| |||||||||||||||||||||||||||||||
|
ended up blocking the user so they would get 5.1.1 for any mail to the user. Rejected 564000 messages in one week with no sign of slowing down. Mailbomb came from all over the net and now way I could get it to stop. Even though I was stopping after RCPT TO: header through checks, I still couldn't get rid of the traffic. This was accounting upwards of around 2GB of traffic a day and lots of unhappy users as server busy attending to rejecting mail, not performing its normal function. In the end, we offloaded our MX record to a mail washing host and now they take care of the problem for us. Our services have now returned to normal! Kelvin On Fri, 2008-03-28 at 20:20 +0100, mouss wrote: > Frank Bonnet wrote: > > Jorey Bump wrote: > >> Frank Bonnet wrote, at 03/28/2008 10:17 AM: > >> > >>> The mailbox of a user here is literally mailbombed ( ~ 4 mails / > >>> seconds ) > >>> I have checked into email syslog and it appears the attack seems > >>> distrinuted > >>> and comes from dozens of randoms servers ... > >>> > >>> I have setup a new account for the user but the attack still continues. > >>> > >>> For now I have aliased the attacked address to /dev/null but I wonder > >>> what would be the most efficient (which generate the smalest load of > >>> the server) > >>> method to refuse/discard emails for this address ? > >> > >> This could be backscatter: > >> > >> http://www.postfix.org/BACKSCATTER_README.html > >> > > > > Thank you for this link > > > > I think the problem would be elsewhere I've found a *lot* of references > > to the qmail-send program in syslog from a growing number of servers. > > > > I have now modified the alias and redirect all emails to this address > > on another isolated machine to analyse the log without disturbing our > > mailhub. > > > > let's see where doee it come from > > There's nothing to see. block the address at smtp time, as Wietse > suggested. the logs will contain enough information, so there is no need > to accept the messages. > > > -- Kelvin Smith <kelvins>
| ||||||||||||||||||||||||||||||
© 2004-2008 readlist.com