Hi,
I believe one of my servers is being attacked through one of my customers e-mail. Someone is basically sending e-mails to random accounts at his domain from random e-mail accounts from somewhere else. Each of their messages is coming from a unique e-mail address and a unique IP address.
Now, we have some MailScanner installed and their dictionary ACL installed. So we are blocking tons of IP addresses, but they keep coming at us with new ones. We also have his default acocunt set to "fail:", however, they are hitting the server so hard that it doesn’t seem to be making any difference. They are basically taking this server offline with so many connections.
I tried suspending his account, but that doesn't seem to make a difference either.
Here is a quick snapshot of my exim_mainlog. I am seeing basically blocks like this every second:
2007-02-19 12:41:07 H=ns33.hostinglmi.net [213.194.149.236] F=<> rejected RCPT <emineralogy@hisdomain.com.com>: no such address here
2007-02-19 12:41:07 H=colo.ir.miami.edu [129.171.4.15] F=<> rejected RCPT <voceanographer@hisdomain.com.com >: no such address here
2007-02-19 12:41:07 H=mail.flexfab.com (pecan.fhi-domain.com) [12.106.149.18] F=<dswoope@flexfab.com> rejected RCPT <qomquebec@ hisdomain.com.com>: no such address here
2007-02-19 12:41:08 H=ns1.consolemul.com (consolemul.com) [82.138.68.46] F=<> rejected RCPT <pqnorm@hisdomain.com.com >: no such address here
2007-02-19 12:41:08 H=mail.congreso.net [66.153.39.114] F=<> rejected RCPT <cbnuzzle@ hisdomain.com.com >: no such address here
2007-02-19 12:41:09 H=cotterpin.hosts.net.nz [210.48.108.203] U=Debian-exim F=<> rejected RCPT <nrhangmen@hisdomain.com.com >: no such address here
I don't know what to do next, and I was wondering if anyone had any suggestions?



LinkBack URL
About LinkBacks
Reply With Quote





