We've been getting connections from systems that look like they're 
dictionary sniffing for names to spam.  Here's a quick snip:

10:01 10:16 SMTPD(00AB0274) [64.30.43.3] connect 194.198.208.9 port 1725
10:01 10:16 SMTPD(00AB0274) [194.198.208.9] HELO sitemail.everyone.net
10:01 10:16 SMTPD(00AB0274) [194.198.208.9] MAIL From: <[EMAIL PROTECTED]>
10:01 10:16 SMTPD(00AB0274) [194.198.208.9] RCPT To:<[EMAIL PROTECTED]>
10:01 10:16 SMTPD(00AB0274) [194.198.208.9] ERR mail.locustcreek.com 
invalid user <[EMAIL PROTECTED]
10:01 10:16 SMTPD(00AB0274) [194.198.208.9] RCPT To:<[EMAIL PROTECTED]>
10:01 10:16 SMTPD(00AB0274) [194.198.208.9] ERR mail.locustcreek.com 
invalid user <[EMAIL PROTECTED]
10:01 10:16 SMTPD(00AB0274) [194.198.208.9] RCPT To:<[EMAIL PROTECTED]>
10:01 10:16 SMTPD(00AB0274) [194.198.208.9] ERR mail.locustcreek.com 
invalid user <[EMAIL PROTECTED]
10:01 10:16 SMTPD(00AB0274) [194.198.208.9] RCPT 
To:<[EMAIL PROTECTED]>
10:01 10:16 SMTPD(00AB0274) [194.198.208.9] ERR mail.locustcreek.com 
invalid user <[EMAIL PROTECTED]
10:01 10:16 SMTPD(00AB0274) [194.198.208.9] RCPT To:<[EMAIL PROTECTED]>

Now, this is just a small sample.  They come in shots of 15-20, but it's 
every hour or so.  I can deny the IP at the router, or something, but is 
there any better way to handle this?

Oblio


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to