"patrick keshishian" writes:
> When you speak of "misconfigured mail servers bouncing spam",
The real question in there is, what does a properly configured mail
server do with spam? My answer is, if it gets as far as content
filtering, drop it as soon as it's classified as spam, don't bounce
it. Bouncing spam is never useful, the purported return address is
extremely unlikely to be deliverable.
A bounce is only useful for valid messages (which happen to be sent to
a mistyped address), which in our context means that the message has
passed greylisting and most likely some content filtering or other.
In all likelihood you will still bounce to a few bogus ones, but
taking this approach makes you a lot less noisy.
The noise you are seeing is from sites which either don't bother much
with filtering, or if they do, belong to that little cult of "bouncing
spam is good" believers.
> - GREY list count is 342 (and growing)
Unless your spamd box is extremely skinny, none of these figures are
particularly worrying. spamd allocates IIRC about 12 kilobytes of
buffers per tarpitted host, for greylist entries just another tuple in
the database.
My list of trap addresses, all harvested from stuff from out there, is
just over 2700. Right now there are 273 hosts in the greylist at the
gateway closest to where I'm sitting (my home net, actually), with 533
in TRAPPED state.
> This is not fun :-\
Well, it should not be a huge problem. IMO people who fake addresses
in other people's domains should be prosecuted for some variety of
fraud, but with the current level of digital competence in law
enforcement that is just not going to happen. In the meantime we have
reasonable countermeasures. See what greyscanner can do for you.
- P
--
Peter N. M. Hansteen, member of the first RFC 1149 implementation team
http://bsdly.blogspot.com/ http://www.datadok.no/ http://www.nuug.no/
"Remember to set the evil bit on all malicious network traffic"
delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
| Tarkan Erimer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Bart Van Assche | Integration of SCST in the mainstream Linux kernel |
| Jeff Garzik | Re: fallocate-implementation-on-i86-x86_64-and-powerpc.patch |
git: | |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Arjan van de Ven | Re: [GIT]: Networking |
| Gerrit Renker | [PATCH 15/37] dccp: Set per-connection CCIDs via socket options |
| Natalie Protasevich | [BUG] New Kernel Bugs |
