Bug 494603 - Some scam emails are not properly detected
Summary: Some scam emails are not properly detected
Status: RESOLVED FIXED
Alias: None
Product: kmail2
Classification: Applications
Component: general (show other bugs)
Version: 6.2.2
Platform: Arch Linux Linux
: NOR normal
Target Milestone: ---
Assignee: kdepim bugs
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-10-12 16:09 UTC by Huanyu Liu
Modified: 2024-10-13 13:09 UTC (History)
1 user (show)

See Also:
Latest Commit:
Version Fixed In: 24.12.0
Sentry Crash Report:


Attachments
Email with obvious phishing links (5.49 KB, application/mbox)
2024-10-12 16:09 UTC, Huanyu Liu
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Huanyu Liu 2024-10-12 16:09:21 UTC
Created attachment 174742 [details]
Email with obvious phishing links

SUMMARY
Some scam emails are not properly detected by KMail. See the attachment for an example (which is an official phishing test from Tsinghua University; some fields concerning personal information are modified).

STEPS TO REPRODUCE
1. Make sure "Security → Informs if message reading is a suspected email scam" in KMail settings is enabled
2. Open the attached email (with obvious phishing links)

OBSERVED RESULT
Nothing is warned by KMail (no matter whether HTML Message is enabled or not)

EXPECTED RESULT
KMail should warn about potential phishing links (as what I have seen previously)

SOFTWARE/OS VERSIONS
Operating System: Arch Linux 
KDE Plasma Version: 6.2.0
KDE Frameworks Version: 6.6.0
Qt Version: 6.7.3
Kernel Version: 6.11.3-arch1-1 (64-bit)
Graphics Platform: Wayland

ADDITIONAL INFORMATION
(None)
Comment 1 Laurent Montel 2024-10-13 11:38:38 UTC
What is the problem ?
Which apps do you use for seeing problem ?
Regards
Comment 2 Huanyu Liu 2024-10-13 11:47:14 UTC
(In reply to Laurent Montel from comment #1)
> What is the problem ?
> Which apps do you use for seeing problem ?
> Regards

I am using KMail 6.2.2.

In the attached mail, there is a link to "register [dot] tsginhua [dot] cn [slash] [blahblahblah]", but the displayed text is "game [dot] tsinghua [dot] edu [dot] cn", which is obviously a phishing mail. I remember that KMail would warn me about this previously, but KMail said nothing this time, even though "Informs if message reading is a suspected email scam" is enabled.
Comment 3 Laurent Montel 2024-10-13 11:57:14 UTC
Ok I add a new autotest.
Will see and debug it.
Thanks
Comment 4 Laurent Montel 2024-10-13 13:09:40 UTC
Git commit be472c743d0b7483899bde9fee99385c3be09a01 by Laurent Montel.
Committed on 13/10/2024 at 13:09.
Pushed by mlaurent into branch 'master'.

Fix 494603: Some scam emails are not properly detected(

FIXED-IN: 24.12.0

M  +2    -0    messageviewer/src/scamdetection/autotests/scamdetectionwebenginetest.cpp
M  +6    -1    messageviewer/src/scamdetection/scamdetectionwebengine.cpp

https://invent.kde.org/pim/messagelib/-/commit/be472c743d0b7483899bde9fee99385c3be09a01