Re: SMTP flood + spamdb

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: patrick keshishian <pkeshish@...>
Cc: <misc@...>
Date: Monday, September 24, 2007 - 1:34 am

"patrick keshishian" writes:

> I'm running spamdb in greylist mode, but these servers were

Then it sounds almost like you were running with a too short passtime,
but then that's easy to adjust.

> At around 1:40 PM (PDT) my SMTP server started getting flooded

We've been seeing a lot of that here, too. Mostly it's a few (maybe
20) a day to the most widely known domain here, then occasionally
somebody pushes the "generate" button for too long and one domain
almost nobody actually uses gets the bouces for 700+ fake
addresses[1]. Bob Beck's greyscanner is rather effective, as is the
more manual methods I've blogged about the observations quite a bit,
starting with [2].

Short summary for those who are not too interested in blog posts: I
started seeing more than the usual amount of bounce activity in my
mail server log summaries, close enough to what you describe. So
after a bit of thinking and log browsing I decided this was generated
mainly by misconfigured mail servers bouncing spam. Then I decided I
wanted to do an experiment, to see if I could poison the well and at
the same time get a feel for the data I was collecting.

I started publishing the fake addresses on a web page[3] as well as
entering them into the list of trap addresses. I've been seeing
evidence that the addresses are actually being harvested and used as
to-be-spammed addresses too: addresses which are all uppercase on the
web page turning up in the spamd logs and greylist dumps in all
lowercase, addresses which have been on my flypaper list for months
turn up all the time, and we see a steadily growing number of hosts in
TRAPPED state.

My users here are not getting any more spam than they used to (as
close as does not matter to none), false positives are pretty much an
unknown, and it looks like we're succeeding in making the spammers
work harder.

[1] http://bsdly.blogspot.com/2007/08/lady-in-distress-or-then-again-maybe.html
[2] http://bsdly.blogspot.com/2007/07/hey-spammer-heres-list-for-you.html
[3] http://www.bsdly.net/~peter/traplist.html

--
Peter N. M. Hansteen, member of the first RFC 1149 implementation team
http://bsdly.blogspot.com/ http://www.datadok.no/ http://www.nuug.no/
"Remember to set the evil bit on all malicious network traffic"
delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
SMTP flood + spamdb, patrick keshishian, (Sun Sep 23, 6:33 pm)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Mon Sep 24, 1:34 am)
Re: SMTP flood + spamdb, patrick keshishian, (Tue Sep 25, 3:08 am)
Re: SMTP flood + spamdb, Craig Skinner, (Tue Sep 25, 4:38 am)
Re: SMTP flood + spamdb, RW, (Tue Sep 25, 7:00 am)
Re: SMTP flood + spamdb, Liviu Daia, (Tue Sep 25, 7:14 am)
Re: SMTP flood + spamdb, RW, (Tue Sep 25, 7:17 pm)
Re: SMTP flood + spamdb, Liviu Daia, (Tue Sep 25, 8:16 pm)
Re: SMTP flood + spamdb, RW, (Wed Sep 26, 12:25 am)
Re: SMTP flood + spamdb, Craig Skinner, (Tue Sep 25, 7:40 am)
Re: SMTP flood + spamdb, RW, (Tue Sep 25, 7:04 pm)
Re: SMTP flood + spamdb, Craig Skinner, (Wed Sep 26, 4:00 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 7:18 am)
Re: SMTP flood + spamdb, Damien Miller, (Wed Sep 26, 8:45 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 9:27 am)
Re: SMTP flood + spamdb, Jeremy C. Reed, (Wed Sep 26, 9:51 am)
Re: SMTP flood + spamdb, Craig Skinner, (Wed Sep 26, 9:41 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 10:02 am)
Re: SMTP flood + spamdb, Eric Johnson, (Thu Sep 27, 5:45 am)
Re: SMTP flood + spamdb, Dave Anderson, (Wed Sep 26, 11:03 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Wed Sep 26, 11:26 am)
Re: SMTP flood + spamdb, RW, (Wed Sep 26, 6:21 pm)
Re: SMTP flood + spamdb, Stuart Henderson, (Wed Sep 26, 11:23 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Wed Sep 26, 10:54 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 1:05 pm)
Re: SMTP flood + spamdb, Rob, (Wed Sep 26, 5:03 pm)
Re: SMTP flood + spamdb, Hannah Schroeter, (Wed Sep 26, 5:33 pm)
Re: SMTP flood + spamdb, Rob, (Wed Sep 26, 5:51 pm)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Wed Sep 26, 6:17 pm)
Re: SMTP flood + spamdb, Jeremy C. Reed, (Wed Sep 26, 1:48 pm)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 2:16 pm)
Re: SMTP flood + spamdb, Bob Beck, (Wed Sep 26, 1:22 pm)
Re: SMTP flood + spamdb, Juan Miscaro, (Thu Sep 27, 12:36 pm)
Re: SMTP flood + spamdb, Bob Beck, (Thu Sep 27, 1:50 pm)
Re: SMTP flood + spamdb, Kurt Mosiejczuk, (Thu Sep 27, 2:04 pm)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 2:13 pm)
Re: SMTP flood + spamdb, Craig Skinner, (Wed Sep 26, 10:29 am)
Re: SMTP flood + spamdb, Luca Corti, (Wed Sep 26, 10:22 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 10:38 am)
Re: SMTP flood + spamdb, Luca Corti, (Wed Sep 26, 11:59 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 10:48 am)
Re: SMTP flood + spamdb, Craig Skinner, (Wed Sep 26, 11:01 am)
Re: SMTP flood + spamdb, Luca Corti, (Wed Sep 26, 12:06 pm)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Wed Sep 26, 4:46 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Tue Sep 25, 7:22 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Tue Sep 25, 4:50 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Tue Sep 25, 3:38 am)
Re: SMTP flood + spamdb, Darrin Chandler, (Sun Sep 23, 8:39 pm)
Re: SMTP flood + spamdb, patrick keshishian, (Sun Sep 23, 11:53 pm)
Re: SMTP flood + spamdb, Stuart Henderson, (Mon Sep 24, 6:47 am)
Re: SMTP flood + spamdb, patrick keshishian, (Mon Sep 24, 11:01 pm)
Re: SMTP flood + spamdb, Stuart Henderson, (Tue Sep 25, 5:29 am)
Re: SMTP flood + spamdb, Stuart Henderson, (Tue Sep 25, 6:56 am)
Re: SMTP flood + spamdb, Craig Skinner, (Tue Sep 25, 7:30 am)
Re: SMTP flood + spamdb, Chris Smith, (Tue Sep 25, 10:51 am)
Re: SMTP flood + spamdb, Craig Skinner, (Wed Sep 26, 3:50 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Tue Sep 25, 6:36 am)
Re: SMTP flood + spamdb, Daniel Ouellet, (Sun Sep 23, 11:58 pm)