Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject: Got Email DDOS attack
PostPosted: Sat Sep 11, 2004 3:00 am 
Offline
Junior Member
User avatar

Joined: Wed Aug 13, 2003 1:25 pm
Posts: 27
Hi,

I recently noticed in my exim log that I am getting a lot of random emails sent to non existing users at my domain.

These emails are just coming from random IP and are sent to random non existing user in my domain.

My exim setup only allow relay from locahost, and reject all other relay. But I am now getting about 1-2 every 5 seconds and my reject log is jammed with those reject message.

Is there any way I can block those spoof email? I have already setup script for iptable to block access from those random hosts.

What should I do next?

Thanks.
Kevin


Top
   
 Post subject:
PostPosted: Sat Sep 11, 2004 6:49 pm 
Offline
Junior Member

Joined: Thu Jun 03, 2004 2:57 pm
Posts: 23
Unfortunately, that's par for the course these days.

See, the spammers have realized that people are not posting their email addresses. So they've been guessing usernames at any domain they can find.

So if you can figure out how to block them, you've just fixed the spam problem.. :/


Top
   
 Post subject:
PostPosted: Sun Sep 12, 2004 10:18 am 
Offline
Senior Member
User avatar

Joined: Fri Aug 15, 2003 2:15 pm
Posts: 111
Website: http://fubegra.net/
While I don't really know much about exim (I use sendmail), I'm pretty sure that you can set it up to use DNS-based IP blacklists. I make use of the SBL and XBL at Spamhaus, and they nip quite a lot of spam in the bud. The SBL covers known spam operations, and the XBL lists known "zombie" machines that send spam and email worms. I also have a local block list to which I add systems that send junk but haven't been listed in the Spamhaus lists.

_________________
Bus error (passengers dumped)


Top
   
 Post subject:
PostPosted: Sun Sep 12, 2004 3:38 pm 
Offline
Junior Member
User avatar

Joined: Wed Aug 13, 2003 1:25 pm
Posts: 27
Thanks for all the suggestions. And yes, my setup included all the possible mean of spam protection, using SBL from various sources, reject relay from anywhere other than localhost.

I guess the the question that I am still having is, is there any additional ways that I do to prevent spammer to send mail to random users on my domain. Although I am already rejecting all mail to unknow users on my host, I am trying to see if there are ways to add additional mean of protection on top of what I have had: iptables blocking, reject open relay, reject unknow user, and with the help of spamassassin.

When I am seeing on average of 1-2 emails sent to my domain's non-existing users every couple seconds or so, I am start to worrying about the server load and my bandwidth limit.

Thanks for all your help!

Regards,
Kevin


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group