Re: Distributed Dictonary email slam

2004-09-06 Thread Jared Mauch
On Sun, Sep 05, 2004 at 07:58:06PM -0400, Christopher X. Candreva wrote: On Sun, 5 Sep 2004, Matt Hess wrote: source hosts.. Now being as we are a secondary mx I'm dropping their record out of our email system as I write this, however, I am curious if other have gone through or are

Re: Distributed Dictonary email slam

2004-09-06 Thread Christopher X. Candreva
On Mon, 6 Sep 2004, Jared Mauch wrote: does anyone have some pointers to a good (possibly radius+sendmail) based approach for checking this? I load rules into the access.db database. lines like this: To:westnet.com ERROR:5.1.1:550 User unknown To:[EMAIL PROTECTED]OK To:[EMAIL

Re: Distributed Dictonary email slam

2004-09-06 Thread Paul Jakma
On Mon, 6 Sep 2004, Jared Mauch wrote: does anyone have some pointers to a good (possibly radius+sendmail) based approach for checking this? Not RADIUS, but Sendmail can do arbitrary LDAP lookups for user-checks. See the README for the details. (and LDAP can itself be distributed, so

Re: Distributed Dictonary email slam

2004-09-05 Thread Christopher X. Candreva
On Sun, 5 Sep 2004, Matt Hess wrote: source hosts.. Now being as we are a secondary mx I'm dropping their record out of our email system as I write this, however, I am curious if other have gone through or are currently going through something of this magnitude (12K spam/dictionary msgs per

Re: Distributed Dictonary email slam

2004-09-05 Thread Barney Wolff
On Sun, Sep 05, 2004 at 03:39:50PM -0600, Matt Hess wrote: And of course a few suggestions to mitigate this would be appreciated.. I currently employ multiple blacklists such as spamcop.net, abuseat.org, spews level 1 and 2, and spamhaus, plus my own blocklists for china and korea to

Re: Distributed Dictonary email slam

2004-09-05 Thread Matt Hess
Impossible as the customer does not wish to give us a list. However, I have thought of that and created some perl foo to go through.. identify the queued junk and remove it completely from our queue .. thus no bounce and no delivery. Christopher X. Candreva wrote: On Sun, 5 Sep 2004, Matt Hess

Re: Distributed Dictonary email slam

2004-09-05 Thread Randy Bush
Impossible as the customer does not wish to give us a list. You want to keep a list of valid accounts on the secondary so you can refuse mail for non-existing accounts on the secondary too. anyway, as they say, that does not scale randy --- Q: Because it reverses the logical flow of

Re: Distributed Dictonary email slam

2004-09-05 Thread Matt Hess
I completely agree, indeed it does not.. which is why we have now dropped doing secondary mx for this domain. Anyway.. thanks to all who responded on and off list.. gave me a few good ideas to tinker with.. Probably the most notable thing from this is the technical level with which spammers