-# ********************************************************************
+# ********************************************************************
#
-# File : $Source: /cvsroot/ijbswa/current/junkbuster.init,v $
+# File : $Source: /cvsroot/ijbswa/current/re_filterfile,v $
#
# Purpose : Rules to process the content of web pages
#
# Copyright : Written by and Copyright (C) 2001 the SourceForge
# IJBSWA team. http://ijbswa.sourceforge.net
#
-# Based on the Internet Junkbuster originally written
-# by and Copyright (C) 1997 Anonymous Coders and
-# Junkbusters Corporation. http://www.junkbusters.com
-#
# This program is free software; you can redistribute it
# and/or modify it under the terms of the GNU General
# Public License as published by the Free Software
# Temple Place - Suite 330, Boston, MA 02111-1307, USA.
#
# Revisions :
-# $Log: junkbuster.init,v $
+# $Log: re_filterfile,v $
+# Revision 1.20 2002/03/12 01:42:50 oes
+# Introduced modular filters
+#
+# Revision 1.19 2002/03/10 19:49:24 oes
+# Added expression to kill referer tracking in JavaScripts
+#
+# Revision 1.18 2002/03/08 17:14:12 oes
+# PNG -> image in comments
+#
+# Revision 1.17 2002/03/07 03:50:54 oes
+# Adapted comments to new built-in images
+#
+# Revision 1.16 2002/02/21 00:12:19 jongfoster
+# Modifying the banner regexps to use long URLS and to autodetect
+# whether to show a logo or a transparent GIF, based on actionsfile
+# setting.
+#
+# Revision 1.15 2001/12/28 23:54:20 steudten
+# Fix for feature Req #495374: http-equiv problem
+#
+# Revision 1.14 2001/12/09 18:55:11 david__schmidt
+# Updated CODE_STATUS to beta, commented out microsuck line in re_filterfile
+# for 2.9.10 beta
+#
+# Revision 1.13 2001/10/13 13:11:20 joergs
+# Fixed WebBug filter.
+#
+# Revision 1.12 2001/10/07 15:46:42 oes
+# Followed Guy's proposal to change the document.cookie job
+#
+# Revision 1.11 2001/09/21 12:34:00 joergs
+# Added filter to replace "Nimda" code by a warning.
+#
+# Revision 1.10 2001/07/20 11:04:26 oes
+# Added Rodneys javascript cookie filter
+#
+# Revision 1.9 2001/07/13 14:03:48 oes
+# Elimiated yet another bug in the banner-by-size jobs. Shame on me!
+#
+# Revision 1.8 2001/06/29 13:34:00 oes
+# - Added explanation for U and T options
+# - Added hint on image replacement by CGI call
+# - Fixed bug in banner-by-size jobs
+#
+# Revision 1.7 2001/06/19 14:21:56 oes
+# Fixed microsuck line
+#
+# Revision 1.6 2001/06/09 14:01:57 swa
+# header. cosmetics. default: no messing ala microsuck.
+#
#
#
-# ********************************************************************/
+
+#################################################################################
+#
+# Syntax:
+#
+# Filters start with a line "FILTER: name". They are then referrable
+# from the actionsfile with +filter{name}
+#
+# Inside the filters, write one Perl-Style substitution per line.
+#
+# For Details see the pcrs manpage contained in this distribution.
+# (and the perlre, perlop and pcre manpages)
#
-# Syntax: One Perl-Style substitution per line.
-# For Details see the perlre, perlop and pcre manpages.
# Note that you are free to choose the delimter as you see fit.
#
-# Note: in addidion to the Perl-options egimosx, U is supported
-# and turns the default to ungreedy matching. Add ? to quantifiers
-# to switch back to greedy.
+# Note2: In addidion to the Perl options gimsx, the following nonstandard
+# options are supported:
+#
+# 'U' turns the default to ungreedy matching. Add ? to quantifiers to
+# switch back to greedy.
+# 'T' (trivial) prevents parsing for backreferences in the substitute.
+# Use if you want to include text like '$&' in your substitute without
+# quoting.
+#
+#################################################################################
+
+
+#################################################################################
+#
+# html-annoyances: Get rid of particularly annoying HTML abuse
#
+#################################################################################
+FILTER: html-annoyances
-# ********************************************************************/
+# New browser windows should be resizeable and have a location and status bar
#
-# Kill OnUnload popups. Yummy.
-# check it out on http://www.zdnet.com/zdsubs/yahoo/tree/yfs.html
+s/resizable="?(no|0)"?/resizable=1/ig s/noresize/yesresize/ig
+s/location="?(no|0)"?/location=1/ig s/status="?(no|0)"?/status=1/ig
+s/scrolling="?(no|0|Auto)"?/scrolling=1/ig
+s/menubar="?(no|0)"?/menubar=1/ig
+
+# The <BLINK> tag was a crime!
#
-# ********************************************************************/
-s/(<body .*?)onunload(.*?>)/$1never$2/i
+s*<blink>|</blink>**ig
-# ********************************************************************/
+# Is this evil?
#
-# Kill refresh tags. I like to refresh myself. Manually.
-# check it out on http://www.airport-cgn.de/ and go to the arrivals page.
+#s/framespacing="?(no|0)"?//ig
+#s/margin(height|width)=[0-9]*//gi
+
+
+#################################################################################
#
-# ********************************************************************/
-s/<meta[^>]*http-equiv[^>]*refresh.*URL=([^>]*?)"?>/<link rev="x-refresh" href=$1>/i
-s/<meta[^>]*http-equiv="?page-enter"?[^>]*content=[^>]*>/<!--no page enter for me-->/i
+# js-annoyances: Get rid of particularly annoying JavaScript abuse
+#
+#################################################################################
+FILTER: js-annoyances
+
+# JS cookies, like found on privacy.net:
+#
+s|(document\.cookie)([ \t\r\n]*=)|documenZapCooky$2|g
+
+# Get rid of Javascript referrer tracking. Test page: http://www.randomoddness.com/untitled.htm
+#
+s|(<script.*)document\.referrer(.*</script>)|$1"Not Your Business!"$2|Usg
-# ********************************************************************/
+# The status bar is for displaying link targets, not pointless blahblah
#
-# If I allow popups, I want them to be resizeable and have a location
-# and status bar: check it out on http://www.airport-cgn.de/ and go to
-# the arrivals page.
+s/status='.*?';*//ig
+
+# Kill OnUnload popups. Yummy. Test: http://www.zdnet.com/zdsubs/yahoo/tree/yfs.html
#
-# ********************************************************************/
-# s/resizable="?(no|0)"?/resizable=1/ig s/noresize/yesresize/ig
-# s/location="?(no|0)"?/location=1/ig s/status="?(no|0)"?/status=1/ig
-# s/scrolling="?(no|0|Auto)"?/scrolling=1/ig
-# s/menubar="?(no|0)"?/menubar=1/ig #s/framespacing="?(no|0)"?//ig
-# #s/margin(height|width)=[0-9]*//gi
+s/(<body .*)onunload(.*>)/$1never$2/iU
+
+
+##################################################################################
+#
+# no-poups: Kill all popups in JS and HTML
+#
+#################################################################################
+FILTER: no-poups
+
+s/window\.open\(/1;''\.concat\(/ig # JavaScript
+s/target=['"]?_blank['"]?/target_who/g # HTML
+
-# ********************************************************************/
+#################################################################################
#
-# Remove frameborder=0 and border=0 from framesets
+# frameset-borders: Give frames a border
#
-# ********************************************************************/
+#################################################################################
+FILTER: frameset-borders
+
s/(<frameset[^>]+?)border=['"]?(no|0)['"]?/$1/ig
s/(<frameset[^>]+?)frameborder=['"]?(no|0)['"]?/$1/ig
-# ********************************************************************/
+
+#################################################################################
#
-# The status bar is for displaying link targets, not pointless buzzwords.
-# Again, check it out on http://www.airport-cgn.de/
+# webbugs: Squish WebBugs (1x1 invisible GIFs used for user tracking)
#
-# ********************************************************************/
-s/status='.*?';*//ig
+#################################################################################
+FILTER: webbugs
+
+s/<img\s+[^>]*?(width|height)\s*=\s*['"]?1\D[^>]*?(width|height)\s*=\s*['"]?1(\D[^>]*?)?>/<!-- Squished WebBug -->/sig
+
+
+#################################################################################
+#
+# no-refresh: Automatic refresh sucks on auto-dialup lines
+#
+#################################################################################
+FILTER: no-refresh
-# ********************************************************************/
+# FIXME: second line like first line for content value
#
-# Kill *all* popups a la popup.c. (But for *all* sites, so I wouldn't do that.)
+s/<meta[^>]*http-equiv[^>]*refresh.*([0-9]+[0-9]|"[2-9]);URL=([^>]*?)"?>/<link rev="x-refresh" href=$2>/i
+s/<meta[^>]*http-equiv="?page-enter"?[^>]*content=[^>]*>/<!--no page enter for me-->/i
+
+
+#################################################################################
#
-# JavaScript: s/window\.open\(/who_wants_this_to.open(/ig
-# HTML : s/target=['"]?_blank['"]?/target_who/g
+# fun: Text replacements for subversive browsing fun!
#
-# Kill banners by size:
-# (Sizes from http://www.iab.net/iab_banner_standards/bannersizes.html)
+#################################################################################
+FILTER: fun
+
+s/microsoft(?!.com)/MicroSuck/ig
+
+# Buzzword Bingo (example for extended syntax)
#
-# ********************************************************************/
-s|<img\s+[^>]*?(width=['"]?468\D)[^>]*(height=['"]?60\D)[^>]*>|<img src=http://i.j.b/send-banner $1 $2>|sig
-s|<img\s+[^>]*?(width=['"]?234\D)[^>]*(height=['"]?60\D)[^>]*>|<img src=http://i.j.b/send-banner $1 $2>|sig
-s|<img\s+[^>]*?(width=['"]?88\D)[^>]*(height=['"]?31\D)[^>]*>|<img src=http://i.j.b/send-banner $1 $2>|sig
-s|<img\s+[^>]*?(width=['"]?120\D)[^>]*(height=['"]?90\D)[^>]*>|<img src=http://i.j.b/send-banner $1 $2>|sig
-s|<img\s+[^>]*?(width=['"]?120\D)[^>]*(height=['"]?60\D)[^>]*>|<img src=http://i.j.b/send-banner $1 $2>|sig
-s|<img\s+[^>]*?(width=['"]?160\D)[^>]*(height=['"]?600\D)[^>]*>|<img src=http://i.j.b/send-banner $1 $2>|sig
-s|<img\s+[^>]*?(width=['"]?120\D)[^>]*(height=['"]?600\D)[^>]*>|<img src=http://i.j.b/send-banner $1 $2>|sig
-s|<img\s+[^>]*?(width=['"]?125\D)[^>]*(height=['"]?125\D)[^>]*>|<img src=http://i.j.b/send-banner $1 $2>|sig
-s|<img\s+[^>]*?(width=['"]?120\D)[^>]*(height=['"]?240\D)[^>]*>|<img src=http://i.j.b/send-banner $1 $2>|sig
-s|<img\s+[^>]*?(width=['"]?180\D)[^>]*(height=['"]?150\D)[^>]*>|<img src=http://i.j.b/send-banner $1 $2>|sig
-s|<img\s+[^>]*?(width=['"]?300\D)[^>]*(height=['"]?250\D)[^>]*>|<img src=http://i.j.b/send-banner $1 $2>|sig
-s|<img\s+[^>]*?(width=['"]?250\D)[^>]*(height=['"]?250\D)[^>]*>|<img src=http://i.j.b/send-banner $1 $2>|sig
-s|<img\s+[^>]*?(width=['"]?240\D)[^>]*(height=['"]?400\D)[^>]*>|<img src=http://i.j.b/send-banner $1 $2>|sig
-s|<img\s+[^>]*?(width=['"]?336\D)[^>]*(height=['"]?280\D)[^>]*>|<img src=http://i.j.b/send-banner $1 $2>|sig
+s* industry[ -]leading \
+| cutting[ -]edge \
+| award[ -]winning # Comments are OK, too!\
+| high[ -]performance \
+| solutions[ -]based \
+| unmatched \
+| unparalleled \
+| unrivalled \
+*<font color=red><b>BINGO!</b></font> \
+*igx
-s|<img\s+[^>]*?(width=['"]?200\D)[^>]*(height=['"]?50\D)[^>]*>|<img src=http://i.j.b/send-banner $1 $2>|sig
-# ********************************************************************/
+#################################################################################
#
-# Squish WebBugs:
+# nimda: Remove Nimda (virus) code
#
-# ********************************************************************/
-s/<img\s+[^>]*?(width|height)\s+=\s+['"]?1\D[^>]*?(width|height)\s+=\s+['"]?1\D[^>]*>/<!-- Squished WebBug -->/sig
+#################################################################################
+FILTER: nimda
-# ********************************************************************/
+s%<script language="JavaScript">(window\.open|1;''\.concat)\("readme\.eml", null, "resizable=no,top=6000,left=6000"\)</script>%<br><hr><font size=7><b>Internet J</b></font><b><font size=6>UNK</font><font size=5 color="red"><i>BUSTER</i></font></b><font size=7> WARNING: This Server is infected with <a href="http://www.cert.org/advisories/CA-2001-26.html">Nimda</a>!</font>%g
+
+
+#################################################################################
+#
+# banners-by-size: Kill banners by size
+#
+#################################################################################
#
-# Fun stuff
+# Standard banner sizes taken from http://www.iab.net/iab_banner_standards/bannersizes.html
#
-# ********************************************************************/
-#s/microsoft(?!.com)/<b>MicroSuck<\/b>/ig
+# Note: Use http://ijbswa.sourceforge.net/config/send-banner?type=trans for a transparent 1x1 image
+# Use http://ijbswa.sourceforge.net/config/send-banner?type=logo for the logo image
+# Use http://ijbswa.sourceforge.net/config/send-banner?type=logo for a grey/white pattern image
+# Use http://ijbswa.sourceforge.net/config/send-banner?type=auto to auto-select.
+#
+#################################################################################
+FILTER: banners-by-size
+
+s|<img\s+[^>]*?(width=['"]?468\D)[^>]*(height=['"]?60[^>]*?)>|<img src=http://ijbswa.sourceforge.net/config/send-banner?type=auto $1 $2>|sig
+s|<img\s+[^>]*?(width=['"]?234\D)[^>]*(height=['"]?60[^>]*?)>|<img src=http://ijbswa.sourceforge.net/config/send-banner?type=auto $1 $2>|sig
+s|<img\s+[^>]*?(width=['"]?88\D)[^>]*(height=['"]?31[^>]*?)>|<img src=http://ijbswa.sourceforge.net/config/send-banner?type=auto $1 $2>|sig
+s|<img\s+[^>]*?(width=['"]?120\D)[^>]*(height=['"]?90[^>]*?)>|<img src=http://ijbswa.sourceforge.net/config/send-banner?type=auto $1 $2>|sig
+s|<img\s+[^>]*?(width=['"]?120\D)[^>]*(height=['"]?600[^>]*?)>|<img src=http://ijbswa.sourceforge.net/config/send-banner?type=auto $1 $2>|sig
+s|<img\s+[^>]*?(width=['"]?120\D)[^>]*(height=['"]?60[^>]*?)>|<img src=http://ijbswa.sourceforge.net/config/send-banner?type=auto $1 $2>|sig
+s|<img\s+[^>]*?(width=['"]?160\D)[^>]*(height=['"]?600[^>]*?)>|<img src=http://ijbswa.sourceforge.net/config/send-banner?type=auto $1 $2>|sig
+s|<img\s+[^>]*?(width=['"]?125\D)[^>]*(height=['"]?125[^>]*?)>|<img src=http://ijbswa.sourceforge.net/config/send-banner?type=auto $1 $2>|sig
+s|<img\s+[^>]*?(width=['"]?120\D)[^>]*(height=['"]?240[^>]*?)>|<img src=http://ijbswa.sourceforge.net/config/send-banner?type=auto $1 $2>|sig
+s|<img\s+[^>]*?(width=['"]?180\D)[^>]*(height=['"]?150[^>]*?)>|<img src=http://ijbswa.sourceforge.net/config/send-banner?type=auto $1 $2>|sig
+s|<img\s+[^>]*?(width=['"]?300\D)[^>]*(height=['"]?250[^>]*?)>|<img src=http://ijbswa.sourceforge.net/config/send-banner?type=auto $1 $2>|sig
+s|<img\s+[^>]*?(width=['"]?250\D)[^>]*(height=['"]?250[^>]*?)>|<img src=http://ijbswa.sourceforge.net/config/send-banner?type=auto $1 $2>|sig
+s|<img\s+[^>]*?(width=['"]?240\D)[^>]*(height=['"]?400[^>]*?)>|<img src=http://ijbswa.sourceforge.net/config/send-banner?type=auto $1 $2>|sig
+s|<img\s+[^>]*?(width=['"]?336\D)[^>]*(height=['"]?280[^>]*?)>|<img src=http://ijbswa.sourceforge.net/config/send-banner?type=auto $1 $2>|sig
+
+# One more. (Where is 200x50 from?)
+#
+s|<img\s+[^>]*?(width=['"]?200\D)[^>]*(height=['"]?50[^>]*?)>|<img src=http://ijbswa.sourceforge.net/config/send-banner?type=auto $1 $2>|sig
-# ********************************************************************/
+
+#################################################################################
+#
+# crude-parental: Crude parental filtering? (Use along with a suitable blocklist).
+# Shows how to deny access to whole page based on a keyword.
#
-# Crude parental filtering? (Use along with a suitable blocklist).
-# Shows how to deny access to whole page based on a keyword.
+#################################################################################
#
# (Note: Middlesex, Sussex and Essex are counties in the UK, not rude words)
# (Note #2: Is 'sex' a rude word?!)
#
-#s%^.*(?<!middle)(?<!sus)(?<!es)sex.*$%<html><head><title>Blocked</title></head><body><h3>Blocked due to possible adult content. Please see <a href="http://dmoz.org/Kids_and_Teens/">this site</a>.</h3></body></html>%is
-#s+^.*warez.*$+<html><head><title>No Warez</title></head><body><h3>You're not searching for illegal stuff, are you?</h3></body></html>+is
+#################################################################################
+FILTER: crude-parental
-# ********************************************************************/
-#
-# http://www.farscapezone.com/wwwboard/messages/1451.html
-#
-# ********************************************************************/
-s/(\w+) was tired/<b>$1 needed more coffee<\/b>/ig
+s%^.*(?<!middle)(?<!sus)(?<!es)sex.*$%<html><head><title>Blocked</title></head><body><h3>Blocked due to possible adult content. Please see <a href="http://dmoz.org/Kids_and_Teens/">this site</a>.</h3></body></html>%is
+s+^.*warez.*$+<html><head><title>No Warez</title></head><body><h3>You're not searching for illegal stuff, are you?</h3></body></html>+is