Re: SMTP flood + spamdb

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Craig Skinner
Date: Tuesday, September 25, 2007 - 1:38 am

patrick keshishian wrote:

Read up on "backscatter spam".

This is a deliberate attack on your domain.

How it works:

A spammer uses infected home user boxes to send random mail to various 
domains, with fake random addresses in your domain as the from or 
reply-to address.

When the target domain of the initial domain does not do recipient 
validation at the smtp connection stage (as it should do), but spools 
and then rejects the mail - to you, hence you are the real target.

Greylisting is of no use whatsoever because the servers sending the 
bounces to you are actual smtp boxes (sendmail, extrange, ....), not 
malware, so they will quickly bypass spamd. Spamd greytraps will help a 
great deal, but you say that the addresses are random.


How to cope with it:

All you can do is make sure that you reject mail for unknown users at 
the smtp connection stage. You can rate limit most mail daemons so they 
don't overwhelm your box. Don't worry about it, I sometimes have up to 
1300 messages a minute hitting my PII 350 box on a 500M ADSL and can not 
tell the difference when surfing about.


How to run a mailserver:

Reject mail for unknown users at the initial smtp connection stage.

For valid users; either reject spam at the smtp connection stage, or 
spool it, process it later, tag it as spam and deliver it to the user's 
spam box - do not bounce it later as you will then be generating 
backscatter for some other poor soul.

Note: some versions of exchange can not do recipient validation at the 
smtp connection stage, so this will always be a problem, and is yet 
another reason never to have exchange as an internet facing mail server.
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
SMTP flood + spamdb, patrick keshishian, (Sun Sep 23, 3:33 pm)
Re: SMTP flood + spamdb, Darrin Chandler, (Sun Sep 23, 5:39 pm)
Re: SMTP flood + spamdb, patrick keshishian, (Sun Sep 23, 8:53 pm)
Re: SMTP flood + spamdb, Daniel Ouellet, (Sun Sep 23, 8:58 pm)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Sun Sep 23, 10:34 pm)
Re: SMTP flood + spamdb, Stuart Henderson, (Mon Sep 24, 3:47 am)
Re: SMTP flood + spamdb, patrick keshishian, (Mon Sep 24, 8:01 pm)
Re: SMTP flood + spamdb, patrick keshishian, (Tue Sep 25, 12:08 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Tue Sep 25, 12:38 am)
Re: SMTP flood + spamdb, Craig Skinner, (Tue Sep 25, 1:38 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Tue Sep 25, 1:50 am)
Re: SMTP flood + spamdb, Stuart Henderson, (Tue Sep 25, 2:29 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Tue Sep 25, 3:36 am)
Re: SMTP flood + spamdb, Stuart Henderson, (Tue Sep 25, 3:56 am)
Re: SMTP flood + spamdb, RW, (Tue Sep 25, 4:00 am)
Re: SMTP flood + spamdb, Liviu Daia, (Tue Sep 25, 4:14 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Tue Sep 25, 4:22 am)
Re: SMTP flood + spamdb, Craig Skinner, (Tue Sep 25, 4:30 am)
Re: SMTP flood + spamdb, Craig Skinner, (Tue Sep 25, 4:40 am)
Re: SMTP flood + spamdb, Chris Smith, (Tue Sep 25, 7:51 am)
Re: SMTP flood + spamdb, RW, (Tue Sep 25, 4:04 pm)
Re: SMTP flood + spamdb, RW, (Tue Sep 25, 4:17 pm)
Re: SMTP flood + spamdb, Liviu Daia, (Tue Sep 25, 5:16 pm)
Re: SMTP flood + spamdb, RW, (Tue Sep 25, 9:25 pm)
Re: SMTP flood + spamdb, Craig Skinner, (Wed Sep 26, 12:50 am)
Re: SMTP flood + spamdb, Craig Skinner, (Wed Sep 26, 1:00 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Wed Sep 26, 1:46 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 4:18 am)
Re: SMTP flood + spamdb, Damien Miller, (Wed Sep 26, 5:45 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 6:27 am)
Re: SMTP flood + spamdb, Craig Skinner, (Wed Sep 26, 6:41 am)
Re: SMTP flood + spamdb, Jeremy C. Reed, (Wed Sep 26, 6:51 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 7:02 am)
Re: SMTP flood + spamdb, Luca Corti, (Wed Sep 26, 7:22 am)
Re: SMTP flood + spamdb, Craig Skinner, (Wed Sep 26, 7:29 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 7:38 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 7:48 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Wed Sep 26, 7:54 am)
Re: SMTP flood + spamdb, Craig Skinner, (Wed Sep 26, 8:01 am)
Re: SMTP flood + spamdb, Dave Anderson, (Wed Sep 26, 8:03 am)
Re: SMTP flood + spamdb, Stuart Henderson, (Wed Sep 26, 8:23 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Wed Sep 26, 8:26 am)
Re: SMTP flood + spamdb, Luca Corti, (Wed Sep 26, 8:59 am)
Re: SMTP flood + spamdb, Luca Corti, (Wed Sep 26, 9:06 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 10:05 am)
Re: SMTP flood + spamdb, Bob Beck, (Wed Sep 26, 10:22 am)
Re: SMTP flood + spamdb, Jeremy C. Reed, (Wed Sep 26, 10:48 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 11:13 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 11:16 am)
Re: SMTP flood + spamdb, Rob, (Wed Sep 26, 2:03 pm)
Re: SMTP flood + spamdb, Hannah Schroeter, (Wed Sep 26, 2:33 pm)
Re: SMTP flood + spamdb, Rob, (Wed Sep 26, 2:51 pm)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Wed Sep 26, 3:17 pm)
Re: SMTP flood + spamdb, RW, (Wed Sep 26, 3:21 pm)
Re: SMTP flood + spamdb, Eric Johnson, (Thu Sep 27, 2:45 am)
Re: SMTP flood + spamdb, Juan Miscaro, (Thu Sep 27, 9:36 am)
Re: SMTP flood + spamdb, Bob Beck, (Thu Sep 27, 10:50 am)
Re: SMTP flood + spamdb, Kurt Mosiejczuk, (Thu Sep 27, 11:04 am)