Re: SMTP flood + spamdb

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: misc@openbsd.org <misc@...>
Date: Tuesday, September 25, 2007 - 8:16 pm

On 26 September 2007, RW wrote:

> 1- why let it get to postfix? This is crap that spamd can deal with,

What I've been seeing here the last few weeks is somewhat
different: robots trying to determine how many connections I'll accept
concurrently. Left alone they can get to 100+ connection attempts per
second from the same IP, they go on until I'm running out of resources
and start delaying the accept(2). When that happens, only one or two
of these connections are subsequently used to try to send the crap, the
rest are closed immediately. Limiting concurrency at SMTP level seems
to actually reduce the number of bots that try that (presumably the
information that my site is way too uninteresting is propagated across
the bot net).

This has nothing to do with backscatter, but FWIW, backscatter alone
has never been a real problem with Postfix until recently. Resource
exhaustion because of insane concurrency as I described can be, and
anvil(8) is a first attempt to a solution (it's not THE solution because
it also hurts legitimate sites like Yahoo).

> Postfix would just be rejecting them and filling its logs.

Oh come on, these days you're probably rejecting > 95% of messages
anyway. :)

> As far as I'm concerned filling the logs of mailservers that are

Unfortunately the people in charge with these servers either don't
have a clue, or don't care.

Regards,

Liviu Daia

--
Dr. Liviu Daia http://www.imar.ro/~daia

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
SMTP flood + spamdb, patrick keshishian, (Sun Sep 23, 6:33 pm)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Mon Sep 24, 1:34 am)
Re: SMTP flood + spamdb, patrick keshishian, (Tue Sep 25, 3:08 am)
Re: SMTP flood + spamdb, Craig Skinner, (Tue Sep 25, 4:38 am)
Re: SMTP flood + spamdb, RW, (Tue Sep 25, 7:00 am)
Re: SMTP flood + spamdb, Liviu Daia, (Tue Sep 25, 7:14 am)
Re: SMTP flood + spamdb, RW, (Tue Sep 25, 7:17 pm)
Re: SMTP flood + spamdb, Liviu Daia, (Tue Sep 25, 8:16 pm)
Re: SMTP flood + spamdb, RW, (Wed Sep 26, 12:25 am)
Re: SMTP flood + spamdb, Craig Skinner, (Tue Sep 25, 7:40 am)
Re: SMTP flood + spamdb, RW, (Tue Sep 25, 7:04 pm)
Re: SMTP flood + spamdb, Craig Skinner, (Wed Sep 26, 4:00 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 7:18 am)
Re: SMTP flood + spamdb, Damien Miller, (Wed Sep 26, 8:45 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 9:27 am)
Re: SMTP flood + spamdb, Jeremy C. Reed, (Wed Sep 26, 9:51 am)
Re: SMTP flood + spamdb, Craig Skinner, (Wed Sep 26, 9:41 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 10:02 am)
Re: SMTP flood + spamdb, Eric Johnson, (Thu Sep 27, 5:45 am)
Re: SMTP flood + spamdb, Dave Anderson, (Wed Sep 26, 11:03 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Wed Sep 26, 11:26 am)
Re: SMTP flood + spamdb, RW, (Wed Sep 26, 6:21 pm)
Re: SMTP flood + spamdb, Stuart Henderson, (Wed Sep 26, 11:23 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Wed Sep 26, 10:54 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 1:05 pm)
Re: SMTP flood + spamdb, Rob, (Wed Sep 26, 5:03 pm)
Re: SMTP flood + spamdb, Hannah Schroeter, (Wed Sep 26, 5:33 pm)
Re: SMTP flood + spamdb, Rob, (Wed Sep 26, 5:51 pm)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Wed Sep 26, 6:17 pm)
Re: SMTP flood + spamdb, Jeremy C. Reed, (Wed Sep 26, 1:48 pm)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 2:16 pm)
Re: SMTP flood + spamdb, Bob Beck, (Wed Sep 26, 1:22 pm)
Re: SMTP flood + spamdb, Juan Miscaro, (Thu Sep 27, 12:36 pm)
Re: SMTP flood + spamdb, Bob Beck, (Thu Sep 27, 1:50 pm)
Re: SMTP flood + spamdb, Kurt Mosiejczuk, (Thu Sep 27, 2:04 pm)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 2:13 pm)
Re: SMTP flood + spamdb, Craig Skinner, (Wed Sep 26, 10:29 am)
Re: SMTP flood + spamdb, Luca Corti, (Wed Sep 26, 10:22 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 10:38 am)
Re: SMTP flood + spamdb, Luca Corti, (Wed Sep 26, 11:59 am)
Re: SMTP flood + spamdb, Liviu Daia, (Wed Sep 26, 10:48 am)
Re: SMTP flood + spamdb, Craig Skinner, (Wed Sep 26, 11:01 am)
Re: SMTP flood + spamdb, Luca Corti, (Wed Sep 26, 12:06 pm)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Wed Sep 26, 4:46 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Tue Sep 25, 7:22 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Tue Sep 25, 4:50 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Tue Sep 25, 3:38 am)
Re: SMTP flood + spamdb, Darrin Chandler, (Sun Sep 23, 8:39 pm)
Re: SMTP flood + spamdb, patrick keshishian, (Sun Sep 23, 11:53 pm)
Re: SMTP flood + spamdb, Stuart Henderson, (Mon Sep 24, 6:47 am)
Re: SMTP flood + spamdb, patrick keshishian, (Mon Sep 24, 11:01 pm)
Re: SMTP flood + spamdb, Stuart Henderson, (Tue Sep 25, 5:29 am)
Re: SMTP flood + spamdb, Stuart Henderson, (Tue Sep 25, 6:56 am)
Re: SMTP flood + spamdb, Craig Skinner, (Tue Sep 25, 7:30 am)
Re: SMTP flood + spamdb, Chris Smith, (Tue Sep 25, 10:51 am)
Re: SMTP flood + spamdb, Craig Skinner, (Wed Sep 26, 3:50 am)
Re: SMTP flood + spamdb, Peter N. M. Hansteen, (Tue Sep 25, 6:36 am)
Re: SMTP flood + spamdb, Daniel Ouellet, (Sun Sep 23, 11:58 pm)