Hi there,

On Fri, 27 May 2005 Pablo Alsina wrote:

> We added a sort of tarpitting solution to our sendmail...
> clamav-milter seems to be suffering. What happens is that the
> maximum number of childs are reached in a 2-4 hour period

People with far more experience than I tell me that this isn't the
way.  Don't forget that sendmail can deal with mail using relatively
far less resource consumption than ClamAv, because it doesn't have to
scan each mail body for thousands of signatures the way that ClamAv
does.  You could hand the offending connections to another MTA that
doesn't use the ClamAv milter of course but you'll always risk running
out of resources before the spammers do anyway - many of them run 500+
threads per machine, they probably won't notice your tarpit.

Perhaps it's better to use a firewalling technique instead of a tarpit?

73,
Ged.
_______________________________________________
http://lurker.clamav.net/list/clamav-users.html

Reply via email to