> The other option is to use a "nobody" alias that would receive all the
> E-mails. This way the spammer wouldn't be able to tell the legitimate
> addresses from the bogus ones.
>
but wouldn't this catch emails that were misspelled by valid people? then
users whould never know that they had an incorrect email address.
Chris
----- Original Message -----
From: "R. Scott Perry" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Thursday, May 31, 2001 2:49 PM
Subject: Re: OSRELAY: [IMail Forum] spammers (I hate them)
> I hate 'em too.
>
> >I'm beggining to find this kind of "attack" into my logs:
> >
> >05:27 04:22 SMTPD(0904026E) [216.53.218.171] MAIL From:
> ><<mailto:[EMAIL PROTECTED]>[EMAIL PROTECTED]>
> >05:27 04:22 SMTPD(0904026E) [216.53.218.171] RCPT
> >To:<<mailto:[EMAIL PROTECTED]>[EMAIL PROTECTED]>
> >05:27 04:22 SMTPD(0904026E) [216.53.218.171] ERR mail.fis.com invalid
user
> ><<mailto:[EMAIL PROTECTED]>[EMAIL PROTECTED]
> >05:27 04:22 SMTPD(0904026E) [216.53.218.171] RCPT
> >To:<<mailto:[EMAIL PROTECTED]>[EMAIL PROTECTED]>
> >05:27 04:22 SMTPD(0904026E) [216.53.218.171] ERR mail.fis.com invalid
user
> ><<mailto:[EMAIL PROTECTED]>[EMAIL PROTECTED]
> >05:27 04:22 SMTPD(0904026E) [216.53.218.171] RCPT
> >To:<<mailto:[EMAIL PROTECTED]>[EMAIL PROTECTED]>
> >05:27 04:22 SMTPD(0904026E) [216.53.218.171] ERR mail.fis.com invalid
user
> ><<mailto:[EMAIL PROTECTED]>[EMAIL PROTECTED]
> >05:27 04:22 SMTPD(0904026E) [216.53.218.171] RCPT
> >To:<<mailto:[EMAIL PROTECTED]>[EMAIL PROTECTED]>
> >05:27 04:22 SMTPD(0904026E) [216.53.218.171] ERR mail.fis.com invalid
user
> ><<mailto:[EMAIL PROTECTED]>[EMAIL PROTECTED]
>
> This is called a "Dictionary attack". It actually isn't spam being
> sent/received. They are trying lots of usernames at your domain that they
> think are likely to exist. They are harvesting E-mail addresses from your
> site.
>
> >Is there any way to avoid this? I heard about limiting the number of
> >persons in the TO: clause. Does this work good? how should I setup that?
> >What happen if someone do this? will be rejected?
>
> You can restrict the number of recipients (to 20, for example), which
would
> slow down the attacker. However, it may also be an inconvenience for some
> of your users who like to forward E-mail to everyone they know. The
E-mail
> wouldn't be rejected, they would just have to connect again to get more
> addresses, slowing them down slightly.
>
> The other option is to use a "nobody" alias that would receive all the
> E-mails. This way the spammer wouldn't be able to tell the legitimate
> addresses from the bogus ones.
>
> -Scott
>
> Declude: Anti-spam and Anti-virus solutions for IMail.
http://www.declude.com
>
>
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>
> An Archive of this list is available at:
> http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
>
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/