Re: [exim] netzero forgeries?

Top Page
Delete this message
Reply to this message
Author: Heiko Schlichting
Date:  
To: B. Cook, exim-users
Subject: Re: [exim] netzero forgeries?
B. Cook wrote:
> Is anyone else being bombarded by these?


You are not the only one. Seems to be increasing over the last days. Here
are the counts of two of my servers:

$ grep -c 'H=(netzero.com)' main-200605[23]? main-200606*

Server 1            Server 2
main-20060520:230    main-20060520:1
main-20060521:5        main-20060521:0
main-20060522:2        main-20060522:0
main-20060523:0        main-20060523:2
main-20060524:0        main-20060524:0
main-20060525:0        main-20060525:0
main-20060526:0        main-20060526:0
main-20060527:0        main-20060527:0
main-20060528:0        main-20060528:0
main-20060529:0        main-20060529:0
main-20060530:0        main-20060530:0
main-20060531:0        main-20060531:0
main-20060601:7307    main-20060601:3575
main-20060602:44432    main-20060602:22149
main-20060603:11371    main-20060603:5482
main-20060604:90859    main-20060604:45453
main-20060605:108807    main-20060605:54457
main-20060606:111112    main-20060606:55805
main-20060607:289712    main-20060607:145813


As you can see, counts in May are very low but not always zero. Adjusting the
blocked names for HELO should be enough to stop this.

Heiko

Heiko Schlichting        | Freie Universität Berlin
heiko@???       | Zentraleinrichtung für Datenverarbeitung (ZEDAT)
Telefon +49 30 838-54327 | Fabeckstraße 32
Telefax +49 30 838454327 | 14195 Berlin