Re: [exim] Preventing exim DoS attacks

Top Page
Delete this message
Reply to this message
Author: Patrick von der Hagen
Date:  
To: exim-users@exim.org
Subject: Re: [exim] Preventing exim DoS attacks
Hi Soumya,

your replied off-list with lots of details, but none of them convincing
me that you are really under attack. Snippets of your configuration are
not the priority, people will be way more likely to offer good advice if
you tell them what is actually happening on your system.

What are those "attackers" doing? Are they sending messages? Do they
just keep connections alive without every sending messages? Do they send
messages to non-existent recipients and your box is busy sending replies?

So, I guess some output of "exiwhat" would be interesting as well as
samples from your log related to "attackers".

On 09.06.2015 16:02, Patrick von der Hagen wrote:
> On 09.06.2015 12:15, soumya tr wrote:
>> Hi,
>>
>> Any one have tips on preventing DoS attacks on port 25?
> Are you just worried there might be a DoS attack in the future or do you
> believe you are under attack right now?
>
> I got the feeling that most people asking on this list about DoS usually
> suffer from some severe misconfiguration (open relay, etc.) and
> misinterpret the situation. So providing some explanation or logs would
> be the right thing to do (tm).
>
>
>


--
Karlsruher Institut für Technologie (KIT)
Steinbuch Centre for Computing (SCC)

Patrick von der Hagen

Zirkel 2, Gebäude 20.21, Raum 004.2
76131 Karlsruhe
Telefon: +49 721 608-46433
E-Mail: hagen@???
Web: http://www.scc.kit.edu

KIT - Universität des Landes Baden-Württemberg und
nationales Forschungszentrum in der Helmholtz-Gemeinschaft