Hi there
One one of our servers, the exim_mainlog is littered with these messages which I suspect is an attempt to buffer-overflow exim. There are too many source IPs to practically block. Any ideas how to filter these out?
Best
Dude
One one of our servers, the exim_mainlog is littered with these messages which I suspect is an attempt to buffer-overflow exim. There are too many source IPs to practically block. Any ideas how to filter these out?
Code:
2013-04-15 14:14:36 [22631] SMTP syntax error in "\373\315\243\302\fq<\003\2618C\215\274\231\307\225]L\307\017\271\227\310\321ugELO|\311\204\200G\312\001\207g?\363\272\200A7\323\373G\212\266]\313\377L\226A`J\301\314\001?\363\315\372=r\316\265\b$\317mLHF\334s\231\317\203;\264E\217n\005\321\251:\214F\021kWGSZ\206\322\265\314\025H\341\313\231\323r\300\313\324\234%d\325\034\276\311\325\341g\007MT%\300\340K\365`\326Y\365?N\035\215\345N\254\256\223\330\222\354\333\330\320\257\301\331\021\[email protected]\332\266F*\333lA#\334\267K\020S%\216\250S\017H\016Tz\305#Z\361\264\024Q\242r\020\337\252=\352\336\337\325\242T:~\316\337\224\224\261\341\326\256\352X\215\356\230\342\364#\345\342\354\214\255\343\2461\233ZB\222\370\343\203\220\273I'\376ZJU\374\336S\341"\263\346\274\022\335\346dF\250\347\301\255\357\350q\036\020`\032\345\206\351u\257|O\031\035\034PG\033\240Y\271uA\354\331h\241\354\240\332\200\354\377t\273\354\232\215\003jNf\227\356\207\374{\357\021b\024\360I\2458gq\314" H=[95.77.252.179]:51242 I=[195.238.172.81]:25 NULL character(s) present (shown as '?')
Dude