Ok Sandy, hope this explains it better...
    This person or persons, using [EMAIL PROTECTED] name changes each time, and
tries sending mail to certain addresses NOT hosted by us, below is an
example from this morning ARGH!

01:22 01:21 SMTPD(272F00D8) [80.24.134.146] MAIL From: <[EMAIL PROTECTED]>
01:22 01:21 SMTPD(272F00D8) [80.24.134.146] RCPT
To:<[EMAIL PROTECTED]>
01:22 01:21 SMTPD(272F00D8) [80.24.134.146] ERR mail.2khiway.net invalid
user <[EMAIL PROTECTED]

Seems he's always trying to send to @crossroadsapplctr.com, and @cwsins.com,
both which I've never heard of. As I said before, the name after john@
changes, as does the IP address he sends from. This one WHOISes back to
Spain.

Any ideas? Is there even anything I can DO that I haven't already? <listing
the address in my kill file and IP in the access list>

Paul


> Well,  is that a domain that you host? That'll tell you whether it's a
> local dictionary attack or a remote relay attempt.
>
> -Sandy


---
[This E-mail scanned for viruses by Declude Virus]


To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html
List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/

Reply via email to