Re: [Exim] Columbian Spammer

Góra strony
Delete this message
Reply to this message
Autor: Wakko Warner
Data:  
Dla: will
CC: Exim-Users (E-mail)
Temat: Re: [Exim] Columbian Spammer
> > Where would be the best place to put an acl that would simply disconnect
> > them every time they tried to connect to our site?
>
> (Sorry about sending this again Ron, I got caught by the gimpy reply-to
> settings on the list ;-) )
>
> I saw this with a customers server a couple of years ago. We put in
> iptables rules to drop the packets for connections from their IP range
> (they seemed to use a few IP's assigned to a brazilian ISP) to port 25.
> The continued to attempt to make connections for months despite this.
> Obviously an automated attack.


How did you set up the rule? Did you just drop the packet or did you return
tcp reset?

--
Lab tests show that use of micro$oft causes cancer in lab animals