At 10:16 PM -0500 10/5/02, [EMAIL PROTECTED]  imposed 
structure on a stream of electrons, yielding:
>Checking logs tonight for another reason, I decided to take a quick 
>look through for IPs to add to my blacklist.

[snip]

>Obviously, it's a dictionary attack with spoofed IPs (is that 
>possible?) or relayed off a bunch of random servers.

More likely, pushed through a lot of different unsecured proxies. 
Open SOCKS and similar proxies are the favorite tool of spammers 
these days because they provide generally more reliable anonymity 
with more direct feedback than SMTP relays.

>How do we battle that?


It's hard. There is the opm.blitzed.org blacklist that can be used to 
reject mail from many open proxies, but that won't stop them from 
trying. you can certainly report the attacks to the relevant ISP's, 
but you can expect slow to no response there since most ISP's have 
abuse response in pure firefighting mode these days.


-- 
Bill Cole                                  
[EMAIL PROTECTED]


#############################################################
This message is sent to you because you are subscribed to
  the mailing list <[EMAIL PROTECTED]>.
To unsubscribe, E-mail to: <[EMAIL PROTECTED]>
To switch to the DIGEST mode, E-mail to <[EMAIL PROTECTED]>
To switch to the INDEX mode, E-mail to <[EMAIL PROTECTED]>
Send administrative queries to  <[EMAIL PROTECTED]>

Reply via email to