Qmail
[Top] [All Lists]

Re: Distributed spam attack.

To: qmail <qmail@list.cr.yp.to>
Subject: Re: Distributed spam attack.
From: Matt <mlist@cmcflex.com>
Date: Thu, 30 Nov 2006 07:18:20 -0700
Delivered-to: sp-com-lists@consult.net
Delivered-to: gmail-qmail@securepoint.com
Delivered-to: sp.com.list@gmail.com
Delivered-to: mailing list qmail@list.cr.yp.to
In-reply-to: <20061130005826.GZ22989@leo.org>
Mailing-list: contact qmail-help@list.cr.yp.to; run by ezmlm
References: <1164808174.22680.10.camel@mtice-ubuntu> <67F36B02-00A3-426C-9A69-51B734BA0035@adamstudios.com> <1164829385.774.TMDA@oaksage.dyndns.org> <40B54F0A-3D80-4AF3-B533-BC96B2184D1D@adamstudios.com> <20061130005826.GZ22989@leo.org>
First, thanks everyone for your replies - they were very insightful.

The attack was just as Randy said:
        >the spam "attack" i experienced was like so:
        
        >tens of thousands of mailservers from all over the world in all
        >kinds  
        >of ip ranges were bouncing spam mails to my server. most of
        the  
        >bounces i looked at were "no such user", "we don't accept
        spam", >etc.

The setup is this: A patched qmail using John's combined patch (which
includes the previously mentioned validcrptto patch).  rblsmtpd,
qmail-scanner with spamassassin and clamd.  I modified the environment
variable for the validrcptto to drop smtp connection after two
unsuccessful validrcptto deliveries.

I agree with Randy's post.  I don't think greylisting would have helped.
Since Nov 23, there were 41,000 unique sending IP's. I feel the system
was taxed the same/less than would have been utilizing a greylist.
However, if someone thinks otherwise please let me know.

I only host about 200 domains, but the clients are financial
institutions so I don't know that I want to block whole countries from
connecting.

I think the most fitting solution is to create a secondary vanilla qmail
machine and change the MX record for that domain, that way I don't get
5000 calls of "is the mail server down?".

John, your patches work great but I'm not using your run script - I'll
have to check it out.

Again, thanks everyone for your suggestions and help.

Matt


<Prev in Thread] Current Thread [Next in Thread>