Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 14 Dec 1998 14:18:28 -0600
From:      George Wenzel <gee2@realtime.net>
To:        Alan Batie <batie@rdrop.com>
Cc:        freebsd-isp@FreeBSD.ORG
Subject:   Re: sendmail morons
Message-ID:  <36757294.4116@realtime.net>
References:  <Pine.BSF.4.05.9812131529240.4741-100000@odyssey.apana.org.au> <Pine.BSF.4.01.9812131835450.4706-100000@velvet.sensation.net.au> <19981213000812.44548@rdrop.com>

next in thread | previous in thread | raw e-mail | index | archive | help
Alan Batie wrote:
> 
> On Sun, Dec 13, 1998 at 06:43:50PM +1100, Rowan Crowe wrote:
> > Also, adding in IPs requires periodic review of the database by a human.
> 
> Since the offending address changes every time (at least in my case),
> what I want is a limit on the number of simultaneous connections from
> the same domain.  These things fill up memory until the whole system
> is paging.  Until then, I'm going to have script something to implement
> such a restriction.
> 
I put up a new mail firewall (www.mailshield.com) and saw something
very troubling in my logs as they flew by in real-time.

I was seeing a pattern where I would reject a message from a specific
ip (a UUNET or PSI dialup IP address for example). Then the SAME
rejection pattern would occur again 1/4th of a second later on
another IP address (another dialup IP, this time from a different ISP).
THEN another and another...  Over a 2 second period the same message
would attempt to get delivered 8 different times by 8 dialup IP
addresses on 8 different ISP's.  Then 20 minutes later the pattern
would come again, from a NEW set of 8 IP addresses.

Now these are some serious spam-bots running.  They hammer /hard/
when they hammer.  This year I went from a level of comfort to
24/7 overload, over a three week period starting in mid November.
The holiday season is bringing out a new crop of spammers, only
now they are better armed.  I replaced my mail server with something
running smarter software, and with the Mailshield product I'm starting
to think I might get to stop wrestling with mail long enough to have
a holiday myself!

Previous attempts to firewall using perimeter MXing caused the problem
to get worse when our mailqueues were clogging with undeliverable 
bounce messages.  Mailshield pushes unknown user rejections to the edge
of your mail network, allowing you to keep the responsibility of
bounce processing limited to the sending mail server.  In the short time
we have been running Mailshield it has made the difference between a
server that is useless, and a server that has room to grow by
almost an order of magnatude.



George
Death to spam!

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-isp" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?36757294.4116>