40 # Filters start with a line "FILTER: name description". They are then referrable
41 # from the actionsfile with +filter{name}
43 # Inside the filters, write one Perl-Style substitution (job) per line.
44 # Jobs that precede the first FILTER: line are ignored.
46 # For Details see the pcrs manpage contained in this distribution.
47 # (and the perlre, perlop and pcre manpages)
49 # Note that you are free to choose the delimter as you see fit.
51 # Note2: In addidion to the Perl options gimsx, the following nonstandard
52 # options are supported:
54 # 'U' turns the default to ungreedy matching. Add ? to quantifiers to
55 # switch back to greedy.
56 # 'T' (trivial) prevents parsing for backreferences in the substitute.
57 # Use if you want to include text like '$&' in your substitute without
60 #################################################################################
63 #################################################################################
65 # js-annoyances: Get rid of particularly annoying JavaScript abuse
67 #################################################################################
68 FILTER: js-annoyances Get rid of particularly annoying JavaScript abuse
70 # Note: Most of these jobs would be safer if restricted to a
71 # <script> context as in:
73 # s/(<script.*)nasty-item(?=.*<\/script>)/$1replacement/sigU
75 # but that would make them match only the first occurance of
76 # nasty-item in each <script>. We need nestable jobs!
78 # Get rid of Javascript referrer tracking.
79 # Test page: http://www.javascript-page.com/referrer.html
81 s|document\.referrer|"Not Your Business!"|gisU
83 # The status bar is for displaying link targets, not pointless blahblah
85 s/([\n =;{}]|window\.)(default)?status\s*=/$1dUmMy=/ig
87 # Kill OnUnload popups. Yummy.
88 # Test: http://www.zdnet.com/zdsubs/yahoo/tree/yfs.html
90 s/(<body\s+[^>]*)onunload(.*>)/$1never$2/siU
91 s|(<script.*)window\.onunload(?=.*</script>)|$1never|sigU
93 # If we allow window.open, we want normal window features:
94 # Test: http://www.htmlgoodies.com/beyond/notitle.html
96 s/(open\s*\([^\)]+resizable=)(["']?)(?:no|0)\2/$1$2yes$2/sigU
97 s/(open\s*\([^\)]+location=)(["']?)(?:no|0)\2/$1$2yes$2/sigU
98 s/(open\s*\([^\)]+status=)(["']?)(?:no|0)\2/$1$2yes$2/sigU
99 s/(open\s*\([^\)]+scroll(?:ing|bars)=)(["']?)(?:no|0)\2/$1$2auto$2/sigU
100 s/(open\s*\([^\)]+menubar=)(["']?)(?:no|0)\2/$1$2yes$2/sigU
101 s/(open\s*\([^\)]+toolbar=)(["']?)(?:no|0)\2/$1$2yes$2/sigU
102 s/(open\s*\([^\)]+directories=)(["']?)(?:no|0)\2/$1$2yes$2/sigU
103 s/(open\s*\([^\)]+fullscreen=)(["']?)(?:yes|1)\2/$1$2no$2/sigU
104 s/(open\s*\([^\)]+always(?:raised|lowered)=)(["']?)(?:yes|1)\2/$1$2no$2/sigU
105 s/(open\s*\([^\)]+zlock=)(["']?)(?:yes|1)\2/$1$2no$2/sigU
106 s/(open\s*\([^\)]+hotkeys=)(["']?)(?:yes|1)\2/$1$2no$2/sigU
107 s/(open\s*\([^\)]+titlebar=)(["']?)(?:yes|1)\2/$1$2yes$2/sigU
110 #################################################################################
112 # html-annoyances: Get rid of particularly annoying HTML abuse
114 #################################################################################
115 FILTER: html-annoyances Get rid of particularly annoying HTML abuse
117 # New browser windows (if allowed -- see no-popups filter below) should be
118 # resizeable and have a location and status bar
120 s/(<a\s+href[^>]+resizable=)(['"]?)(?:no|0)\2/$1$2yes$2/igU
121 s/(<a\s+href[^>]+location=)(['"]?)(?:no|0)\2/$1$2yes$2/igU
122 s/(<a\s+href[^>]+status=)(['"]?)(?:no|0)\2/$1$2yes1$2/igU
123 s/(<a\s+href[^>]+scrolling=)(['"]?)(?:no|0)\2/$1$2auto$2/igU
124 s/(<a\s+href[^>]+menubar=)(['"]?)(?:no|0)\2/$1$2yes$2/igU
126 # The <BLINK> tag was a crime!
128 s*<blink>|</blink>**ig
131 #################################################################################
133 # content-cookies: Kill cookies that come in the HTML or JS content
135 #################################################################################
136 FILTER: content-cookies Kill cookies that come in the HTML or JS content
138 # JS cookies, like found on privacy.net:
140 s|document\.cookie(?=[ \t\r\n]*=)|ZappedCookie|ig
144 s|<meta\s+http-equiv=['"]?set-cookie.*>|<!-- ZappedCookie -->|igU
147 #################################################################################
149 # webbugs: Squish WebBugs (1x1 invisible GIFs used for user tracking)
151 #################################################################################
152 FILTER: webbugs Squish WebBugs (1x1 invisible GIFs used for user tracking)
154 s/<img\s+[^>]*(?:width|height)\s*=\s*['"]?1(?=\D)[^>]*(?:width|height)\s*=\s*['"]?1(?=\D)[^>]*?>//siUg
157 ##################################################################################
159 # popups: Kill all popups in JS and HTML
161 #################################################################################
162 FILTER: popups Kill all popups in JS and HTML
164 s/([\n =;{}]|window\.)open\s*\\?\(/$1concat(/ig # JavaScript
165 s/ target\s*=\s*(['"]?)(_blank|_new)\1?/ notarget/ig # HTML
168 #################################################################################
170 # frameset-borders: Give frames a border, make them resizable and scrollable
172 #################################################################################
173 FILTER: frameset-borders Give frames a border and make them resizable
175 s/(<frameset\s+[^>]*)framespacing=(['"]?)(no|0)\2/$1/igU
176 s/(<frameset\s+[^>]*)frameborder=(['"]?)(no|0)\2/$1/igU
177 s/(<frameset\s+[^>]*)border=(['"]?)(no|0)\2/$1/igU
178 s/(<frame\s+[^>]*)noresize/$1/igU
179 s/(<frame\s+[^>]*)frameborder=(['"]?)(no|0)\2/$1/igU
180 s/(<frame\s+[^>]*)scrolling=(['"]?)(no|0)\2/$1/igU
183 #################################################################################
185 # refresh-tags: Kill automatic refresh tags (for dial-on-demand setups)
187 #################################################################################
188 FILTER: refresh-tags Kill automatic refresh tags (for dial-on-demand setups)
190 # Note: Only deactivates refreshes with more than 9 seconds delay to
191 # preserve monster-stupid but common redirections via meta tags.
193 s/<meta\s+http-equiv\s*=\s*(['"]?)refresh\1\s+content\s*=\s*(['"]?)\d{2,}\s*(;\s*url\s*=\s*([^>\2]*))?\2\s*>/<link rev="x-refresh" href="$4">/iU
196 #################################################################################
198 # img-reorder: Reorder attributes in <img> tags to make the banners-by-* filters more effective
200 #################################################################################
201 FILTER: img-reorder Reorder attributes in <img> tags to make the banners-by-* filters more effective
203 # In the first step src is moved to the start, then width is moved to the second
204 # place to guarantee an order of src, width, height.
205 # This makes banners-by-size more effective and allows both banners-by-size
206 # and banners-by-link to preserve the original image URL in the alt attribute.
208 s|<img\s+?([^>]*)src\s*=\s*(['"])([^>\\\2]+)\2|<img src=$2$3$2$1|siUg
209 s|<img\s+?([^>]*)src\s*=\s*([^'">\\\s]+)|<img src=$2$1|sig
211 s|<img (src=(?:(['"])[^>\\\\2]+\2\|[^'">\\\s]+?))([^>]*)width\s*=\s*(["']?)(\d+?)|<img $1 width=$4$5$4$3|siUg
214 #################################################################################
216 # banners-by-size: Kill banners by size
218 #################################################################################
220 # Standard banner sizes taken from http://www.iab.net/iab_banner_standards/bannersizes.html
222 # Note: Use http://config.privoxy.org/send-banner?type=trans for a transparent 1x1 image
223 # Use http://config.privoxy.org/send-banner?type=pattern for a grey/white pattern image
224 # Use http://config.privoxy.org/send-banner?type=auto to auto-select.
226 # Note2: Use img-reorder before this filter to ensure maximum matching success
228 #################################################################################
229 FILTER: banners-by-size Kill banners by size
232 s@<img\s+(?:src\s*=\s*(['"]?)([^>\\\1\s]+)\1)?[^>]*?(width=(['"]?)88\4)[^>]*?(height=(['"]?)31\6)[^>]*>@<img src=$1http://config.privoxy.org/send-banner?type=auto$1 alt=$1Killed-$2-by-size$1 $3 $5>@sig
233 # 120*60, 120*90, 120*240, 120*600
234 s@<img\s+(?:src\s*=\s*(['"]?)([^>\\\1\s]+)\1)?[^>]*?(width=(['"]?)120\4)[^>]*?(height=(['"]?)(?:600?|90|240)\6)[^>]*>@<img src=$1http://config.privoxy.org/send-banner?type=auto$1 alt=$1Killed-$2-by-size$1 $3 $5>@sig
236 s@<img\s+(?:src\s*=\s*(['"]?)([^>\\\1\s]+)\1)?[^>]*?(width=(['"]?)125\4)[^>]*?(height=(['"]?)125\6)[^>]*>@<img src=$1http://config.privoxy.org/send-banner?type=auto$1 alt=$1Killed-$2-by-size$1 $3 $5>@sig
238 s@<img\s+(?:src\s*=\s*(['"]?)([^>\\\1\s]+)\1)?[^>]*?(width=(['"]?)160\4)[^>]*?(height=(['"]?)600\6)[^>]*>@<img src=$1http://config.privoxy.org/send-banner?type=auto$1 alt=$1Killed-$2-by-size$1 $3 $5>@sig
240 s@<img\s+(?:src\s*=\s*(['"]?)([^>\\\1\s]+)\1)?[^>]*?(width=(['"]?)180\4)[^>]*?(height=(['"]?)150\6)[^>]*>@<img src=$1http://config.privoxy.org/send-banner?type=auto$1 alt=$1Killed-$2-by-size$1 $3 $5>@sig
241 # 234*60, 468*60 (Most Banners!)
242 s@<img\s+(?:src\s*=\s*(['"]?)([^>\\\1\s]+)\1)?[^>]*?(width=(['"]?)(?:234|468)\4)[^>]*?(height=(['"]?)60\6)[^>]*>@<img src=$1http://config.privoxy.org/send-banner?type=auto$1 alt=$1Killed-$2-by-size$1 $3 $5>@sig
244 s@<img\s+(?:src\s*=\s*(['"]?)([^>\\\1\s]+)\1)?[^>]*?(width=(['"]?)240\4)[^>]*?(height=(['"]?)400\6)[^>]*>@<img src=$1http://config.privoxy.org/send-banner?type=auto$1 alt=$1Killed-$2-by-size$1 $3 $5>@sig
246 s@<img\s+(?:src\s*=\s*(['"]?)([^>\\\1\s]+)\1)?[^>]*?(width=(['"]?)(?:250|300)\4)[^>]*?(height=(['"]?)250\6)[^>]*>@<img src=$1http://config.privoxy.org/send-banner?type=auto$1 alt=$1Killed-$2-by-size$1 $3 $5>@sig
248 s@<img\s+(?:src\s*=\s*(['"]?)([^>\\\1\s]+)\1)?[^>]*?(width=(['"]?)336\4)[^>]*?(height=(['"]?)280\6)[^>]*>@<img src=$1http://config.privoxy.org/send-banner?type=auto$1 alt=$1Killed-$2-by-size$1 $3 $5>@sig
250 # Note: 200*50 was also proposed, but it probably causes too much collateral damage:
252 #s@<img\s+(?:src\s*=\s*(['"]?)([^>\\\1\s]+)\1)?[^>]*?(width=(['"]?)200\4)[^>]*?(height=(['"]?)50\6)[^>]*>@<img src=$1http://config.privoxy.org/send-banner?type=auto$1 alt=$1Killed-$2-by-size$1 $3 $5>@sig
255 #################################################################################
257 # banners-by-link: Kill banners by their links to known clicktrackers
259 #################################################################################
260 FILTER: banners-by-link Kill banners by their links to known clicktrackers
262 # Common case with width and height attributes:
264 s@<a\s+href\s*=\s*(['"]?)([^>\1\s]*?(?:\
265 adclick # See www.dn.se \
266 | atwola\.com/(?:link|redir) # see www.cnn.com \
267 | /jump/ # redirs for doublecklick.net ads \
268 | tracker | counter # common \
269 | adlog\.pl # see sf.net \
270 )[^>\1\s]*)\1[^>]*>\s*<img\s+(?:src\s*=\s*(['"]?)([^>\\\3\s]+)\3)?[^>]*((?:width|height)\s*=\s*(['"]?)\d+?\6)[^>]*((?:width|height)\s*=\s*(['"]?)\d+?\8)[^>]*>\
271 @<img $5 $7 src=$1http://config.privoxy.org/send-banner?type=auto$1 alt=$1Killed $4 by link to $2$1>@sigx
273 # Rare case w/o explicit dimensions:
275 s@<a\s+href\s*=\s*(['"]?)([^>\1\s]*?(?:adclick|atwola\.com/(?:link|redir)|doubleclick\.net/jump/|tracker|counter|adlog\.pl)[^>\1\s]*)\1[^>]*>\s*<img\s+(?:src\s*=\s*(['"]?)([^>\\\3\s]+)\3)?[^>]*>@<img src=$1http://config.privoxy.org/send-banner?type=auto$1 alt=$1Killed $4 by link to $2$1>@sig
277 #################################################################################
279 # fun: Text replacements for subversive browsing fun!
281 #################################################################################
282 FILTER: fun Text replacements for subversive browsing fun!
284 s/microsoft(?!.com)/MicroSuck/ig
286 # Buzzword Bingo (example for extended regex syntax)
288 s* industry[ -]leading \
290 | customer[ -]focused \
292 | award[ -]winning # Comments are OK, too! \
293 | high[ -]performance \
294 | solutions[ -]based \
298 *<font color="red"><b>BINGO!</b></font> \
302 #################################################################################
304 # nimda: Remove Nimda (virus) code
306 #################################################################################
307 FILTER: nimda Remove Nimda (virus) code
309 s%<script language="JavaScript">(window\.open|1;''\.concat)\("readme\.eml", null, "resizable=no,top=6000,left=6000"\)</script>%<br><font size="7"> WARNING: This Server is infected with <a href="http://www.cert.org/advisories/CA-2001-26.html">Nimda</a>!</font>%g
312 #################################################################################
314 # shockwave-flash: Kill embedded Shockwave Flash objects
316 #################################################################################
317 FILTER: shockwave-flash Kill embedded Shockwave Flash objects
319 s|<embed [^>]*application/x-shockwave-flash.*</embed>|<!-- Squished Shockwave Flash Embed -->|sigU
322 #################################################################################
324 # quicktime-kioskmode: Make Quicktime movies saveable
326 #################################################################################
327 FILTER: quicktime-kioskmode Make Quicktime movies saveable
329 s/(<embed\s+[^>]*)kioskmode\s*=\s*(["']?)true\2/$1/ig
332 #################################################################################
334 # js-events: Kill all JS event bindings (Radically destructive! Only for extra nasty sites)
336 #################################################################################
337 FILTER: js-events Kill all JS event bindings (Radically destructive! Only for extra nasty sites)
339 s/(on|event\.)((mouse(over|out|down|up|move))|(un)?load|contextmenu|selectstart)/never/ig
340 # Not events, but abused on the same type of sites:
341 s/(alert|confirm)\s*\(/concat(/ig
344 #################################################################################
346 # crude-parental: Crude parental filtering? (Use along with a suitable blocklist).
347 # Shows how to deny access to whole page based on a keyword.
349 #################################################################################
350 FILTER: crude-parental Crude parental filtering (demo only)
352 # (Note: Middlesex, Sussex and Essex are counties in the UK, not rude words)
353 # (Note #2: Is 'sex' a rude word?!)
355 s%^.*(?<!middle)(?<!sus)(?<!es)sex.*$%<html><head><title>Blocked</title></head><body><h3>Blocked due to possible adult content. Please see <a href="http://dmoz.org/Kids_and_Teens/">this site</a>.</h3></body></html>%is
356 s+^.*warez.*$+<html><head><title>No Warez</title></head><body><h3>You're not searching for illegal stuff, are you?</h3></body></html>+is
359 #################################################################################
361 # demoronizer: Correct Microsoft's abuse of standardized character sets, which
362 # leave the browser to (mis)-interpret unknown characters, with
363 # sometimes bizarre results on non-MS platforms.
365 # credit: ripped from the demoroniser.pl script by:
366 # John Walker -- January 1998, http://www.fourmilab.ch/webtools/demoroniser
368 #################################################################################
369 FILTER: demoronizer fixing MS's non-standard use of std charsets.
371 s/(&\#[0-2]\d\d)\s/$1; /g
372 # per Robert Lynch: http://slate.msn.com//?id=2067547, just a guess.
373 # Must come before x94 below.
374 s/\xE2\x80\x94/ -- /g
386 # Bullet type character.
390 #s-\x98-<sup>~</sup>-g
391 #s-\x99-<sup>TM</sup>-g
396 ##############################################################################
399 # $Log: default.filter,v $
400 # Revision 1.11.2.7 2002/09/25 15:09:39 oes
401 # Preserve original quoting style in <img> tags wherever possible. Fixes Bug #605956
403 # Revision 1.11.2.6 2002/08/23 14:12:26 oes
404 # Proofed frameset-borders against "fremaborder=0 border=0"
406 # Revision 1.11.2.5 2002/08/22 15:05:20 oes
407 # Added Filter to make Quicktime movies saveable (thanks to aaron@linville.org for the idea)
409 # Revision 1.11.2.4 2002/08/10 11:32:29 oes
410 # Attribute values in replacement tags of banners-by-size filter now undelimited. (Fixes bug #592493)
412 # Revision 1.11.2.3 2002/08/05 11:43:56 oes
413 # Fixed a bug in the popups filter that was introduced with the last fix :-(
415 # Revision 1.11.2.2 2002/08/01 11:20:13 oes
416 # Fixed bugs 587802, 577802 and an unreported one
418 # Revision 1.11.2.1 2002/07/26 15:18:26 oes
419 # - All filters reviewed and many shorcomings fixed
420 # - New filters: img-reorder, banners-by-link and js-events
421 # - Jobs reorderd because they are now executed in order of
424 # Revision 1.11 2002/05/24 00:57:18 oes
425 # Made WeBugs job ungreedy; Fixes bug 559190
427 # Revision 1.10 2002/04/18 10:14:19 oes
428 # renamed some filters
430 # Revision 1.9 2002/04/11 07:36:35 oes
431 # Generalized js-popup filter
433 # Revision 1.8 2002/04/10 17:07:21 oes
434 # Fixed potentially desctructive jobs, added noflash filter
436 # Revision 1.7 2002/04/09 18:34:51 oes
437 # Fixed HTML syntax in replacements
439 # Revision 1.6 2002/04/03 19:49:52 swa
442 # Revision 1.5 2002/03/27 15:30:26 swa
443 # have a consistent appearance
445 # Revision 1.4 2002/03/26 22:29:54 swa
446 # we have a new homepage!
448 # Revision 1.3 2002/03/24 16:08:03 jongfoster
449 # Fixing banners-by-size for new config URLs
451 # Revision 1.2 2002/03/24 13:02:18 swa
452 # name change related issues.
454 # Revision 1.1 2002/03/24 11:37:39 jongfoster
457 # Revision 1.24 2002/03/16 20:39:54 oes
458 # - Added descriptions to the filters so users will know what they select in the cgi editor
459 # - Added content-cookies filter
460 # - Bugfixed many jobs (Thanks to Al for some hints)
462 # Revision 1.22 2002/03/12 13:42:50 oes
463 # Fixing & Optimizing REs
465 # Revision 1.21 2002/03/12 11:59:20 oes
466 # Beefed up Buzzword Bingo
468 # Revision 1.20 2002/03/12 01:42:50 oes
469 # Introduced modular filters
471 # Revision 1.19 2002/03/10 19:49:24 oes
472 # Added expression to kill referer tracking in JavaScripts
474 # Revision 1.18 2002/03/08 17:14:12 oes
475 # PNG -> image in comments
477 # Revision 1.17 2002/03/07 03:50:54 oes
478 # Adapted comments to new built-in images
480 # Revision 1.16 2002/02/21 00:12:19 jongfoster
481 # Modifying the banner regexps to use long URLS and to autodetect
482 # whether to show a logo or a transparent GIF, based on actionsfile
485 # Revision 1.15 2001/12/28 23:54:20 steudten
486 # Fix for feature Req #495374: http-equiv problem
488 # Revision 1.14 2001/12/09 18:55:11 david__schmidt
489 # Updated CODE_STATUS to beta, commented out microsuck line in re_filterfile
492 # Revision 1.13 2001/10/13 13:11:20 joergs
493 # Fixed WebBug filter.
495 # Revision 1.12 2001/10/07 15:46:42 oes
496 # Followed Guy's proposal to change the document.cookie job
498 # Revision 1.11 2001/09/21 12:34:00 joergs
499 # Added filter to replace "Nimda" code by a warning.
501 # Revision 1.10 2001/07/20 11:04:26 oes
502 # Added Rodneys javascript cookie filter
504 # Revision 1.9 2001/07/13 14:03:48 oes
505 # Elimiated yet another bug in the banner-by-size jobs. Shame on me!
507 # Revision 1.8 2001/06/29 13:34:00 oes
508 # - Added explanation for U and T options
509 # - Added hint on image replacement by CGI call
510 # - Fixed bug in banner-by-size jobs
512 # Revision 1.7 2001/06/19 14:21:56 oes
513 # Fixed microsuck line
515 # Revision 1.6 2001/06/09 14:01:57 swa
516 # header. cosmetics. default: no messing ala microsuck.